pik.li pik.li

Legal

Privacy policy

This Privacy Policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and describes which personal data are processed in connection with pik.li, for what purposes, on what legal basis and for how long, to whom they are disclosed and what rights data subjects have. It is addressed to everyone who uses pik.li: users of the website, Customers who have created an account, Visitors who open a short link and anyone who contacts InCloud.

Last updated: 24 September 2026 · Version 2026-09-24.2

This text is published in nine languages. The Italian version is authoritative; the versions in other languages are translations provided for convenience only and, in the event of any discrepancy, the Italian text prevails.

In brief

  • The controller is InCloud S.r.l. Data are hosted on servers located with infrastructure providers (Hetzner, Vultr, DigitalOcean, Contabo, Microsoft Azure, Amazon Web Services) and at InCloud's premises in Vignola; for security reasons, traffic passes through the Cloudflare network.
  • When a Visitor opens a short link, InCloud records the full IP address together with the date and time, the estimated country and city, the device and the referring page. The Customer who created the link sees the IP address only in partial form; the full address is accessible only to authorised InCloud staff and, upon a valid request, to the authorities.
  • The full IP address is also recorded when the account is accessed: it serves to protect the Customer against account takeover and may be disclosed to the authorities.
  • If an account is closed, its data are kept for 6 months and then deleted; invoices and payment data are kept for 10 years, as the law requires.
  • Data are disclosed to the competent authorities where the law requires or permits it. InCloud does not sell data and does not use them to train artificial intelligence models.
  • Data subjects may access their data, obtain a copy, request rectification or erasure and object to processing; they may also lodge a complaint with the Garante per la protezione dei dati personali (the Italian data protection authority).

This summary is for guidance only: the full text below prevails in all cases.

1.Controller and contact details

The controller is InCloud S.r.l. (“InCloud”), whose identification and contact details are set out at the end of this section, and which determines the purposes and means of the processing of personal data described in this Privacy Policy.

InCloud has not designated a data protection officer (DPO). For any question about their data, or to exercise their rights, data subjects may write to the data protection contact given below; InCloud responds within one month.

Company name
InCloud S.r.l.
VAT number and tax code
IT04209270364
Registered office
Via Unità d'Italia 135, 41058 Vignola (MO), Italy
Certified e-mail (PEC)
[email protected]
Data protection contact
[email protected]
Customer support
[email protected]
Abuse reports
[email protected]
Requests from authorities
[email protected]

2.Categories of data subjects

  • Website users: those who browse pik.li and consult its pricing page, link checker or documentation.
  • Customers: those who register, create links and, where applicable, purchase a plan or a domain name.
  • Visitors: those who open a short link and are redirected to the destination. Visitors need no account and are often unfamiliar with pik.li: with regard to them, this Privacy Policy is also provided pursuant to Article 14 GDPR.
  • Persons submitting reports and other requesters: those who report a link, lodge an appeal, open a support request or contact InCloud in their capacity as an authority.

For link statistics, InCloud acts as controller: it determines how click data are collected, made visible and deleted. The Customer who created the link has access to aggregated data and to the data of individual clicks, with the Visitor's IP address shown in partial form. Business plan Customers who, in order to meet their own obligations, need a data processing agreement may request one from InCloud.

3.Data processed, purposes, legal bases and retention periods

The table below sets out, for each category of data, the purpose of the processing, the legal basis and the retention period. The letters in the “Legal basis” column refer to the points of Article 6(1) GDPR.

Account: e-mail address, username, password (stored only as a hash), recovery e-mail address if any, language and theme, account status, plan, limits or measures imposed by InCloud staff, dates of registration, confirmation and last activity, version of the Terms accepted and date of acceptance.

PurposeCreating and managing the account, sending the confirmation e-mail and service notices, applying plan limits, proving acceptance of the Terms.

Legal basisPerformance of a contract (point (b)); for proof of acceptance of the Terms, legitimate interests (point (f)).

RetentionFor as long as the account exists. If deletion is requested, the account remains pending deletion for 6 months, deactivated but with its data retained, and is then permanently deleted.

Two-step verification: secret seed (encrypted), hashes of the recovery codes and time at which the last code was used.

PurposeProtecting access to the account, if the Customer enables verification.

