Legal
Privacy Policy
Last updated: 27 May 2026
Einblik is a link-shortening and analytics service operated by Vantino SARL, Case postale 2933, 1211 Genève 2, Switzerland (“Einblik”, “we”, “us”). We collect as little personal data as we can to run the service, host it in Switzerland, and tell you plainly who else processes it. This policy explains what we process, why, on what legal basis, and the choices you have.
1. Controller and roles
Vantino SARL is the controller for account data and for the operation of our website. For the click analytics generated when someone follows a short link, the Einblik customer who created the link is the controller and Einblik acts as their processor. Team customers can request a Data Processing Agreement (DPA) at support@einblik.com.
2. Personal data we process
- Account data — your email address and the organization, profile and role details you provide. Sign-in is handled by our identity provider (Keycloak); if you choose “Sign in with Google”, Google authenticates you and shares your email with us.
- Links you create — the short code, destination URL, title, optional tags and the domain.
- Click analytics — when a short link is followed we
record a timestamp, the visitor’s IP address (used to derive a coarse
location — typically country/region), the referring URL, marketing
parameters present in the link (e.g. UTM tags and ad click identifiers
such as
gclid/fbclid), the browser/OS family and related hints from the user-agent, language, and any “Do Not Track” or Global Privacy Control signal the browser sent. To count unique visitors we derive a daily-rotating, salted identifier from the request — there is no cookie, and it cannot be linked across days, so we cannot (and do not) recognise returning visitors. See §6, Cookies. - Billing data — payments are processed by Stripe. We do not see or store full card numbers; we store a Stripe customer and subscription identifier and your plan status.
- Support & email — messages you send us, and the delivery metadata for transactional and onboarding emails we send you.
3. Why we process it, and our legal bases
- To provide the service (create/redirect links, show your analytics, manage your team, bill you) — performance of our contract with you.
- To produce link analytics for our customers — our (and their) legitimate interest in understanding link performance. The analytics are cookieless and use no persistent identifier, so no cookie-consent banner is required.
- To keep the service safe (prevent abuse, scan destination URLs for malware/phishing, secure accounts) — legitimate interest and legal obligation.
- To communicate with you (service notices, onboarding guidance) — contract and legitimate interest.
4. What we never do
- We do not sell or rent personal data — ever.
- We do not use third-party advertising trackers or ad cookies, and we do not track you across other websites.
- We do not build cross-site behavioural profiles.
5. Where data is processed, and international transfers
Application data, account data and click analytics are stored and processed on Google Cloud in the europe-west6 (Zürich, Switzerland) region. Some sub-processors operate outside Switzerland/the EEA — notably transactional email (United States) and certain IP-geolocation lookups. Where data is transferred outside Switzerland/the EEA, we rely on the European Commission’s Standard Contractual Clauses (and their Swiss equivalent) or an adequacy decision.
Sub-processors
- Google Cloud — hosting, compute and databases (Zürich, Switzerland).
- Amazon Web Services (SES) — transactional and onboarding email (United States).
- Stripe — payment processing and subscription management.
- Cloudflare — DNS and delivery of this website.
- IP geolocation — we resolve approximate location primarily from a local offline database (MaxMind GeoLite2, to which no visitor data is sent); if needed we fall back to third-party lookup services (ipstack, ip-api.com, ipinfo.io) which receive the visitor IP address for that lookup only.
6. Cookies
Our link analytics are cookieless. Following a short link sets no cookie and stores nothing on your device. To count unique visitors we compute a one-way hash of the link, your IP address and your browser’s user-agent together with a secret salt that rotates every day and is then deleted. You’re counted once within a day; the next day the salt is gone, so the value can’t be recomputed or linked back to you — there is no persistent identifier and we cannot recognise you across days or across sites. Because nothing is stored on your device and no lasting identifier is used, no cookie-consent banner is required.
The only cookies involved are the strictly necessary session cookies/tokens from our identity provider that keep you signed in to the Einblik app. We use no third-party advertising or cross-site cookies.
7. Retention
Click-level analytics are retained for 30 days on Free accounts and for the life of the subscription on Team accounts, after which raw events are deleted or aggregated. Account data is kept while your account is active. When you delete your account we remove your account data and flag your links and analytics for purge, subject to a short grace period and any retention the law requires (e.g. billing records).
8. Your rights
Under the Swiss Federal Act on Data Protection (revFADP/nLPD) and, where it applies, the EU/UK GDPR, you may request access to, correction, deletion, restriction, export (portability) of, or object to the processing of your personal data, and withdraw any consent. Email support@einblik.com and we will respond within 30 days. If a link’s analytics are involved, we may refer you to the customer who created the link (the controller). You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, your local authority.
9. Security
Data is encrypted in transit (HTTPS/TLS), hosted in Switzerland, and access is restricted to what is needed to operate the service. We scan link destinations against known malware/phishing lists on creation. No method of transmission or storage is perfectly secure, but we work to protect your data and will notify you of a breach as required by law.
10. Children
Einblik is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.
11. Changes
We may update this policy; we will change the “last updated” date above and, for material changes, notify account holders by email.
12. Contact
Questions or requests about privacy? Email support@einblik.com or write to Vantino SARL, Case postale 2933, 1211 Genève 2, Switzerland.