pik.li pik.li

Legal

Privacy policy

This notice, provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), explains which personal data pik.li processes, why, on what legal basis, for how long, to whom it is disclosed and what rights you have. It applies to everyone who uses pik.li: visitors to the website, account holders, people who open a short link and anyone who writes to us.

Last updated: September 24, 2026 · Version 2026-09-24

This text is published in nine languages. The Italian version is authoritative: the others are translations provided for convenience and, in the event of any discrepancy, the Italian version prevails.

In short

  • The controller is InCloud S.r.l. Data is hosted on servers at infrastructure providers (Hetzner, Vultr, DigitalOcean, Contabo, Microsoft Azure, Amazon Web Services) and at InCloud's premises in Vignola; traffic passes through Cloudflare's network for security.
  • When someone opens a short link, we never store their IP address in clear text: only a hash computed with a key that changes every day, plus country, estimated city, device and referring page.
  • For account logins, on the other hand, we record the full IP address: it is used to protect you against account theft and may be disclosed to the authorities.
  • If you close your account, the data is kept for 6 months and then deleted; invoices and payments are kept for 10 years, as the law requires.
  • We disclose data to the competent authorities when the law requires or allows us to do so. We do not sell data and we do not use it to train artificial intelligence models.
  • You can access your data, download it, correct it, object to its processing and request its erasure; you can lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority).

This summary is only meant to help you find your way; the full text below is what applies.

1.Controller and contact details

The controller is InCloud S.r.l., whose details are given below: it decides why and how the data described in this notice is processed.

We have not appointed a data protection officer (DPO). For any question about your data, or to exercise your rights, write to the data protection contact given below: we reply within one month.

Company
InCloud S.r.l.
VAT number and tax code
IT04209270364
Registered office
Via Unità d'Italia 135, 41058 Vignola (MO), Italy
Certified e-mail (PEC)
[email protected]
Data protection contact
[email protected]
Abuse reports
[email protected]
Requests from authorities
[email protected]

2.Who this notice is for

  • Visitors to pik.li: people who browse the website, the pricing page, the link checker or the documentation.
  • Account holders: people who register, create links and, if they wish, purchase a plan or a domain.
  • Link visitors: people who open a short link and are redirected to the destination. They do not need an account and are often unfamiliar with pik.li: for them, this notice serves as the information notice under Article 14 of the GDPR.
  • People who contact us: those who report a link, submit an appeal, open a support request or write to us as an authority.

For link statistics, InCloud is the controller: we decide how click data is collected, pseudonymised and deleted, and the link owner sees only pseudonymous and aggregated data. Business customers who need a data processing agreement for their own obligations can ask us for one.

3.What data we process, why and for how long

The table lists each category of data, the purpose, the legal basis under the GDPR and the retention period.

Account: e-mail address, username, password (stored only as a hash), any recovery e-mail, language and theme, account status, plan, limits or measures decided by our staff, dates of registration, confirmation and last activity, version of the terms accepted and date of acceptance.

PurposeCreating and managing the account, sending you the confirmation e-mail and service notices, applying the plan limits, proving acceptance of the terms.

Legal basisPerformance of the contract (Article 6(1)(b) GDPR); for proof of acceptance of the terms, legitimate interest (point (f)).

RetentionFor the entire life of the account. If you request deletion, the account remains pending deletion for 6 months, deactivated but with the data retained, and is then permanently deleted.

Two-step verification: the secret seed (encrypted), the hashes of the recovery codes and the time the last code was used.

PurposeProtecting access to your account, if you turn on two-step verification.

Legal basisContract (point (b)) and legitimate interest in security (point (f)).

RetentionAs long as two-step verification is on: when you turn it off, the seed and the codes are deleted.

Login sessions: full IP address, country and city estimated from the address, browser, operating system, device type, start date and date of last activity of each open login.

PurposeKeeping you logged in, showing you your open sessions so that you can close them, detecting unauthorised access, responding to requests from authorities.

Legal basisContract (point (b)) and legitimate interest in the security of your account and of the Service (point (f)).

RetentionAs long as the session is open: we delete it when you log out, when you close it from Settings → Security or when our staff closes it. The login cookie expires after 14 days at the latest; a session that is never logged out of remains recorded until the account is permanently deleted.

Activity log: significant actions on accounts and links (logins, password changes, changes of destination, links disabled or deleted, settings changed, data exported, payments, actions by our staff), with date, author and, where recorded, IP address.

