Version 1 of 28 September 2026.
This document is the site-specific privacy notice of 1lk.it. It supplements the general DreamersWare Privacy Policy, which covers the processing common to all sites (browsing, orders, payments). For cookies see the 1lk.it Cookie Policy.
1. Data controller
DreamersWare S.r.l.s. — Via Carlo Porta 2, 21052 Busto Arsizio (VA), Italy
Varese Companies Register, tax code and registration no. 04151010123 · REA VA-405537
Share capital €1,200.00 fully paid · VAT ID IT04151010123
Innovative start-up registered in the special section of the Companies Register
Privacy contact: show email address (subject "Privacy rights request") · Certified email: show certified email (PEC)
2. What data we process
2.1 Browsing and security. IP address, date and time, requested page and user-agent are kept in the server logs for security and abuse prevention.
2.2 Registered users. We process:
- email address and username;
- your password, stored only in encrypted form (hash) that nobody can read;
- the billing details you provide;
- your subscription plan;
- the content you create: short links, QR codes, bio pages and their settings.
2.3 Visitors of short links, QR codes and bio pages. When someone opens a link created on 1lk.it, we record:
- date and time;
- country and city, derived from the IP address with a geolocation database running on our own server, without sending the IP to third parties;
- browser language, browser and operating system;
- referring site (referrer).
The IP address is never stored in clear. Instead we keep a pseudonymous code (a hash computed with a secret key), used only to count unique visitors and deleted after 30 days. The link owner sees these statistics per click or in aggregate form, but cannot identify the visitors. We do not profile visitors and do not combine this data with other sources.
2.4 Payments. For bank transfers we process the data shown on the transaction (payer, amount, reference). Cryptocurrency payments go through CoinPayments.net, which processes the payment data as an independent controller under its own privacy policy. DreamersWare only receives the outcome and the transaction references, never wallet keys or credentials.
2.5 Contact and support. We process the data you send us through the contact form or by email.
2.6 Spam protection. Our forms (sign-up, login, contact) are protected by Google reCAPTCHA v3, which analyses technical data about the device and the interaction to tell humans from bots.
2.7 Link safety. The destination URLs of links created by users are checked against lists of malicious sites (Google Safe Browsing, abuse.ch URLhaus). Only the destination URL is sent to these services, never visitor data.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service to registered users (account, links, QR codes, bio pages, service emails such as activation and password reset) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Providing customers with statistics on their links | Legitimate interest of DreamersWare and of the customer in measuring link performance (Art. 6(1)(f)), balanced by data minimisation and pseudonymisation: no clear IP, pseudonym deleted after 30 days, no profiling |
| Security and prevention of abuse, spam and malicious links | Legitimate interest (Art. 6(1)(f)) |
| Invoicing and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Answering contact requests | Pre-contractual measures or contract (Art. 6(1)(b)), legitimate interest (Art. 6(1)(f)) |
4. How long we keep data
- Server logs: at most 7 days, unless an incident is under investigation.
- Visitor pseudonymous code: 30 days.
- Click statistics (date, country, city, language, browser, operating system, referrer): for the whole life of the link. They are deleted together with the link or the account.
- Account data: until the account is deleted.
- Tax documents: 10 years (Art. 2220 of the Italian Civil Code).
- Support emails: for as long as the request requires, plus 24 months for evidence purposes.
5. Recipients
- Hetzner Online GmbH, hosting in Germany, data processor (Art. 28 GDPR).
- Aruba Business S.r.l., delivery of service emails, Italy.
- Google Ireland Ltd.: reCAPTCHA and Safe Browsing.
- abuse.ch: URLhaus, receives URLs only.
- CoinPayments.net, independent controller for cryptocurrency payments.
- The bank, for bank transfers.
Some providers (Google, CoinPayments) may process data outside the EU. In that case the EU-US adequacy decision (Data Privacy Framework) or the European Commission's standard contractual clauses apply.
6. Your rights
You can exercise the rights under Articles 15–22 GDPR (access, rectification, erasure, restriction, portability, objection) by writing to show email address. You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
For link visitors: since the IP is not stored in clear, we are normally unable to link the statistics to a person (Art. 11 GDPR).
7. Changes
We may update this notice. Significant changes will be highlighted on this page, with their date.