Privacy Notice
Last updated 2026-08-19
What we collect when you build a site with Urlifly, why we collect it, and how you stay in control of it.
Who we are
Urlifly Ltd, a limited company in Ireland trading as Urlifly, is the data controller for personal data processed through urlifly.com. Contact details are at the foot of this page.
Where you use Urlifly to run your own site, you are the controller of your visitors' data and we act as your processor for that data.
What we collect and why
Account data (name, email, login credentials, authentication provider) — to create and secure your account. Legal basis: performance of our contract with you.
Business and site content (business name, type, description, address, opening hours, images, catalogue items, and the AI-generated copy produced from them) — to build, host, and publish your site. Legal basis: contract.
Site activity (pageviews, bookings, contact-form messages, subscription and plan status) — to provide dashboards, notifications, and billing. Legal basis: contract and our legitimate interest in operating the product.
Technical data (IP address, device and browser information, error logs) — for security, fraud prevention, and reliability. Legal basis: legitimate interests.
Support and marketing communications — to answer you and, where you have opted in, to send product updates you can unsubscribe from at any time. Legal basis: legitimate interests and consent.
Who we share it with
Service providers acting on our instructions: hosting and database infrastructure, email delivery, AI text-generation providers (which process the business details you submit to write your copy), and support tooling.
Stripe, our payment processor, for taking payments, managing subscriptions, tax compliance and invoicing. Stripe handles card data directly; we never see or store your full payment details.
Professional advisers (legal, accounting) and public authorities where we are required to disclose by law. We do not sell your personal data.
International transfers
Some providers process data outside the EEA. Where that happens we rely on adequacy decisions or Standard Contractual Clauses together with appropriate technical safeguards.
Retention
We keep account and site data while your account is active and for a short period afterwards so you can restore or export it. Analytics are kept in aggregated form; billing and tax records are kept as long as the law requires. After that, data is deleted or anonymised.
Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests, and you can withdraw consent at any time. Email privacy@urlifly.com (data protection requests) and we'll respond within one month. You can also complain to the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.
Security
We use encryption in transit, row-level access controls on our database, scoped credentials, and least-privilege access for staff. No system is perfectly secure, but we take appropriate technical and organisational measures and will notify you of a breach where the law requires it.
Cookies
We use essential cookies to keep you signed in and to keep the service secure — these cannot be turned off. We use privacy-friendly, aggregated analytics to count pageviews on published sites; we do not run advertising or cross-site tracking cookies. You can clear or block cookies in your browser, though signing in will stop working without the essential ones.
Optional cookies (analytics and marketing) are only set with your consent, which you can give, change or withdraw at any time on our cookie preferences page at urlifly.com/cookies. Your choice is stored for 182 days.
How to exercise your rights
Use the request form at urlifly.com/data-requests to ask for access, correction, erasure, export, restriction or objection — you get a reference number by email and we track the statutory deadline against it. You can also write to privacy@urlifly.com.
We acknowledge requests within 5 working days and complete them within one month, extendable by up to two further months for complex requests, in which case we tell you why. We may ask you to confirm your identity first. You can complain to the Irish Data Protection Commission or your local supervisory authority at any time.
Security reports
If you believe you have found a vulnerability, report it to security@urlifly.com. Our machine-readable contact details are published at urlifly.com/.well-known/security.txt and our disclosure expectations are set out at urlifly.com/legal-notices.