1. Who we are and what this covers
SHCD.US ("we", "us") runs shcd.us, a service for short links, dynamic QR codes and branded domains. This policy covers three groups of people:
- Customers: people with an SHCD.US account, or who create a guest link.
- Scanners: anyone who opens an SHCD.US link or scans one of our QR codes, including on a customer's branded domain.
- Visitors: people browsing our website.
For customer accounts and our website, we are the controller of your data. For scan analytics, the customer who created the link decides why those stats are collected, so they're the controller and we act as their processor, handling the data only to provide the Service to them.
2. What we collect
Customers
- Account details: name, email, phone number, password (stored only as a one-way hash), time zone, and the version of our Terms you accepted.
- Billing: handled by Stripe. We receive your plan, subscription status and the last four digits and brand of your card; we never see or store full card numbers.
- Your links: destinations, custom names, settings, branded domains, and the results of our safety checks.
- Guest links: the email address you confirm the link with.
- Merchandise orders: shipping name and address, and the artwork you upload, which we pass to Printful to make and ship your order.
- Support and referrals: what you send us, and who referred you.
Scanners
When a link is opened we record: the time; the IP address; approximate location (city, region and country) looked up from that IP; device type, operating system and browser from the user-agent; the referring site, if any; language preferences; and any utm_ campaign tags in the link. We don't record the scanner's cookies, contacts, precise location or any identity.
Visitors
- Standard server logs (IP, browser, pages requested), kept for security and troubleshooting.
- Google Analytics usage statistics, only if you accept analytics cookies. Until then, analytics runs in a cookieless, consent-denied mode.
- If you try the live demo on our homepage: the device type, browser and rough region of the phone that scans the demo code, shown on the screen that displayed it. Kept in memory for 30 minutes, then deleted. Never stored in our database.
Abuse reports
The link you report, your reason and details, your email if you choose to give it, and a one-way fingerprint of your connection (not your IP) so we can count distinct reporters.
3. Why we use it (and our legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Running your account, redirecting links, showing your analytics | Contract |
| Billing, tax and accounting records | Legal obligation; contract |
| Checking destinations for phishing and malware, handling abuse reports, preventing fraud | Legitimate interests (keeping scanners and our domain safe) |
| Scan analytics for link owners | The link owner's legitimate interests; we process on their behalf |
| Service emails (confirmations, receipts, security notices) | Contract |
| Product tips and onboarding emails | Legitimate interests; unsubscribe any time |
| Website analytics cookies | Consent |
4. Who we share it with
We share data only with service providers that help us run SHCD.US, under contracts that limit them to that purpose:
| Provider | What for | What they receive |
|---|---|---|
| Stripe | Payments and subscriptions | Name, email, billing details |
| Printful | Making and shipping merchandise | Order, shipping address, artwork |
| Google (Web Risk / Safe Browsing) | Checking link destinations for threats | Destination URLs only |
| Google Analytics | Website statistics (with consent) | Pseudonymous usage data |
| IP geolocation provider | Turning a scanner's IP into an approximate city and country | The scanner's IP address |
| Email delivery provider | Sending account and link emails | Email address, message content |
| Hosting provider | Running our servers and database | All data we store |
We may also disclose information if the law requires it, to respond to valid legal process, or to protect people from fraud, phishing or harm. We'll push back on requests that are overbroad. If SHCD.US is ever sold or merged, data would transfer under this policy and we'd tell you first.
Link owners see aggregated scan analytics (counts, approximate location, device, browser, referrer, time) and a per-link anonymous visitor count. They never see scanners' IP addresses.
5. How long we keep it
- Scan records: IP addresses are truncated (the last part is removed) after 30 days. The remaining scan data stays for as long as the link's owner keeps the link and their plan includes that history, and is deleted with the link or account.
- Account data: for as long as your account is open. When you close it we delete your links, analytics and profile within 30 days, apart from billing records we must keep for tax purposes (usually 7 years) and backups, which roll off within 35 days.
- Unconfirmed guest links: lapse after 24 hours. Confirmed guest links and their email are kept with the link so we can contact its creator about abuse.
- Abuse reports and blocked links: kept up to 2 years to recognise repeat abuse.
- Live demo data: 30 minutes, memory only.
6. Cookies and similar storage
| Name | Purpose | Type |
|---|---|---|
laravel_session, XSRF-TOKEN | Keep you logged in, protect forms, and remember that you've unlocked a password-protected link | Strictly necessary |
remember_web_* | "Remember me" login, only if you tick it | Strictly necessary |
_ga, _ga_* | Google Analytics website statistics | Analytics, only with your consent |
Browser storage (shcd.consent, UI preferences) | Remember your cookie choice and small display settings | Strictly necessary |
Change your mind any time with the Cookie settings link at the bottom of every page.
7. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you, and get a copy in a portable format.
- Correct anything that's wrong.
- Delete your data (subject to records we're legally required to keep).
- Object to or restrict processing based on legitimate interests, and opt out of product emails.
- Withdraw consent to analytics cookies at any time.
Email privacy@shcd.us. We'll confirm who you are (usually by replying to your account email) and respond within 30 days. If you scanned a code and want your scan data removed, tell us the link; we'll handle it with the link's owner. You can also complain to your local data protection authority.
California residents (CCPA / CPRA)
In the last 12 months we collected the categories described in section 2: identifiers (name, email, IP), commercial information (plan and orders), internet activity (scans and website use), and approximate geolocation. We use them for the purposes in section 3. We do not sell or "share" personal information as those terms are defined in California law, and we don't knowingly collect data from anyone under 16. You have the rights to know, delete and correct, and to not be discriminated against for using them. An authorised agent can make a request on your behalf with your signed permission.
Europe and the UK
We're based in the United States and our servers are in the US. When we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) or the provider's certification under the EU-US Data Privacy Framework. If you're a customer and need a Data Processing Agreement for your scan analytics, email us and we'll send one.
8. Security
All traffic is encrypted with HTTPS. Account passwords and link passwords are stored as one-way hashes. Card data stays with Stripe. Access to production data is limited to the people who need it to run the Service. No system is perfectly secure; if a breach affects your personal data, we'll tell you and the relevant authorities as the law requires.
9. Children
SHCD.US isn't meant for children under 16 and we don't knowingly collect their data. If you believe a child has given us personal information, email us and we'll delete it.
10. Changes
If we change this policy in a way that matters, we'll email account holders and update the date at the top before it takes effect.
11. Contact
SHCD.US · privacy@shcd.us