Legal basisPerformance of a contract (point (b)) and legitimate interests in security (point (f)).

RetentionFor as long as verification remains enabled: when it is disabled, the seed and codes are deleted.

Login sessions: full IP address, country and city estimated from the IP address, browser, operating system, device type, and start date and last activity date of each open session.

PurposeKeeping the Customer logged in, displaying open sessions so that the Customer can close them, detecting unauthorised access, responding to requests from authorities.

Legal basisPerformance of a contract (point (b)) and legitimate interests in the security of the Customer's account and of the Service (point (f)).

RetentionFor the duration of the session, which is deleted when the Customer logs out or closes it from Settings → Security, or when InCloud staff close it. The login cookie expires after 14 days at the latest; a session from which the Customer never logs out remains recorded until the account is permanently deleted.

Activity log: significant operations on accounts and links (logins, password changes, destination changes, disabling or deletion of links, changes to settings, data exports, payments, actions by InCloud staff), with date, author and, where recorded, IP address.

PurposeSecurity, evidence of the decisions taken, history of link changes, oversight of the actions of InCloud staff, responding to authorities.

Legal basisLegitimate interests (point (f)); compliance with a legal obligation, where logging is required by law (point (c)).

RetentionFor as long as the account exists and until it is permanently deleted.

Billing data: first name and surname, address, country and, for businesses, company name, VAT number (with the result of the check in the EU VIES system), tax code, PEC address, recipient code (codice destinatario) and telephone number.

PurposeCalculating the tax due, issuing invoices and receipts, complying with tax and accounting obligations.

Legal basisCompliance with legal obligations (point (c)) and performance of a contract (point (b)).

RetentionIn the profile, for as long as the account exists. The data shown on invoices and receipts are kept for 10 years from issue, as required by tax and civil law (Article 2220 of the Italian Civil Code), even after the account has been deleted.

Payments and orders: provider used, transaction reference, amount, fee, tax, date, status, and any refund requests with their reason and outcome. InCloud neither sees nor stores card numbers, PayPal credentials or cryptocurrency wallet keys, which are handled exclusively by the provider.

PurposeActivating plans and orders, reconciling payments received, handling refunds, disputes and fraud.

Legal basisPerformance of a contract (point (b)) and compliance with legal obligations (point (c)).

Retention10 years, together with the accounting records.

Domain names: names of the custom domains connected or purchased, DNS records, verification status and, for purchases, order data and registration and expiry dates.

PurposeServing links on the Customer's domain, registering and managing purchased domains.

Legal basisPerformance of a contract (point (b)).

RetentionFor as long as the domain remains connected to the account; purchase order data are subject to the rules in the “Payments and orders” row.

Link clicks (Visitor data): date and time, public identifier of the click, full IP address, technical fingerprints used to count unique visitors, country, region and city estimated from the IP address, device type, browser and operating system, browser language, referring page, user-agent string, originating network (ASN), and an indication of whether the click appears to be automated.

PurposeStatistics for the Customer who created the link; security of the Service, detection of automated traffic and prevention of abuse; responding to requests from authorities.

Legal basisLegitimate interests (point (f)) of Customers in measuring the use of their links, and of InCloud in protecting the Service and Visitors, preventing abuse and being able to respond to requests from authorities. As safeguards for data subjects, the Customer sees the IP address only in partial form (for IPv4 addresses, without the last of the four groups of digits; for IPv6 addresses, limited to the first three groups), the full address is accessible only to authorised InCloud staff, and the data are kept for a limited period.

RetentionAccording to the plan of the Customer who created the link: Base 90 days, Premium 730 days, Business 1095 days; the same period applies to IP addresses. Every night, an automated procedure deletes the clicks that have exceeded that period, and all click data are in any event deleted when the account concerned is permanently deleted. Files exported by the Customer remain available for download for 7 days.

Reports and appeals: link concerned, reason, details given by the person submitting the report, that person's e-mail address if given and their account if logged in, the decision taken by InCloud and the person who took it.

PurposeHandling reports of illegal or harmful content, appeals and complaints, as provided for by the Digital Services Act; responding to authorities.

Legal basisCompliance with legal obligations (point (c)) and legitimate interests (point (f)).

RetentionFor as long as the reported link exists and therefore, at the latest, until the account that created it is permanently deleted.

