Short.io logo
Marketing Analytics Attribution · Api Tools

Short.io

Short.io turns long URLs into branded short links on your own domain, with real-time click analytics, dynamic QR codes and a REST API. A permanent free plan covers 1,000 branded links without a credit card.

Active GDPR compliant Free plan · Free trial Freemium API available 18+ Verified by Guidaio
Overview

What is Short.io?

Short.io is a white-label link shortener operated by Short.cm Inc, a Delaware corporation. Instead of publishing a generic short link, you point your own domain at the service and every shortened URL carries your brand; a free s.gy subdomain is available if you would rather not bring a domain. The company reports 13 billion links created, 100 billion clicks tracked, 1.2 million active users and coverage in more than 180 countries, from a fully distributed team of twelve people across four countries.

The product organises itself around six pillars. Analytics record a real-time click stream with more than thirty data points per click, broken down by device, browser, referrer and geography down to city level. Custom domains come with free automated SSL from Let's Encrypt; you can connect an existing domain by DNS, buy one inside the app from 7 USD a year, or start on the free subdomain. QR codes are dynamic, so a printed code can be repointed later without reprinting, and they export to PNG, SVG and PDF with custom colours and logos. API access exposes more than fifteen REST endpoints, official JavaScript, Node.js, iOS and Android SDKs, bulk operations and webhooks, serving around five million calls a day. Link management adds folders, tags, search, CSV bulk editing and a UTM builder. Team collaboration brings Admin, User and Read-only roles, shared analytics and SAML 2.0 single sign-on on the upper tiers.

Several features are AI-assisted: slug generation, an in-product assistant, and AI QR codes that Google's Gemini models repaint as artwork while keeping them scannable. Each plan carries a monthly AI usage allowance, from 1 to 100 USD.

Link-level controls include password protection, expiration, click limits, cloaking, referrer hiding and encrypted links. The infrastructure runs on AWS with six points of presence, a 99.9% uptime SLA and peak capacity above 200,000 redirects per second. Short.io holds ISO 27001 certification and SOC 2 Type II compliance, and publishes a trust centre.

What it does

  • Create branded short links on your own custom domain, with free automated SSL
  • Track clicks in real time by country, city, device, browser and referrer
  • Generate dynamic QR codes whose destination can be changed without reprinting
  • Create, edit and manage links programmatically through a REST API and official SDKs
  • Route visitors by country, region, city or operating system, including mobile deep links
  • Run A/B tests and build UTM-tagged campaign links
  • Work as a team with roles, shared folders and SAML single sign-on
Audience

When to use Short.io / When not to

A quick filter to help you decide if Short.io is the right fit.

When to use Short.io

  • Marketing teams running multi-channel campaigns who need UTM tagging, A/B tests and click attribution in one place
  • Agencies managing several clients, since each account can carry its own branded domain and separate analytics
  • Developers and engineering teams integrating link creation into their own products through the REST API and SDKs
  • Bloggers, affiliate marketers and freelancers who want readable, on-brand links on the permanent free plan
  • Regulated organisations in finance, healthcare or the public sector that require ISO 27001, SOC 2 Type II, a DPA or a HIPAA BAA

When not to use Short.io

  • Organisations whose procurement requires a verifiable registered office, as no postal address is published anywhere on the site
  • Compliance teams that must document whether customer data feeds AI model training, a question the site never answers
  • Small teams on a tight budget who need several seats, because multi-user access only starts on the 48 USD/month Team plan
  • Anyone under 18, since the terms require legal majority to open an account
  • Users in Cuba, Iran, North Korea or the Crimea, Donetsk and Luhansk regions, which the sanctions clause excludes
Get started

How to use Short.io

A typical end-to-end flow, from setup to results.

  1. Paste a long URL into the shortening field on the home page to get an instant .s.gy link, no account needed
  2. Create a free account - no credit card is requested
  3. Choose your domain strategy: keep the free s.gy subdomain, buy a domain inside the app from 7 USD a year, or connect a domain you already own
  4. If you connect your own domain, apply the DNS settings from the setup guide and let the free SSL certificate issue automatically
  5. Create your first branded links, giving them custom slugs, tags and folders
  6. Add UTM parameters with the built-in builder so campaigns report correctly in your analytics
  7. Import or bulk-create links from CSV, or automate creation through the REST API and SDKs
  8. Install the Chrome, Firefox or Edge extension, or use the '/shorten' Slack command, to shorten from anywhere
  9. Connect analytics and marketing tools such as Google Analytics, Google Tag Manager, Meta Pixel or AdRoll
  10. Invite teammates with Admin, User or Read-only roles, and configure SAML single sign-on on the higher plans
Quick read

