This website requires JavaScript to run properly.
to.it.com
Privacy policy

Privacy, made clear.

This policy explains how to.it.com collects, uses, shares, and protects personal data for accounts, public mini pages, short links, QR codes, analytics, subscriptions, support, and safety.

Last updated: June 9, 2026

to.it.com/privacy
GDPR aware

Data we explain

Account and identity data
Pages, links, and widgets
Views, clicks, and QR scans
Billing, support, and safety

Public pages

Analytics

Security

User rights

This Privacy Policy explains how to.it.com (“to.it.com”, “we”, “us”) processes personal data when you use our link-in-bio and short-link platform, including public mini pages, bento-style profiles, widgets, QR codes, redirect routing, account dashboards, analytics, billing, support, and moderation.

Public pages and short links are designed to be shared. Account settings, billing data, unpublished drafts, security logs, and internal administrative data remain private unless you choose to share them or disclosure is required by law.

01

Data controller

The data controller for the purposes of the General Data Protection Regulation (GDPR) is Entreprise Individuelle (EI) – DA SILVA AVELAR William, trade name: to.it.com, SIRET: 831 461 363 00028, address: 10 rue de Penthièvre, 75008 Paris, France.

For privacy questions or requests, contact contact@to.it.com.

Personal data is hosted on infrastructure provided by Scaleway in France or the European Union, with additional processors used where needed to deliver payment, email, security, analytics, support, and product services.

02

Scope of this policy

This policy applies when you visit to.it.com, create or manage an account, publish a profile page, create short links, generate QR codes, configure widgets, use analytics, subscribe to a paid plan, contact support, or interact with our public pages and redirects.

It also applies to visitors who view a to.it.com public page, click a link, scan a QR code, submit a form, report illegal content, or otherwise interact with pages and links hosted or routed by the Service.

This policy also covers the optional to.it.com browser extension for Chrome and Firefox: connecting your account, creating short links from the current tab or a right-clicked link, and disconnecting the extension from the dashboard or the extension itself.

This policy does not govern third-party websites, apps, social networks, payment pages, shops, forms, ticketing platforms, newsletter tools, or destinations that users link to or embed. Those third parties are responsible for their own privacy practices.

03

Data we collect

We collect personal data that you provide directly, data generated by your use of the Service, data needed to operate public pages and redirects, and limited data received from service providers such as payment processors, email providers, infrastructure providers, and analytics tools where enabled.

  • Account and identity data: email address, name if provided, password/session data, authentication metadata, account settings, workspace membership, and communication preferences.
  • Page and profile data: public handle, display name, bio, avatar, theme settings, widget configuration, social links, public paths, campaign slugs, publication status, and SEO/social preview settings.
  • User content: links, destination URLs, media, text, embeds, forms, product or event cards, map details, contact buttons, newsletter blocks, and other content you add to pages.
  • Short-link and QR data: slugs, target URLs, redirect settings, expiration or scheduling settings, QR code metadata, UTM parameters, and click or scan events.
  • Browser extension data: the page or link URL you choose to shorten, OAuth tokens stored locally in the browser, extension connection metadata (workspace, user agent, last used), and anonymous install/connect/create product metrics (browser name and extension version).
  • Analytics and visitor data: page views, clicks, QR scans, referrers, approximate country or region, device type, browser type, timestamps, and aggregated performance metrics.
  • Billing data: subscription tier, payment status, currency, amount, tax information, invoice identifiers, Stripe customer/subscription identifiers, and limited checkout metadata. We do not store full card numbers on our servers.
  • Technical and security data: IP address, logs, rate-limit data, abuse signals, device/browser details, errors, security events, and diagnostic information.
  • Support and moderation data: messages you send us, illegal-content reports, rights requests, abuse reviews, moderation decisions, and related correspondence.

04

Public pages and private account data

Profile pages, public links, campaign pages, QR codes, social previews, and content you publish are public by design. Anyone with the URL may be able to access, share, index, screenshot, archive, or interact with them.