Support requests: tickets opened from the Support section of the dashboard (subject, messages, attached images, status, replies from InCloud staff) and messages sent by e-mail. Attached images are re-encoded and saved without the metadata of the original file, such as GPS location, device model or the date the picture was taken.

PurposeResponding to requests, resolving the problems reported and keeping track of requests.

Legal basisPerformance of a contract, where the request concerns the account or a purchase (point (b)); otherwise, legitimate interests in responding (point (f)).

Retention24 months from the closure of the ticket or from the last message, after which they are deleted; they are in any event deleted when the account is permanently deleted, unless they are needed for a pending dispute.

Notifications: the alerts shown to the Customer in the bell menu and those intended for InCloud staff (for example new sign-ups, logins, password changes, orders, links created or disabled, click thresholds reached), which contain the e-mail address or name of the account and, for logins, the browser and IP address. Some alerts intended for staff are also sent via WhatsApp to the administrator's phone.

PurposeKeeping the Customer informed of what happens in their account; enabling InCloud staff to detect abuse, suspicious logins and orders promptly.

Legal basisPerformance of a contract (point (b)) and legitimate interests in the security and management of the Service (point (f)).

RetentionIn the bell menu: 60 days for read notifications, 240 days for unread ones. WhatsApp messages remain on the administrator's phone until they are deleted.

API keys and webhooks: name and prefix of the key, hash and encrypted copy of the key, date of last use, number of requests; webhook URLs, secrets and delivery logs.

PurposeAuthenticating API calls and sending events to the Customer's systems.

Legal basisPerformance of a contract (point (b)).

RetentionUntil the key is revoked or the webhook is deleted and, at the latest, until the account is permanently deleted; delivery logs follow the fate of the webhook.

Requests from authorities: the request or order received, details of the authority and of the officials handling it, checks carried out, data disclosed and the relevant dates.

PurposeResponding to authorities, demonstrating that InCloud has acted in accordance with the law, keeping the register of orders.

Legal basisCompliance with legal obligations (point (c)); legitimate interests in documenting InCloud's own conduct (point (f)).

Retention5 years from the closure of the request, unless the authority specifies a different period or a different period is needed for the defence of legal claims.

InCloud does not send newsletters or marketing communications. The e-mails it sends are exclusively service messages: address confirmation, password reset, tax documents and notices concerning the account or links.

InCloud does not sell personal data and does not use them to train artificial intelligence models.

4.Sources of the data

  • From the data subject: the information entered in forms, the links created, and the messages and attachments sent.
  • From the data subject's device: with every request, the browser transmits technical data (IP address, user agent, language, referring page).
  • From Cloudflare and from a geolocation database installed on InCloud's servers: country, region, city and network estimated from the IP address. The database is queried on InCloud's servers and the address is not transmitted to third parties.
  • From payment providers: the outcome of the payment and its reference, never the details of the payment instrument.
  • From the European Commission's VIES system: the outcome of the check on businesses' VAT numbers.
  • From threat lists and from InCloud's artificial intelligence system: assessments of destinations, which concern the linked pages and not the people who create or open the links.
  • From authorities: the requests and orders they send.

5.Automated link checks and artificial intelligence

Every destination undergoes automated checks: quick rules when the link is created and, within about ten minutes, a comparison against the Google Safe Browsing and abuse.ch URLhaus threat lists and an assessment by an artificial intelligence system that InCloud runs on its own servers in Italy; no external artificial intelligence provider receives the links or the data. The system receives the destination address, the link title and certain technical signals, and returns a risk score, a category and a brief explanation. It does not receive the Customer's name, e-mail address or other account data, and it is not trained on their data.

The score concerns the destination page, not the person: InCloud does not carry out profiling of data subjects. A link may nevertheless be disabled automatically, without human intervention, when it is flagged by a threat list or when the score exceeds, with a high degree of confidence, the threshold set by InCloud. This is a decision based solely on automated processing, which affects the Customer's use of the Service and is necessary for the performance of the contract and for the protection of Visitors (Article 22(2)(a) GDPR).

Safeguards for the Customer: the reason for the decision is always visible in the dashboard; the Customer may lodge an appeal from the link's page and obtain a review by a person within two working days; they may express their point of view and contest the decision by writing to InCloud; InCloud staff may lift automated blocks at any time. Measures concerning accounts, such as blocks and closures, are always taken by a person.