Pros & Cons

Pros

  • A genuinely usable permanent free plan: 1,000 branded links, five custom domains, 50,000 tracked clicks a month and API access
  • Custom domains are available from the free tier upward, with automatic SSL at no cost
  • Strong security posture: ISO 27001 certified, SOC 2 Type II compliant, with a public trust centre and annual third-party audits
  • Compliance paperwork is available rather than promised: standard DPA, SCCs, UK IDTA and a HIPAA BAA
  • The subprocessor list is published in full, naming each vendor, its purpose and the data shared
  • A mature API with official SDKs across four platforms, handling around five million calls a day
  • An established, profitable vendor with more than a decade on the market and no dependence on outside funding

Cons

  • No postal address is published anywhere on the site, in any of the usual legal locations
  • The company's own founding year is inconsistent across its pages, and no verifiable incorporation date exists
  • The site never states whether customer data is used to train AI models, although prompts reach three separate AI providers
  • No Article 27 EU representative is designated, despite the claim of GDPR compliance
  • No documented way to exclude your data from AI training
  • Free, Hobby and Pro plans include a single user; team access only begins at 48 USD a month
  • Prices are absent from the main pricing cards, which render in JavaScript, and appear only in the comparison table
Pricing

Pricing & Plans

Short.io offers a permanent free plan, not merely a time-limited trial: it includes 1,000 branded links, five custom domains and 50,000 tracked clicks per month, and requires no credit card. The lowest paid entry point is the Hobby plan at 5.00 USD per month. Paid tiers rise to 18 USD for Pro, 48 USD for Team and 148 USD for Enterprise, all quoted monthly. Annual billing is advertised as saving 17%, a seven-day free trial is offered on the paid plans, and prices can be displayed in nineteen currencies.

Free - 0 USD
  • 1 user
  • 5 custom domains
  • 1
  • 000 branded links
  • 1
  • 000 link automations
  • 50
  • 000 tracked clicks/month
Pro - 18 USD/month
  • 1 user
  • 10 custom domains
  • unlimited branded links and tracked clicks
  • 10
  • 000 automations/year
  • 1 GB storage
  • 14 USD/month AI allowance
  • adds password protection
Team - 48 USD/month
  • unlimited users
  • 50 custom domains
  • 100
  • 000 automations/year
  • 10 GB storage
  • 35 USD/month AI allowance
  • adds city and region targeting
  • mobile deep links
Enterprise - 148 USD/month
  • unlimited custom domains and automations
  • 200 GB storage
  • 100 USD/month AI allowance
  • adds multiple teams
  • SAML single sign-on
  • raw data export to S3 and a dedicated IP
Optional extras
  • additional API capacity at 50 USD/month per 50 requests per second
  • and in-app domain purchase from 7 USD/year
Special offers — Permanent free plan with 1,000 branded links, five custom domains and API access, with no credit card required · Seven-day free trial on the paid plans · 17% saving advertised on annual billing compared with monthly · Free s.gy subdomain for immediate use without buying a domain · Free automated SSL certificates through Let's Encrypt on every custom domain · A free trial can be arranged on request through the enterprise quote form
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Short.io handles your data.

GDPR overview

GDPR coverage is concrete and documented. The policy page is titled "Privacy Policy and GDPR", was last updated in August 2026, and claims compliance with the GDPR, CCPA and other international regimes. It lists the six data subject rights - access, rectification, erasure, restriction, portability and objection - with a stated 30-day response window and a dedicated contact at privacy@short.io. Legal bases are named: contract, legitimate interest, consent and legal obligation. Transfers out of the EEA rely on the European Commission's Standard Contractual Clauses, and UK transfers on the IDTA or UK Addendum. A standard DPA is available, a full subprocessor table is published, and a HIPAA BAA can be executed. One gap stands out: no Article 27 EU representative is designated anywhere on the site.

Who owns the data?

The privacy policy states plainly that Short.cm Inc does not sell personal data. The company collects account details, the links you create, click statistics, the prompts you submit to its AI features, technical identifiers and billing data. You keep the right to access, correct, export and erase that data, and you can delete your account from the dashboard at any time. Intellectual property in the service itself stays with the vendor. One clause deserves attention: any feedback or feature request you send becomes non-proprietary and non-confidential, granting the company a perpetual, worldwide, irrevocable and royalty-free licence to use it without compensation.