Unpublished drafts, internal dashboard settings, billing data, account credentials, private workspace data, support communications, and administrative logs are not intended to be public.

You are responsible for not publishing personal data, confidential information, private contact details, client information, or sensitive content unless you have the right and intention to make it public.

05

How we use data

We use personal data to operate, secure, maintain, improve, and support the Service.

  • Create and manage accounts, sessions, profiles, workspaces, pages, blocks, widgets, short links, and QR codes.
  • Render public pages, route redirects, resolve short links, generate QR outputs, and display social previews.
  • Provide analytics such as views, clicks, top links, referrers, approximate geography, devices, QR scans, and campaign performance.
  • Process subscriptions, enforce plan limits, manage billing status, and provide payment-related support.
  • Send transactional emails such as verification, login, password reset, billing, security, subscription, product, and support messages.
  • Respond to support requests, privacy requests, illegal-content notices, rights-holder reports, and moderation appeals where available.
  • Detect, prevent, investigate, and respond to spam, phishing, fraud, malware, impersonation, abusive traffic, rights violations, security incidents, and policy violations.
  • Debug errors, improve reliability, develop new features, measure product usage, and understand aggregate performance.
  • Comply with legal obligations, enforce our Terms, and protect rights, users, visitors, third parties, and the platform.

07

Email communications

We use email in connection with the Service. Transactional emails may include account verification, login, password reset, security alerts, billing updates, subscription notices, product status messages, support replies, moderation notices, and administrative communications.

If we offer optional marketing emails, they will be sent only where permitted and, where required, only after opt-in through to.it.com-owned flows. Marketing emails include an unsubscribe mechanism.

We do not purchase, rent, scrape, or use third-party email lists for marketing. We may maintain suppression records to respect unsubscribe requests, complaints, and invalid addresses.

Email delivery providers may process email addresses, message metadata, delivery events, bounces, complaints, and suppression data on our behalf.

08

Cookies and similar technologies

We use essential cookies and similar technologies to operate the website, secure accounts, remember cookie preferences, maintain sessions, and protect against abuse.

With your consent where required, we may use optional cookies or scripts for analytics, advertising measurement, support chat, diagnostics, or product improvement.

You can manage cookie preferences through the cookie settings link where available. Browser settings may also allow you to block or delete cookies, but some features may stop working correctly.

09

Analytics for pages, links, and QR codes

to.it.com provides simple analytics to account holders, such as page views, link clicks, QR scans, top links, referrers, approximate country or region, device type, browser type, timestamps, and campaign-level metrics.

Analytics may be generated from visitor interactions with public pages, short links, redirects, QR codes, and widgets. We aim to keep analytics practical and not more intrusive than needed for the Service.

Some analytics may be aggregated or anonymized for product improvement, reliability measurement, abuse prevention, and business reporting.

10

Data sharing and processors

We share personal data with service providers that process it on our instructions, under contractual safeguards appropriate to their role. We do not sell your personal data.

We may also disclose information where required by law, to enforce our Terms, respond to legal process, protect safety, prevent abuse, investigate security incidents, or protect the rights of users, visitors, third parties, or to.it.com.

  • Hosting and infrastructure providers, including Scaleway.
  • Payment processing providers, including Stripe.
  • Email delivery providers, including Amazon SES or similar services.
  • Security, CDN, DNS, bot-protection, and abuse-prevention providers, including Cloudflare where used.
  • Error monitoring and diagnostic providers, such as Sentry where enabled.
  • Support or chat tools, such as Crisp where enabled.
  • Analytics and advertising measurement providers, such as Google tools, only where enabled and consented to when required.
  • AI or language-model providers, such as OpenAI, only for limited tasks where enabled, such as writing assistance, moderation triage, support workflows, or internal quality processes.
  • Professional advisers, authorities, courts, regulators, or law-enforcement bodies where legally required or necessary.

11

Automated processing and abuse prevention

We may use automated processing to operate redirects, publish pages, generate analytics, enforce limits, detect suspicious activity, identify phishing or malware risks, rate-limit traffic, prevent spam, and support moderation workflows.

