Privacy & Data Handling
How SnipLink handles personal data, anonymizes IP addresses, and ensures compliance with privacy regulations.
Privacy by Design: SnipLink is built with privacy as a core principle. We collect minimal data, anonymize where possible, and never sell personal information.
IP Address Anonymization
SnipLink employs a multi-layer approach to IP address handling that balances analytics utility with user privacy. This section documents our anonymization methodology.
The Anonymization Process
When a link is clicked or QR code is scanned, the visitor's IP address goes through our privacy pipeline:
| Step | Process | Result |
|---|---|---|
| 1. Geolocation | IP is used to derive country and city at the edge (Cloudflare) | Country code + approximate city name |
| 2. Hashing | IP is hashed with SHA-256 using a daily rotating salt | Irreversible hash for unique visitor counting |
| 3. Truncation | Hash is truncated to prevent rainbow table attacks | 12-character anonymous identifier |
| 4. Storage | Only the truncated hash is stored; original IP is discarded | Anonymous click record |
Technical Implementation
The anonymization algorithm uses industry-standard cryptographic primitives:
// Conceptual pseudocode (actual implementation may vary)
function anonymizeIP(ip: string): string {
// Daily rotating salt prevents correlation across days
const dailySalt = getDailySalt(); // Rotates at midnight UTC
// SHA-256 hash is computationally irreversible
const hash = sha256(ip + dailySalt);
// Truncation adds additional protection against brute force
return hash.substring(0, 12);
}
// Example:
// Input: "192.168.1.100"
// Output: "a7f3e2d1c9b8" (truncated hash)
// The original IP cannot be recovered from this hashWhy This Approach?
- Daily salt rotation: Prevents tracking users across days. A visitor on Monday and the same visitor on Tuesday will have different hashes.
- SHA-256: Cryptographically secure one-way function. Cannot be reversed to obtain the original IP.
- Hash truncation: Reduces uniqueness further, making rainbow table attacks computationally infeasible while maintaining statistical utility.
- Edge processing: Geolocation happens at Cloudflare's edge, so the raw IP never reaches our application servers.
Data Categories
SnipLink categorizes data by sensitivity and applies appropriate handling:
| Category | Examples | Handling | Retention |
|---|---|---|---|
| Non-Personal | Browser type, OS, device category | Stored directly | Plan-based |
| Derived | Country, city (from IP) | Extracted, IP discarded | Plan-based |
| Anonymized | Visitor hash (from IP) | Hashed + truncated | Plan-based |
| Personal | Raw IP address | Never stored | Not retained |
Data Retention Periods
Analytics data retention varies by subscription plan:
| Plan | Click Events | Aggregated Stats | Webhook Logs |
|---|---|---|---|
| Free | 30 days | 90 days | 7 days |
| Pro | 1 year | 2 years | 30 days |
| Business | 2 years | Unlimited | 90 days |
| Enterprise | Custom | Custom | Custom |
GDPR & CCPA Compliance
SnipLink's data handling practices are designed to support your compliance needs:
GDPR (EU)
- Lawful basis: Analytics processing is based on legitimate interest (website performance measurement)
- Data minimization: We collect only what's necessary for analytics
- Anonymization: IP addresses are anonymized, removing personal data status
- Data subject rights: Users can request data deletion via workspace owners
CCPA (California)
- No sale of data: SnipLink does not sell personal information
- Disclosure: We disclose what data we collect in our privacy policy
- Deletion requests: Workspace owners can delete data on behalf of visitors
Note: While SnipLink implements privacy-respecting practices, you remain responsible for your own compliance obligations. Consult with a legal professional for specific compliance requirements.
API Data Handling
When using the SnipLink API, consider these data handling aspects:
Analytics API Responses
- Click counts are aggregated (no individual visitor data)
- Geographic data shows country/city totals, not individual locations
- Device/browser data is categorized and aggregated
Webhook Payloads
- Never contain raw IP addresses
- Geographic data is derived from anonymized IP processing
- Event IDs allow deduplication without tracking users
Link Metadata
- Creator information is associated with workspace accounts
- Click counts are aggregated totals
- No visitor-specific data is exposed via the API
Security Measures
Data protection is enforced through multiple layers:
- Encryption in transit: All API communication uses TLS 1.3
- Encryption at rest: Database and backups are encrypted with AES-256
- Access controls: Role-based permissions limit data access
- Audit logging: Security events are logged for monitoring
- SOC 2 alignment: Our practices align with SOC 2 trust principles