Media2URL
Privacy

Privacy Policy

Media2URL privacy policy and user data protection details.

Last updated: July 26, 2026

Global privacy disclosures regarding how Media2URL collects, processes, stores, shares, and protects customer data, uploads, cookies, and audit logs.

Media2URL is committed to transparent, compliant, and secure media hosting. When you upload files, configure workspaces, share links, process media, or subscribe to our platform, we process data strictly to operate the service, enforce security controls, and comply with legal obligations.

This Privacy Policy details our privacy commitments in plain, enforceable language. It applies globally to all visitors, account holders, recipients of shared links, safety reporters, and legal inquiries under global data protection frameworks including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

1. Information We Collect

Account & Profile Information: When registering an account or workspace, we collect your email address, login authentication identifiers (Supabase Auth tokens, hashed passwords, Google OAuth profile identifiers), and subscription tier status. For paid plans, subscription data and invoices are recorded, while full credit card numbers and financial credentials are processed exclusively by our PCI-DSS compliant payment gateways.

Media Assets, Metadata & Content: We process files you upload (images, videos, PDFs, GIFs, audio files) along with operational metadata including original filenames, MIME types, file size metrics, storage object keys (Cloudflare R2), folder structures, link slugs, visibility configurations (Public, Unlisted, Private, Password-protected), expiry timestamps, and password hash signatures.

Network Telemetry & Security Logs: Our edge delivery network and servers record request telemetry including IP addresses, browser types, device fingerprints, operating systems, user agents, referrers, request timestamps, bandwidth consumption, API rate limits, HTTP status codes, and security violation events. IP addresses are geolocated to country and region levels for analytics and fraud detection.

2. Data Processing & Storage Architecture

Infrastructure Segregation: Application database records, metadata indexes, and user authentication tokens are logically segregated from cloud object storage buckets containing raw media files.

Encryption Standards: All file transfers, dashboard communications, and API requests use mandatory TLS 1.3/1.2 (HTTPS) encryption in transit. Files stored in object storage buckets are protected using AES-256 server-side encryption at rest.

Access Isolation: Public assets are served via CDN edge nodes according to your link settings. Private, unlisted, password-protected, or expiring assets require token-validated session verification or valid password entries before file bytes are transmitted.

3. Legal Bases for Processing (GDPR)

Contractual Performance: Processing data necessary to deliver account dashboards, generate hosted URLs, execute media processing operations (cropping, merging, trimming, converting), and manage paid subscriptions.

Legitimate Interests: Protecting platform security, preventing spam and automated DDoS floods, enforcing plan quotas, investigating abuse reports, and optimizing system performance.

Legal & Regulatory Compliance: Retaining audit trails and responding to valid subpoenas, court orders, DMCA copyright notices, law enforcement inquiries, and mandatory child exploitation reporting requirements.

4. Third-Party Subprocessors

Infrastructure & Storage: Cloudflare R2 (Object Storage and CDN Delivery), Supabase (Database, Auth, and Metadata Storage), Vercel (Frontend Application Hosting).

Payments & Billing: Transactional payment gateways process checkout, invoicing, and subscription renewals without exposing full card details to Media2URL.

Communications & Operations: Transactional email services deliver account verification, password resets, security notifications, and abuse intake receipts.

5. International Data Transfers & Standard Contractual Clauses

Global Routing: Media2URL operates globally. Your data may be processed or stored in servers located in the United States, European Union, and edge locations worldwide.

Transfer Mechanisms: Where data is transferred outside the European Economic Area (EEA) or United Kingdom, we rely on Standard Contractual Clauses (SCCs) and adequacy decisions to ensure equivalent data protection safeguards.

6. Data Subject Rights (GDPR / CCPA / CPRA)

Right of Access and Portability: You have the right to request a copy of your personal data, metadata records, and uploaded files in a structured, machine-readable format.

Right to Erasure (Right to be Forgotten): You may delete files, folders, or your entire account at any time through the dashboard. Upon account deletion, personal identifiers and active file paths are permanently purged, subject to legal holds and accounting retention mandates.

Right to Restrict & Opt-Out: You may restrict non-essential analytical logging or unsubscribe from marketing emails by adjusting account preferences. We do not sell or share personal data for cross-context behavioral advertising.

7. Data Breach Notification Protocol

In the event of a confirmed security incident impacting your unencrypted personal data, Media2URL will notify affected account holders and relevant regulatory authorities within 72 hours of verification, detailing the nature of the breach, affected data categories, and remediation actions taken.

Contact Media2URL about this page

If you have questions about this policy, your account, billing, uploads, abuse reports, DMCA notices, privacy requests, refunds, or legal/safety concerns, visit the Contact page or email us directly. For account-specific requests, email from the account address when possible.