Skip to content
EndURL

Data Processing

Last updated: 23 August 2026

This page describes the data-processing relationship between EndURL and its customers in plain language. Enterprise customers requiring a signed Data Processing Agreement should contact legal@endurl.com.

1. Roles

For account data, EndURL acts as a data controller. For click analytics processed on behalf of a workspace, EndURL acts as a processor and the workspace owner as controller — you decide retention, whether analytics run at all, and who on your team can see them.

2. Subprocessors

EndURL relies on the following subprocessors:

  • Google Cloud / Firebase — hosting, authentication, database, storage (data location: us-central1)
  • Razorpay — payment processing (India)

3. Retention and deletion

Raw click events are retained per your plan (30 days to 2 years) and then deleted automatically via time-to-live policies. Aggregated statistics persist for dashboard history. Account deletion removes personal data and tombstones links; backups age out on the platform's standard schedule.

4. Security measures

Technical measures are described on the Security page: encryption in transit and at rest, least-privilege access rules, hashed credentials and API keys, audit logging, and abuse controls.