Cookie Policy
Last updated: August 16, 2026
1. What are cookies?
Cookies are small text files placed on a computer or mobile device when a website is used. They can remember actions and preferences, such as login state, so information does not need to be entered again on every visit. Similar technologies include local storage and web beacons (also called pixels); this policy covers those technologies as well.
2. How we use browser storage
UrlShorter uses cookies and similar browser storage for these purposes:
- Keeping you signed in and securing the session;
- Remembering eligible guest links created without an account;
- Remembering the cookie choice so the banner does not appear on every page;
- Controlling optional analytics and advertising loaders according to that site choice.
Essential storage is set when the related feature is used. Choosing "Essential only" prevents UrlShorter's optional analytics and advertising loaders, but it does not disable storage needed for sign-in, guest ownership, security, or an aggregate public-page view counter.
3. Storage set by UrlShorter
| Name | Storage and duration | Purpose |
|---|---|---|
| urlshorter_session | Signed, HttpOnly cookie; up to 7 days | Authenticates the current account and carries the signed session fields needed for access checks. |
| urlshorter_oauth_state | Signed, HttpOnly cookie; up to 10 minutes | Correlates and validates an in-progress Google sign-in flow. |
| urlshorter_guest_history | Signed, HttpOnly cookie; up to 30 days | Stores a limited set of signed short-code ownership claims used to refresh guest statistics or adopt eligible links after sign-in. |
| guest_pages | Signed, HttpOnly cookie; up to 30 days | Stores up to 20 guest hosted-page identifiers so the same browser can edit or delete those pages. Guest page records are also configured to expire after 30 days. |
| page_viewed_<id> | HttpOnly cookie; 30 minutes | Stops the same browser from repeatedly increasing a supported public page's aggregate view total during the 30-minute window. It is not used as an advertising profile. |
| urlshorter_user_links | First-party cookie readable by the app; up to 1 year | Caches link summaries, including destinations, codes, click totals, dates, and active state, for dashboard feedback. Server authorization remains authoritative. |
| sidebar_state | First-party cookie; up to 7 days | Remembers whether the dashboard sidebar was expanded or collapsed. |
| urlshorter_cookie_consent | Local storage; until removed by the visitor or browser | Records "accepted" or "essential" so optional scripts can follow the choice on later visits. |
The browser may also hold a urlshorter_guest_history local-storage entry containing up to 50 recently created guest-link summaries. It remains until the visitor clears browser data or the application replaces it. This local display cache and the signed HttpOnly ownership cookie have the same name but are separate browser storage mechanisms.
4. Optional providers and processing
If an optional provider client is loaded, Google or another third party may place or read third-party cookies and use web beacons, pixels, IP addresses or other network identifiers, and similar technologies. Requests can include device and browser information, page and referrer URLs, and analytics or advertising interaction data. Google explains how it handles information from partner sites in How Google uses information from sites or apps that use its services.
- Optional analytics.When Google Analytics is configured, its browser script is loaded only after you choose "Accept all." Hosting and performance providers may also process limited request and performance data needed to operate and diagnose the service; those operational measurements are distinct from optional advertising profiles.
- Advertising cookies. Eligible public content pages may display ads served by Google AdSense where advertising is configured. After a visitor chooses "Accept all" in the site controls, UrlShorter may load the optional advertising client, and Google and its partners may use cookies or similar technologies to serve and measure ads under their own policies. Read Google's advertising technology policy.
- Provider-set names and duration. Google and other configured providers control the exact cookie names and lifetimes they set. Common Google names can include prefixes such as
_ga,_gid,_gcl,__gads, or__gpi; the applicable provider policy is authoritative.
The site control determines whether UrlShorter attempts to load its optional browser clients. It does not delete provider storage already present, control processing on external sites, indicate that a provider has reviewed or approved UrlShorter, or represent that one selection satisfies every jurisdiction's requirements.
6. Cookies and short-link redirects
When someone opens a short link, UrlShorter may process the timestamp, referrer, user agent, and network-derived information needed to serve the redirect, protect the service, and summarize link activity. The account product currently promises click totals and recent activity rather than identity-level visitor profiles. This measurement happens server-side during the redirect; UrlShorter does not set an optional analytics or advertising cookie merely because someone follows a short link. Details are in the Privacy Policy.
7. Changes to this policy
This Cookie Policy may be updated as the service, providers, or legal requirements change. The "Last updated" date above identifies the latest published revision.
8. Contact
Questions about this policy can be submitted through the contact form.