6.Recipients of the data

Data are disclosed only to: the parties that help operate the Service as processors, bound by a contract under Article 28 GDPR; the providers that process data as independent controllers when the data subject uses their services (for example, payment providers); and the authorities, where the law requires or permits it.

InCloud S.r.l.

Activity and data receivedAuthorised InCloud staff, bound by confidentiality. Access is limited to what each person's duties require; significant operations, including viewing an account as it appears to the Customer, are logged. Only authorised staff can see Visitors' full IP addresses.

Place of processing and safeguardsItaly.

Hetzner Online GmbH · The Constant Company, LLC (Vultr) · DigitalOcean, LLC · Contabo GmbH · Microsoft Ireland Operations Ltd (Azure) · Amazon Web Services EMEA SARL (AWS) · InCloud S.r.l. (Vignola)

Activity and data receivedInfrastructure providers: the servers running pik.li and its databases and services, including the mail server, are located with these providers and at the premises of InCloud S.r.l. in Vignola (MO). The providers process data solely on InCloud's behalf, as processors.

Place of processing and safeguardsThe location depends on each provider's data centre; InCloud's premises are in Italy. For providers whose parent company is in the United States (Vultr, DigitalOcean, Microsoft and Amazon), see the section on transfers.

Prompter (InCloud AI service)

Activity and data receivedArtificial intelligence system that assesses destinations. It runs on InCloud servers in Italy and is part of InCloud's own infrastructure, not that of a third party: no external artificial intelligence provider receives the links or the data.

Place of processing and safeguardsItaly.

Cloudflare, Inc.

Activity and data receivedNetwork, DNS and security services protecting pik.li, the link domains and Customers' domains: processes traffic, including IP addresses, and derives the approximate location of Visitors.

Place of processing and safeguardsUnited States, with a global network that includes data centres in the European Union. Certification under the EU-US Data Privacy Framework and standard contractual clauses incorporated into the data processing agreement.

Google LLC — Safe Browsing

Activity and data receivedSafe Browsing: receives the destination addresses of links in order to check them against its own threat lists. It receives no data relating to Customers or Visitors.

Place of processing and safeguardsUnited States. Certification under the EU-US Data Privacy Framework.

Google LLC — reCAPTCHA

Activity and data receivedreCAPTCHA on the login, registration, password recovery, report and link creation forms: receives the IP address, technical browser data and information on interaction with the page, in order to distinguish humans from automated programs.

Place of processing and safeguardsUnited States. Certification under the EU-US Data Privacy Framework.

abuse.ch — URLhaus

Activity and data receivedURLhaus: receives the host names of destinations in order to check them against its own list of sites distributing malware.

Place of processing and safeguardsSwitzerland (adequacy decision of the European Commission).

InCloud mail server (mail.abcomputer.eu · Vultr)

Activity and data receivedInCloud's outgoing mail server, hosted with Vultr: processes the recipient's e-mail address and the content of service e-mails, tax documents and notices.

Place of processing and safeguardsInCloud server hosted with Vultr; for the transfer, see the section on transfers.

WhatsApp Ireland Ltd. (Meta)

Activity and data receivedDelivers to the administrator's phone, through InCloud's internal messaging system, certain staff alerts described in the “Notifications” row, which may contain the e-mail address or name of an account, the destination of a link and the browser used to log in. InCloud does not send WhatsApp messages to Customers.

Place of processing and safeguardsIreland (EU), with possible transfers to the United States covered by the EU-US Data Privacy Framework.

PayPal (Europe) S.à r.l. et Cie, S.C.A.

Activity and data receivedPayments: payment takes place on the PayPal website, which receives the order reference, the amount and a description, and handles refunds. For the payment, PayPal acts as an independent controller.

Place of processing and safeguardsLuxembourg (EU).

NOWPayments

Activity and data receivedCryptocurrency payments, when enabled: receives the order reference, the amount and a description. For the payment, it acts as an independent controller.

Place of processing and safeguardsOutside the European Union: the transfer is necessary for the performance of the payment chosen by the Customer (Article 49(1)(b) GDPR).

Internet.bs Corp.

