h/hoist/cc
  • Features
  • Pricing
Log inGet started

Legal

Privacy Policy

Version 1.1 · Last updated 3 August 2026
On this page
  1. 1Who We Are & Scope
  2. 2Data We Collect
  3. 3Purposes & Consent
  4. 4Marketing Communications
  5. 5Disclosure & Transfers
  6. 6Analytics
  7. 7Data Retention
  8. 8Your Rights
  9. 9Accuracy & Security
  10. 10Data Breach Notification
  11. 11Children's Data
  12. 12Data Protection Officer
  13. 13Cookies
  14. 14Changes to this Policy

Pure Digital Pte Ltd (UEN 201830211Z) ("Pure Digital", "Hoist", "we", "us", "our") operates the Hoist URL-shortening service at hoist.cc. This Privacy Policy explains how we collect, use, disclose and protect personal data, in accordance with the Personal Data Protection Act 2012 of Singapore ("PDPA"). "Personal data" has the meaning given in the PDPA.

Hoist is built around a deliberately privacy-conscious design: we do not log IP addresses, and we do not store personally identifiable information in our click analytics. This Policy describes only what we actually collect.

1. Who We Are and Scope

1.1Pure Digital is the organisation responsible for personal data processed through the Service. This Policy applies to our marketing website, app/dashboard and API.

2. The Personal Data We Collect

2.1Account data: your email address and name, and your workspace/team membership and roles.

2.2Authentication data: a bcrypt hash of your account password (we never store the plaintext), short-lived one-time 6-digit codes sent to verify email ownership at signup, and short-lived magic-link tokens issued solely for account recovery. Where you enable password protection on a link, we store only a bcrypt hash of that link password — never the plaintext.

2.3Link data: the destination URLs you shorten, your slugs/hoists, custom domains and related settings. Destination URLs may themselves contain personal data if you choose to include it; you are responsible for that choice.

2.4Click ("lift") analytics — privacy-conscious by design. For each lift we record only: country (2-letter code, derived solely from hosting/CDN provider headers), coarse city, device type (desktop/mobile/tablet/bot), operating system, browser, and the referrer domain (hostname only — not the full path). There is no IP address field in our database; we do not store IP addresses, and we do not collect personally identifiable information about the people who click your links. Geo-data is derived only from hosting/CDN headers, not from any IP geolocation that we perform or retain.

2.5Payment data: processed by Stripe. We do not store full card numbers; we may retain limited billing metadata (e.g. plan, invoice and transaction records).

3. Purposes, Consent and Notification

3.1We collect, use and disclose personal data only for purposes that a reasonable person would consider appropriate in the circumstances and which we have notified to you, including to: provide, secure and operate the Service; authenticate you; generate analytics for you; process billing; provide customer support; detect, prevent and address abuse, fraud and illegal use; and comply with legal obligations.

3.2We rely on your consent (including deemed consent for personal data reasonably necessary to provide a service you have requested) and, where applicable, on exceptions to consent permitted under the PDPA (for example, the legitimate-interests exception to detect and prevent abuse and protect the Service and the public).

3.3We will not, as a condition of providing the Service, require you to consent to the collection, use or disclosure of personal data beyond what is reasonable to provide the Service. You may withdraw consent as described in Clause 8.

4. Marketing Communications

4.1We send transactional emails (e.g. magic links and billing notices) via Resend. With your consent, we may also send product updates or marketing emails. Every marketing message will identify us, contain accurate header and subject-field information, and include an unsubscribe facility. Consistent with the Spam Control Act 2007 (Second Schedule), the unsubscribe facility will remain valid for at least 30 days after the message is sent, and we will stop sending further such messages within 10 business days after you submit an unsubscribe request.

5. Disclosure and Subprocessors; Cross-Border Transfers

5.1We share personal data with the following service providers ("subprocessors"), who process it on our behalf:

  • Vercel — hosting and deployment — United States
  • Neon — PostgreSQL database hosting — United States
  • Resend — transactional email — United States
  • Stripe — payment processing — United States

5.2Because these subprocessors are located outside Singapore, such transfers are subject to the PDPA's Transfer Limitation Obligation (Section 26). We take reasonable steps to ensure each overseas recipient is bound by legally enforceable obligations (through data-processing agreements and/or contractual clauses) to provide the transferred personal data a standard of protection comparable to the PDPA.

