Overview
Data privacy is an important part of using SPRL responsibly. Organizations using SPRL may process information related to their customers, users, campaigns, links, forms, and other business activities.
Customers are responsible for ensuring that the information they submit to or process through SPRL is handled in accordance with applicable privacy and data protection requirements.
Good to Know:
Only collect and process information that is necessary for your intended business purpose, provide appropriate privacy notices, and restrict access to personal information to authorized users.
What Is Personal Information?
Personal information generally refers to information that can identify, relate to, describe, or reasonably be associated with an individual.
Depending on how SPRL is used, examples may include:
- Name and contact information.
- Email addresses.
- Telephone numbers.
- Account or user information.
- Information submitted through forms.
- Information associated with marketing campaigns.
- Other information provided by customers through SPRL services.
Important:
The type of information processed through SPRL depends on how you configure and use the platform. Customers should avoid collecting unnecessary personal information.
Your Responsibility as a Customer
When you use SPRL to collect, upload, store, transmit, or otherwise process information relating to other individuals, you are responsible for determining the appropriate legal and privacy requirements that apply to your activities.
- Collect information for legitimate and defined purposes.
- Provide appropriate privacy information to individuals.
- Collect only information that is reasonably necessary.
- Maintain appropriate access controls.
- Handle personal information securely.
- Follow applicable privacy and data protection laws.
- Respect applicable data retention requirements.
Data Minimization
Data minimization means limiting the collection and processing of personal information to what is necessary for the intended purpose.
Before collecting information through an SPRL feature, consider whether each field is actually required for your business process.
| Practice | Recommendation |
|---|
| Collect | Collect only information necessary for the intended purpose. |
| Forms | Avoid unnecessary personal-information fields. |
| Access | Limit access to authorized users. |
| Retention | Review information that is no longer required. |
Information Collected Through Forms
If you use SPRL forms to collect information from customers, prospects, employees, or other individuals, you should clearly explain what information you are collecting and why.
Depending on your use case, your privacy notice may explain:
- What information is being collected.
- Why the information is being collected.
- How the information will be used.
- How the information may be shared.
- How long the information may be retained.
- How individuals can exercise applicable privacy rights.
Recommendation:
Do not rely solely on the SPRL Privacy Policy to explain your own data collection practices. Your organization may need to provide its own privacy notice based on how you use SPRL and the information you collect.
Customer and Contact Data
If you upload or manage customer or contact information through SPRL, ensure that you have an appropriate basis and authorization for processing that information.
- Use accurate and appropriately sourced contact information.
- Maintain appropriate permissions for marketing communications.
- Respect unsubscribe or opt-out requests where applicable.
- Avoid uploading information that is not required.
- Restrict access to authorized personnel.
Organizations should also review the applicable laws and regulations governing their marketing and communications activities.
Marketing & Privacy
Marketing activities may involve personal information such as names, email addresses, telephone numbers, or other contact details.
Before using personal information for marketing purposes, organizations should determine the applicable consent, notice, lawful-basis, opt-out, and other requirements for their jurisdiction and intended activity.
- Use appropriately collected contact information.
- Provide required notices to recipients.
- Respect applicable consent requirements.
- Honor unsubscribe and opt-out requests.
- Do not use contact information for unrelated purposes without appropriate authorization.
Access to Personal Information
Access to personal information should be limited to users who require it for legitimate business purposes.
Organizations should establish internal access-management practices appropriate to their size and operations.
- Provide access only to authorized users.
- Avoid sharing account credentials.
- Review access when responsibilities change.
- Remove access when it is no longer required.
- Protect administrative accounts with appropriate security controls.
Protecting Sensitive Information
Some information may require additional protection because of its nature or the potential impact of unauthorized disclosure.
Avoid using SPRL features to collect or process sensitive information unless the specific use case is appropriate, legally permitted, and supported by your organization's privacy and security controls.
Security Reminder:
Do not include passwords, API keys, authentication codes, payment credentials, or other confidential security information in forms, URLs, support requests, or publicly accessible content.
Personal Information in URLs
Be particularly careful when placing information in URLs because URLs may appear in browser history, analytics systems, logs, referrer information, screenshots, emails, or other systems.
Avoid placing unnecessary personal or confidential information directly into URLs, URL parameters, or short-link paths.
- Do not place passwords in URLs.
- Do not place API keys in URLs.
- Avoid unnecessary personal information in query parameters.
- Use non-sensitive identifiers where possible.
- Review destination URLs before creating public short links.
Important:
A shortened URL does not make sensitive information in the original URL safe. Avoid shortening URLs that contain passwords, private tokens, or unnecessary personal information.
Data Security
Privacy and security are closely connected. Organizations should use appropriate technical and organizational measures to protect personal information from unauthorized access, alteration, disclosure, or loss.
- Use strong account credentials.
- Enable two-factor authentication where available.
- Protect API credentials.
- Review user access periodically.