Activity and data receivedRegistrar of the domains operated by InCloud and of those purchased by Customers through pik.li: receives the domain name (which may contain a person's name, if the Customer so chooses) and InCloud's contact details, not the Customer's.

Place of processing and safeguardsThe Bahamas, a country not covered by an adequacy decision: the transfer of the domain name alone is necessary for the performance of the contract requested by the Customer (Article 49(1)(b) GDPR).

komoot GmbH — Photon

Activity and data receivedAddress suggestions while billing details are being entered: receives from InCloud's server the text typed and the country selected, not the Customer's IP address.

Place of processing and safeguardsGermany (EU).

European Commission — VIES

Activity and data receivedVerification of businesses' VAT numbers: receives the VAT number and the country.

Place of processing and safeguardsEuropean Union.

Activity and data receivedJudicial authorities, police forces and other competent authorities, where the law requires or permits it, as explained in the “Disclosure of data to authorities” section.

Place of processing and safeguardsItaly and the European Union; outside the Union, only through the cooperation channels provided for by law.

Activity and data receivedAccountants, lawyers and auditors, for invoicing, litigation and legal compliance, bound by professional secrecy or by a duty of confidentiality.

Place of processing and safeguardsItaly.

7.Transfers of data to third countries

The servers hosting pik.li are located with the infrastructure providers listed in the table (Hetzner, Vultr, DigitalOcean, Contabo, Microsoft Azure and Amazon Web Services) and at InCloud's premises in Vignola. For providers whose parent company is in the United States (Vultr, DigitalOcean, Microsoft and Amazon), any transfer of data outside the European Union is covered by the EU-US Data Privacy Framework, for certified companies, and in all cases by the standard contractual clauses adopted by the European Commission. The other transfers outside the Union are those shown in the table: Cloudflare and Google (United States), WhatsApp (possible transfers to the United States), abuse.ch (Switzerland), NOWPayments for cryptocurrency payments and, for the domain name only, Internet.bs (the Bahamas).

For the United States, transfers are based on the European Commission's adequacy decision on the EU-US Data Privacy Framework, for certified providers, and on the standard contractual clauses adopted by the Commission (Article 46(2)(c) GDPR) incorporated into the agreements with the providers. Switzerland benefits from an adequacy decision. The transfer of the domain name to the Bahamas is based on Article 49(1)(b) GDPR. Data subjects may request a copy of the safeguards in place from InCloud.

8.Retention periods

The retention period for each category of data is shown in the table. The following general rules also apply:

  • Link clicks, including Visitors' IP addresses: according to the plan of the Customer who created the link, with automatic deletion every night and, in any event, upon permanent deletion of the account.
  • Closed account: remains “pending deletion” for 6 months, deactivated and with its links disabled, and is then permanently deleted together with the associated data.
  • Invoices, receipts and payment data: 10 years, even after the account has been deleted.
  • Statistics export files: 7 days.
  • Bell notifications: 60 days if read, 240 days if unread.
  • Technical server logs: 30 days. Backups: 30 days, after which deleted data also disappear from the backups.

The 6-month period following a deletion request strikes a balance between the right to erasure and two other needs: the establishment, exercise or defence of legal claims, for example where abuse committed through the Customer's links comes to light after the account has been closed, and compliance with legal obligations, including requests from authorities (Article 17(3)(b) and (e) GDPR). During that period the data are only stored and protected and are not used for any other purpose.

If an authority asks for specific data to be preserved, InCloud keeps them for as long as requested, even beyond the periods stated. At the end of that time, the data are deleted or anonymised.

9.Disclosure of data to authorities

InCloud discloses personal data to the judicial authorities, the police and other competent authorities where the law requires or permits it: to comply with an order or a binding request (Article 6(1)(c) GDPR); to protect the life or physical safety of a person in an emergency (point (d)); and, within the limits of the law, in the legitimate interests of InCloud and of society at large in preventing and prosecuting abuse and offences committed through the Service (point (f)).

The data that may be disclosed are those available at the time of the request relating to accounts, logins (including session IP addresses), links, campaigns, clicks (including Visitors' full IP addresses), payments, reports and abuse, limited to what the request covers. Data that InCloud does not hold, or that have already been deleted on expiry of the retention periods, cannot be disclosed.

