Privacy Policy
Effective Date: January 12, 2026
This Privacy Policy ("Policy") describes how Studio Next Steps LLC and its affiliates (collectively, "QubitLink", "we", "us", or "our") collect, use, and disclose information about you when you use our website, API, software, and services (collectively, the "Services"). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this privacy notice or our practices with regard to your personal information, please contact us at privacy@qubitlink.co.
By accessing or using our Services, you acknowledge that you have read this Policy and understand its content. This Policy applies to all information collected through our Services, as well as any related services, sales, marketing, or events.
1. Information We Collect
We collect information that you strictly provide to us, information specifically necessary for the functionality of our URL shortening and analytics services, and information automatically collected when you use our Services.
1.1 Information You Provide to Us
- Account Registration Data: When you register for an account, we collect your full name, email address, password (which is cryptographically hashed and not visible to us), and optional profile information such as a profile picture. If you use our Social Login features (e.g., "Continue with Google"), we collect your basic profile information from the identity provider, including your name, email, and Google ID.
- Billing Information: If you subscribe to a paid plan (Pro or Ultra), you must provide billing information such as your credit card number and billing address. This information is collected and processed directly by our third-party payment processor, Stripe. We do not store full credit card numbers on our servers.
- User Content: We collect the content you create using our Services, specifically the long URLs you submit for shortening ("Original URLs"), the custom aliases you create, link titles, tags, and any custom Landing Page content (text, images, external links) you publish.
- Communications: If you contact us directly, we may receive additional information about you such as your name, email address, the contents of the message and/or attachments you may send us, and any other information you may choose to provide.
1.2 Information We Collect Automatically
When you use our Services, or when users visit the shortened links you create, we automatically collect certain information.
- Usage Data & Logs: We log information about your use of the Services, including the type of browser you use, access times, pages viewed, your IP address, and the page you visited before navigating to our Services.
- Link Analytics Data: A core feature of QubitLink is providing analytics. When a user interacts with a QubitLink shortened URL, we automatically collect:
- IP Address: Used to derive approximate geolocation (Country, City) and for security auditing.
- Device Information: Device type (Desktop, Mobile, Tablet), Operating System (iOS, Android, Windows), and Browser type.
- Referrer Data: The website or application where the link was clicked (e.g., Facebook, Twitter, Email).
- Timestamp: The exact date and time of the interaction.
- Cookies and Similar Technologies: We use cookies, local storage, and similar tracking technologies to track the activity on our Service and hold certain information (e.g., authentication tokens).
2. How We Use Your Information
We verify and process your personal information for legitimate business interests, the fulfillments of our contract with you, compliance with our legal obligations, and/or your consent.
2.1 Providing and Improving the Service
- To create and manage your account and user profile.
- To provide the URL redirection service and generate QR codes.
- To process payments and manage subscriptions.
- To analyze usage trends and improve user experience.
- To provide customer support and respond to user requests.
2.2 Security and Safety (QubitShield)
We employ an advanced security system, QubitShield, to ensure the safety of our platform and the internet community. We use information (including submitted URLs and metadata) to:
- Scan Destination URLs: We automatically scan all submitted URLs for malware, phishing attempts, ransomware, and other malicious content.
- AI Analysis: We utilize Artificial Intelligence models to analyze URL patterns and metadata to detect evolving threats and social engineering attacks. To continuously improve the safety of our platform, information processed by QubitShield for security analysis is used to train and refine our AI models to better identify new and emerging threats.
- Threat Intelligence: We verify URLs against third-party threat intelligence databases to block known malicious entities.
- Enforce Policies: To detect and block prohibited content types, including specific technical abuses (e.g., infinite redirect loops, deep web .onion links) and unauthorized content categories (e.g., non-consensual sexual content).
2.3 AI-Powered Features
If you consent to use our optional AI features (e.g., "Generate Title", "AI Summary"), we process the visible text content of your destination URL using Large Language Models (LLMs) to generate relevant titles or summaries. This data is processed under a strict Zero Data Retention (ZDR) policy. We do not use your data to train our AI models, and all inputs are discarded immediately after processing.
3. Sharing Your Information
We do not sell or rent your personal data to third parties. We may share your information with the following categories of third parties for the purposes described in this Policy:
- Cloud Infrastructure Providers: We use industry-standard cloud providers to host our infrastructure, databases, and file storage. Data is encrypted at rest and in transit.