These controls help keep public pages, short links, QR codes, and visitors safer. They do not by themselves produce legal effects concerning you, but they may lead to temporary blocks, reviews, or restrictions where abuse or risk is detected.

Where AI-assisted features are enabled, we may use language-model providers for limited tasks such as draft copy assistance, support workflows, moderation triage, or internal quality review. We may log prompts and responses where needed for security, debugging, abuse prevention, and product improvement.

12

Data retention

We retain personal data only for as long as necessary for the purposes described in this policy, unless a longer period is required or permitted by law.

  • Account data: kept while your account is active and deleted or anonymized within a reasonable period after account closure, except where retention is needed for legal, security, tax, fraud-prevention, backup, or dispute reasons.
  • Published pages, links, widgets, QR codes, and related configuration: kept while your account or workspace is active and for a reasonable period after deletion or termination where needed for audit, recovery, abuse prevention, or legal compliance.
  • Analytics data: kept according to your plan, product limits, and operational needs; detailed events may be aggregated, shortened, anonymized, or deleted over time.
  • Billing and tax records: retained as required by French accounting, commercial, and tax rules, typically up to 10 years from the relevant accounting period.
  • Security and application logs: generally kept for a limited period, such as up to 6 months, unless needed longer for incident investigation, abuse prevention, legal claims, or compliance.
  • Marketing email data, if offered: kept until you unsubscribe or become inactive according to our retention practices, with suppression records kept where needed to honor opt-outs.
  • Support, moderation, and illegal-content reports: retained as needed to handle requests, document decisions, prevent abuse, comply with law, and defend legal claims.

13

Security

We implement appropriate technical and organizational measures to protect personal data, including access controls, secure transport where standard, infrastructure safeguards, monitoring, logging, and abuse-prevention controls.

No online service is completely secure. We cannot guarantee absolute security, but we work to protect the Service and respond to risks appropriately.

You are responsible for using a strong password, protecting your login methods, keeping account access limited to trusted people, and ensuring that public links and destinations you publish are safe.

14

Your rights

Where GDPR or other applicable privacy laws apply, you may have rights over your personal data. These rights may depend on your location, the type of data, and the legal basis for processing.

To exercise your rights, contact contact@to.it.com. We may need to verify your identity before responding. Where your request concerns content controlled by another to.it.com user, we may direct you to that user or assess the request according to applicable law.

  • Access your personal data.
  • Correct inaccurate or incomplete data.
  • Request deletion in certain cases.
  • Restrict or object to certain processing.
  • Request data portability where applicable.
  • Withdraw consent where processing is based on consent, without affecting processing already carried out before withdrawal.
  • Lodge a complaint with a supervisory authority, such as the CNIL in France.

15

International transfers

Some processors may process personal data outside the European Economic Area. Where required, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, adequacy decisions, and, where applicable, the EU-U.S. Data Privacy Framework.

Examples may include payment processing, email delivery, analytics, error monitoring, support tools, security providers, and AI or language-model providers.

16

Children

The Service is not intended for children under 16, or the minimum legal age required in your jurisdiction. We do not knowingly collect personal data from children below that age.

If you believe a child has provided personal data to us without appropriate authorization, contact us so we can review and take appropriate action.

17

Changes to this policy

We may update this Privacy Policy from time to time to reflect product changes, legal requirements, subprocessors, or operational practices.

For material changes, we will provide appropriate notice through the Service, by email to account holders, or both. The “Last updated” date shows when this policy was last revised.

18

Contact

For privacy questions, rights requests, cookie questions, or data-protection concerns, contact contact@to.it.com.

Postal address: Entreprise Individuelle (EI) – DA SILVA AVELAR William, trade name to.it.com, 10 rue de Penthièvre, 75008 Paris, France.

Privacy promise

We do not sell your personal data.

We use personal data to operate pages, route links, secure accounts, process subscriptions, provide analytics, prevent abuse, and improve to.it.com.