5.3We may also disclose personal data: to comply with applicable law, regulation, or a lawful request from law enforcement or a regulator; to enforce our Terms or AUP, including investigating potential violations; to detect, prevent or address fraud, security or technical issues; and to protect the rights, property and safety of Hoist, our users and the public. We may disclose data in connection with a merger, acquisition, financing or sale of assets, subject to this Policy.

6. Analytics

6.1We use Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) for visitors in the European Economic Area, the United Kingdom and Switzerland, and by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, United States) for visitors elsewhere ("Google"). Google processes this information as our data processor under Google's Data Processing Terms.

6.2What we collect through Google Analytics. The pages you view and the order you view them in; the date, time and duration of your visit; the website, search or advertisement that referred you to us; your device type, operating system, browser and screen size; and an approximate location (country, and in some cases region or city) derived from your IP address. We also record a small number of specific product events: creating an account, creating your first hoist, and beginning a checkout. If you subscribe to a paid plan, our servers send the transaction reference, amount and plan name to Google Analytics.

6.3According to Google, Google Analytics 4 does not log or store IP addresses. Your IP address is used transiently to derive an approximate location and is then discarded.

6.4What we do not send to Google Analytics. We do not send your name, your email address, your password, your payment card details, the destination URLs of your hoists, or the contents of any link you create.

6.5Legal basis. If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on your consent under Article 6(1)(a) of the UK and EU General Data Protection Regulation. You give that consent through our cookie banner and may withdraw it at any time. If you are elsewhere, we rely on your consent or deemed consent under the Personal Data Protection Act 2012 of Singapore, or on our legitimate interest in understanding how our service is used.

6.6International transfers. Google may process this information on servers in the United States and in other countries outside Singapore, the European Economic Area and the United Kingdom. Where information is transferred out of the European Economic Area or the United Kingdom, Google relies on the European Commission's Standard Contractual Clauses and the United Kingdom International Data Transfer Addendum, as set out in Google's Data Processing Terms.

6.7Retention. Event-level Google Analytics data is retained for 14 months and is then deleted. Aggregated reports derived from that data may be retained for longer.

6.8Your choices. You can accept or decline analytics cookies using our cookie banner, and you can change your choice at any time using the "Manage cookie preferences" control on our Cookie Policy. You can also install Google's Analytics Opt-out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout. Google's privacy policy is available at https://policies.google.com/privacy, and Google explains how it handles data from sites that use its services at https://policies.google.com/technologies/partner-sites.

Consent and regional differences

6.9Our cookie banner uses Google Consent Mode. If you visit Hoist from the European Economic Area, the United Kingdom, Switzerland, Norway, Iceland or Liechtenstein, analytics and advertising storage are denied by default: no analytics or advertising cookies are set, and Google receives only anonymous, cookieless signals, until you choose to accept. If you visit from anywhere else, analytics and advertising storage are granted by default, and you may decline at any time using the same banner.

6.10Advertising cookies are set only where we are actively running the advertising services described in our Cookie Policy. Where we are not, no advertising cookies are set regardless of your choice.

Google Advertising Features

6.11We have enabled Google signals in our Google Analytics property. Google signals is one of the Google Analytics Advertising Features, and this clause is our disclosure of that use, as required by Google's Advertising Features policy.

6.12What Google signals does. When Google signals is enabled, Google Analytics may associate the information described in this Clause 6 with information Google already holds about visitors who are signed in to a Google account and who have themselves consented, in their Google account settings, to that association. Google's information may include their location, search history, YouTube history, and data from sites that partner with Google. We use this only to produce aggregated reporting inside Google Analytics: estimated age, gender and interest categories for our audience as a whole, and reporting on visits made across more than one device.

6.13What Google signals does not do. It does not give us access to any individual's Google account, search history, YouTube history, or browsing activity on other websites. Google Analytics reports these categories only in aggregate, and withholds data entirely where the number of visitors is small enough that an individual could be identified. We do not receive, and cannot derive, the identity of any signed-in visitor from these reports. Google signals does not change what we send to Google Analytics, which remains as described above in this Clause 6.