- Payment Processors: We use Stripe, Inc. for payment processing. Your financial data is handled directly by Stripe in accordance with their privacy policy.
- AI Service Providers: We use third-party AI APIs to provide AI-generated content features. For optional features (e.g., Generate Title, AI Summary), data is processed under strict ZDR agreements. For security-related analysis through QubitShield, data is used to improve our threat detection capabilities and train our specialized security models.
- Authentication Providers: We use secure third-party authentication services for user login and identity management.
- Email Service Providers: We use third-party email delivery services to send system notifications (e.g., verification emails, password resets).
4. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes set out in this Policy.
- Account Data: Retained for the duration of your account's existence. If you request account deletion, all your personal data, including shortened URLs, lead data, and click history, is permanently removed within 30 days.
- Link Analytics: Analytics data retention is determined by your subscription plan. Our systems automatically prune logs older than the following periods:
- Free Plan: Cleared daily if older than 7 days.
- Pro Plan: Cleared daily if older than 30 days.
- Ultra Plan: Cleared daily if older than 365 days.
- Security Logs: Logs related to security incidents (e.g., QubitShield blocks) may be retained for longer periods to assist in abuse prevention and legal compliance.
- Malicious Data Retention (QubitShield): To protect the integrity of our platform and the broader internet community, we permanently retain data specifically identified as malicious (including but not limited to phishing links, malware distribution points, and illicit sensitive content), even after account deletion. This data is anonymized and used exclusively to train QubitShield AI models and enhance our threat detection capabilities. Note: This exception applies only to verified malicious or harmful content; all legitimate, non-malicious user data and links are deleted in accordance with our standard deletion policy upon account termination.
5. International Data Transfers
Our servers are located in multiple regions to provide performance and redundancy. By using our Services, you acknowledge that your information may be transferred to, stored, and processed in countries other than your own (including the United States, Singapore and United Arab Emirates), where data protection laws may differ. We take all necessary steps to ensure your data is treated securely and in accordance with this Policy, including the use of Standard Contractual Clauses (SCCs) where applicable for transfers.
6. Your Rights & Choices
Depending on your location, you may have rights under local data protection laws.
6.1 United States (CCPA/CPRA)
For residents of California:
- Right to Know: You may request details about the categories of personal information we have collected, the sources, and the purposes for collection.
- Right to Delete: You may request the deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: We do not sell your personal information. You have the right to opt-out of the sharing of your personal information for cross-context behavioral advertising. (See our footer for "Do Not Sell or Share My Personal Information").
- Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
6.2 UAE (Dubai - PDPL)
For residents of the UAE:
- Right to Know: You have the right to know what data is being processed.
- Right to Rectification/Erasure: You have the right to correct inaccurate data or request deletion of your personal data.
- Security: We implement robust security measures (e.g., AES encryption) to protect your redirected data.
- Cross-Border Transfer: We ensure data transfers comply with UAE regulations regarding adequate protection.
6.3 Singapore (PDPA)
For residents of Singapore:
- Consent: We obtain deemed or explicit consent before collecting personal data.
- Access and Correction: You have the right to request access to and correction of your personal data.
- Purpose Limitation: We only use data for the specific purposes stated in this policy.
- DPO Contact: You may contact our Data Protection Officer (DPO) at privacy@qubitlink.co for any concerns.
6.4 United Kingdom (UK GDPR) & EEA
For users in the UK and EEA:
- Lawful Basis: We process data based on Consent, Contract, or Legitimate Interests.
- GDPR Rights: You include rights to access, rectification, erasure, restriction of processing, and data portability.
- Cookie Consent: We do not use non-essential tracking cookies without your active opt-in consent.
To exercise any of these rights, please contact us at privacy@qubitlink.co. You may also manage cookies via your browser or unsubscribe from marketing emails at any time.
7. Children's Privacy
Our Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information immediately.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
SNS USA
4 Stayman Ct
Catonsville MD 21228, USA
SNS Dubai
IFZA Business Park, DDP, PO Box 342001,
Dubai, United Arab Emirates.
SNS Singapore
42 Choa Chu Kang Street 64, #13-15 The Quintet,
Singapore 689104
Email:privacy@qubitlink.co