Privacy Policy

How we collect, use, and protect your information

Last updated: January 2025

Our Commitment to Your Privacy

At SafGo, your privacy is fundamental to everything we do. This policy explains how we collect, use, store, and protect your information when you use our link management platform. We believe in transparency and give you control over your data.

1. Information We Collect

We collect different types of information to provide and improve our services. This includes information you provide directly, information collected automatically, and information from third-party sources when you connect your accounts.

Information You Provide

When you register for an account or use our services, you may provide:

  • Account Information: Email address, password, name, profile picture, and contact details
  • Billing Information: Payment method details, billing address, and tax information (processed securely through Stripe)
  • Communication Data: Messages you send us, support requests, and feedback
  • Link Content: URLs you shorten, custom aliases, descriptions, and metadata you add
  • Preferences: Communication preferences, dashboard settings, and feature configurations

Information Collected Automatically

When you use SafGo, we automatically collect certain information for analytics and service improvement:

  • Click Analytics: Timestamps, geographic location (country/city level), referrer sources, and device information for links you create
  • Device Information: Browser type and version, operating system, device type, screen resolution, and language preferences
  • Network Information: IP address (anonymized for analytics), ISP, and connection type
  • Usage Patterns: Pages visited, features used, time spent, and interaction patterns within our platform
  • Performance Data: Error logs, loading times, and technical performance metrics

Information from Third Parties

With your permission, we may receive information from:

  • Social Media Platforms: Profile information when you connect social accounts for analytics integration
  • Analytics Providers: Aggregated data about website performance and user behavior
  • Integration Partners: Data from tools you connect to SafGo through our API or integrations

2. How We Use Your Information

We use the information we collect for specific, legitimate purposes that benefit you and improve our services. We never sell your personal data or use it for purposes beyond what's described here.

Core Service Operations

  • Account Management: Creating and maintaining your account, authenticating your identity, and providing customer support
  • Link Management: Creating shortened links, tracking clicks, generating QR codes, and providing analytics insights
  • Payment Processing: Processing subscription payments, managing billing cycles, and handling refunds
  • Platform Security: Preventing fraud, detecting abuse, monitoring for security threats, and maintaining system integrity

Communication

  • Essential Notifications: Account security alerts, billing notifications, and important service updates
  • Customer Support: Responding to your questions, resolving technical issues, and providing assistance
  • Product Updates: New feature announcements and educational content (only with your consent)

Service Improvement

  • Analytics and Insights: Understanding how users interact with our platform to improve user experience
  • Feature Development: Developing new features based on usage patterns and user feedback
  • Performance Optimization: Monitoring system performance and optimizing speed and reliability
  • Personalization: Customizing your dashboard and recommending relevant features

Legal and Compliance

  • Regulatory Compliance: Meeting legal obligations and regulatory requirements in jurisdictions where we operate
  • Dispute Resolution: Resolving disputes, enforcing our terms of service, and protecting our rights
  • Safety and Security: Preventing misuse of our platform and protecting users from harmful content

3. Information Sharing and Disclosure

We never sell your personal information. Your data is not a product. We only share your information in the specific circumstances outlined below, and always with appropriate safeguards in place.

Service Providers

We work with trusted third-party service providers to operate our platform:

  • Cloud Infrastructure: AWS and Google Cloud for hosting, data storage, and content delivery
  • Payment Processing: Stripe for secure payment processing and subscription management
  • Email Services: SendGrid for transactional emails and notifications
  • Analytics: Analytics providers for understanding platform usage (with anonymized data)
  • Customer Support: Support platforms to help us respond to your questions efficiently

All service providers are bound by strict data processing agreements and can only use your information to provide services to us.

Legal Requirements

We may disclose your information when required by law or when we believe disclosure is necessary to:

  • Comply with legal process, court orders, or government requests
  • Enforce our Terms of Service or investigate potential violations
  • Protect the rights, property, or safety of SafGo, our users, or the public
  • Prevent fraud, security breaches, or other illegal activities

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity. We will notify you via email and/or prominent notice on our website before your information becomes subject to a different privacy policy.

With Your Consent

We may share your information with third parties when you explicitly consent, such as when you connect third-party integrations or choose to share analytics data publicly.

Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot identify individual users for industry research, business intelligence, and platform improvement purposes.

4. Data Security and Protection

Protecting your data is our top priority. We implement comprehensive security measures and follow industry best practices to safeguard your information against unauthorized access, breaches, and other security threats.

Technical Safeguards

  • Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
  • Secure Infrastructure: Hosted on enterprise-grade cloud platforms with built-in security features and compliance certifications
  • Access Controls: Multi-factor authentication, role-based access, and principle of least privilege for all system access
  • Network Security: Firewalls, intrusion detection systems, and regular penetration testing
  • Data Backup: Regular automated backups with encryption and geographically distributed storage

Organizational Measures

  • Employee Training: Regular security awareness training and data protection education for all team members
  • Access Management: Strict controls on who can access personal data, with regular access reviews and immediate revocation upon role changes
  • Incident Response: Comprehensive incident response plan with procedures for detection, containment, and notification
  • Vendor Management: Due diligence and ongoing monitoring of all third-party service providers

Monitoring and Auditing

  • Continuous Monitoring: 24/7 security monitoring with automated threat detection and alerting
  • Regular Audits: Internal and external security audits, vulnerability assessments, and compliance reviews
  • Activity Logging: Comprehensive logging of all access to personal data with tamper-proof audit trails

5. Data Retention and Deletion

We only retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, or resolve disputes. Our retention practices balance your privacy rights with our legitimate business needs.

Retention Periods

  • Account Data: Retained while your account is active and for 90 days after account closure for reactivation purposes
  • Link Data: Retained while your account is active; individual links can be deleted at any time
  • Analytics Data: Aggregated analytics retained for up to 5 years for business intelligence; individual click data retained for 2 years
  • Billing Records: Retained for 7 years to comply with financial and tax regulations
  • Support Communications: Retained for 3 years for customer service quality and training purposes
  • Security Logs: Retained for 1 year for security monitoring and incident response

Data Deletion Process

When data reaches the end of its retention period or you request deletion:

  • Personal data is securely deleted from our active systems within 30 days
  • Backup copies are overwritten during the next backup cycle (within 90 days)
  • Data required for legal compliance may be retained in secure, isolated systems
  • Anonymized or aggregated data may be retained indefinitely for analytics purposes

6. Your Privacy Rights and Choices

You have important rights regarding your personal information. We respect these rights and provide easy ways for you to exercise them. Depending on your location and applicable laws (including GDPR, CCPA, and other privacy regulations), you may have the following rights:

Data Access and Portability

  • Right to Access: Request a copy of your personal data and information about how we process it
  • Data Portability: Receive your data in a structured, machine-readable format to transfer to another service
  • Account Dashboard: Access and download most of your data directly through your SafGo dashboard

Data Correction and Control

  • Right to Rectification: Correct inaccurate or incomplete personal information
  • Account Settings: Update your profile, preferences, and communication settings at any time
  • Link Management: Edit, disable, or delete individual links and their associated data

Data Deletion and Restriction

  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Account Deletion: Permanently delete your entire account and associated data
  • Right to Restriction: Limit how we process your data in certain circumstances

Communication and Processing

  • Marketing Opt-out: Unsubscribe from marketing emails while continuing to receive essential account notifications
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Consent Withdrawal: Withdraw consent for processing that requires your consent

How to Exercise Your Rights

To exercise any of these rights:

  • Use your account dashboard for most data management tasks
  • Email us at support@safgo.io with your specific request
  • We will respond within 30 days (or as required by applicable law)
  • We may need to verify your identity before processing certain requests

Important: These rights are not absolute and may be limited by applicable law or our legitimate business interests. We will explain any limitations when responding to your request.

7. Cookies and Tracking Technologies

We use cookies, pixels, and similar technologies to enhance your experience, analyze usage patterns, and improve our services. We believe in transparency about these technologies and give you control over non-essential cookies.

Types of Cookies We Use

  • Essential Cookies: Required for basic platform functionality, including authentication, security, and core features. These cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with our platform, identify popular features, and improve user experience.
  • Preference Cookies: Remember your settings, dashboard configurations, and personalization choices.
  • Performance Cookies: Monitor system performance, loading times, and technical metrics to optimize our platform.

