Home / Privacy Policy

Privacy Policy

Last updated 2026-09-21

We handle personal data under GDPR (EU/UK) and CCPA/CPRA (California). See the sections below and our Cookie Policy.

RabbitFoot Tech (“lit.onl”, “we”, “us”) operates short links at lit.onl and the product site (accounts, docs, API) at litonl.com. This Privacy Policy explains what we collect, why, and your rights under GDPR, UK GDPR, CCPA/CPRA, and similar laws.

Controller & contact

Data controller: RabbitFoot Tech. Privacy requests: [email protected].

What we collect

  • Account data — email, username, password hash, organization name, billing country (via Paddle).
  • Link data — destination URLs, slugs, expiry, UTM fields, redirect rules, password gates.
  • Click analytics — IP address, user agent, referrer, request headers/cookies, geo (from CDN headers), and optional fingerprint signals when enabled on a link (canvas, screen, language, etc.).
  • Technical logs — rate limits, errors, security events (no secrets in logs).
  • Support & email — transactional mail (welcome, invites, billing, expiry) via Elastic Email.

How we use data

To provide and secure the service, authenticate users, bill paid plans, prevent abuse, comply with law, and improve reliability. We do not sell personal information. We do not use click data for third-party ad profiling.

Legal bases (EEA/UK)

  • Contract — running your account and links.
  • Legitimate interests — security, fraud prevention, aggregated product metrics.
  • Consent — non-essential cookies/analytics/marketing where required (see Cookie Policy).
  • Legal obligation — tax, billing records, lawful requests.

Your rights

Depending on your location you may request access, correction, deletion, portability, restriction, or objection. California residents may request disclosure, deletion, and opt out of “sale”/“sharing” (we do not sell). Use [email protected] — we respond within applicable deadlines.

Retention

Account data while active and for a reasonable period after closure. Click history per plan window (see pricing). Logs rotated on a short schedule. Billing records kept as required for tax.

Subprocessors

  • Hetzner (hosting, EU)
  • Cloudflare (DNS, CDN, security)
  • Paddle (payments)
  • Elastic Email (transactional email)

International transfers

We prefer EU hosting where possible. When data leaves the EEA/UK we use appropriate safeguards (Standard Contractual Clauses or equivalent).

Security

We implement access controls, encryption in transit (TLS), least-privilege production access, and monitoring. Report security issues to [email protected].

Children

The service is not directed at children under 16. We do not knowingly collect their data.

Changes

We will post updates on this page with a revised “Last updated” date.