Reuse rights

Your links, analytics and exports remain yours to reuse freely: Short.io places no restriction on what you do with the click data you generate, and it can be exported as CSV, JSON or raw S3 feeds on the higher plans. The vendor's own reuse is bounded by stated purposes: running and improving the service, processing payments, powering AI-assisted features, fighting fraud and meeting legal obligations. Prompts sent to the AI features travel to third-party providers to produce a response, and destination URLs are shared with security vendors for malware and phishing checks. Note that AI-generated QR artwork is served from a public URL so it stays scannable. What you may not do is resell, sublicense or redistribute the service itself.

Data retention & training

Retention summary
Short.io keeps personal data only for as long as it needs to run the service and meet its legal obligations, without publishing a fixed period for account data. You can request deletion at any time and the company undertakes to respond within 30 days; you can also delete your account yourself from the dashboard settings. Analytics data has a stated retention of 26 months. Backups follow a tiered schedule: daily backups kept for 30 days, weekly backups for 90 days and monthly backups for one year, alongside real-time replication and point-in-time recovery. If you buy a domain through the service, it is transferred to your own AWS account within 14 days of purchase, or to a third-party registrar within 60 days.
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Short.io's US and global service runs on Amazon Web Services in the United States, which places the data under US jurisdiction. A standby disaster-recovery cluster is maintained with Hivelocity in Dallas, Texas, so the service can be restored if the primary region fails. Replicas sent there are encrypted at rest and the network links carrying them are encrypted in transit; the disk-encryption keys stay sealed in each server's firmware TPM and are never shared with Hivelocity, so its staff cannot read the stored data. Redirect traffic is served from six points of presence - North Virginia, Frankfurt, Milan, Sao Paulo, Seoul and Bangkok - in an active-active multi-region setup with sub-30-second failover. Data is encrypted with AES-256 at rest and TLS 1.2 or above in transit. Recovery objectives are stated as under one hour for RPO and under four hours for RTO. Transfers out of the EEA rely on Standard Contractual Clauses.

Hosting countries
🇺🇸 United States
Availability

Where Short.io works

Country-level availability.

Not available in

Cuba excluded by the sanctions and export compliance clause of the terms of serviceIran excluded by the sanctions and export compliance clause of the terms of serviceNorth Korea excluded by the sanctions and export compliance clause of the terms of serviceCrimea region of Ukraine subject to comprehensive sanctions under the terms of serviceDonetsk region of Ukraine subject to comprehensive sanctions under the terms of serviceLuhansk region of Ukraine subject to comprehensive sanctions under the terms of serviceMainland China not excluded, but directed to a separate local version of the service at shortio.cn
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Short.io.

  • AI-generated QR artwork is served from a public URL so that it stays scannable, which means the prompt you wrote and the link it encodes are not private
  • Destination URLs of the links you create are shared with Google Web Risk, SURBL and Netcraft for malware and phishing checks
  • The vendor takes no published position on whether your data trains AI models, and offers no documented opt-out, while three AI providers receive your prompts
  • Feedback and feature requests you submit become non-proprietary, granting the company a perpetual, worldwide, royalty-free licence with no compensation
  • Phone verification routes your number through Meta's WhatsApp, Telegram or Twilio depending on your country
  • Links created on the free s.gy domain sit on infrastructure the vendor owns, with usage rights limited to the test period, so treat them as disposable rather than permanent
  • Liability is capped at twice the fees paid over twelve months and disputes fall under Delaware law, which may be remote for non-US customers
Setup

Setup & Integrations

Technical difficulty

Very low to moderate, depending on how far you go. Shortening a link on the home page needs no account at all, and signing up requires no credit card. Using the free s.gy subdomain or buying a domain inside the app involves no configuration whatsoever. Connecting a domain you already own is the only step needing technical work: you apply DNS records from a setup guide, and SSL is then issued automatically. Automation through the API or SDKs assumes developer skills, and SAML single sign-on requires configuration on your identity provider.

