GDPR — Your data rights
Last updated: September 2026
This document explains how tapurl.io processes personal data under the EU General Data Protection Regulation (GDPR) and what rights you have as a data subject. It supplements our privacy policy.
1. Who controls your data
tapurl.io is the data controller for the data collected when you use the service. For any data-related question, contact us via the contact page.
2. What data and on what legal basis
We process account data (email, password hash), link data, click data (IP, User-Agent, referrer, country via GeoIP, device, OS, timestamp, SubID) and conversion data. Legal bases:
- Performance of a contract — account and link data are needed to provide the service.
- Legitimate interest — click data is used for analytics and abuse detection.
- Consent — analytics cookies (Google Analytics) load only after you consent via the banner.
We do not sell personal data and do not use it for advertising.
3. Your rights under GDPR
As a data subject in the EU/EEA you have the right to:
- access — obtain a copy of the data we hold about you;
- rectification — correct inaccurate data;
- erasure (“right to be forgotten”) — delete your account and associated data;
- restriction — pause processing in certain circumstances;
- portability — receive your data in a machine-readable format;
- object — object to processing based on legitimate interest;
- withdraw consent — disable analytics cookies at any time.
4. How to exercise your rights
You can delete your account and all associated data at any time by contacting us via the contact page. We process requests within 30 days. We may ask you to verify your identity before acting on a request.
5. International transfers and storage
Country detection runs locally via MaxMind GeoLite2 — IP addresses are never sent to MaxMind. Google Analytics 4 loads only with your consent and anonymizes IPs. Retention periods are described in our privacy policy.
6. Complaints
If you believe we process your data improperly, you have the right to lodge a complaint with the data-protection supervisory authority in your country.