Privacy Policy
Neon Deer Data Labs Inc. operates checkredirects.io. This policy describes how we handle your personal data.
What we collect
- Accounts and organizations: Names, email addresses, user and organization identifiers, roles, invitations, sign-in details, API-key records, usage information and support-access settings. We record which Terms you accepted, when and how you accepted them, and related email, IP address and browser information.
- Inspection inputs: Complete URLs and any information they contain, including credentials; request headers and cookies; additional fields you provide; and inspection, saved configuration, monitor, integration and export settings. We do not save one-time request headers, cookies or authentication settings with inspection records. Submitted URLs, saved settings and credentials, additional fields and results may be stored.
- Inspection results: Inspected and destination URLs, redirect sequences, response and error details, network addresses and locations, connection security and performance information, page information and additional fields you provide.
- Integrations, support and security: Google Sheets connection credentials and spreadsheet identifiers; export, delivery, usage and retention records; and records of support and administrative access. These can include user identifiers, IP addresses, actions taken and the types of information accessed.
- Communications: Email recipients and complete message contents. Product emails use contact and organization details, roles, plan and billing information, usage and product activity, invitations, referrals and rewards, dates and product links, subject to the data-collection setting below.
- Error reporting and website analytics: Sentry receives error reports and performance information, which may include error messages, URL paths, request details, technical identifiers and account or organization details. Plausible receives public-site page URLs (including query strings), referring pages, website activity, IP addresses and browser/device information. The data-collection setting below controls account details attached to browser reports sent to Sentry.
- Billing: Billing contact and organization details, plan and purchase details, transaction identifiers and status, amounts, currency and receipts. Card details are entered directly with Stripe; we do not store card numbers.
How we use your data
- To provide, support and secure the inspection service
- To enforce usage limits and billing
- To improve the product
- To send account notices, usage warnings and product emails
Redirect statistics
Unless an organization opts out in Settings, successful inspections can contribute to combined statistics about redirects between domains. These include domain names and related identifiers, redirect relationships, response information, the browser or other software used for checks, dates and counts. They exclude URL usernames and passwords, paths, query strings and fragments, and the identity of the user or organization requesting the check. A domain may still identify a website operator or individual.
Public sharing and exports
Inspection results are private unless someone in your organization enables a public share link. Shared results omit URL usernames and passwords, information after a URL's ? or #, response headers, network and connection-security details, captured page information and detailed error messages. URL paths remain visible. Do not publish a share link if a path contains sensitive information.
CSV and Google Sheets exports preserve complete stored URLs, including usernames and passwords, query strings, fragments and paths. Anyone with access to the exported file or Sheet can read those values.
Data storage
We store service data in a hosted database. Google Sheets connection credentials are encrypted at rest using AES-256-GCM. API keys are stored as one-way SHA-256 hashes.
Third-party services
See our service providers and other data recipients for the services and destinations that receive data and the information each receives.
Data collection settings
You can turn off data collection in Organization Settings. This stops contributions to redirect statistics and product emails, and removes the user and organization profile attached to browser error reports. Error reporting continues and may include technical identifiers and details about the error. Security and billing records and essential account emails are unaffected.
Plausible measures visits to our public website separately and is not controlled by this setting. See our list of service providers for details.
Your rights
You can:
- Have an organization owner delete the organization through Settings, subject to the retention and deletion details below
- Export inspection results using the CSV export feature
- Request access to personal data we hold about you by contacting [email protected]
We may need to verify your identity and authority before releasing information.
Data retention
Details of individual redirects are retained for 7 days on Free, 30 days on Pro and 90 days on Business. Result summaries and associated check history are retained for 30 days on Free, 90 days on Pro and 6 months on Business. Expired records are removed through regular cleanup. The retention period is based on the plan recorded for each result; changing plans does not alter the retention periods of existing results.
Deleting an organization removes its records and stored credentials from our main application database. Certain security, audit and Terms-acceptance records may remain after direct account identifiers are removed. Service providers' records follow separate retention schedules and are not automatically erased. We coordinate required deletion by our appointed subprocessors; their policies do not override our obligations under applicable law or any DPA. Requests concerning copies held by destinations you selected must be made directly to them.
Contact
Contact [email protected] for privacy requests or [email protected] for customer requests under a DPA.