Skip to main content

Privacy Policy

Effective Date: 06 August 2026  ·  Version: 3.3  ·  Sections: 33

This Privacy Policy (hereinafter the "Policy") delineates, exhaustively and in thirty-three (33) sections, the categories of information that URLZY.IN (hereinafter "we", "us", or "our") may collect, receive, process, store, utilise, disclose, and otherwise manipulate in connection with your utilisation of the urlzy.in platform (hereinafter the "Platform"), together with the purposes for which such information is employed, the legal bases upon which such processing is founded, and the rights and remedies available to you in respect thereof. By accessing or utilising the Platform, you hereby acknowledge that you have read, understood, and unconditionally consented to the collection and processing of information as described herein, in accordance with all applicable data-protection statutes and regulations in force, including the Digital Personal Data Protection Act, 2023 (India) and, to the extent applicable, the General Data Protection Regulation (EU) 2016/679.

1. Introduction and Scope

This Policy applies to all Personal Data processed by us in connection with the Platform, including data supplied by you directly, data collected automatically through your interaction with the Platform, and data received from Third-Party Services integrated into the Platform. This Policy governs the processing of Personal Data irrespective of the terminal device, browser, or access mechanism employed by you, and extends to all subdomains, directories, progeny, and ancillary utilities of the Platform. Nothing herein shall operate to derogate from any right or protection conferred upon you by any mandatory provision of applicable law.

2. Definitions and Interpretation

For the purposes of this Policy, the following locutions shall be ascribed the meanings set forth herebelow, and cognate expressions shall be construed accordingly:

  • "Personal Data" shall mean any information relating to an identified or identifiable natural person (a "Data Subject"), including, without limitation, name, email address, Internet Protocol address, device identifiers, and behavioural telemetry;
  • "Processing" shall mean any operation or set of operations performed upon Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, combination, restriction, erasure, or destruction;
  • "Client-Side Processing" shall mean any operation executed exclusively within the browser environment of the user's terminal device, wherein the relevant data is neither transmitted to, nor persisted upon, any remote server infrastructure controlled by us;
  • "Media Asset" shall mean any digital image, photograph, document facsimile, graphic, or analogous binary payload ingested into the Platform's ancillary processing utilities;
  • "Third-Party Service" shall mean any external application, utility, network, or entity not owned, operated, or controlled by us, but whose functionality may be integrated, referenced, or invoked by the Platform;
  • "Data Principal" shall mean the natural person to whom the Personal Data relates, as that term is employed under the Digital Personal Data Protection Act, 2023 (India).

3. Legal Framework and Governing Legislation

This Policy is drafted to accord with, and shall be interpreted in a manner consistent with, the data-protection and privacy enactments applicable to the Platform, including, without limitation: (i) the Digital Personal Data Protection Act, 2023 (India) and any rules thereunder; (ii) the Information Technology Act, 2000 (India) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; (iii) to the extent the Platform serves data subjects within the European Economic Area, the General Data Protection Regulation (EU) 2016/679; and (iv) any other statute, regulation, or guideline that may hereafter be enacted, adopted, or amended. In the event of any inconsistency between this Policy and any mandatory provision of applicable law, the mandatory provision shall prevail to the extent of the inconsistency.

4. Consent and Its Withdrawal

By utilising the Platform, creating an account, or otherwise affirmatively engaging with the Platform's functionalities, you thereby accord your free, specific, informed, unconditional, and unambiguous consent to the Processing of your Personal Data as described in this Policy. You retain the absolute right to withdraw such consent, in whole or in part, at any time, by contacting us at support@urlzy.in or by utilising any consent-management interface presented by the Platform. Any such withdrawal shall be prospective in effect and shall not affect the lawfulness of Processing conducted prior to the withdrawal. Upon the withdrawal of consent, certain Platform functions that are contingent upon such Processing may become unavailable or materially degraded.

5. Information We Collect — Overview

We collect Personal Data through three principal channels: (i) information that you voluntarily and deliberately furnish to us; (ii) information that is collected automatically through your interaction with the Platform; and (iii) information that we receive from integrated Third-Party Services. The specific categories of information collected through each channel are particularised in Sections 6, 7, and 12 hereof respectively.

  • Minimum Necessary Principle. We collect only such Personal Data as is reasonably necessary to achieve the purposes identified in this Policy, and we shall not process Personal Data in excess of what is required for such purposes.
  • Lawfulness and Fairness. All Processing conducted under this Policy is undertaken lawfully, fairly, and in a manner that is transparent to the Data Principal.

