Legal
Privacy Notice
Last updated · 17 July 2026
This notice explains what personal information QSY.to processes, why, on what legal basis, how long we keep it, and the rights you have. A destination reached through a QSY.to link is controlled by its own operator and has its own privacy practices.
01Who is responsible for your information
QSY.to is the controller of the personal information described in this notice. QSY.to is contactable by email only, at privacy@qsy.to.
This notice covers the QSY.to website, access requests, accounts, route administration, redirects, and correspondence including support and abuse reports.
02Information we process
Depending on how you use QSY.to, we process:
- Access and account information — name, email address, username, a one-way hash of your password (never the password itself), account role, status and dates, and anything you include with an access request.
- Route information — the requested QSY.to address, destination URL, redirect type, any notes, changes, status and administrative history.
- Redirect and traffic information — the route requested, date and time, and an aggregated visit count. For each visit we store the referring page and browser user-agent, and a salted one-way hash of the visitor’s IP address — we do not store the raw IP address in the application.
- Security information — sign-in events and failed sign-in attempts. A failed-attempt record includes the raw IP address and is used only to rate-limit and block abuse; it is deleted automatically after 24 hours.
- Communications — emails you send us and our replies (support, privacy requests, complaints, abuse reports).
- Session information — a single strictly necessary cookie that keeps you signed in and protects forms (see section 4).
Please do not send special-category information, criminal-offence information, or another person’s private information unless we specifically ask for it and you have a lawful reason to provide it.
03Why we use it and our lawful bases
| Purpose | Information | Lawful basis |
|---|---|---|
| Consider an access request and create or administer an account | Access, account and communications information | Steps requested before entering a contract; performance of our agreement |
| Create, change and operate routes | Account and route information | Performance of our agreement |
| Deliver redirects and maintain traffic counts | Route, request and limited technical information | Performance of our agreement for account holders; our legitimate interests in operating and understanding the service |
| Authenticate users, secure the service and prevent fraud, phishing, malware and abuse | Account, security and log information | Our legitimate interests in security and service integrity; legal obligation where applicable |
| Respond to enquiries, rights requests, complaints and abuse reports | Contact and communications information | Legal obligation; performance of our agreement; legitimate interests in administration and dispute handling |
| Establish, exercise or defend legal claims and comply with valid legal requests | Relevant account, route, log and communications information | Legal obligation; legitimate interests in protecting legal rights |
Where we rely on legitimate interests, we consider whether the use is necessary and balance it against your rights and reasonable expectations. We do not use personal information for advertising, we do not sell it, and we do not make decisions producing legal or similarly significant effects about you solely by automated means.
04Cookies and similar technologies
QSY.to uses a single, strictly necessary cookie. It is used only to keep a signed-in account session and to protect forms against cross-site request forgery. We do not use advertising cookies or analytics cookies, and the site loads no third-party trackers — fonts and other assets are served from QSY.to itself.
| Cookie | Purpose | Duration |
|---|---|---|
qsyt_session |
Maintains an authenticated account session and underpins form-protection tokens | Session (deleted when you close the browser or sign out) |
Browser controls can remove cookies, although blocking this necessary cookie will prevent signing in. If we ever introduce non-essential cookies, we will update this notice and ask for consent first where the law requires it.
05Who receives information
We disclose information only as reasonably necessary to:
- our hosting and email provider, Hostinger, which operates the servers, database, backups and mail delivery on our behalf;
- professional advisers (for example insurers or accountants) where genuinely needed;
- courts, regulators, law-enforcement bodies or other authorities where disclosure is legally required or reasonably necessary to protect rights and safety; and
- a successor operator if the service is genuinely reorganised or transferred, subject to appropriate safeguards.
We do not sell personal information.
06International transfers
Our hosting and email provider may process information on servers inside or outside the United Kingdom, within its own infrastructure. Where information is transferred outside the UK, we rely on an applicable adequacy regulation or approved contractual safeguards. For more information about the safeguard used for a particular transfer, email privacy@qsy.to.
07How long we keep it
We keep personal information only for as long as it is reasonably needed:
- Failed sign-in records (which include a raw IP address): deleted automatically after 24 hours.
- Access requests: kept while we deal with them and for a reasonable period afterwards, then deleted; declined or abandoned requests are not kept indefinitely.
- Account and active route records: kept while the account or route is active, and removed within a reasonable period after closure unless needed for a dispute, abuse prevention or a legal obligation.
- Traffic records (referrer, browser and the salted hash of the IP address): kept while the link is active to provide the account holder’s usage statistics.
- Email correspondence: kept for as long as needed to handle the matter and any follow-up.
- Server logs and backups held by our hosting provider are retained and rotated according to that provider’s own cycle.
We may keep a limited record for longer where required by law or reasonably necessary to establish, exercise or defend legal claims. When information is no longer needed, we delete or anonymise it.
08Security
We use proportionate technical and organisational measures to protect personal information, including access controls, password hashing, encrypted (HTTPS) connections, hardened session cookies, storing visitor IP addresses only as salted hashes, rate-limiting and security logging. No internet service can guarantee absolute security. Keep your credentials confidential and report a suspected compromise to privacy@qsy.to.
09Your data-protection rights
Depending on the circumstances, you may have the right to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information;
- ask us to restrict how information is used;
- object to processing based on legitimate interests;
- receive information you provided in a portable format where the legal conditions apply; and
- withdraw consent at any time where processing is based on consent.
These rights are not absolute and exemptions may apply. To make a request, email privacy@qsy.to. We may need to verify your identity and will respond within the period required by law.
10Data-protection complaints
You can make a data-protection complaint by emailing privacy@qsy.to with the subject “Data protection complaint”. We will acknowledge a qualifying complaint within 30 days, investigate it appropriately and tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint. We would appreciate the chance to address your concern first, but you are not required to contact us before approaching the ICO.
11Children
Accounts are not offered to people under 18, and we do not knowingly collect children’s information for account administration. Public redirects may be followed by visitors of any age. If you believe a child has supplied personal information to us, contact privacy@qsy.to.
12Changes to this notice
We may update this notice when the service, providers or law changes. We will publish the updated version with a revised date and, where appropriate, bring material changes to account holders’ attention.
13Contact
Controller: QSY.to
Privacy email: privacy@qsy.to
Related terms: Terms of Service