Home / Privacy Policy

Privacy Policy

Last updated 2026-09-24

We handle personal data under GDPR (EU/UK) and CCPA/CPRA (California). See the sections below and our Cookie Policy.

Operator: Rabbit Foot Technologies Ltd (trading as lit.onl)

Rabbit Foot Technologies Ltd (trading as lit.onl) (“we”, “us”) operates short links at lit.onl and the product site (accounts, docs, API) at litonl.com. This Privacy Policy explains what we collect, why, and your rights under GDPR, UK GDPR, CCPA/CPRA, and similar laws.

Controller & contact

Data controller: Rabbit Foot Technologies Ltd. Privacy requests: [email protected].

What we collect

  • Account data — email, username, password hash, organization name, billing country (via Paddle).
  • Link data — destination URLs, slugs, expiry, UTM fields, redirect rules, password gates.
  • Click analytics — IP address (hashed where stored in fingerprint payloads), user agent, referrer, request headers/cookies, geo (from CDN headers). When you enable enriched clicks, password gates, or confirm-before-leave on a link, we run a brief collect page that may store a device fingerprint (e.g. canvas/WebGL hashes, screen size, language, timezone, font metrics) in fingerprint_json for fraud and analytics — not for third-party ad profiling.
  • Document sharing (Growth+) — when someone views a PDF or deck you host: optional viewer email; coarse browser fingerprint (user-agent snippet sent from the viewer); country and device class; HttpOnly session cookie (lit_doc_view_*) to authorize PDF range requests; per-page dwell time; pointer clicks stored as page number plus x/y percent for heatmap analytics (we do not record full session replay or keystrokes); watermark text if you enable it. See our Data Processing Addendum if you process viewers’ data as a business customer.
  • Technical logs — rate limits, errors, security events (no secrets in logs).
  • Support & email — transactional mail (welcome, invites, billing, expiry) via Elastic Email.

How we use data

To provide and secure the service, authenticate users, bill paid plans, prevent abuse, comply with law, and improve reliability. We do not sell personal information. We do not use click data for third-party ad profiling.

Legal bases (EEA/UK)

  • Contract — running your account and links.
  • Legitimate interests — security, fraud prevention, aggregated product metrics.
  • Consent — non-essential cookies/analytics/marketing where required (see Cookie Policy).
  • Legal obligation — tax, billing records, lawful requests.

Your rights

Depending on your location you may request access, correction, deletion, portability, restriction, or objection. California residents may request disclosure, deletion, and opt out of “sale”/“sharing” (we do not sell). Use [email protected] — we respond within applicable deadlines.

Retention

Account data while active and for a reasonable period after closure. Click history per plan window (see pricing). Logs rotated on a short schedule. Billing records kept as required for tax.

Subprocessors

  • Hetzner (hosting, EU)
  • Cloudflare (DNS, CDN, security)
  • Paddle (payments)
  • Elastic Email (transactional email)

International transfers

We prefer EU hosting where possible. When data leaves the EEA/UK we use appropriate safeguards (Standard Contractual Clauses or equivalent).

Security

We implement access controls, encryption in transit (TLS), least-privilege production access, and monitoring. Report security issues to [email protected].

Children

The service is not directed at children under 16. We do not knowingly collect their data.

Changes

We will post updates on this page with a revised “Last updated” date.