PRIVACY POLICY

Effective Date: 22 April 2026

Last Updated: 15 August 2026

This Privacy Policy explains how Compit Ltd. collects and uses personal data through UME.LA. It is intended to provide the information required by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. WHO WE ARE

UME.LA is operated by Compit Ltd., registered in England and Wales under company number 12484949, with a registered address at 7 Bell Yard, London, WC2A 2JR, United Kingdom.

For the processing described in this Policy, Compit Ltd. is the data controller unless another organisation is identified as acting independently.

ICO Registration Number: ZC220428

Privacy enquiries and data-rights requests: feedback@umela.io

Abuse reports: abuse@umela.io

2. SCOPE

This Policy applies to:

  • https://umela.io and the UME.LA account and link-management application;
  • the https://ume.la redirect service and short links;
  • the Telegram Bot (@referbot) and Telegram Mini App;
  • people who create or manage links, including guest users;
  • people who follow or scan a UME.LA short link; and
  • people who contact us or submit an abuse report.

Destination websites reached through a short link operate under their own privacy policies. Link creators may also have their own data protection obligations for the analytics they access through UME.LA.

3. PERSONAL DATA WE PROCESS

CategoryDataSource
Account DataName, email address, password hash, account role and status, account creation dateProvided by you or generated by the Service
Authentication DataAuthentication provider, provider identifier, Google profile claims authorised by you, Telegram identifier, name and usernameGoogle, Telegram or you
Guest Account DataInternal guest user identifier and session detailsGenerated automatically when a feature requires a guest session
Session and Technical DataIP address, session source, country, region, city and continent derived from IP, browser, operating system, device type, brand and modelCollected automatically
Link DataDestination URL, short URL, domain, alias, tags, UTM parameters, expiration settings, QR-code configuration and link statusProvided by you or generated by the Service
Click DataLink and account identifiers, destination and short URLs, click or scan indicator, IP address, GeoIP latitude and longitude, country, region, city and continent, user agent, browser, operating system, device details, referrer, referrer domain, UTM parameters and time of the eventCollected automatically when a short link is followed or scanned
Subscription and Payment DataProvider, provider customer, subscription and payment identifiers, product, amount, currency, status, billing period, renewal and refund data, and provider webhook payloadsCreem or Telegram
Abuse Report DataReporter name and email, reported URL, abuse category, explanation, report status and timestampsProvided by the reporter and generated during review
Communication DataEmail address, message content and related support or security correspondenceProvided by you
Website Analytics DataPages viewed, page and session events, approximate location, browser and device information, referrer, timestamps, and pseudonymous client and session identifiersCollected through Google Analytics 4

We do not receive full payment-card details from Creem. Payment providers process payment credentials under their own terms and privacy notices.

4. CLICK ANALYTICS

When a person follows or scans a UME.LA short link, the Service records individual event-level Click Data. This collection is automatic and does not require the visitor to have an account.

GeoIP latitude and longitude are estimates derived from the visitor's IP address. They are not GPS coordinates and may not identify the visitor's exact physical location.

The account holder who owns the link can view and export event-level analytics for that link. Depending on the available fields, this can include the visitor's IP address, approximate location, user agent, device information, referrer and UTM parameters. Authorised UME.LA administrators can access analytics for support, security and administration. Analytics shared through a public analytics link are presented through the sharing functionality selected by the link owner.

Link owners must use the analytics lawfully, provide any notice required for their own use of the data, and must not use UME.LA analytics to unlawfully identify, profile, discriminate against or contact visitors.

Website analytics

We use Google Analytics 4 ("Google Analytics") to understand how people use our websites and application and to improve navigation, content, reliability and performance. Google Analytics collects page and event information, referrer information, approximate location, browser and device information, and pseudonymous client and session identifiers.

Google receives an IP address when the Analytics request is made and uses it to provide the service and derive approximate location. Google states that Google Analytics 4 does not log or store individual IP addresses. We do not receive an IP address from Google Analytics. This is separate from the event-level Click Data collected by UME.LA when a short link is followed.