PurposeSecurity, proof of the decisions taken, history of link changes, oversight of our staff's actions, responding to authorities.

Legal basisLegitimate interest (point (f)); legal obligation where logging is required (point (c)).

RetentionFor the entire life of the account and until it is permanently deleted.

Billing data: first name and surname, address, country and, for businesses, company name, VAT number (with the result of the check in the European VIES system), tax code, PEC, recipient code and telephone number.

PurposeCalculating the correct tax, issuing invoices and receipts, fulfilling tax and accounting obligations.

Legal basisLegal obligation (point (c)) and contract (point (b)).

RetentionIn your profile, for as long as you have the account. The data shown on invoices and receipts is kept for 10 years from issue, as required by tax and civil law (Article 2220 of the Italian Civil Code), even after the account has been deleted.

Payments and orders: provider used, transaction reference, amount, fee, tax, date, status, any refund requests with reason and outcome. We do not see or store card numbers, PayPal credentials or wallet keys: the provider handles them.

PurposeActivating plans and orders, reconciling payments received, handling refunds, disputes and fraud.

Legal basisContract (point (b)) and legal obligation (point (c)).

Retention10 years, together with the accounting records.

Domains: names of the custom domains you connect or purchase, DNS records, verification status and, for purchases, order data and registration and expiry dates.

PurposeServing your links on your domain, registering and managing purchased domains.

Legal basisContract (point (b)).

RetentionAs long as the domain remains connected to the account; purchase order data follows the “Payments and orders” row.

Link clicks (visitor data): date and time, a public identifier of the click, a hash of the IP address and a hash of IP address and browser (to count unique visitors), country, region and city estimated from the address, device type, browser and operating system, browser language, referring page, user-agent string, originating network (ASN), an indication of whether the visit appears to be automated.

PurposeStatistics for the link owner; detection of automated traffic and abuse; responding to authorities.

Legal basisLegitimate interest (point (f)) of link owners in measuring the use of their links and of InCloud in protecting the Service, with pseudonymisation as a safeguard: the IP address is never stored in clear text, but is turned into a hash with a secret key that changes every day and is destroyed within two days, so that the address cannot be traced back from the hash.

RetentionDepends on the plan of the link owner: Base 90 days, Premium 730 days, Business 1095 days. An automated process deletes older clicks every night. Files exported by the owner remain available for download for 7 days.

Reports and appeals: the link concerned, the reason, the details you write, your e-mail address if you provide it, your account if you are logged in, our decision and who took it.

PurposeHandling reports of illegal or harmful content, appeals and complaints as required by the Digital Services Act; responding to authorities.

Legal basisLegal obligation (point (c)) and legitimate interest (point (f)).

RetentionAs long as the reported link exists, and therefore at the latest until the permanent deletion of the account that created it.

Support requests: the tickets you open from the Support section of the user area (subject, messages, attached images, status, replies from our staff) and the messages you send us by e-mail. Attached images are re-encoded and saved without the metadata of the original file, such as GPS location, device model or date taken.

PurposeReplying to you, solving the problem and keeping track of requests.

Legal basisContract, when the request concerns your account or a purchase (point (b)); otherwise, legitimate interest in replying (point (f)).

Retention24 months from the closure of the ticket or from the last message, after which they are deleted; in any case they are deleted upon permanent deletion of the account, unless they are needed for an ongoing dispute.

Notifications: the notices we show you under the bell icon and those intended for our staff (for example new sign-ups, logins, password changes, orders, links created or disabled, click thresholds reached), which contain the e-mail address or name of the account and, for logins, the browser and IP address. Some staff notices are also delivered via WhatsApp to the administrator's phone.

PurposeKeeping you informed about what happens to your account; enabling our staff to notice abuse, suspicious logins and orders quickly.

Legal basisContract (point (b)) and legitimate interest in the security and management of the Service (point (f)).

RetentionUnder the bell icon: 60 days if read, 240 days if unread. WhatsApp messages remain on the administrator's phone until they are deleted.

API keys and webhooks: name and prefix of the key, a hash and an encrypted copy of the key, date of last use, number of requests; webhook addresses, secrets and delivery logs.

PurposeAuthenticating API calls and sending events to your systems.

Legal basisContract (point (b)).

RetentionUntil you revoke the key or delete the webhook, and at the latest until the account is permanently deleted; delivery logs follow the webhook.

Requests from authorities: the request or order received, details of the authority and of its officials, the checks carried out, the data disclosed and the dates.

PurposeResponding to authorities, demonstrating that we acted in accordance with the law, keeping the register of orders.

