gecis.inBack to home

Privacy Policy

Last updated: 3 September 2026

What we collect when you use gecis.in, why we collect it, and how long we keep it. Written to be understood rather than to be short.

1. What we collect

When you shorten a link: the destination address, the time it was created, and a hash of your IP address salted with a value that rotates daily. Your raw IP address is not stored at this step — only the hash, and only so the abuse limits can be enforced.

When someone clicks a short link: the time of the click, the visitor's IP address, a hash of that IP address, a visitor key, country, region, city, continent and approximate coordinates, device type, vendor and model, browser and version, operating system and version, rendering engine, the raw User-Agent string, the referring domain and full referring URL, the utm_source, utm_medium, utm_campaign, utm_term and utm_content parameters, how the click was triggered, and whether it looked automated. Twenty-eight fields in total, listed individually on the home page.

When you join the waitlist: your email address and the plan you picked.

When you report a link: the link, the reason, your description, your email address if you chose to leave one, and a hash of your IP address.

2. Why we collect it

The click data is the service. It exists so that whoever created a link can see how that link performed. The IP hashes and the rate-limit counters exist to keep the shortener from becoming a phishing tool. Email addresses are used for the waitlist announcement and nothing else. We do not profile you, we do not build audiences, and we do not sell anything to advertisers.

3. Cookies

There are no tracking cookies on this site. The only cookie we set is gecis_locale, which remembers whether you chose English or Turkish.

Unique visitors are counted without cookies: the IP hash and a hash of the User-Agent are combined into a visitor key, using a salt that rotates every day. The same person on the next day produces a different key, so the value can count a day but cannot follow a person across days.

4. How long we keep it

Raw IP addresses are kept for at most 90 days. The click table is partitioned by month and expired partitions are dropped whole, so the raw addresses in them are destroyed irreversibly rather than marked for deletion.

IP hashes, visitor keys and the rest of the click statistics are kept for as long as the link exists. They cannot be reversed into an IP address.

Waitlist emails are kept until the service launches, or until you ask us to delete yours.

5. Who else sees it

We do not sell your data and we do not share it for advertising. Two processors are involved: Cloudflare, Inc. for traffic management, bot protection and the country header, and Hetzner Online GmbH in Germany, whose data centre houses the hardware we run on. There is no third-party analytics script on this site. We disclose data to authorities only where we are legally obliged to.

6. Security

All traffic is served over TLS. The database is not reachable from the public internet and is accessed only through the application's own service account. Destination validation refuses any target that resolves to a private, local or reserved address, which also protects our infrastructure from being used as a proxy.

7. Your rights

You can ask us what we hold about you, ask for it to be corrected, and ask for it to be deleted. Write to [email protected] and we will answer within 30 days.

For a request about a raw IP address we need the approximate time of the click and the short link involved. Without those two things we have no way to find the row, because nothing in our data connects an IP address to a name.

If you are in Türkiye, your rights under Law No. 6698 (KVKK) and the exact procedure for exercising them are set out in the KVKK disclosure.

8. Contact