Our Google Analytics use is for statistical service-improvement purposes. We do not use Google Analytics User-ID, Google Signals, advertising personalisation or remarketing features. We do not combine Google Analytics identifiers with a UME.LA account identity.

5. PURPOSES AND LAWFUL BASES

PurposeDataLawful basis
Create and manage accounts, guest sessions and linksAccount, Authentication, Guest Account, Session, Technical and Link DataPerformance of a contract or steps requested before entering a contract
Authenticate users and protect sessionsAccount, Authentication, Session and Technical DataContract and our legitimate interests in account and service security
Provide link analytics to link ownersClick, Link and Technical DataOur and the link owner's legitimate interests in measuring link use, understanding traffic and operating the requested analytics service
Measure and improve use of our websites and applicationWebsite Analytics DataConsent where required for Analytics storage; legitimate interests in aggregate service measurement and improvement where permitted by law
Detect malicious links, fraud, abuse and technical threatsLink, Click, Session, Technical and Abuse Report DataOur legitimate interests in protecting users and the Service, and legal obligation where applicable
Process Premium subscriptions, renewals, cancellations and refundsAccount, Subscription and Payment DataContract and legal obligation for accounting, tax and consumer-law records
Investigate reports and enforce our Terms and AUPAccount, Link, Click, Technical, Abuse Report and Communication DataLegitimate interests and legal obligation where applicable
Respond to support and privacy requestsAccount and Communication DataContract, legitimate interests and legal obligation, depending on the request
Establish, exercise or defend legal claimsRelevant recordsLegitimate interests and legal obligation where applicable

Our legitimate interests include operating a reliable link-management service, providing the analytics requested by link creators, measuring and improving our websites, preventing phishing and malware, investigating abuse, protecting accounts and defending legal rights. We consider necessity, proportionality and the impact on affected people when relying on legitimate interests.

6. AUTOMATED SECURITY CHECKS

Submitted destination URLs are checked against local threat-list data supplied through Google Web Risk. If a local hash match requires confirmation, the full destination URL is sent to the Google Web Risk API. Newly created links are checked when submitted and may be checked again approximately 10 minutes, 30 minutes, 1 hour, 6 hours and 24 hours after creation. Links migrated or queued in bulk may receive a reduced schedule.

An automated result may prevent creation of a link or mark an existing link as unsafe. You may request a review by contacting abuse@umela.io. We do not use Click Data for advertising or automated decisions that produce legal or similarly significant effects on visitors.

7. DISCLOSURES AND SERVICE PROVIDERS

We do not sell or rent personal data. Depending on how the Service is used, data may be disclosed to:

RecipientPurpose and data involved
Link ownersEvent-level Click Data for links they own, as described in Section 4
Google Web RiskA destination URL when an API confirmation lookup is required
Google OAuthAuthentication requests and the profile information authorised by the user
Google AnalyticsWebsite Analytics Data used to produce usage statistics and improve the Service
Google Favicon and Google Fonts servicesThe user's IP address and request metadata; favicon requests also contain the destination domain or URL for which an icon is requested
TelegramBot, Mini App, Telegram authentication and Telegram Stars subscription functions
CreemCheckout, subscription, payment, cancellation and refund processing as Merchant of Record
CloudflareDNS, content delivery, network security and associated request metadata where enabled for our domains
InfomaniakDelivery and receipt of email communications where used for our corporate email service
Fasthosts Internet Ltd.Hosting and infrastructure services where used for production systems
Professional advisers and authoritiesLegal, accounting, audit, fraud prevention and disclosures required or permitted by law

Some providers, including authentication platforms and payment providers, may act as independent controllers for parts of their processing. Their own privacy notices also apply.

When a visitor follows a short link, the visitor's browser connects to the destination website. The destination operator will receive normal web-request information such as the visitor's IP address, user agent and potentially referrer information. We do not control the destination operator's processing.

