Legal

Privacy Policy

How we collect, use, and protect your data — in plain language, with the detail you need.

Last updated · July 5, 2026

01Overview

This Privacy Policy explains how TRIMS (“TRIMS”, “we”, “us”) collects, uses, shares, and protects information when you use our link management platform, websites, APIs, and related services (the “Services”).

We built TRIMS to be privacy-respecting by default. We collect the minimum data needed to operate a fast, reliable link and analytics product, we never sell your personal information, and we give you clear controls over your data.

Who this applies to
This policy applies to account holders, members of a workspace, and visitors who click a TRIMS-powered short link. Where you use TRIMS on behalf of an organization, that organization is the controller of end-user data and this policy describes our role as processor.

02Information we collect

We collect information in three ways: information you provide, information collected automatically, and information from third parties.

Information you provide

  • Account data — name, email address, password (stored only as a salted hash), and profile details.
  • Workspace data — workspace names, custom domains, team member invitations, and billing contact details.
  • Content — the destination URLs, aliases, titles, tags, and QR designs you create.
  • Payment data — handled by our payment processor; we store only a token, card brand, and last four digits, never full card numbers.
  • Support communications — messages you send us and their contents.

Information collected automatically

  • Click events — when someone opens a short link we record a timestamp, coarse geolocation (country/city from IP), device, operating system, browser, and referrer.
  • Usage data — pages viewed, features used, and diagnostic logs to keep the Services reliable.
  • Device & connection — IP address (used for geolocation and abuse prevention, then truncated/hashed), and user-agent.

Information from third parties

  • Authentication providers — if you sign in with Google, we receive your basic profile and email.
  • Integrations — data you choose to connect (e.g. Shopify orders, Stripe events) for conversion attribution.

03How we use information

We use the information we collect to provide, secure, and improve the Services:

  • Create and manage your account, workspaces, and short links.
  • Resolve link redirects and record click analytics for you.
  • Attribute conversions and revenue when you enable conversion tracking.
  • Detect and prevent fraud, abuse, malware, and bot traffic.
  • Provide customer support and respond to your requests.
  • Send transactional messages (receipts, security alerts, product notices).
  • Improve reliability, performance, and features through aggregated analytics.
  • Comply with legal obligations and enforce our Terms.
No sale of personal data
We do not sell your personal information, and we do not use the contents of your links to build advertising profiles.

05Cookies & similar technologies

We use a small number of cookies and local storage keys, categorized as follows:

TypePurpose
EssentialAuthentication session, CSRF protection, and workspace selection. Required for the app to function.
PreferencesRemember UI choices such as theme and layout.
AnalyticsFirst-party, privacy-friendly product analytics. No third-party ad cookies.

Short-link redirects do not set advertising cookies on visitors. You can control cookies through your browser settings; disabling essential cookies will prevent you from signing in.

06Link clicks & visitor analytics

When a visitor opens a TRIMS short link, we process the request to redirect them and to give the link owner analytics. This is a core function of the Services.

  • We derive coarse geolocation (country and city) from the IP address using a maintained database; we do not store precise location.
  • We parse the user-agent for device, OS, and browser to power breakdowns.
  • IP addresses are used transiently for geolocation and abuse detection and are then truncated or hashed for storage.
  • Click data is scoped to the workspace that owns the link; other customers cannot see it.

If you are an end user who clicked a link and wish to exercise rights over this data, contact the organization that created the link (the controller); we will assist them as processor.

07Sharing & subprocessors

We share information only as needed to run the Services, and never with data brokers. Categories of recipients:

RecipientPurpose
Cloud hosting & CDNRun the application and serve redirects globally
Payment processorProcess subscriptions and store card tokens
Email providerSend transactional and account emails
Geolocation databaseMap IP addresses to country/city
Integrations you enableOnly the data required for that integration

Each subprocessor is bound by data-processing terms. We may also disclose information to comply with the law, protect our rights, or in connection with a merger or acquisition (with notice where required).

08Data retention

We keep personal data only as long as necessary for the purposes described here.

  • Account data — retained while your account is active and for a limited period afterward for legal and accounting reasons.
  • Analytics history — retained according to your plan's retention window (up to unlimited on Premium).
  • Backups — deleted data may persist in encrypted backups for a short rolling window before permanent deletion.

When you delete your account we remove or anonymize your personal data, except where retention is legally required.

09International data transfers

TRIMS operates globally, so your information may be processed in countries other than your own. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum.

10Your rights & choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct inaccurate or incomplete data.
  • Delete your data (“right to be forgotten”).
  • Restrict or object to certain processing.
  • Port your data to another service in a machine-readable format.
  • Withdraw consent where processing is based on consent.

You can exercise most rights directly in Settings → Account (export or delete), or by emailing info@trims.app. We respond within the timeframes required by law and never charge for reasonable requests.

11How we protect your data

Security is foundational. We apply layered technical and organizational measures, including TLS 1.3 in transit, AES-256 encryption at rest for sensitive fields, hashed passwords, two-factor authentication, scoped API tokens, audit logging, and continuous bot and malware detection. See our Security page for details.

12Children's privacy

The Services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us information, contact us and we will delete it.

13Changes to this policy

We may update this policy as the Services evolve or the law changes. We will post the new version here with an updated date and, for material changes, notify you by email or in-app. Continued use after changes take effect constitutes acceptance.

14Contact us

For privacy questions or to exercise your rights, contact our privacy team:

If you are in the EEA/UK and believe we have not resolved your concern, you may lodge a complaint with your local supervisory authority.

Questions about this document? Reach us at info@trims.app.