LEGAL

Privacy policy

Last updated 1 September 2026. This policy covers redirectduck.com, app.redirectduck.com and the API.

The short version
We keep an account record so you can log in and be billed, and we count redirect hits so you can see them. We truncate visitor IP addresses at the edge, we do not set tracking cookies on redirected traffic, we do not sell data and we do not build advertising profiles. You choose whether your domains and their logs sit in the US or the EU.

1. What we collect

Account data. Your email address, a hashed password or the identifier from your single sign-on provider, your workspace name, and the names and roles of people you invite.

Configuration data. The domains you add, the rules you write, tags, projects and the change history of each. This is content you supply and we process it on your behalf.

Billing data. Plan, billing period, invoices and the country used for tax. Card details are entered on our payment provider's form and never reach our servers; we store the last four digits and the expiry so you can recognise the card.

Product usage. Login timestamps, API calls per token, and error reports from the dashboard. We use a privacy-friendly analytics tool with no cross-site tracking.

2. Redirect traffic

When a visitor opens one of your redirected links, our edge records a single event so we can show you analytics and defend the service against abuse. The event holds the timestamp, the requested hostname and path, the rule that matched, the status code returned, the referrer, a country derived from the IP address, and the browser and device family parsed from the user agent.

The IP address is truncated before the event is written: the last octet of an IPv4 address and the last 80 bits of an IPv6 address are dropped. The full address exists only in memory for the fraction of a second needed to answer the request, and in abuse-prevention counters that hold a salted hash for 24 hours.

We do not set cookies on redirected traffic, we do not inject scripts or pixels into any response, and we do not link a visitor across two different customers' domains.

3. Why we process it

Under the GDPR we rely on performance of a contract to run your account and serve your redirects, on a legitimate interest to keep the service secure and to prevent abuse, and on a legal obligation to keep invoices and tax records. Marketing email is sent only with consent and every message carries an unsubscribe link.

For configuration data and redirect events you are the controller and RedirectDuck is the processor. Our data processing agreement is part of the terms and needs no separate signature.

4. Cookies

CookiePurposeLife
rd_sessionKeeps you logged in to the dashboard.30 days
rd_csrfProtects forms against cross-site request forgery.Session
rd_zoneRemembers the zone filter you last used.1 year

All three are strictly necessary for the dashboard to work, so no consent banner is shown. There are no advertising or third-party tracking cookies anywhere on our sites. Details are in the cookie policy.

5. Where data lives

Each domain is assigned an edge zone when you add it. Domains in the EU zone are served from Frankfurt, Amsterdam and Paris, and their events are stored in Germany. Domains in the US zone are served from Ashburn, Dallas and Portland, and their events are stored in Virginia.

Account and billing records sit in the EU regardless of zone. Where a subprocessor transfers data out of the EEA, the transfer runs on the European Commission's standard contractual clauses.

6. Subprocessors

HetznerDEHosting for the EU zone, application servers and event storage.
AWSUSHosting for the US zone and object storage for exports.
StripeUS / IEPayments, card handling and invoicing.
PostmarkUSTransactional email: verification, alerts and receipts.
Let's EncryptUSCertificate issuance for your domains.

We announce a new subprocessor at least 30 days before it starts handling customer data. Subscribe to the notice list from your workspace settings.

7. Retention

Raw redirect events are kept for 30 days, then reduced to daily aggregates. Aggregates follow your plan: 7 days on Free, 30 on Starter, 90 on Pro and 365 on Agency. Configuration and change history live as long as the workspace does.

When you delete a workspace, redirects stop immediately and everything except invoices is erased within 30 days, including backups on their normal rotation. Invoices are kept for as long as tax law requires.

8. Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and receive it in a portable format. Export and deletion are both self-service in the dashboard; anything else, write to us and we answer within 30 days.

If you believe we have handled your data badly, you can complain to your local supervisory authority. We would rather you told us first.

9. Security

Traffic is encrypted in transit with TLS 1.2 or newer and data is encrypted at rest. Access to production is limited to named engineers, protected by two-factor authentication and logged. Passwords are hashed with Argon2id. We run an annual external penetration test and publish the summary on request. A breach affecting your data is reported to you within 72 hours of discovery.

10. Contact

SC OPERACK SYSTEMS SRL, Brașov, Romania. CUI 45662784. Data protection questions go to privacy@redirectduck.com. Material changes to this policy are announced by email 30 days before they take effect, and every version stays available in the archive.

Read the terms →Processing agreement