Legal basisLegal obligation (point (c)); legitimate interest in documenting our actions (point (f)).

Retention5 years from the closure of the request, unless different periods are specified by the authority or are necessary to defend ourselves in legal proceedings.

We do not send newsletters or marketing communications. The e-mails you receive are service messages: confirmation of your address, password reset, tax documents and notices about your account or your links.

We do not use your data to train artificial intelligence models and we do not sell it.

4.Where the data comes from

  • From you: what you write in forms, the links you create, the messages and attachments you send us.
  • From your device: with every request, the browser sends technical data (IP address, user-agent, language, referring page).
  • From Cloudflare and from a geolocation database installed on our servers: country, region, city and network estimated from the IP address. The database lookup takes place on our servers and the address is not sent to anyone.
  • From payment providers: the outcome of a payment and its reference, never the payment instrument.
  • From the European Commission's VIES system: the result of the check on a business's VAT number.
  • From threat lists and from our artificial intelligence system: verdicts on destinations, which concern the linked pages and not the people who create or open the links.
  • From authorities: the requests and orders they send us.

5.Automated checks on links and artificial intelligence

Every destination is checked automatically: fast rules at creation, then, within about ten minutes, a comparison with the threat lists Google Safe Browsing and URLhaus by abuse.ch and an assessment by an artificial intelligence system that InCloud operates on its own servers in Italy: no external artificial intelligence provider receives the links or the data. The system receives the destination address, the link title and some technical signals, and returns a risk score, a category and a short explanation. It does not receive your name, your e-mail or any other account data, and it is not trained on your data.

The score concerns the destination page, not you as a person: we do not profile people. However, a link may be disabled automatically, without human intervention, when a threat list flags it or when the score exceeds our threshold with high confidence. This is an automated decision that affects your use of the Service; it is necessary for performing the contract and protecting visitors (Article 22(2)(a) GDPR).

Your safeguards: you always see the reason in your user area; you can appeal from the link's page and a person reviews the decision within two working days; you can express your point of view and contest the decision by writing to us; our staff can overturn automatic blocks at any time. Measures on accounts, such as blocks and closures, are always decided by a person.

6.Who we disclose data to

We disclose data only to those who help us run the Service (processors, bound by a contract under Article 28 GDPR), to providers that process data as independent controllers when you use their services (for example payment providers) and to authorities when the law requires or allows it.

InCloud S.r.l.

What it does and what it receivesAuthorised InCloud staff, bound by confidentiality. Access is limited to what each role needs, and significant actions, including accessing an account as if one were its holder, are logged.

Location and safeguardsItaly.

Hetzner Online GmbH · The Constant Company, LLC (Vultr) · DigitalOcean, LLC · Contabo GmbH · Microsoft Ireland Operations Ltd (Azure) · Amazon Web Services EMEA SARL (AWS) · InCloud S.r.l. (Vignola)

What it does and what it receivesInfrastructure providers: the servers on which pik.li, its databases and its services run, including the mail server, are located at these providers and at the premises of InCloud S.r.l. in Vignola (MO). The providers process data only on our behalf, as processors.

Location and safeguardsThe location depends on each provider's data centre; InCloud's premises are in Italy. For providers whose parent company is in the USA (Vultr, DigitalOcean, Microsoft and Amazon), see the section on transfers.

Prompter (InCloud AI service)

What it does and what it receivesThe artificial intelligence system that assesses destinations. It runs on InCloud's servers in Italy, is part of InCloud's infrastructure and is not a third party: no external artificial intelligence provider receives the links or the data.

Location and safeguardsItaly.

Cloudflare, Inc.

What it does and what it receivesNetwork, DNS and security in front of pik.li, the link domains and customers' domains: it sees the traffic, including IP addresses, and derives the approximate location of visitors.

Location and safeguardsUSA, with a global network that includes data centres in the EU. EU-US Data Privacy Framework certification and standard contractual clauses in its data processing agreement.

Google LLC — Safe Browsing

What it does and what it receivesSafe Browsing: receives the destination addresses of links in order to compare them against its threat lists. It receives no data about you.

Location and safeguardsUSA. EU-US Data Privacy Framework certification.

Google LLC — reCAPTCHA

What it does and what it receivesreCAPTCHA on the login, registration, password recovery, report and link creation forms: receives the IP address, technical data about the browser and information about interaction with the page, in order to distinguish people from automated programs.

