Privacy Policy
Last updated October 1, 2026
This policy explains how frwd2 ("frwd2", "we", "us") handles personal data when you visit frwd2.in, open a frwd2 short link, use the dashboard, or call the frwd2 API, SDK or MCP server. We collect only what we need to run the service and keep it secure.
Who is responsible
frwd2, [Registered address], is the data controller for account, website and newsletter data. Contact us about privacy at privacy@frwd2.in.
Organizations that create links with frwd2 decide what those links point to. For personal data they put into link titles or destinations, the organization is the controller and we process it on their behalf.
What we collect
| Data | When | Why |
|---|---|---|
| Name, email address, password (stored only as a salted hash) | You create an account | To run your account and sign you in |
| Google or GitHub account ID, name and verified email | You sign in with Google or GitHub | To link that identity to your frwd2 account |
| Links you create: destination URL, short ID, title, expiry | You or your organization create a link | To provide the redirect and show your links |
| The random browser ID of the browser that made a link | You shorten a link without an account | To give you the same short link if you shorten that address again from the same browser |
| Session data: IP address, browser user agent, device name, a random browser ID, sign-in times | You sign in | To keep you signed in, show your active devices and detect misuse |
| IP address and a random browser ID (short-lived) | Any request to the API, including anonymous shortening | Rate limiting and abuse prevention |
| Email address and signup date | You subscribe to the newsletter | To send product updates you asked for |
| API key names and last-used time | Your organization uses API keys | To let you audit and revoke keys |
| Payment records: the plan and period you bought, the amount and currency, your country, and Razorpay's order and payment IDs | You buy a plan | To switch your plan on and keep a record of what was paid |
| Name, email address, company and the message you write | You send a custom-plan request from the pricing page | To reply to your request |
People who open short links: each time a short link is opened we record a click: the time, the link, the country (as reported by Cloudflare), the domain of the referring website, and the device type, browser and operating system worked out from the browser's user agent. We don't store the visitor's IP address or full user agent. To count unique visitors we keep a one-way hash of the IP address and user agent that changes every day, so a visitor can't be recognised from one day to the next. Link owners, organization members and frwd2 administrators see this only as aggregated reports; we don't build profiles of visitors. Requests pass through Cloudflare, which processes technical data such as IP addresses to deliver and protect the service.
Payments: card, UPI and bank details are entered in Razorpay's payment form and go to Razorpay. We never receive or store them. Your country, as reported by Cloudflare, decides whether prices are shown in rupees or US dollars.
We don't sell personal data, and we don't use it for advertising.
Legal bases (EEA, UK and similar laws)
- Contract: account data, links, sessions and payment records, to provide the service you signed up for; and custom-plan requests, to answer what you asked us.
- Legitimate interests: security logs, rate limiting and abuse prevention, to keep frwd2 safe for everyone; and click statistics, so link owners can see how their links are used.
- Consent: the newsletter. You can withdraw consent at any time with the unsubscribe link in any email.
- Legal obligation: where we must keep or disclose data by law.
Who we share data with
We use a small number of service providers (processors) who handle data only on our instructions:
- Cloudflare, Inc.: hosting, databases (D1), caching (KV), network and security.
- Google LLC and GitHub, Inc.: only if you choose to sign in with them.
- Razorpay: payment processing, only if you buy a plan. We send it your name, email address and the amount to charge; it collects your payment details itself.
We may also disclose data if required by law, to respond to valid legal requests, or to protect people from harm such as phishing or malware distributed through short links.
International transfers
Cloudflare runs a global network, so data may be processed outside your country. Where required, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
How long we keep data
- Account and links: while your account exists. Deleting a link removes it immediately; deleting an organization removes its links and API keys.
- Deleted accounts: when you delete your account from the dashboard it is closed straight away: you are signed out everywhere, your links stop working and organizations you own are deactivated. The data itself is kept so the account can be restored if you ask. To have it erased permanently, email privacy@frwd2.in.
- Sessions: sign-ins expire 7 days after last use. The session history (device, IP, times) is kept while your account exists so you can review and revoke access.
- Rate-limit counters (IP address and browser ID): deleted within about an hour of the rate-limit window ending.
- Click records: deleted after 90 days. Daily click counts per link, which contain no information about visitors, are kept for reporting and removed when the link's organization is deleted.
- Payment records: while your account exists, as the history of what you bought.
- Custom-plan requests: until we have dealt with your request and deleted it. You can ask us to delete yours at any time.
- Newsletter: until you unsubscribe. We keep a record that you unsubscribed so we don't email you again.
- Anonymous links: kept so they keep working. They aren't connected to an account; each is stored with the random browser ID of the browser that made it.
Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal data, object to or restrict certain processing, and withdraw consent. You can export your links yourself as CSV or JSON from the dashboard, and close your account from its Account page. For anything else, including permanent erasure, emailprivacy@frwd2.in. We respond within 30 days. You can also complain to your local data protection authority.
Security
Passwords are hashed, API keys and refresh tokens are stored only as hashes, all traffic is encrypted with TLS, and sign-in uses short-lived access tokens with rotating refresh tokens. No system is perfectly secure; if we learn of a breach affecting your data, we'll notify you and the authorities as the law requires.
Children
frwd2 isn't directed at children under 16, and we don't knowingly collect their data.
Cookies
We use only strictly necessary cookies and browser storage. See the Cookie Policy.
Changes
We'll update the date at the top when this policy changes, and tell account holders by email about significant changes before they take effect.