Security & Compliance

Clear data practices,
minimal storage

Klinky stores only the data needed to run your links, account, and analytics. Persistent product data is kept with established infrastructure providers.

Minimal data collection
GDPR-aware operations
EU-based core storage

EU-based core storage

Klinky stores core account, link, and analytics records with EU-based services where practical. Redirects are processed at Cloudflare's global edge for speed, while persistent product records stay with the services listed here.

This isn't a feature you pay extra for. It's how Klinky works.

Database: Frankfurt, Germany

Core product data is stored in Supabase's EU region with encryption at rest.

Compute: Amsterdam, Netherlands

Application servers run on Fly.io's European infrastructure.

Backups: Core Provider Controls

Backup handling follows the controls of the core infrastructure providers.

We only store what we need

No tracking. No profiling. No data selling.

What we store

  • Your email address

    For account access and billing notifications

  • Billing information

    Handled securely by Stripe. We don't store card details.

  • Link data

    Your short links, destination URLs, and click counts

  • Click analytics

    Timestamp, referrer, and country (anonymized IP addresses)

What we don't store

  • Personal identifiable information

    We don't collect names, addresses, or phone numbers

  • Visitor tracking data

    No cookies for tracking individual users across sites

  • Marketing data

    No behavior profiling or advertising identifiers

  • Third-party sharing

    Persistent product data stays with the core services listed above

We store the minimum needed to run the service and charge you fairly. Nothing more.

Built on established infrastructure providers

We rely on mature infrastructure providers and keep the product data model intentionally small.

Provider-level assurance

These are provider-level controls and reports, not Klinky certifications. They support Klinky's vendor review and security posture. They do not make Klinky independently SOC 2 or ISO 27001 certified.

  • Supabase: SOC 2 Type 2 compliant and ISO 27001 certified
  • Fly.io: SOC 2 Type 2 certified; hardware in ISO 27001 datacenters
  • Cloudflare: SOC 2 Type II report for covered services
  • Stripe: annual SOC 1 and SOC 2 Type II reports; PCI Service Provider Level 1

How data moves through Klinky

Each provider receives the slice of information needed for its role. This keeps the service inside audited provider environments where practical, while Klinky remains responsible for application logic, access controls, vendor choices, and customer commitments.

Cloudflare

Cloudflare receives the public request, applies edge security, and routes redirects or app traffic.

Fly.io

Fly.io runs the application logic for link creation, link lookup, redirects, and API requests.

Supabase

Supabase stores core account, link, and analytics records in the configured EU database region.

Stripe

Stripe handles billing and card processing. Klinky does not store card details.

Supabase

Database & Authentication

  • Hosted database in Frankfurt
  • Authentication and database provider
  • AES-256 encryption at rest
  • TLS-encrypted connections
  • Role-based access controls

Fly.io

Application Hosting

  • API hosting for the current backend
  • European application region
  • HTTPS for API traffic
  • Operational monitoring
  • Isolated application runtime

Cloudflare

Edge Network & Security

  • DDoS protection and WAF
  • 275+ global edge locations
  • TLS encryption for all traffic
  • No persistent data at edge
  • Fast redirect and asset delivery

Note on edge processing: While link redirects process at Cloudflare's global edge for speed, edge processing is transient. Core product data is stored with EU-based services where available, while edge services keep redirects fast.

Security by default

256-bit SSL/TLS

All traffic encrypted in transit

AES-256 Encryption

Data encrypted at rest

DDoS Protection

Cloudflare shields against attacks

Automatic Updates

Security patches applied automatically

Questions about security?

We're happy to provide additional information or discuss your specific compliance requirements.