Security and privacy

A GDPR-compliant URL shortener, hosted in the EU

94.si is a URL shortener and QR code generator run by CNJ d.o.o. in Ljubljana, Slovenia, since 2016. Your data and your visitors' data stay in the European Union and are processed under the GDPR, and every destination is checked with Google Web Risk before a link is saved. The app is available in English and Slovenian.

Privacy by default

Advertising pixels are the one exception to the cookie rule: if a Business Pro customer enables a Meta, Google Ads or LinkedIn pixel on a link with their own domain, the pixel may set cookies, and the customer has to inform visitors.

Servers and processors in the EU

Purpose Processor Location
Hosting and storage Hetzner Online GmbH EU data centres
Sign-in codes and notifications Amazon Web Services EMEA SARL (Amazon SES) Luxembourg
Payments Stripe Payments Europe, Ltd. Ireland
Website font Google Fonts, Google Ireland Limited Ireland
Destination safety checks Google Web Risk receives the destination URL only

We do not sell data or pass it to third parties for their own purposes. Website statistics run on a self-hosted Plausible Analytics instance, without cookies or cross-site tracking.

Every destination checked with Google Web Risk

Scammers like short links because they hide where a link goes. 94.si checks every new destination, and every change to an existing one, against Google Web Risk, the business service built on the same lists as Google Safe Browsing. A destination listed for malware, phishing or unwanted software cannot be saved, and the form says so while you type. Only the destination URL is sent to Google, nothing about you or your visitors.

Direct links to Windows programs, installers, scripts and disk images (.exe, .msi, .bat, .ps1, .vbs, .iso and similar) are refused too; link to the page that offers the download instead.

Domains that filters trust

Every day we check that the 94.si domains are on no block list: Google Web Risk and the security DNS filters used by companies, carriers and home networks, including Cloudflare, Quad9, DNS4EU, AdGuard, OpenDNS, CleanBrowsing, Control D and Mullvad. That keeps short links opening in browsers, mail clients and corporate networks.

Passwordless sign-in and encryption

Accounts have no password to steal: each sign-in uses a one-time link or code sent by email. All traffic, including redirects on short links and custom domains, runs over HTTPS with TLS. Business plans add per-project access, user roles, an audit trail of changes and single sign-on (SSO) on request.

Frequently asked questions

Is 94.si GDPR compliant?

Yes. 94.si is run by CNJ d.o.o. in Ljubljana, Slovenia, under Slovenian law and the GDPR. Data is stored in the EU, no cookies are set when someone clicks a short link, link owners see only aggregated statistics, and organisations can sign a data processing agreement under Article 28 GDPR.

Where is the data stored?

On servers of Hetzner Online GmbH in data centres in the European Union. Email delivery (Amazon SES, Luxembourg) and payments (Stripe, Ireland) are also handled by EU entities.

Does 94.si set cookies when a short link is clicked?

No. No cookies are set on a click and visitors are not recognised across links. The exception is a link on which a Business Pro customer enables an advertising pixel on their own domain; the customer then has to inform visitors about cookies.

Try 94.si for free

Up to 20 links, QR codes and click statistics on the free plan. No password, no credit card. Questions about a DPA or a team plan: info@94.si.

Create a free accountPrivacy policy (Slovenian)

In Slovenian: Varnost in zasebnost pri 94.si.