Location and safeguardsUSA. EU-US Data Privacy Framework certification.

abuse.ch — URLhaus

What it does and what it receivesURLhaus: receives the host names of destinations in order to compare them against its list of sites that distribute malware.

Location and safeguardsSwitzerland (adequacy decision of the European Commission).

InCloud mail server (mail.abcomputer.eu · Vultr)

What it does and what it receivesInCloud's outgoing mail server, hosted at Vultr: receives the e-mail address and the content of service e-mails, tax documents and notices.

Location and safeguardsInCloud server at Vultr; for the transfer, see the section on transfers.

WhatsApp Ireland Ltd. (Meta)

What it does and what it receivesDelivers to the administrator's phone, through InCloud's internal sending system, some of the staff notices described in the “Notifications” row, which may contain the e-mail address or name of an account, the destination of a link and the browser used for a login. We do not send WhatsApp messages to customers.

Location and safeguardsIreland (EU), with possible transfers to the USA covered by the EU-US Data Privacy Framework.

PayPal (Europe) S.à r.l. et Cie, S.C.A.

What it does and what it receivesPayments: you pay on PayPal's website, which receives the order reference, the amount and a description and handles refunds. It is an independent controller for the payment.

Location and safeguardsLuxembourg (EU).

NOWPayments

What it does and what it receivesCryptocurrency payments, when enabled: receives the order reference, the amount and a description. It is an independent controller for the payment.

Location and safeguardsOutside the EU: the transfer is necessary to carry out the payment you choose (Article 49(1)(b) GDPR).

Internet.bs Corp.

What it does and what it receivesRegistrar of the domains we operate and of those you purchase through pik.li: receives the domain name (which may contain a person's name, if you choose it that way) and InCloud's contact details, not yours.

Location and safeguardsBahamas, a country without an adequacy decision: the transfer of the domain name alone is necessary for performing the contract you ask us for (Article 49(1)(b) GDPR).

komoot GmbH — Photon

What it does and what it receivesAddress suggestions while you fill in your billing details: receives from our server the text you are typing and the country selected, not your IP address.

Location and safeguardsGermany (EU).

European Commission — VIES

What it does and what it receivesChecking businesses' VAT numbers: receives the VAT number and the country.

Location and safeguardsEU.

What it does and what it receivesJudicial authorities, law enforcement agencies and other competent authorities, when the law requires or allows it, as explained in the “Disclosure of data to authorities” section.

Location and safeguardsItaly and the EU; outside the EU only through the cooperation channels provided for by law.

What it does and what it receivesAccountants, lawyers and auditors, for invoices, disputes and legal obligations, bound by professional secrecy or by a confidentiality agreement.

Location and safeguardsItaly.

7.Transfers outside the European Union

The servers hosting pik.li are located at the infrastructure providers listed in the table (Hetzner, Vultr, DigitalOcean, Contabo, Microsoft Azure and Amazon Web Services) and at the premises of InCloud S.r.l. in Vignola. For providers whose parent company is in the United States (Vultr, DigitalOcean, Microsoft and Amazon), any transfer of data outside the EU, if it takes place, is covered by the EU-US Data Privacy Framework for certified companies and in any case by the standard contractual clauses approved by the European Commission. The other transfers outside the EU are those shown in the table: Cloudflare and Google (USA), WhatsApp (possible transfers to the USA), abuse.ch (Switzerland), NOWPayments for cryptocurrency payments and, for the domain name only, Internet.bs (Bahamas).

For the USA we rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework, for certified providers, and on the standard contractual clauses approved by the Commission (Article 46(2)(c) GDPR) included in the providers' agreements. Switzerland is covered by an adequacy decision. The transfer of the domain name to the Bahamas is based on Article 49(1)(b) GDPR. You can ask us for a copy of the safeguards.

8.How long we keep data

The retention period for each category is shown in the table. The general rules are as follows:

  • Link clicks: according to the link owner's plan, with automatic deletion every night.
  • Closed account: remains “pending deletion” for 6 months, deactivated and with its links disabled, and is then permanently deleted together with the associated data.
  • Invoices, receipts and payments: 10 years, even after the account has been deleted.
  • Statistics export files: 7 days.
  • Notifications under the bell icon: 60 days if read, 240 days if unread.
  • Technical server logs: 30 days. Backup copies: 30 days, after which deleted data also disappears from the backups.

The 6 months after the deletion request balance your right to erasure against two needs: establishing, exercising or defending legal claims, for example when abuse committed with your links is discovered after closure, and complying with legal obligations, including requests from authorities (Article 17(3)(b) and (e) GDPR). During that period the data is only stored and protected, and is not used for anything else.