Third-Party Tracking

We may use third-party services that set their own cookies:

  • Analytics Providers: Help us understand aggregate usage patterns (data is anonymized)
  • Payment Processors: Enable secure payment processing for subscription services
  • Support Tools: Provide customer support features and improve service quality

Managing Cookies

You have several options for managing cookies:

  • Browser Settings: Configure your browser to block or delete cookies (may affect functionality)
  • Cookie Preferences: Manage non-essential cookies through our cookie preference center
  • Opt-out Links: Use direct opt-out links provided by third-party services

8. International Data Transfers

SafGo operates globally from our headquarters in Hong Kong. To provide our services, your information may be transferred to, stored, and processed in countries other than your own. We ensure appropriate safeguards are in place for all international transfers.

Data Processing Locations

  • Primary Infrastructure: Asia-Pacific regions for optimal performance and data residency
  • Backup and Recovery: Geographically distributed backups in secure, compliant data centers
  • Service Providers: Trusted partners in various countries, all subject to strict data protection agreements

Transfer Safeguards

For transfers outside your country, we implement appropriate safeguards:

  • Adequacy Decisions: Transfer to countries with adequate data protection levels as recognized by relevant authorities
  • Standard Contractual Clauses: Legally binding agreements that ensure the same level of protection as in your country
  • Certification Programs: Work with service providers certified under recognized international privacy frameworks
  • Technical Measures: Strong encryption, access controls, and monitoring for all international data flows

9. Children's Privacy

SafGo is designed for business and professional use and is not intended for children. We are committed to protecting the privacy of minors and comply with applicable laws regarding children's data protection.

Age Restrictions

  • Minimum Age: SafGo is not intended for individuals under 13 years old (or the minimum age in your jurisdiction)
  • Teen Users (13-17): May use SafGo with parental consent for educational or supervised purposes only
  • Business Accounts: Full access requires users to be 18 years or older

Protection Measures

  • We do not knowingly collect personal information from children under 13
  • We do not target advertising or marketing to minors
  • If we discover we have collected information from a child under 13, we will delete it promptly
  • Parents or guardians can contact us to review, update, or delete their child's information

10. Changes to This Privacy Policy

We may update this privacy policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We are committed to keeping you informed about any changes that affect your privacy rights.

How We Notify You

  • Material Changes: We will email you at least 30 days before significant changes take effect
  • Minor Updates: Posted on this page with an updated "Last updated" date
  • In-App Notifications: Important changes may also be announced through your SafGo dashboard
  • Legal Requirements: Changes required by law may be implemented immediately with prompt notification

Your Options

When we make changes:

  • Review the updated policy carefully to understand how your data will be handled
  • Contact us if you have questions or concerns about the changes
  • If you disagree with material changes, you may close your account before they take effect
  • Continued use of SafGo after changes take effect constitutes acceptance of the updated policy

11. Contact Us and Data Protection Officer

We welcome your questions, concerns, and feedback about this privacy policy and our data practices. Our team is committed to addressing your privacy-related inquiries promptly and thoroughly.

General Privacy Inquiries

  • Email: support@safgo.io
  • Response Time: We aim to respond within 48 hours
  • Website: https://safgo.io/contact
  • Business Address: Hong Kong

Data Subject Rights Requests

For requests related to your privacy rights (access, deletion, portability, etc.):

  • Email: support@safgo.io with "Privacy Rights Request" in the subject line
  • Required Information: Include your account email and specific request details
  • Verification: We may need to verify your identity before processing requests
  • Response Time: Within 30 days (or as required by applicable law)

Security Incidents

If you believe there has been a security incident involving your data:

  • Immediate Reporting: support@safgo.io with "Security Incident" in the subject line
  • Emergency Contact: Available 24/7 for urgent security matters

Regulatory Authorities

You have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your privacy concerns adequately. We encourage you to contact us first so we can work to resolve any issues directly.

Privacy Policy Summary

This policy was last updated on January 2025. It covers how SafGo collects, uses, shares, and protects your personal information. We are committed to transparency, giving you control over your data, and protecting your privacy rights under applicable laws including GDPR, CCPA, and other international privacy regulations.