Current pre-launch service · no advertising trackers
Privacy Policy
UTMora is designed to minimize campaign data collection while providing a private workspace and optional tracked links for Pro users.
Who controls your data
The data controller and UTMora operator is ФОП Гаврик Станіслав Сергійович, Полтава, Україна. Privacy contact: utmoreumt@gmail.com. UTMora is available worldwide. No data protection officer or representative has been appointed. If a representative becomes legally required, this section will be updated with the representative's contact details.
Data we process
- Public builder: destination URLs and UTM values are processed in your browser to create a preview. They are not saved to a UTMora workspace or sent to a UTMora database by the builder.
- Account: email address, authentication identifiers, session data, and sign-in records needed for email magic-link authentication and any identity method that is later enabled.
- Pro workspace: campaigns, saved destination URLs, UTM values, generated-link snapshots, settings, and related records you choose to store.
- Tracked links: link identifiers, click time, referrer hostname when available, a coarse technical client category, and whether an obvious technical event is counted. UTMora does not store a clicker's IP address, full referrer URL, raw user-agent, fingerprint, precise location, or visitor identifier in its application click records.
- Operations and support: messages you send and limited security, error, and request information processed by hosting infrastructure to operate and protect the service.
Why we use data and our legal bases
- Account, authentication, and workspace: to take requested steps and perform the service agreement, including signing you in, storing records you choose to save, and keeping them available to you.
- Tracked click events: for the legitimate interests of the account owner and UTMora in providing the deliberately requested tracked-link and basic click-count feature. The event data is minimized and does not include an IP address or visitor identifier in UTMora's application records.
- Security and abuse prevention: for UTMora's and users' legitimate interests in protecting accounts, the service, and third parties, using proportionate technical and request information.
- Support: to perform or take steps concerning the service agreement and for the legitimate interest in answering requests, diagnosing problems, and keeping an appropriate record of the response.
- Legal and compliance: when processing is necessary to meet a legal obligation or to establish, exercise, or defend legal claims.
Consent is used only where the law requires a separate choice. UTMora does not rely on consent for processing that is necessary to provide an account or requested workspace feature. Where legitimate interests are used, you may object by contacting us; the request will be assessed against any compelling grounds to continue.
Cookies and analytics
Necessary authentication cookies are used to maintain a signed-in session and protect the authentication flow. No external product analytics, advertising tracker, or cross-site marketing cookie is enabled in the current service. If optional analytics is introduced, this policy and any required consent controls will be updated before it is enabled.
Service providers
- Supabase: authentication and database infrastructure. The production project's primary region is Frankfurt, Germany. Provider support and subprocessors may process limited data elsewhere.
- Vercel: website hosting, deployment, delivery, security, and request/error logs. Vercel and its subprocessors operate global infrastructure.
- Cloudflare: authoritative DNS and domain/security configuration. UTMora's current website records are DNS-only, so Cloudflare is not currently used as an HTTP reverse proxy for the site.
- Google: the monitored Gmail mailbox used for support; Google processes the contents and addressing information of messages sent to that mailbox.
- Merchant of Record: none is selected or connected and no payments are currently accepted. Before checkout opens, this policy and the checkout will identify the selected Merchant of Record and explain its role.
International transfers
UTMora is operated from Ukraine, while the providers above may process data in the European Economic Area, the United States, and other locations used by their subprocessors. Depending on the destination and the applicable provider agreement, transfer safeguards may include data processing terms, an adequacy arrangement, or standard contractual clauses; coverage can depend on the active provider plan and relationship. The primary database region does not mean that all operational or support data stays only in that region. You may contact us for current information about safeguards relevant to your data.
Retention and deletion
- Public builder: inputs are not retained by the UTMora application.
- Account and workspace: retained while the account is maintained. A Pro downgrade restricts access but does not delete workspace records.
- Tracked links and click events: retained with the related saved link. Deleting the saved link or account deletes the related primary application records; deactivation or downgrade alone does not.
- Support messages: normally deleted within 24 months after the last substantive exchange, unless they remain necessary for an unresolved request, security incident, dispute, legal claim, or legal obligation.
- Provider logs and backups: retained and rotated under the active provider plan and security schedule. After primary records are deleted, residual copies may remain temporarily in access-restricted backups or security logs until their normal expiry and are not used to continue providing the deleted account.
- Future transaction records: no transaction records exist today. When payments open, the Merchant of Record and UTMora may need to retain billing, tax, refund, and dispute records for the periods required by applicable law; the policy will be updated before collection begins.
There is not yet a self-service account-deletion control. Send a deletion request to utmoreumt@gmail.com. After identity and scope are verified, UTMora will normally complete the primary-data deletion within 30 days, unless a longer period or limited retention is permitted or required by applicable law. Deletion may be delayed only for a stated operational or legal reason.
Your choices and rights
Depending on applicable law, you may have rights to know the sources, purpose, location, recipients, and safeguards for your data; access, correct, delete, restrict, or export it; object to certain processing; withdraw consent where consent is used; and complain to the Ukrainian Parliament Commissioner for Human Rights or another competent supervisory authority. Use the Support & Contact page to make a request. We may verify identity proportionately before acting on a request.
Security, children, and changes
UTMora uses account authentication, server-side authorization, and database row-level security to protect workspace data, but no system can guarantee absolute security. The service is not directed to children. Material policy changes will be posted here with a revised date.