Privacy policy
We never store a raw IP address. Scans are counted by country, coarse region and device — and by a hash that is re-salted every day, so it cannot be traced to a person or followed across dates.
Last updated 2026-08-31
1. Who we are
Klip is a short link and QR code service operated from Nairobi, Kenya by Githu Kelvin. This policy covers klipqr.com, the Klip dashboard at app.klipqr.com, the Klip API, and every short link or QR code that resolves through us. We are the data controller for the information described below. You can reach us at hello@klipqr.com.
Two different people appear in this policy and they are treated differently. A customeris someone with a Klip account who creates links. A scanner is someone who scans a printed code or clicks a link — usually a stranger to us, who never agreed to anything and often does not know Klip exists. Almost every design decision below exists because of that second person.
2. What we collect
If you have an account
| Data | Why |
|---|---|
| Email address and name | To identify your account, verify it is yours, and contact you about the service |
| Workspace name and plan | To apply the right limits and bill the right amount |
| API keys | Stored as a SHA-256 hash plus the first eight characters for display. We cannot recover a key you have lost — only issue a new one |
| Your links | The destination URL, the short code, and when it was created or changed |
When someone scans a code or clicks a link
This is the part worth reading carefully, because it is where a link shortener normally collects the most and says the least. One row is written per scan. It contains, in full:
| Field | Example | Note |
|---|---|---|
| Which link | 7hK2mQx | And which workspace owns it |
| Scan or click | qr / link / bot | Chat-app previews are recorded as bots, not counted as people |
| Country | KE | Two-letter code, from the network edge |
| Region | Nairobi County | Coarse subdivision. Never a city-level or street-level position |
| Device class | mobile | Mobile, tablet or desktop |
| Operating system | android | Which camera app scanned it, effectively |
| Referring host | chatgpt.com | The site the click came from, hostname only |
| Referring URL | truncated to 128 characters | See the note directly below |
| Edge location | NBO | Which of our provider's data centres served it |
| Visitor hash | a3f2c1d4e5b60789 | See "the hash" below |
| Time | timestamp | Used for time-of-day reporting |
About the referring URL. When a click arrives from another website, the browser tells us which page it came from. We store the hostname as its own field — that is the one we report on — and also keep the first 128 characters of the full address. A full referring address can in principle carry personal data in its query string, put there by the site that linked to you and not by us. We do not display it to anyone, we do not query it, and it expires with the rest of the scan data. We are removing this field entirely; until then it is disclosed here rather than left unmentioned.
To tell one scanner from two we need something stable, and the obvious thing to use is the IP address. We do not store it. Instead we combine the address with a secret that isreplaced every day, hash the result, and keep the first eight bytes of that.
Two consequences follow, and both are deliberate. The hash cannot be turned back into an address — not by us, not by anyone who obtained our database. And because yesterday's secret is gone and was never written down, the same person scanning on two days produces two unrelated hashes. We can therefore report "how many of today's scans were repeats" and we are structurally unable to build a profile of anyone across time. Our own analytics screen says "same-day repeat scans" for exactly this reason, rather than the "unique visitors" every competitor claims.
3. What we never collect
- Raw IP addresses. Not stored, not logged for analytics, not retained.
- Precise location. Country and coarse region only. No GPS, no city pin.
- Anything about the destination. We redirect you to a site; we do not read that site, inject anything into it, or follow you once you arrive.
- Cross-site tracking of scanners. A redirect sets no cookie. There is nothing to carry from one scan to the next.
- Interstitials or ads on the redirect path. Nothing loads between the scan and the destination — no ad script, no consent frame, no "you are being redirected" page. This is a product commitment as much as a privacy one.
4. Cookies and advertising
Short links and QR codes set no cookies at all. The redirect is a single response that sends the browser onward.
On this marketing site and in the dashboard:
- Your theme choice (light, dark or system) and the dashboard's sidebar state are kept in your browser's local storage. They never leave your device.
- Sign-in uses a session cookie, without which the dashboard cannot know it is you.
- Google Analytics measures which pages people read. It is configured with consent defaulting to denied for analytics and advertising storage, which means it currently writes no cookie and reports aggregate traffic only. If we later ask for consent, granting it is what turns cookies on; refusing keeps things exactly as they are today.
