Privacy

Privacy-first link analytics: what we count, and what we refuse to collect

Blinkhop counts clicks by day, country, referrer domain and device type, with no cookies and without storing IP addresses. Here is how it works, and why it is enough.

About this post

Published
October 11, 2026
Reading time
5 minutes
Author
The Blinkhop team
Topics
Privacy, Analytics
On this page

Every link shortener counts clicks. The real question is what else it collects along the way. Blinkhop’s link analytics are privacy-first by design: we count clicks in aggregate and refuse to collect anything that would let us, or anyone else, follow an individual person. Here is exactly what we count, what we don’t, and why we think it’s enough.

When someone clicks a zou.sh link, we add one to a small set of daily counters for that link:

  • Day: the date of the click
  • Country: taken from Cloudflare’s country header
  • Referrer domain: the site the click came from, such as a social network or a newsletter platform, and only its domain, not the full page address
  • Device type: mobile or desktop

That’s the whole list. Each link’s total click count is public on its preview page: add + to the link, as in https://zou.sh/launch+, to see it. The API returns it too, through GET /links/{code}.

What we refuse to collect

What we leave out matters as much as what we count:

  • No cookies. Redirects set no cookies, and neither does blinkhop.com.
  • No IP addresses with clicks. We never store the IP address of someone who clicks a link. Rate limiting keeps addresses in memory for at most 24 hours and never writes them to disk.
  • No individual click records. We store counts, not events. There is no log of who clicked what and when, so there is nothing to build a profile from, sell or leak.
  • No trackers on our own site. The website runs no analytics trackers and no ads, and it serves its fonts and images itself.
  • No IP address at link creation. Creating a link stores the destination URL, the code, the creation time and how it was created (web, API or MCP). That’s all.
  • No selling of data. Our business model is paid plans.

How bot filtering works

A click count is only useful if it counts people, and a lot of traffic to a short link isn’t human. When you paste a link into Slack, WhatsApp or Discord, the app fetches it to build a preview card. Search engine crawlers, monitoring scripts and headless browsers fetch links too. If we counted all of that, a link could show clicks before a single person had opened it.

So we don’t count it. Requests from bots, link preview services, scripts and headless browsers are still redirected normally, but they don’t touch the counters. Most automated clients announce themselves, for example in the user agent string they send, and those requests are left out of the counts.

No filter is perfect. A script that pretends to be a regular browser can slip through, so read the numbers as a careful count of human clicks rather than an exact one.

Why aggregated data is enough for marketers

The questions marketers ask about a link are almost always aggregate questions:

  • Did people click? Daily totals show how many, and when.
  • Which channel worked? Referrer domains show whether clicks came from a newsletter, a social network or a partner site.
  • Where is the audience? Country counts show which markets respond.
  • Mobile or desktop? Device type tells you which version of the landing page matters most.

None of these questions needs to know who the visitor is. Answering them with counts means a click doesn’t cost your audience any privacy.

Two habits get more out of aggregated data:

  • Tag destinations with UTM parameters. Add utm_source, utm_medium and utm_campaign to the destination URL so the analytics on your own site attribute each visit. The free UTM builder makes this quick.
  • Use one short link per channel. Shortening the same URL twice returns the same short link, so a different utm_source for each channel gives you a separate link, and a separate count, for the newsletter, the poster’s QR code and each social network.

With an account (early access), the analytics dashboard will show these counts over time, with 30 days of history on a free account, 1 year on Pro and 2 years on Team.

How Cloudflare fits in

Cloudflare sits in front of all our domains and provides CDN, TLS and DDoS protection. It acts as our processor.

It also supplies the country of each click. Cloudflare adds a header with a two-letter country code to each request, and we read that code instead of running our own IP address lookups. The country goes straight into the daily counter.

As the network in front of our domains, Cloudflare handles requests on our behalf, as any CDN does. Our privacy policy describes its role. And there are no captchas or bot walls in front of the site, the API, the MCP server or redirects, so people on Tor and VPNs get the same experience as everyone else.

The short version

  • We count day, country, referrer domain and device type.
  • We never store individual clicks, profiles or the IP addresses of people who click, and we set no cookies.
  • We filter out bots, link previews, scripts and headless browsers.
  • You get numbers that answer campaign questions without tracking anyone.

Read more on the analytics feature page, or see what data Blinkhop collects.

More from the blog

Your next link is one paste away.

Free, no sign-up. Links that never expire.