6. Information You Voluntarily Provide

In the course of registering for an account, configuring your profile, utilising the Platform's tools, or communicating with us, you may voluntarily furnish the following categories of information:

  • Account Information: Your name, email address, password (stored in a cryptographically hashed and salted form), and any subscription or plan metadata associated with your account;
  • Profile Information: Display names, biography text, avatar imagery, and any biographical or professional particulars that you elect to publish upon public pages hosted by the Platform;
  • ChallengeMe Data: Chess.com usernames, challenge descriptions, social-profile links, and cognate particulars furnished in connection with the Platform's chess-landing-page utility;
  • Correspondence: The content of any communications, support requests, or enquiries that you address to us, together with any attachments furnished therewith;
  • Payment Data: Billing particulars furnished in connection with subscription payments, which are collected and processed by our payment processors and are not stored upon our servers in plain form.

7. Information Collected Automatically

Through your interaction with the Platform, we may automatically collect the following categories of information, which may in certain circumstances constitute Personal Data:

  • Device and Traffic Data: Internet Protocol address, browser type and version, operating system, referrer uniform resource locator, timestamps of access, language preferences, and approximate geolocation (at city or country granularity) derived from your IP address;
  • Usage Telemetry: Records of tool utilisation, link-creation events, click events, page-view events, and aggregated analytical metrics necessary for the operational provision of the Platform's services;
  • Security Logs: Internet Protocol addresses and operational metadata associated with suspected malicious, abusive, or bot-driven activity, which may be retained upon a persistent blacklist for the protection of the Platform and its users;
  • Verification Data: Verification responses generated by third-party bot-detection apparatus, which are processed by such third parties in accordance with their own policies and may include ephemeral tokens and device signals.

8. Client-Side Processing of Media Assets (No Server Storage)

Certain ancillary utilities of the Platform, including but not limited to the SquareUp perspective-correction instrument and cognate image-processing utilities, are architected to operate exclusively through Client-Side Processing. In respect of such utilities, we make the following unconditional representations:

  • Media Assets selected, uploaded, or otherwise ingested by you into such utilities are read into your local device's memory solely through your browser's file-reading application programming interface, and are rendered, transformed, and manipulated entirely within your own terminal device;
  • No Media Asset is transmitted, uploaded, streamed, or otherwise communicated to any server, data centre, cloud repository, or storage infrastructure owned, leased, or operated by us or on our behalf;
  • Consequently, we neither receive, process, store, duplicate, retain, nor gain access to the substantive content of any Media Asset, and we expressly disclaim any responsibility for the confidentiality, integrity, or security thereof, which remain at all times within your exclusive custody and control;
  • Any output file generated through such Client-Side Processing is produced locally on your device, and no server-side copy, derivative, cache, or artefact thereof shall subsist by reason of our acts or omissions;
  • For the avoidance of doubt, this Section applies to Media Assets only. Usage telemetry (such as the fact that a particular tool was invoked) may still be recorded solely for quota-enforcement and operational purposes, in accordance with Section 9 hereof.

9. Usage Telemetry and Quota Enforcement

To administer free-tier entitlements, enforce subscription quotas, and protect the Platform against abuse, we record limited usage telemetry, including the invocation of particular tools, the frequency and timing of such invocations, and the allocation thereof to guest or account holders. Such telemetry is retained solely for quota-enforcement, fraud-detection, and operational-accounting purposes, is not combined with any Media Asset content (which is never transmitted to us, per Section 8), and is aggregated or anonymised wherever it is practicable to do so. We do not use such telemetry to construct behavioural advertising profiles.

10. How We Use Information

We employ the Personal Data collected for the following purposes:

  • To provision, operate, maintain, and improve the Platform and its constituent services;
  • To generate and deliver analytical reports, click statistics, and usage metrics to authorised account holders;
  • To enforce usage quotas, subscription entitlements, and plan matrices associated with your account;
  • To detect, investigate, and mitigate fraudulent, malicious, abusive, or otherwise unlawful activity, including the screening of target hostnames against global threat-intelligence repositories;
  • To communicate administrative notices, service updates, and, where you have provided consent, promotional correspondence;
  • To verify the identity of account holders and to authenticate credentials at sign-in;
  • To comply with legal, regulatory, and judicial obligations, and to establish, exercise, or defend legal claims.