Data are disclosed to authorities of third countries only through the judicial cooperation channels provided for by international agreements or through the Italian authorities (Article 48 GDPR), save in emergencies where the law permits otherwise.

InCloud informs the data subject of the disclosure, unless this is prohibited by law or by the authority, or could prejudice an investigation or endanger anyone's safety. For the same period, the data subject's rights of access and information may be restricted, in the cases provided for by Article 23 GDPR and by the national implementing provisions.

The procedures are described on the Cooperation with the authorities page.

10.Rights of the data subject

Under the GDPR, data subjects have the rights listed below. They may be exercised free of charge and InCloud responds within one month; for complex requests, that period may be extended by two further months, with the reasons stated.

  • Access: to obtain confirmation as to whether or not data concerning them are being processed and to receive a copy.
  • Rectification: to have inaccurate data corrected or incomplete data completed. Profile data can be changed directly in Settings.
  • Erasure: to obtain the erasure of data where they are no longer necessary, where consent has been withdrawn or where the data subject objects to the processing. The Customer may close their account themselves from Settings → Privacy & account; permanent deletion takes place after 6 months, as explained in the “Retention periods” section.
  • Restriction: to obtain restriction of processing, for example for the time needed to verify the accuracy of contested data.
  • Portability: to receive the data provided to InCloud in a structured, commonly used and machine-readable format. From Settings → Privacy & account, the Customer can download their data in JSON format and their links in CSV format at any time.
  • Objection: to object, on grounds relating to their particular situation, to processing based on legitimate interests. InCloud then ceases the processing, unless it demonstrates compelling legitimate grounds or the data are needed for the establishment, exercise or defence of legal claims.
  • Automated decisions: to obtain human intervention, to express their point of view and to contest a decision taken by automated means, as described in the section on automated checks.
  • Withdrawal of consent: for optional cookies, by means of the shield-shaped button in the bottom corner of every page, without affecting the lawfulness of processing carried out before withdrawal.

To exercise their rights, data subjects may write to the data protection contact from the e-mail address associated with their account, or indicate another way of verifying their identity. Visitor data include no names or contact details: to link a click to the data subject, InCloud may need additional information from them, such as the IP address used and the time of the click; without it, InCloud may be unable to identify them (Article 11 GDPR), in which case it will inform them accordingly.

Data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of the European Union of their habitual residence, their place of work or the place of the alleged infringement. In Italy, the supervisory authority is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it. Data subjects may also bring proceedings before the courts.

11.Security measures

  • All connections are encrypted (HTTPS with HSTS) and the servers accept traffic only from the Cloudflare network.
  • Account and link passwords are stored only as hashes; the two-step verification seed is encrypted.
  • Visitors' full IP addresses are accessible only to authorised InCloud staff; in statistics and exports, the Customer sees them in partial form.
  • API keys, provider credentials and Service secrets are encrypted in the database; cookies are signed to prevent tampering.
  • Rate limits and anti-bot checks protect the forms; automated checks protect Visitors from harmful destinations.
  • Access by InCloud staff is restricted according to role, and every significant operation, including viewing an account as it appears to the Customer, is recorded in the activity log together with the reason for it.

In the event of a personal data breach that presents a risk to the rights and freedoms of data subjects, InCloud notifies the Garante within 72 hours of becoming aware of it and, where required by law, communicates the breach directly to the data subjects (Articles 33 and 34 GDPR).

12.Minors

pik.li is not intended for minors and does not accept accounts from persons under 18 years of age (see the Terms of Service). Anyone who believes that a minor has provided data to InCloud may report it: the data will be deleted.

13.Cookies and advertising

The cookies and similar technologies used by pik.li, and how to change one's choices, are described in the Cookie Policy.

pik.li does not currently display advertising and does not use advertising or profiling cookies. The Terms of Service allow InCloud to host advertising on the website: should this involve tools that process personal data, InCloud will update this Privacy Policy and the Cookie Policy before doing so and will request consent where necessary. Under no circumstances is advertising inserted into links or between the click and the destination.

14.Changes to this Privacy Policy

InCloud updates this Privacy Policy when the Service or the law changes. The date and version shown at the top identify the text in force. In the event of material changes, InCloud informs registered Customers by e-mail or by a notice in the dashboard before the changes take effect.