6.14Sensitive categories. We do not use Google signals, or any other Google Analytics Advertising Feature, to build or infer audiences based on the sensitive categories set out in Google's Advertising Features policy and its personalised advertising policies.

6.15Cookies and identifiers. Where Google signals operates, Google may use its own advertising cookies and identifiers alongside the first-party Google Analytics cookies described in our Cookie Policy. For visitors in the European Economic Area, the United Kingdom, Switzerland, Norway, Iceland and Liechtenstein, none of this occurs unless and until you accept through our cookie banner, because analytics and advertising storage are denied by default in those regions as described in Clause 6.9.

6.16How to opt out. In addition to the choices described in Clause 6.8, you may at any time:

  • turn off Ads Personalisation in your Google account at https://myadcenter.google.com, which stops Google associating your signed-in account information with our Analytics data;
  • view, download and delete the activity Google holds against your Google account at https://myactivity.google.com;
  • decline analytics through our cookie banner.

6.17Google describes the Google Analytics Advertising Features and how to control them at https://support.google.com/analytics/answer/2700409, and describes how it uses data for advertising at https://policies.google.com/technologies/ads.

7. Data Retention

7.1We retain click analytics according to your plan tier: Free — 30 days; Starter — 1 year; Pro — retained until you delete the link or your account (unlimited retention period). Account data is retained while your account is active and for a reasonable period afterward for legal, accounting, security and dispute-resolution purposes, after which it is deleted or anonymised in accordance with the PDPA.

8. Your Rights

8.1Subject to the exceptions in the PDPA, you may: request access to the personal data we hold about you and to information on how it has been used or disclosed in the year before your request; request correction of errors or omissions; and withdraw consent to our collection, use or disclosure of your personal data, on giving reasonable notice (we will inform you of the likely consequences, which may include our inability to continue providing the Service).

8.2The PDPA's Data Portability Obligation has been enacted but is not yet in force. We will support data-porting requests once it commences and the prescribed requirements apply.

8.3To exercise any right, contact our Data Protection Officer (Clause 12). We may verify your identity, may charge a reasonable fee for access requests where permitted, and will respond within the timeframes required by the PDPA.

9. Accuracy, Protection and Security

9.1We make reasonable efforts to ensure personal data is accurate and complete where it may be used to make a decision affecting you.

9.2We implement reasonable security arrangements, including encryption in transit (HTTPS), hashed link passwords (bcrypt), access controls, and an audit log of administrative actions. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Data Breach Notification

10.1If we assess a data breach to be notifiable under the PDPA — that is, it is likely to result in significant harm to affected individuals, or it affects 500 or more individuals (regardless of harm) — we will notify the Personal Data Protection Commission (PDPC) as soon as practicable and no later than 3 calendar days after we assess that the breach is notifiable, and we will notify affected individuals where the PDPA requires.

11. Children's Data

11.1The Service is not directed to, or intended for, individuals under 18 years of age. We do not knowingly collect their personal data. If we learn we have collected such data without appropriate consent, we will delete it.

12. Data Protection Officer; Complaints

12.1In accordance with the PDPA's Accountability Obligation, we have appointed a Data Protection Officer (DPO). Contact: dpo@hoist.cc; Pure Digital Pte Ltd, 22 Sin Ming Lane, #06-76, Midview City, Singapore 573969.

12.2If you have a question or concern about your personal data, please contact our DPO first. You also have the right to lodge a complaint with the PDPC (pdpc.gov.sg).

13. Cookies

13.1We use minimal cookies. Please see the Hoist Cookie Policy for details.

14. Changes to this Policy

14.1We may update this Privacy Policy from time to time. We will post the revised version with a new "Last Updated" date and, where required, obtain fresh consent.

14.2Version 1.1 — 3 August 2026: added disclosure of Google Analytics 4, the Google Analytics Advertising Features we use, and our cookie consent mechanism.

h/hoist/cc

Product

  • Features
  • Pricing

Company

  • About
  • Contact
© 2026 Pure Digital Pte Ltd · Singapore
PrivacyTermsCookiesAcceptable Use