11. Legal Bases for Processing

Where the General Data Protection Regulation (EU) 2016/679 or an analogous regime requires the identification of a legal basis for Processing, our Processing activities are founded upon one or more of the following:

  • Consent: where you have freely granted your consent to a specific Processing activity, which you may withdraw at any time;
  • Contractual Necessity: where Processing is necessary for the performance of a contract to which you are a party, or for the taking of steps at your request prior to entering into such a contract;
  • Legal Obligation: where Processing is necessary for compliance with a legal obligation to which we are subject;
  • Legitimate Interests: where Processing is necessary for the purposes of our legitimate interests, including the operation, security, and improvement of the Platform, provided that such interests are not overridden by your fundamental rights and freedoms.

12. Sharing and Disclosure

We do not sell, rent, lease, barter, or otherwise commercialise your Personal Data. We may disclose your Personal Data to the following categories of recipients, in each case only to the extent necessary and in accordance with applicable law:

  • Service Providers: Third-party processors engaged to provide hosting, email delivery, payment processing, analytics, and bot-detection services, all of whom are bound by contractual obligations of confidentiality and data security;
  • Security Intermediaries: Threat-intelligence services, to which only target hostnames and their operational metadata are communicated for the purpose of malicious-content screening; no personal data is so shared;
  • Legal Authorities: Courts, tribunals, regulators, and law-enforcement agencies, where disclosure is required by law, regulation, legal process, or enforceable governmental request, or where we in good faith believe that such disclosure is necessary to protect the rights, property, or safety of ourselves, our users, or the public;
  • Corporate Transactions: Actual or prospective acquirers, merger partners, or assignees in connection with any merger, acquisition, reorganisation, insolvency, or other transfer of all or part of our business, subject to confidentiality obligations and, where applicable, the requirement of your consent.

13. Prohibition on Sale of Personal Data

We do not, and shall not, sell, rent, lease, trade, or otherwise transfer your Personal Data to any third party in exchange for monetary or other valuable consideration, nor shall we share your Personal Data for the purpose of cross-context behavioural advertising without your affirmative, prior, and unambiguous consent. The Platform's economic model is founded upon subscription entitlements and value-added services, and not upon the commoditisation of Personal Data. Any future change to this position shall be effected exclusively through an amendment to this Policy in accordance with Section 32 hereof, and through the procurement of any consent that applicable law may require.

14. Service Providers and Processors

We engage carefully vetted Third-Party Service providers as data processors to assist in the provision of the Platform, including providers of web hosting, infrastructure, email transmission, payment processing, customer-support tooling, and analytics. Each such processor is engaged under a written contract that obliges it to: (i) process Personal Data solely upon our documented instructions; (ii) implement appropriate technical and organisational measures for the protection of Personal Data; (iii) not process Personal Data for its own independent purposes; and (iv) assist us in fulfilling data-subject rights requests and security obligations. Where a processor engages sub-processors, the processor shall remain fully responsible for the acts and omissions of such sub-processors.

15. Security Intermediaries and Threat Intelligence

To safeguard the Platform and its users against malicious, fraudulent, and phishing activity, we interrogate global threat-intelligence repositories (including, inter alia, the SURBL multi-domain blocklist, the URIBL composite, and the Spamhaus Domain Block List) in respect of target hostnames submitted for shortening. Only the target hostname and its operational metadata are communicated to such repositories; no name, email address, or other personal identifier is disclosed. The responses received are employed solely to determine whether a submitted link may be created, and to maintain a persistent blacklist of offending Internet Protocol addresses where abuse is detected.

16. Disclosure to Legal Authorities

We shall disclose Personal Data to courts, tribunals, regulators, law-enforcement agencies, and other governmental authorities where such disclosure is: (i) required by a valid legal process, statutory mandate, or enforceable governmental request; or (ii) reasonably believed by us, in good faith, to be necessary for the prevention, detection, or prosecution of crime, the protection of the rights, property, or safety of ourselves, our users, or the public, or the establishment, exercise, or defence of legal claims. Where permitted by law and operationally feasible, we shall notify you of any such disclosure before or at the time of compliance, unless such notification is itself prohibited by law.

17. International and Cross-Border Transfers

Your Personal Data may be processed, stored, and transferred to jurisdictions outside the Republic of India, including to countries whose data-protection regimes may differ from those of your own jurisdiction. By utilising the Platform, you consent to such cross-border processing. Where required by applicable law, we shall ensure that any such transfer is subject to appropriate and recognised safeguards, including standard contractual clauses, adequacy determinations, or other legally effective transfer mechanisms, such that the level of protection guaranteed by this Policy is not undermined.

