How redirects.pro handles data.
Last updated: July 26, 2026. This policy explains what data is processed when you use the checker, create an account, upgrade, use the API, submit sitemap audits, upload CSV files, or contact support.
1. Who this policy covers
This policy applies to redirects.pro, including the public redirect checker, account dashboard, paid Agency workflows, API, sitemap audits, CSV uploads, exports, shareable reports, billing flows, and support communications. "We", "us", and "our" refer to the operator of redirects.pro.
2. Data we collect
We collect only the data needed to run a redirect QA product, protect the service, capture early-access interest, bill paid accounts when checkout opens, and support users.
- Account data: email address, password hash, account plan, subscription status, API token, and timestamps.
- Manual check data: submitted URL, redirect result JSON, final URL, hop count, loop status, created time, IP address for anonymous checks, and optional share token.
- API data: API token authentication status, submitted URL or URL batch, redirect results, usage-window counters, timestamps, IP address, and user agent.
- Sitemap and CSV job data: uploaded or extracted URLs, sitemap source URL, job status, row-level results, error messages, and exportable report data.
- Early-access data: email address, optional name and company, desired plan, workflow interest, source/intent, IP address, and timestamps.
- Billing data: Stripe customer ID, subscription ID, subscription status, checkout and portal state, and billing-event metadata needed to unlock or remove paid access.
- Technical data: IP address, user agent, request path, error logs, security logs, cooldown state, rate-limit counters, and operational diagnostics.
- Optional analytics data: if you accept analytics cookies, Google Analytics and Microsoft Clarity may process page views, browser/device details, approximate location, interactions, and usage patterns.
- Support data: emails, messages, attachments, troubleshooting details, and any information you choose to send us.
3. Data we do not intentionally collect
- We do not store raw card numbers. Payment details are handled by Stripe.
- We do not intentionally collect special-category personal data.
- We do not use redirects.pro to sell personal data.
- We do not use advertising cookies in the current MVP.
- We load Google Analytics and Microsoft Clarity only after analytics cookie consent, and we do not load them on noindex client report pages.
4. URLs and redirect results may contain sensitive information
URLs can contain names, IDs, search terms, campaign tags, authentication tokens, or other sensitive strings. Do not submit URLs unless you are authorized to test them. Avoid submitting secrets in query strings. Prefer API headers over query-string tokens when using automated workflows.
5. Why we use data
- Provide redirect checks, redirect-chain results, reports, dashboard history, API responses, sitemap jobs, CSV jobs, and exports.
- Capture and respond to early-access interest while paid checkout is closed.
- Create and manage accounts, sessions, API tokens, billing status, and paid entitlements.
- Detect abuse, enforce cooldowns, apply API limits, protect infrastructure, and investigate security issues.
- Process subscription events, invoices, cancellations, and customer billing support through Stripe.
- Respond to support, legal, privacy, billing, and security requests.
- Improve reliability, product quality, conversion flows, and user experience, including optional analytics where you consent.
- Meet legal, tax, accounting, and compliance obligations where applicable.
6. Legal bases for EU/UK users
Where GDPR or UK GDPR applies, we rely on these legal bases as appropriate:
- Contract: to provide accounts, paid plans, API access, sitemap audits, CSV jobs, reports, support, and billing.
- Legitimate interests: to secure the service, prevent abuse, debug errors, measure product usage, and improve workflows.
- Legal obligation: to keep billing, tax, accounting, fraud-prevention, and compliance records.
- Consent: for optional analytics cookies, Microsoft Clarity session analytics, marketing, optional features if introduced later, and cookie notice preferences.
7. Sharing and processors
We share data only where needed to operate the service or comply with obligations.
- Stripe processes checkout, payment methods, invoices, Customer Portal, subscription events, and related billing data.
- Hosting and infrastructure providers process server files, databases, logs, emails, backups, and network traffic.
- Email providers may process transactional or support messages.
- Google Analytics may process analytics events after you accept analytics cookies.
- Microsoft Clarity may process interaction analytics and session replay data after you accept analytics cookies.
- Professional advisers, authorities, or dispute handlers may receive data when legally necessary.
- Successors may receive data if redirects.pro is involved in a merger, acquisition, financing, or asset transfer.
8. International transfers
Your data may be processed in countries other than your own, depending on hosting, payment, email, support, and infrastructure providers. Where required, we rely on appropriate safeguards, provider terms, contractual protections, or other lawful mechanisms.
9. Retention
We retain data for as long as needed to provide the service, maintain account history, support paid workflows, protect against abuse, resolve disputes, and meet legal obligations. Check history, sitemap jobs, CSV jobs, and logs may remain until deleted, anonymized, rotated, or no longer needed. Billing records may be retained longer for tax, accounting, fraud, and compliance reasons.
10. Shareable reports
When a shareable report is created, anyone with the private report URL can view the report. Do not share report links with people who should not see the checked URL or redirect result. Shared report access may be logged for abuse prevention and product diagnostics.
11. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, export, or object to processing of your data. You may also have the right to withdraw consent where processing is based on consent and to complain to a data protection authority. Email hello@redirects.pro to make a request.
12. Security
We use password hashing, CSRF protection for sensitive account actions, API tokens, Stripe-hosted billing flows, plan gates, abuse controls, and access restrictions for helper files. No internet service is perfectly secure. Keep your password and API token private, rotate tokens if exposed, and contact us if you suspect misuse.
13. Children
redirects.pro is a professional tool and is not intended for children. Do not use the service if you are under the age required to consent to online services in your location.
14. Changes
We may update this policy as the product, legal requirements, providers, or data practices change. Material changes will be reflected by updating the "Last updated" date and, where appropriate, by giving account holders additional notice.
15. Contact
Privacy, data, security, DPA, or legal requests: hello@redirects.pro.