- Monitor important account activity.
- Keep sensitive information out of public resources.
Data Retention
Organizations should establish appropriate retention practices for personal information they process through SPRL.
Do not retain personal information indefinitely when it is no longer required for the purpose for which it was collected, unless retention is required or permitted by applicable law or a legitimate business requirement.
- Define appropriate retention periods.
- Review information that is no longer required.
- Remove information when appropriate.
- Consider applicable legal and regulatory retention requirements.
Privacy Rights
Depending on the applicable jurisdiction and circumstances, individuals may have privacy rights relating to their personal information.
These rights may include rights relating to access, correction, deletion, restriction, objection, portability, or other forms of control over personal information.
The specific rights available to an individual depend on applicable law and the circumstances of the processing activity.
Important:
Organizations using SPRL to process personal information should establish their own procedures for responding to applicable privacy requests from their customers, users, employees, or other individuals.
Data Processing Agreement
Enterprise customers may require contractual terms governing the processing of personal information. SPRL provides a Data Processing Agreement for Enterprise use where applicable.
The Data Processing Agreement should be reviewed together with the SPRL Privacy Policy and the customer's own privacy and data protection requirements.
International Data Protection Requirements
Privacy requirements can differ depending on where an organization operates, where individuals are located, and how personal information is processed.
Customers are responsible for determining which privacy and data protection laws apply to their activities and for implementing the appropriate compliance measures.
- Identify the jurisdictions relevant to your business.
- Review applicable privacy obligations.
- Provide required privacy notices.
- Establish appropriate data-handling procedures.
- Review contractual requirements where applicable.
Privacy Best Practices
| Privacy Area | Recommended Practice |
|---|
| Data Collection | Collect only information necessary for the intended purpose. |
| Transparency | Provide appropriate privacy information to individuals. |
| Access | Limit access to authorized users. |
| Security | Apply appropriate security controls to protect information. |
| Retention | Review information that is no longer required. |
| Rights | Maintain processes for applicable privacy requests. |
| Compliance | Review applicable privacy and data protection requirements. |
Privacy Checklist
| Practice | Status |
|---|
| Purpose of data collection identified | Recommended |
| Only necessary information collected | Recommended |
| Appropriate privacy notice provided | Required if applicable |
| Access limited to authorized users | Recommended |
| Personal information protected | Required |
| Retention requirements reviewed | Recommended |
| Applicable privacy rights considered | Recommended |
| Marketing permissions reviewed | Required if applicable |
| Data Processing Agreement reviewed | Recommended for Enterprise |
Frequently Asked Questions
What information can be processed through SPRL?
The information processed through SPRL depends on how you use the platform. It may include account information, contact information, campaign data, form submissions, link-related information, and other information provided through supported services.
Who is responsible for the personal information I upload?
Customers are responsible for ensuring that their collection and processing of personal information complies with applicable privacy and data protection requirements.
Should I collect all available customer information?
No. Follow the principle of data minimization and collect only information that is necessary for your intended business purpose.
Can I use personal information for marketing?
Marketing use depends on applicable laws, regulations, permissions, notices, and the circumstances in which the information was collected. Organizations should ensure that their marketing activities comply with applicable requirements.
Can I put personal information in a short URL?
It is strongly recommended to avoid placing unnecessary personal or confidential information in URLs. URLs may be exposed through browser history, analytics, logs, referrers, screenshots, and other systems.
Does SPRL provide a Data Processing Agreement?
Yes. SPRL provides a Data Processing Agreement for Enterprise customers where applicable.
How should I protect personal information?
Use appropriate access controls, strong credentials, two-factor authentication where available, secure integrations, and appropriate internal data-handling procedures.
What should I do if I believe personal information has been exposed?
Secure the affected account or integration, investigate the incident, preserve relevant information needed for investigation, and follow your organization's applicable incident-response and privacy procedures. Contact SPRL Support where assistance is required.
Quick Reference
| Topic | Summary |
|---|
| Data Collection | Collect information only when it is necessary for a defined purpose. |
| Privacy Notice | Provide appropriate information about how personal information is collected and used. |
| Access | Restrict personal information to authorized users. |
| URLs | Avoid placing unnecessary personal or confidential information in URLs. |
| Marketing | Follow applicable requirements for consent, notices, and opt-outs. |
| Retention | Review and manage information that is no longer required. |
| Enterprise DPA | Review the Data Processing Agreement where applicable. |
| Security | Apply appropriate controls to protect personal information. |
Learn More:
Explore the SPRL Help Center for detailed guides on Security Overview, Two-Factor Authentication, Managing Login Sessions, Password Security Best Practices, Recognizing Phishing Attempts, API Security, Domain & SSL Security, Reporting Security Issues, and Security FAQs.
Tip: Treat personal information as valuable business data. Collect only what you need, clearly explain how it is used, restrict access, protect it appropriately, and regularly review whether it is still required.