Every link shortener counts clicks. The real question is what else it collects along the way. Blinkhop’s link analytics are privacy-first by design: we count clicks in aggregate and refuse to collect anything that would let us, or anyone else, follow an individual person. Here is exactly what we count, what we don’t, and why we think it’s enough.
What our link analytics count
When someone clicks a zou.sh link, we add one to a small set of daily counters for that link:
- Day: the date of the click
- Country: taken from Cloudflare’s country header
- Referrer domain: the site the click came from, such as a social network or a newsletter platform, and only its domain, not the full page address
- Device type: mobile or desktop
That’s the whole list. Each link’s total click count is public on its preview page: add + to the link, as in https://zou.sh/launch+, to see it. The API returns it too, through GET /links/{code}.
What we refuse to collect
What we leave out matters as much as what we count:
- No cookies. Redirects set no cookies, and neither does blinkhop.com.
- No IP addresses with clicks. We never store the IP address of someone who clicks a link. Rate limiting keeps addresses in memory for at most 24 hours and never writes them to disk.
- No individual click records. We store counts, not events. There is no log of who clicked what and when, so there is nothing to build a profile from, sell or leak.
- No trackers on our own site. The website runs no analytics trackers and no ads, and it serves its fonts and images itself.
- No IP address at link creation. Creating a link stores the destination URL, the code, the creation time and how it was created (web, API or MCP). That’s all.
- No selling of data. Our business model is paid plans.
How bot filtering works
A click count is only useful if it counts people, and a lot of traffic to a short link isn’t human. When you paste a link into Slack, WhatsApp or Discord, the app fetches it to build a preview card. Search engine crawlers, monitoring scripts and headless browsers fetch links too. If we counted all of that, a link could show clicks before a single person had opened it.
So we don’t count it. Requests from bots, link preview services, scripts and headless browsers are still redirected normally, but they don’t touch the counters. Most automated clients announce themselves, for example in the user agent string they send, and those requests are left out of the counts.
No filter is perfect. A script that pretends to be a regular browser can slip through, so read the numbers as a careful count of human clicks rather than an exact one.
Why aggregated data is enough for marketers
The questions marketers ask about a link are almost always aggregate questions:
- Did people click? Daily totals show how many, and when.
- Which channel worked? Referrer domains show whether clicks came from a newsletter, a social network or a partner site.
- Where is the audience? Country counts show which markets respond.
- Mobile or desktop? Device type tells you which version of the landing page matters most.
None of these questions needs to know who the visitor is. Answering them with counts means a click doesn’t cost your audience any privacy.
Two habits get more out of aggregated data:
- Tag destinations with UTM parameters. Add
utm_source,utm_mediumandutm_campaignto the destination URL so the analytics on your own site attribute each visit. The free UTM builder makes this quick. - Use one short link per channel. Shortening the same URL twice returns the same short link, so a different
utm_sourcefor each channel gives you a separate link, and a separate count, for the newsletter, the poster’s QR code and each social network.
With an account (early access), the analytics dashboard will show these counts over time, with 30 days of history on a free account, 1 year on Pro and 2 years on Team.
How Cloudflare fits in
Cloudflare sits in front of all our domains and provides CDN, TLS and DDoS protection. It acts as our processor.
It also supplies the country of each click. Cloudflare adds a header with a two-letter country code to each request, and we read that code instead of running our own IP address lookups. The country goes straight into the daily counter.
As the network in front of our domains, Cloudflare handles requests on our behalf, as any CDN does. Our privacy policy describes its role. And there are no captchas or bot walls in front of the site, the API, the MCP server or redirects, so people on Tor and VPNs get the same experience as everyone else.
The short version
- We count day, country, referrer domain and device type.
- We never store individual clicks, profiles or the IP addresses of people who click, and we set no cookies.
- We filter out bots, link previews, scripts and headless browsers.
- You get numbers that answer campaign questions without tracking anyone.
Read more on the analytics feature page, or see what data Blinkhop collects.