8. INTERNATIONAL TRANSFERS

Some recipients may process data outside the United Kingdom. Where UK data protection law requires a transfer safeguard, we rely on an applicable adequacy regulation, the UK Extension to the EU-US Data Privacy Framework where available, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard.

Provider processing locations and safeguards may vary according to the provider service used. You can contact feedback@umela.io for more information about a relevant transfer.

9. RETENTION AND ACCOUNT DELETION

DataCurrent retention behaviour
Account, authentication, links and related configurationKept while the account or relevant record exists. Deleting an account removes the active account and linked application records from the primary account database, subject to the exceptions below
Server-side sessionsExpire after 30 days of inactivity and are removed on logout or account deletion
Click DataKept without a fixed automatic expiry to provide historical analytics and security records. Click Data is not automatically deleted when the link owner's account is deleted
Google Analytics DataUser-level and event-level data is retained in Google Analytics for up to 14 months. Aggregate reports that no longer identify an individual visitor may be retained for longer
Payment and refund recordsKept after account deletion with the direct account reference removed where supported. Financial records are normally retained for six years or longer where required by law or needed to resolve a payment dispute
Abuse reports and security recordsKept for as long as reasonably necessary to investigate the report, prevent repeat abuse, comply with law and establish or defend legal claims; the application does not currently apply a fixed automatic expiry
Registration and password-reset verification dataShort-lived verification codes generally expire after 5 minutes; the related verification process generally expires after 30 minutes
Support and privacy correspondenceKept for as long as needed to handle the request and maintain an appropriate record of the outcome

Account deletion does not erase data that must or may lawfully be retained for payment records, abuse prevention, security, legal claims or compliance. It also does not currently erase historical Click Data from the analytics database. Where retained data no longer needs a direct account association, we may remove or limit that association.

Infrastructure logs and backup copies may persist until the applicable security, hosting or backup rotation ends. Data in backups is used only for continuity, security and recovery and is overwritten in the ordinary backup cycle.

10. COOKIES AND LOCAL STORAGE

We use cookies and local storage for authentication, security, theme preferences and Google Analytics. Google Analytics cookies are used for statistical measurement, not advertising. See our Cookie Policy at https://umela.io/legal/cookies.

11. YOUR RIGHTS

Subject to the conditions and exceptions in data protection law, you may have the right to:

  • obtain access to your personal data;
  • correct inaccurate or incomplete data;
  • request deletion of data;
  • restrict processing;
  • receive data you provided in a portable format;
  • object to processing based on legitimate interests;
  • withdraw consent where processing is based on consent; and
  • complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

To exercise a right, contact feedback@umela.io and provide enough information for us to identify the relevant account, short link, click or report. We may need to verify your identity. Rights are not absolute; for example, we may retain information where required by law or necessary to defend legal claims.

Visitors to short links can object to the processing of Click Data by identifying the relevant short link and approximate date and time of the visit. Because we do not authenticate short-link visitors, we may need additional information to locate the event without disclosing data about another person.

12. SECURITY

We use access controls, secure cookies, password hashing, network protections and monitoring intended to protect personal data. No online service can guarantee absolute security. You are responsible for keeping your login credentials secure and for signing out of devices you do not control.

13. CHILDREN

The Service is not directed to children under 13. We do not ask users to provide their age and cannot always determine a user's age from account or click data. If you believe a child has provided personal data inappropriately, contact feedback@umela.io or use the abuse reporting channels for urgent safety concerns.

14. CHANGES

We may update this Policy to reflect changes to the Service, providers or law. The current version and its update date will be available at https://umela.io/legal/privacy. Where appropriate, we will provide additional notice of material changes.

Compit Ltd.

7 Bell Yard, London, WC2A 2JR, United Kingdom

General support: support@umela.io

Privacy enquiries and data-rights requests: feedback@umela.io

Product feedback and suggestions: feedback@umela.io

Abuse reports: abuse@umela.io