Privacy Policy
Last updated 2 August 2026
Linkora measures link clicks without advertising cookies and without storing raw IP addresses. This page explains exactly what is recorded, why, and for how long.
1. Who this covers
Two groups of people interact with Linkora, and they are treated differently:
- Account holders — people an administrator has created an account for. Accounts are not self-serve; there is no public sign-up.
- Visitors — anyone who follows a short link on linkora.skrill.app. Visitors have no account and are never asked to identify themselves.
2. What we record when a short link is clicked
Each click writes a single record containing:
- The time of the click and which link was followed.
- An approximate country, region, city, continent, timezone and coordinates, derived from network-level geolocation at request time.
- The device type, operating system and browser, derived from the user-agent string.
- The browser language, referring platform, configured UTM campaign fields, destination URL and redirect response time.
- A QR code identifier, campaign and placement when the link was opened from one of your saved QR codes.
- Whether the request appears human or automated. Automated requests are retained for diagnosis but excluded from human click and unique-visitor totals.
- The referring site, reduced to its domain.
- A non-reversible visitor hash, described below.
We do not store the raw IP address, the full user-agent string, the full referring URL, or any advertising identifier.
3. How unique visitors are counted without cookies
Counting unique visitors normally requires a cookie or a stored IP address. Linkora uses neither. Instead, the IP address and user-agent of a request are combined with a server-side secret and the current date, then hashed. The result cannot be reversed back into an IP address, and because the date is part of the input, the same visitor produces a different hash tomorrow.
The practical consequence is that Linkora can tell you how many distinct people clicked a link today, but cannot re-identify any of them, link their activity across days, or track them across different links belonging to different accounts. No consent banner is required because no tracking cookie is set.
4. Cookies we do set
One cookie is used: a session cookie issued after an account holder logs in. It is strictly necessary to keep you signed in, is HTTP-only, and is not readable by JavaScript. It carries no analytics purpose and is never read when resolving a short link.
It expires after 12 hours, or after 30 days if you select “Remember me”. Logging out deletes it.
A second, non-essential cookie remembers your language choice so an unprefixed address opens in the language you last picked. It holds only a language code and is never used for analytics.
5. Account data
For account holders we store the name, email address, an optional company and job title, notification and regional preferences, and a bcrypt hash of the password. Passwords are never stored in a recoverable form, and neither are short-link passwords.
6. Retention
- Click records are retained for as long as the link exists. Deleting a link deletes its click history and its QR codes.
- The daily visitor-hash records used for unique counting are discarded automatically after 48 hours.
- Password reset and verification codes expire after 10 minutes and are single-use.
- Account data is retained until the account is deleted by an administrator.
7. Who the data is shared with
Analytics are scoped to the account that owns the link. No account can query another account's links or clicks. Linkora does not sell data, does not operate an advertising network, and does not share click records with third parties.
Data is processed by the infrastructure this deployment runs on — typically a hosting provider and a managed MongoDB database. If email delivery is configured, verification codes and scheduled reports pass through an email provider.
8. Your rights
Account holders can view and correct their profile in Settings, export their own click data as CSV from Reports, and delete links along with their click history at any time. For access or deletion requests that go beyond the in-product controls, contact the administrator of this deployment.
Because visitor records carry no identifier that can be traced back to a person, we are generally unable to locate an individual visitor's records on request — that is a deliberate consequence of not storing identifiers.