Current service · no advertising trackers
Privacy Policy
UTMora is designed to minimize campaign data collection while providing a private workspace and optional tracked links for Pro users.
Who controls your data
The data controller and UTMora operator is ФОП Гаврик Станіслав Сергійович, Полтава, Україна. Privacy contact: utmoreutm@gmail.com. UTMora is available worldwide. No data protection officer or representative has been appointed. If a representative becomes legally required, this section will be updated with the representative's contact details.
Data we process
- Public builder: destination URLs and UTM values are processed in your browser to create a preview. They are not saved to a UTMora workspace or sent to a UTMora database by the builder.
- Account: email address, authentication identifiers, session data, and sign-in records needed for email magic-link authentication and any identity method that is later enabled.
- Pro workspace: campaigns, saved destination URLs, UTM values, generated-link snapshots, settings, and related records you choose to store.
- Tracked links: link identifiers, click time, referrer hostname when available, a coarse technical client category, and whether an obvious technical event is counted. UTMora does not store a clicker's IP address, full referrer URL, raw user-agent, fingerprint, precise location, or visitor identifier in its application click records.
- Product usage and acquisition: first-party launch metrics and PostHog EU record only allowlisted event names for landing, builder, signup, workspace, pricing, checkout start, Pro activation, and tracked-link creation. For UTMora's own allowlisted outreach links, they may also record the normalized source, medium, campaign, and placement labels. Unknown or user-authored values are discarded. Public events use a stable random browser identifier stored in first-party local storage for up to 180 days; it is not a fingerprint and contains no PII. After sign-in, UTMora sends a server-side identity merge that connects that anonymous identifier to a keyed pseudonym. The keyed pseudonym cannot reveal the Supabase account UUID to PostHog. These events do not contain destination or generated URLs, search terms, email addresses, direct user or record IDs, IP addresses supplied by UTMora, raw user-agent strings, or payment details.
- Operations and support: messages you send and limited security, error, and request information processed by hosting infrastructure to operate and protect the service.
Why we use data and our legal bases
- Account, authentication, and workspace: to take requested steps and perform the service agreement, including signing you in, storing records you choose to save, and keeping them available to you.
- Tracked click events: for the legitimate interests of the account owner and UTMora in providing the deliberately requested tracked-link and basic click-count feature. The event data is minimized and does not include an IP address or visitor identifier in UTMora's application records.
- Security and abuse prevention: for UTMora's and users' legitimate interests in protecting accounts, the service, and third parties, using proportionate technical and request information.
- Support: to perform or take steps concerning the service agreement and for the legitimate interest in answering requests, diagnosing problems, and keeping an appropriate record of the response.
- Minimal product analytics: for UTMora's legitimate interest in understanding launch-stage feature use, comparing UTMora's own outreach placements, and improving the service. The events are deliberately limited, use a server-side PostHog integration, and do not use a browser SDK, autocapture, or session replay. The identity merge allows pre-auth and post-auth events to be counted as one pseudonymous analytics person without sending an email or raw account UUID.
- Legal and compliance: when processing is necessary to meet a legal obligation or to establish, exercise, or defend legal claims.
Consent is used only where the law requires a separate choice. UTMora does not rely on consent for processing that is necessary to provide an account or requested workspace feature. Where legitimate interests are used, you may object by contacting us; the request will be assessed against any compelling grounds to continue.
Cookies and analytics
Necessary authentication cookies are used to maintain a signed-in session and protect the authentication flow. Product analytics also uses a first-party local-storage value containing a random UUID with a 180-day expiry; it is not a fingerprint, contains no PII, and is used only to keep public product events coherent in one browser. When a visitor arrives through one of UTMora's specifically allowlisted outreach links, UTMora stores the normalized first-touch source, medium, campaign, and placement for up to 30 days in a signed, HttpOnly, same-site first-party cookie. Minimal product events and that allowlisted context are written to existing Vercel runtime logs and sent server-to-server to PostHog's EU Cloud. UTMora does not load the PostHog browser SDK, enable autocapture or session replay, or create cross-site marketing identifiers. After authentication, a server-side `$identify` event connects the anonymous browser identifier to a keyed pseudonym; no email or raw account UUID is sent to PostHog.
Service providers
- Supabase: authentication and database infrastructure. The production project's primary region is Frankfurt, Germany. Provider support and subprocessors may process limited data elsewhere.
- Vercel: website hosting, deployment, delivery, security, and request/error logs. Vercel and its subprocessors operate global infrastructure.
- Cloudflare: authoritative DNS and domain/security configuration. UTMora's current website records are DNS-only, so Cloudflare is not currently used as an HTTP reverse proxy for the site.
- Google: the monitored Gmail mailbox used for support; Google processes the contents and addressing information of messages sent to that mailbox.
- Paddle: Merchant of Record for Pro subscriptions. Paddle processes checkout, payment, tax, subscription, refund, and dispute information under its buyer terms and privacy notice; UTMora receives the billing identifiers and lifecycle events needed to provide Pro access.
- PostHog EU Cloud: receives the minimal product-event names, allowlisted normalized acquisition labels when present, and anonymous or keyed-pseudonymous distinct identifiers described above for product analytics. Person profiles, autocapture, session replay, surveys, and feature flags are not used.
International transfers
UTMora is operated from Ukraine, while the providers above may process data in the European Economic Area, the United States, and other locations used by their subprocessors. Depending on the destination and the applicable provider agreement, transfer safeguards may include data processing terms, an adequacy arrangement, or standard contractual clauses; coverage can depend on the active provider plan and relationship. The primary database region does not mean that all operational or support data stays only in that region. You may contact us for current information about safeguards relevant to your data.
Retention and deletion
- Public builder: inputs are not retained by the UTMora application.
- Account and workspace: retained while the account is maintained. A Pro downgrade restricts access but does not delete workspace records.
- Tracked links and click events: retained with the related saved link. Deleting the saved link or account deletes the related primary application records; deactivation or downgrade alone does not.
- Support messages: normally deleted within 24 months after the last substantive exchange, unless they remain necessary for an unresolved request, security incident, dispute, legal claim, or legal obligation.
- Provider logs and backups: retained and rotated under the active provider plan and security schedule. After primary records are deleted, residual copies may remain temporarily in access-restricted backups or security logs until their normal expiry and are not used to continue providing the deleted account.
- Transaction records: Paddle and UTMora may retain billing, tax, refund, and dispute records for the periods required by applicable law and their respective legal obligations.
- Product analytics: the first-touch acquisition cookie expires after 30 days. Product events are retained and deleted under the active PostHog EU project settings and provider plan. A verified deletion request will include the related keyed pseudonym where it can be derived safely.
There is not yet a self-service account-deletion control. Send a deletion request to utmoreutm@gmail.com. After identity and scope are verified, UTMora will normally complete the primary-data deletion within 30 days, unless a longer period or limited retention is permitted or required by applicable law. Deletion may be delayed only for a stated operational or legal reason.
Your choices and rights
Depending on applicable law, you may have rights to know the sources, purpose, location, recipients, and safeguards for your data; access, correct, delete, restrict, or export it; object to certain processing; withdraw consent where consent is used; and complain to the Ukrainian Parliament Commissioner for Human Rights or another competent supervisory authority. Use the Support & Contact page to make a request. We may verify identity proportionately before acting on a request.
Security, children, and changes
UTMora uses account authentication, server-side authorization, and database row-level security to protect workspace data, but no system can guarantee absolute security. The service is not directed to children. Material policy changes will be posted here with a revised date.