If an authority asks us to preserve specific data, we keep it for the time requested, even beyond these periods. On expiry, the data is deleted or anonymised.

9.Disclosure of data to authorities

We disclose personal data to judicial authorities, law enforcement agencies and other competent authorities when the law requires or allows us to do so: to comply with an order or a binding request (Article 6(1)(c) GDPR); to protect the life or physical safety of a person in an emergency (point (d)); within the limits of the law, for our legitimate interest and that of the public in preventing and prosecuting abuse and crimes committed through the Service (point (f)).

The data that may be disclosed is the data we hold at that time on accounts, logins (including the IP addresses of sessions), links, campaigns, clicks, payments, reports and abuse, limited to what the request concerns. We cannot disclose what we do not keep, such as the clear-text IP address of whoever opens a link.

We disclose data to authorities of countries outside the European Union only through the judicial cooperation channels provided for by international agreements or through the Italian authorities (Article 48 GDPR), except in emergencies where the law allows it.

We inform you of the disclosure, unless the law or the authority prohibits it or informing you could jeopardise an investigation or put someone in danger. For the same period, your rights of access and information may be restricted, in the cases provided for by Article 23 GDPR and by the national rules implementing it.

The procedures are described on the Cooperation with authorities page.

10.Your rights

Under the GDPR you have the following rights. Exercising them is free of charge and we reply within one month; if a request is complex, we may extend the time limit by two months, explaining why.

  • Access: to know whether we process data concerning you and to receive a copy of it.
  • Rectification: to correct inaccurate or incomplete data. Profile data can be changed directly in Settings.
  • Erasure: to have data erased when it is no longer needed, when you withdraw consent or when you object. You can close your account yourself from Settings → Privacy & account; permanent deletion takes place after 6 months, as explained in the “How long we keep data” section.
  • Restriction: to ask us to freeze processing while a dispute about the data is being resolved.
  • Portability: to receive the data you have provided to us in a machine-readable format. From Settings → Privacy & account you can download your data in JSON and your links in CSV at any time.
  • Objection: to object to processing based on legitimate interest, on grounds relating to your particular situation. We stop, unless there are compelling legitimate grounds or the data is needed to defend legal claims.
  • Automated decisions: to obtain human intervention, to express your point of view and to contest a decision taken automatically, as described in the section on automated checks.
  • Withdrawal of consent: for optional cookies, from the shield-shaped button at the bottom of every page, without affecting processing already carried out.

To exercise a right, write to the data protection contact from your account's e-mail address, or tell us how we can verify your identity. The data of link visitors is pseudonymous: we cannot link a click to a person, so for that data we may not be able to identify you (Article 11 GDPR); in that case we will tell you.

You may lodge a complaint with a supervisory authority, in particular in the EU country where you live or work or where the alleged infringement took place. In Italy: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, www.garanteprivacy.it. You may also go to court.

11.How we protect data

  • Every connection is encrypted (HTTPS with HSTS) and the servers accept traffic only from Cloudflare's network.
  • Account and link passwords are stored only as hashes; the two-step verification seed is encrypted.
  • The IP addresses of link visitors are turned into a hash with a secret key that changes every day and is destroyed within two days.
  • API keys, provider credentials and the Service's secrets are encrypted in the database; signed cookies prevent tampering.
  • Rate limits and anti-bot checks protect the forms; automated checks protect visitors from harmful destinations.
  • Our staff's access is limited according to role, and every significant action, including accessing an account as if one were its holder, is written to the activity log together with the reason.

If a data breach puts your rights at risk, we notify the Garante within 72 hours and, where the law requires it, we inform you directly.

12.Minors

pik.li is not intended for minors and does not accept accounts from people under 18 (see the Terms of service). If you believe that a minor has provided us with data, write to us and we will delete it.

13.Cookies and advertising

The cookies and similar technologies used by pik.li, and how to change your choices, are described in the Cookie policy.

pik.li currently shows no advertising and uses no advertising or profiling cookies. The Terms of service allow us to host advertising on the website: if we do so with tools that process personal data, we will update this notice and the Cookie policy before starting and ask for consent where necessary. Under no circumstances do we insert advertising into links or between the click and the destination.

14.Changes to this notice

We update this notice when the Service or the law changes. The date and version at the top show which text is in force. If a change is substantial, we inform registered users by e-mail or with a notice in the user area before it takes effect.