- Google AdSense. We intend to show ads on guides and tool pages — never on the redirect path. When we do, Google and its partners may use cookies to serve ads based on your prior visits to this and other sites, and we will ask for your consent first where the law requires it. You can control this atMy Ad Center and reviewhow Google uses data from sites that use its services. At the time of writing no advertising script is loaded anywhere on this site.
5. Why we are allowed to process it
- To perform our contract with you — running your account, resolving your links, and producing the analytics you are paying for.
- Our legitimate interests — keeping the service up, counting scans in aggregate, and detecting phishing, malware and spam. Shorteners are abused within days of launch, and the checks that prevent it are the reason a Klip link is not blocklisted by association.
- Your consent — for advertising cookies and any non-essential analytics cookie, asked for separately and withdrawable at any time.
- Legal obligation — where we must retain or disclose something, for example a valid court order.
6. Who else handles it
We keep this list short on purpose. Every name here processes data on our instructions.
| Who | What they do for us | Where |
|---|---|---|
| Cloudflare | Serves every page and redirect; stores the link cache, rendered QR images and scan events | Global edge network |
| Neon (on Amazon Web Services) | The main database: accounts, links, daily analytics totals | AWS eu-central-1 (Frankfurt, Germany) |
| Google (Analytics) | Page analytics for this marketing site only | Global |
| Google (AdSense) | Advertising on content pages, once it ships | Global |
We do not sell personal data, and we do not share it with advertisers, data brokers or third-party analytics beyond what is listed here. When we add or replace a processor this table changes on the same day.
7. Where it is stored
Our database is hosted in AWS eu-central-1 (Frankfurt, Germany). If you are in Kenya, that means your data leaves the country, which the Data Protection Act 2019 treats as a cross-border transfer; we rely on the safeguards our processors provide, including the European Commission's standard contractual clauses, and on the destination being a jurisdiction with a comparable protection regime. If you are in the European Economic Area or the United Kingdom, your data is processed within the EEA by default. Scan events are processed at whichever edge location is nearest the person scanning, which is what makes a redirect fast, and are aggregated into the same database.
8. How long we keep it
- Account and link data: for as long as the account exists. See the note on deletion below — links are a special case, on purpose.
- Raw scan events: about 90 days, then they age out of the store automatically. We do not choose this per record; the store expires them.
- Daily totals: aggregated counts with no visitor hash in them, kept for as long as your plan's retention window says — 7 days on Free, 365 days on Starter, indefinitely on Studio.
- The daily salt: replaced every 24 hours and never recorded, which is what makes yesterday's hashes permanently unresolvable.
9. Your rights
Under Kenya's Data Protection Act 2019 and, where it applies, the GDPR, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it in a portable form. Write to hello@klipqr.com and we will respond within 30 days. You can complain to Kenya's Office of the Data Protection Commissioner, or to your local supervisory authority in the EEA or UK.
Scan events cannot be deleted individually. The store they live in has no delete operation — that is a property of the technology, not a policy choice. What we can say is that those rows contain no name, no email, no account identifier and no IP address; the only field that could identify anyone is a hash whose key is destroyed daily; and everything in them expires by itself within about 90 days. If you ask us to erase your data we delete everything we can delete and tell you plainly that this category expires rather than being erased on request.
Deleting your account does not immediately break your printed codes. Someone standing in front of a poster you printed last year is not a party to your decision to leave. When an account is closed, dashboard access ends at once and your links keep resolving for 30 days, after which they show a plain "this code has been turned off" page rather than an error. If you need a link dead immediately, disable it before you close the account — that takes effect worldwide within about 30 seconds.
10. Security
Traffic is HTTPS-only and the site is served with HSTS. API keys are stored as hashes, never in a form we could read back to you. Every query in the API is scoped to one workspace, and we test that isolation against production by trying to reach another account's links and confirming the answer is "no such link" rather than "not allowed" — because the second answer confirms the link exists. No system is perfectly secure, and if a breach affects your personal data we will notify you and the relevant authority as required.
11. Children
Klip is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to us and we will remove it.
12. Changes and contact
When this policy changes the date at the top changes with it, and it is generated from the file itself rather than typed by hand, so it cannot quietly fall out of date. Material changes will be announced to account holders by email before they take effect.
Questions, requests and complaints:hello@klipqr.com. Our terms of service cover what we owe each other on the service itself.