18. Cookies and Similar Technologies

We employ cookies, web beacons, and analogous tracking technologies to maintain authenticated sessions, persist user preferences, enforce guest-usage quotas, and analyse aggregate traffic patterns for the improvement of the Platform. A subset of such technologies may be administered by Third-Party Services, including analytics providers and content-delivery networks, subject to their respective privacy policies. You may configure your browser to refuse cookies or to alert you when cookies are proposed; however, certain features of the Platform may be inaccessible or function incorrectly in the absence of cookies. For the avoidance of doubt, Media Assets processed through Client-Side Processing utilities are never stored within cookies or local storage beyond the duration of the active browser session. You are referred to the Platform's Cookie Policy at /pages/cookies.php for comprehensive information concerning the specific cookies deployed and the methods available for their management.

19. Local Storage and Browser Data

In addition to cookies, the Platform employs local-storage objects within your browser environment for the retention of interface preferences, including the selection of the visual theme and cognate configuration choices. Such local-storage objects reside exclusively upon your terminal device, are not transmitted to our servers, and may be expunged at any time through the privacy and security settings of your browser. The Platform does not employ local-storage objects to track you across unrelated websites, and any data so stored is strictly limited to the functional configuration of the Platform.

20. Data Security Safeguards

We implement industry-standard administrative, technical, and physical safeguards designed to protect Personal Data against unauthorised access, alteration, disclosure, or destruction, including, without limitation, transport-layer encryption in transit, hashed and salted credential storage, least-privilege access controls, regular security patching, and access logging. Notwithstanding the foregoing, no method of transmission over the internet, or method of electronic storage, is absolutely secure, and we cannot guarantee the absolute security of any information transmitted to or stored by the Platform. You transmit information at your own risk.

21. Data Retention and Lifecycle

We retain Personal Data only for so long as is necessary to fulfil the purposes described in this Policy, to comply with legal and regulatory obligations, and to establish, exercise, or defend legal claims. Our retention periods are calibrated by reference to the following criteria:

  • Account-related Personal Data is retained for the duration of your account's existence and for a reasonable period thereafter to facilitate reactivation and to comply with record-keeping obligations;
  • Security logs and threat-intelligence records are retained for as long as the relevant risk persists, and in the case of offending Internet Protocol addresses, upon a persistent blacklist;
  • Usage-quota telemetry is retained only for so long as is necessary for quota enforcement and operational accounting, after which it is aggregated, anonymised, or securely deleted;
  • As noted in Section 8, Media Assets processed through Client-Side Processing utilities are not retained by us in any form whatsoever.

22. Your Rights and Choices — Overview

To the extent conferred by applicable law, you may exercise the rights particularised in Sections 22 through 26 hereof in respect of your Personal Data. We shall respond to all verified requests within the timeframes prescribed by applicable law, and in no event later than thirty (30) days from the receipt of a complete request, save where a longer period is permitted by law and communicated to you together with the reasons therefor. We may require the verification of your identity prior to giving effect to any request, and we shall not discriminate against you for exercising any such right.

23. Right of Access and Data Portability

You shall have the right to obtain from us confirmation as to whether Personal Data concerning you is being processed, and, where that is the case, access to such Personal Data together with information concerning the purposes of the Processing, the categories of Personal Data concerned, the recipients to whom such Personal Data has been disclosed, and the envisaged retention periods. Where the Processing is founded upon consent or a contract and is carried out by automated means, you shall further have the right to receive the Personal Data concerning you in a structured, commonly used, and machine-readable format, and to transmit such data to another controller without hindrance from us, where technically feasible.

24. Right to Rectification and Erasure

You shall have the right to obtain from us the rectification of inaccurate, incomplete, or out-of-date Personal Data concerning you, and the right to have incomplete Personal Data completed, including by means of supplying a supplementary statement. You shall further have the right to obtain the erasure of Personal Data concerning you where one or more of the following grounds applies:

  • The Personal Data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
  • You withdraw the consent upon which the Processing is based and there is no other legal ground for the Processing;
  • You object to the Processing and there are no overriding legitimate grounds for the Processing;
  • The Personal Data has been unlawfully processed; or
  • Erasure is required to comply with a legal obligation.

The foregoing right to erasure shall not apply where Processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defence of legal claims, or for any other ground recognised by applicable law.

