Privacy Policy

Effective Date: February 28, 2026 · Last Updated: February 28, 2026

y.hn is operated by Yazhou Hu, sole proprietor (“we,” “our,” or “us”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the y.hn website, application, and related services (collectively, the “Service”).

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (optional)
  • Password (stored in cryptographically hashed form)
  • Profile information you choose to provide

1.2 Usage Data

We automatically collect:

  • Links you create, edit, and manage
  • Click analytics data on your short links (IP addresses, approximate geolocation, device type, browser, operating system, referrer URL)
  • Service usage patterns and feature interactions
  • Device information (model, operating system version, unique device identifiers)
  • Log data (access times, pages viewed, IP address, referring URL)

1.3 Payment Information

All payment processing is handled by Paddle.com Market Limited (“Paddle”), our Merchant of Record. We do not collect, store, or have access to your full payment card details. Paddle processes your payment information in accordance with their Privacy Policy. We receive limited transaction information from Paddle, such as transaction IDs, subscription status, and billing country.

1.4 Cookies and Similar Technologies

We use cookies and similar tracking technologies to:

  • Maintain your session and authentication state
  • Remember your preferences and settings
  • Analyze Service usage and performance
  • Provide analytics for short link clicks

You can control cookie settings through your browser. Disabling cookies may affect the functionality of the Service.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process your link shortening and management requests
  • Generate analytics and statistics for your short links
  • Process transactions and manage your subscription (via Paddle)
  • Send you service-related communications (e.g., account notifications, security alerts)
  • Detect and prevent fraud, abuse, and security threats
  • Respond to your inquiries and provide customer support
  • Comply with legal obligations

3. Analytics and Tracking

3.1 Link Analytics

When someone clicks a short link created through y.hn, we collect anonymous click data (approximate location, device type, browser, operating system, referrer) to provide you with analytics. This data is associated with your links, not with the clicker's personal identity.

3.2 Third-Party Integrations

If you choose to enable third-party integrations (such as Meta Pixel, Google Analytics, or Google Tag Manager), those services will collect data according to their own privacy policies. Enabling these integrations is optional and under your control.

3.3 Service Analytics

We may use anonymized, aggregated analytics to understand how the Service is used and to improve our offerings.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data based on the following legal grounds:

  • Contract performance: To provide and maintain the Service you requested.
  • Legitimate interests: To improve the Service, prevent fraud, and ensure security.
  • Consent: Where you have given consent for specific processing activities (e.g., marketing communications).
  • Legal obligation: To comply with applicable laws and regulations.

5. Data Sharing and Disclosure

We do not sell your personal information. We may share data with:

  • Paddle (Merchant of Record): To process payments, manage subscriptions, handle invoicing, and comply with tax obligations.
  • Service providers: Who assist in operating our infrastructure (hosting, CDN, email delivery, error monitoring). These providers are contractually obligated to protect your data.
  • Law enforcement or regulatory bodies: When required by law, legal process, or to protect our rights, safety, or property.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

6. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure password hashing
  • Access controls and authentication
  • Regular security reviews

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Data Retention

  • Account data is retained while your account is active.
  • Link analytics data is retained according to your subscription plan.
  • You may delete your links and account at any time.
  • Upon account deletion, your personal data will be removed within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, financial records).
  • Aggregated, anonymized data may be retained indefinitely.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data (“right to be forgotten”).
  • Data portability: Request a machine-readable copy of your data.
  • Restriction: Request that we limit the processing of your data.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including countries that may not provide the same level of data protection. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy and applicable law.

10. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will take steps to delete it promptly. If you believe a child under 16 has provided us with personal data, please contact us.

11. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last Updated” date. For significant changes, we may also notify you via email or through the Service. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: