Privacy policy
Version 1.1, 8 Oct 2026
In short
No cookies, no tracking, no visitor addresses stored. When you open a short link we count the visit in a daily total for that link. We keep nothing that could tell us who you are.
Who is responsible
svh.li is run by SevinHub, Sergiu Vincze, Belgian sole proprietorship (eenmanszaak), Blivensstraat 43 bus 101, 2100 Antwerpen, Belgium, company number (KBO/BCE) 1042.245.006. We are the controller of the personal data described here. Contact: admin@sevinhub.com.
When you open a short link
Your browser sends us some information with every request. This is what we do with it:
Your IP address: used in memory to look up your country in a database file kept on our own server, and to protect the service against overload. It is then discarded. It is never written to our database or to any log.
Your browser type (user agent): used only to sort the visit as phone, tablet, computer or automated program. It is not stored.
The page you came from (referrer): we keep only the website name, for example facebook.com, never the full address.
Your language preference: read to show our pages in your language. Not stored.
What we store is a count per link and per day, split by country, device type, website you came from, and whether you scanned a QR code or clicked. There is no record of single visits, no time of day and no identifier. A QR code carries the link in capital letters; that is how we tell a scan from a click, without any cookie.
Our web server keeps no access log for svh.li, and its error log does not record visitor addresses.
Receipts and these pages
Reading a link receipt (a link with + at the end), this page or any other page here records nothing about you, not even a count.
Cookies and similar technology
We set no cookies and store nothing on your device: no local storage, no fingerprinting, no third-party scripts, fonts or images. Because nothing is stored on your device, there is no consent banner.
The only cookies are on the private desk used by SevinHub staff, and only after they sign in: a strictly necessary session cookie and, if they tick "Remember this device for 30 days", a second cookie that keeps them signed in on that device for 30 days.
Reports about a link
If you report a link, we receive what you send: the link, the reason, your explanation, your name and email address, and we note the language of the page you used. We use it to handle the report, take a decision and tell you about it, as the EU Digital Services Act requires. We keep a report for 12 months after it is closed, then delete it. We share it with authorities only when the law requires us to.
People and projects who make links
Accounts belong to SevinHub staff and SevinHub projects. We keep their email address, name, a hash of their password, their two-step sign-in key (encrypted), the day they last signed in, a count of failed sign-in attempts (five in a row lock the account for 15 minutes), hashes of their API keys with the websites each key may point links to and the day it was last used, and a log of the changes they make to links. We keep this while the account exists and for 12 months after it is closed.
If an account holder ticks "Remember this device for 30 days" when signing in, that device keeps a random key in a cookie for 30 days. We store only a hash of the key, the account, the type of device (phone, tablet or computer), the day it was made, the day it was last used and the day it ends: no address and no browser details. Signing out on that device, "Sign out everywhere", a new password or a new sign-in code ends it.
Checking where links go
When a link is made or changed, we check its destination. We may send the destination's domain name (never anything about visitors) to Spamhaus, as a DNS query, and to the registry of that domain, to learn how old it is. Lists of harmful sites from URLhaus (abuse.ch) and Phishing.Database are downloaded to our server and checked there.
Where the data is
Everything is stored on our server with Contabo GmbH in the European Union. Country lookups use the IP to Country Lite database by DB-IP (CC BY 4.0), kept on our server: no data is sent to DB-IP. The company that answers name lookups (DNS) for our domain does not receive what you do on this site.
Legal basis
Counting visits in daily totals and protecting the service: our legitimate interest in running a safe and reliable service (GDPR article 6(1)(f)). Reports: our legal obligation under the Digital Services Act (article 6(1)(c)) and our legitimate interest in keeping links safe. Accounts: the agreement with the account holder (article 6(1)(b)).
Your rights
You can ask to see, correct or delete personal data we hold about you, to restrict or object to its use, and to receive it in a usable form. Write to admin@sevinhub.com. Visit counts are not linked to any person, so there is nothing about your visits that we could find.
You can also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), www.dataprotectionauthority.be.
Changes
If we change this policy, we change the version number and date at the top. We never start collecting new data before this page says so.