25. Right to Restrict and Object

You shall have the right to obtain the restriction of Processing where: (i) you contest the accuracy of the Personal Data; (ii) the Processing is unlawful and you oppose the erasure thereof, requesting the restriction of its use instead; (iii) we no longer need the Personal Data but you require it for the establishment, exercise, or defence of legal claims; or (iv) you have objected to the Processing and the outcome of the balancing exercise is pending. You shall further have the right to object, on grounds relating to your particular situation, at any time to Processing founded upon our legitimate interests, and we shall cease such Processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.

26. Automated Decision-Making and Profiling

The Platform does not employ your Personal Data for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, save for automated fraud- and abuse-detection apparatus that operate upon operational metadata and threat-intelligence signals rather than upon your substantive personal content. Where any automated decision-making is deployed in the future, we shall implement appropriate safeguards, including the right of the Data Subject to obtain human intervention, to express their point of view, and to contest the decision, in accordance with applicable law.

27. Children's Privacy

The Platform is not directed to, and is not intended for, persons below the age of majority in their respective jurisdictions. We do not knowingly collect Personal Data from minors, and where the consent of a parent or lawful guardian is required by law in respect of a minor's Personal Data, such consent shall be procured prior to any such Processing. If we become aware that Personal Data of a minor has been collected without verifiable parental consent, we shall take prompt steps to delete such data and deactivate the corresponding account. If you believe that we have inadvertently collected the Personal Data of a minor, please notify us immediately at support@urlzy.in.

28. Third-Party Services and External Links

The Platform may contain links to, or integrate functionality from, Third-Party Services, including advertising networks, analytics providers, payment gateways, content-delivery networks, and external social and video platforms such as YouTube, LinkedIn, and Quora. This Policy does not apply to the information practices of such third parties, and we encourage you to review their respective privacy policies. The deployment of cookies or analogous technologies by such Third-Party Services, and the collection, use, and disclosure of information by them, are outside our control, and we bear no responsibility or liability therefor.

29. Data Breach Notification

In the event of a personal-data breach giving rise to a risk to the rights and freedoms of Data Subjects, we shall, without undue delay and, where feasible, within seventy-two (72) hours of becoming aware thereof, notify the competent supervisory authority, unless the breach is unlikely to result in such a risk. Where the breach is likely to result in a high risk to the rights and freedoms of Data Subjects, we shall also communicate the breach to the affected Data Subjects without undue delay, in plain and clear language, describing the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to be taken to address the breach and mitigate its adverse effects, save where we have rendered the data unintelligible through encryption, where subsequent measures have eliminated the high risk, or where notification would involve a disproportionate effort.

30. Grievance Redressal and Contact for Data Concerns

We are committed to the prompt and equitable resolution of any grievance concerning the Processing of Personal Data. Any Data Subject who is aggrieved by a decision of the Platform concerning their Personal Data may file a complaint with us at support@urlzy.in, setting forth the grounds of the grievance in reasonable detail. We shall acknowledge receipt of every such complaint without undue delay and shall endeavour to resolve the same within thirty (30) days of receipt. If you remain dissatisfied with the resolution offered, you may escalate the matter to the Data Protection Board of India or any other competent supervisory authority, as applicable in your jurisdiction.

31. Do Not Track Signals

The Platform may not presently recognise or respond to "Do Not Track" (DNT) signals transmitted by certain browsers. Notwithstanding the foregoing, you retain the ability to manage and restrict cookies, local-storage objects, and analogous tracking technologies directly through the configuration interfaces of your browser, as more particularly described in the Platform's Cookie Policy at /pages/cookies.php, and the Platform does not employ cross-context behavioural advertising that would require DNT compliance.

32. Changes to This Policy

We reserve the right to amend, modify, supplement, or replace this Policy at any time. Any material changes shall be communicated by posting the revised Policy on the Platform, and the date of the latest revision shall be indicated at the top of this page. Where any such amendment constitutes a material change that affects your rights, we shall, to the extent required by applicable law, obtain your consent or provide you with a reasonable period of prior notice. Your continued utilisation of the Platform following the posting of any revised Policy shall constitute your acceptance of such revisions.

33. Contact Information

All enquiries, requests, and notices concerning this Policy or your Personal Data shall be directed to: support@urlzy.in. We shall use commercially reasonable efforts to respond to all bona fide enquiries within a reasonable period. For the purposes of the Digital Personal Data Protection Act, 2023 (India), the platform operator acts as the Data Fiduciary in respect of the Processing activities described herein, and all grievance communications shall be addressed to the designated contact at the aforementioned address.