Deployment

Web appMobile appBrowser extensionAPISlack appChrome extensionIOS appAndroid app

Apps stores

Integrations

Zapier Make Segment Google Analytics Google Tag Manager Meta Pixel AdRoll Slack Google Chrome Firefox Microsoft Edge WordPress Mailchimp Google Ads

Supported languages

EnglishArabicBulgarianBengaliGermanSpanishFrenchHebrewHindiIndonesianItalianJapaneseKoreanDutchPolishPortugueseRussianSwedishThaiTurkishUkrainianVietnameseChinese
Company

Behind Short.io

Company name
Short.cm Inc
Founded
INFORMATION_NOT_FOUND
Country of origin
🇺🇸 United States
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇫🇷 France
Support contact

Fundraising

No fundraising is published on the site: Short.cm Inc discloses no investors, no funding rounds and no amounts raised
The only financial milestone the company states first-hand is on its about page - profitability reached in 2019, described as sustainable growth

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Is there a free plan, or only a trial?
There is a permanent free plan, not a trial. It includes 1,000 branded links, five custom domains, 50,000 tracked clicks per month, QR codes and API access, and no credit card is required. A separate seven-day free trial is offered on the paid plans.
Can I use my own domain on the free plan?
Yes. Custom domains are available from the free tier upward, and SSL certificates are issued automatically at no cost through Let's Encrypt. You can connect a domain you already own by DNS, buy one inside the app from 7 USD a year, or use the free s.gy subdomain.
What analytics does Short.io provide?
A real-time click stream with more than thirty data points per click, including country and city-level geography, device and browser type, referrer, status code, method and user agent. Data can be exported as CSV or JSON, and as raw S3 feeds on the Enterprise plan.
Is there an API?
Yes. Short.io publishes a REST API with more than fifteen endpoints, official SDKs for JavaScript, Node.js, iOS and Android, plus bulk operations and webhooks. The company reports around five million API calls a day. Documentation is at developers.short.io.
What security certifications does Short.io hold?
The company is ISO 27001 certified, achieved in 2023, and SOC 2 Type II compliant, achieved in 2024, with annual independent audits. A public trust centre is available, SOC 2 reports are shared under NDA, and data is encrypted with AES-256 at rest and TLS 1.2 or above in transit.
Can Short.io sign a DPA or a HIPAA BAA?
Yes to both. Standard Data Processing Agreements are provided, covering GDPR, CCPA, Standard Contractual Clauses and UK GDPR, and Business Associate Agreements can be executed for healthcare organisations.
Where is my data hosted?
The US and global service runs on Amazon Web Services in the United States. A standby disaster-recovery cluster is maintained with Hivelocity in Dallas, Texas, where replicas are encrypted at rest and the disk-encryption keys stay sealed in each server's firmware TPM.
Does Short.io use my data to train AI models?
The site does not say. Its privacy policy documents that prompts and related context are sent to AI subprocessors, naming OpenAI, Google Gemini and AWS Bedrock, but it takes no position on whether customer data is used for model training, and no opt-out is documented.
How long is my data kept?
Personal data is kept only as long as necessary to run the service and meet legal obligations, and you can request deletion at any time. Analytics data is retained for 26 months. Backups run daily with 30-day retention, weekly with 90-day retention and monthly with one-year retention.
Is there a minimum age?
Yes. The terms of service require account holders to be at least 18 years old, or to have reached legal majority and capacity where they reside.
Conclusion

Should you pick Short.io?

Short.io is a mature, unusually well-documented link shortener. A decade on the market, profitable since 2019 and reporting 13 billion links created, it is not a project at risk of disappearing. Its free plan is genuinely useful rather than decorative, since custom domains and API access are included from the first tier, and its compliance package - ISO 27001, SOC 2 Type II, a standard DPA, a HIPAA BAA and a fully published subprocessor list - is stronger than most tools of this size offer.

The reservations are about transparency rather than capability. The company publishes no postal address anywhere on its site, and its own pages disagree on the year it was founded, so no verifiable incorporation date exists. More consequential for anyone running a data protection review: although prompts, link content and destination URLs pass through OpenAI, Google Gemini and AWS Bedrock, the site never states whether customer data is used to train models, and documents no way to opt out. No Article 27 EU representative is designated either, which sits awkwardly beside an explicit GDPR compliance claim.

Pricing is fair but the shape matters: Free, Hobby and Pro each include a single user, so any genuine team collaboration starts at 48 USD a month. For an individual creator, an affiliate marketer or a developer wiring links into a product, the free and low tiers are excellent value. For a regulated organisation, the certifications will satisfy security review while the AI-training silence and the missing legal identity are the two questions worth putting to the vendor in writing before signing.