Privacy Policy
This policy explains what personal data DataDad processes, why, who helps us process it, how long we keep it, and the rights you have under the GDPR.
Updated
Who is responsible
The controller of the personal data described here is:
Petr PellerSole trader (OSVČ), Czech Republicsupport@data.dadWrite to support@data.dad with any privacy question or request.
Your account
When you create a DataDad account, we store:
- Your e-mail address and whether you confirmed it.
- Your password as a salted hash (PBKDF2-SHA-256). We never store the password itself.
- Passkeys, if you add them: the public key, its name, and when it was created and last used. The private key stays on your device.
- Sessions: a session record and the
dd_sesscookie that keeps you signed in for up to 30 days. - Your projects, settings, monitors and keyword lists.
- Sign-in protection records with hashed IP addresses and e-mail addresses, kept for about 20 minutes to limit repeated attempts.
We send account e-mails, such as confirmation and sign-in links, to your address.
Uptime monitoring
For each monitor, we store its name, URL and settings, and the results of its checks: the time, outcome, response time, HTTP status and error. We also store incidents with their reason, status page and badge settings, recent heartbeat pings, and domain expiry dates that we read from public registry data (RDAP). We do not store response bodies.
We keep check results and incidents for 365 days. An incident that is still open stays until it ends and then follows the same period.
Alert contacts
For alerts, we store the e-mail addresses and mobile numbers you add, whether each one is confirmed, paused or removed from text messages by a STOP reply, and the consent record of each mobile number. For each alert we send, we keep a delivery log: the time, the monitor, the contact, the result and, for text messages, the price and the provider’s message ID.
When you remove a contact, we delete it together with its delivery log. Every alert e-mail has an unsubscribe link.
Text messages
We use your mobile number only to send the alerts and one-time codes you asked for. We do not sell, rent or share mobile numbers, text message opt-in data or consent with third parties or affiliates for marketing or promotional purposes. Twilio processes the number only to deliver our messages.
- With the number, we store when you agreed to receive texts and which version of the opt-in text you saw, whether you confirmed the number, and whether it replied STOP.
- One-time codes are stored only as a hash. They expire after 10 minutes and are deleted when you confirm the number.
- Your credit history shows only the last three digits of a number. We do not write numbers, codes or message text to our logs.
- Twilio receives the number and the text of each message, and reports to us whether it was delivered.
- Our legal basis is your consent, which you can withdraw at any time: reply STOP, pause or remove the number in the dashboard, or write to us.
Removing the number deletes it, its consent record and its delivery log. See also the SMS Terms.
Payments
You buy text message credit through Stripe Checkout. Stripe collects your payment details; we never see your card number. We send Stripe your account ID, your e-mail address and the pack you chose. We store the Checkout session ID, the pack, the amount, the payment status, Stripe’s payment ID, and every change to your credit balance.
Analytics for our customers
When a customer adds DataDad to a website or app, we process data about that site’s visitors or app’s users on the customer’s behalf. The customer is the controller and we are its processor. If you visited a customer’s website or used its app, contact that customer about your data; we help them answer.
The website script
The script sends the page path, the referring website, campaign tags (such as utm_source), the events and goals the customer chooses with their properties, and a tab identifier that exists only in the open page. In the optional consent mode, it also sends visitor and session IDs from first-party cookies. Other URL query parameters are dropped. Ad click IDs are mapped to campaign tags and not stored.
Our server adds the time, the country, region and city derived from the IP address, and the browser, operating system and device type from the user agent. In the default cookieless mode, it also adds a daily visitor ID: a hash of the IP address, the user agent, the website and a random value that changes each UTC day. We delete each daily random value after 48 hours. We do not store the IP address or the full user agent.
The app SDK
The app SDK sends event and screen names, event and session IDs, an install ID, a project-specific hash of the device’s vendor identifier, the first open time, an optional hash of the app’s own account ID, and the app and SDK versions. It does not use the advertising identifier or location.
Retention and deletion
We keep a customer’s analytics data while the project exists. When the customer deletes the project, we erase its analytics data from our stores. Backups expire on their own schedule.
Our website
We measure our own website with DataDad in cookieless mode, as described above. If you ask to join a beta, we store the company, app name, app URL, e-mail address, traffic range and product you enter for 180 days. We use your IP address only to limit repeated requests.
Purposes and legal bases
- To provide the service you signed up for (account, monitors, alerts, reports, credit): performance of our contract with you, Art. 6(1)(b) GDPR.
- To send text messages: your consent, Art. 6(1)(a) GDPR.
- To keep payment and accounting records: our legal obligations, Art. 6(1)(c) GDPR.
- To keep the service secure and stop abuse (sign-in protection, rate limits, logs), and to measure our own website: our legitimate interests, Art. 6(1)(f) GDPR.
- Beta requests: steps you ask for before a contract, Art. 6(1)(b) GDPR.
- Analytics for customers: we process this data on the customer’s instructions; the customer chooses the legal basis.
Processors and transfers
| Provider | What it does | Location |
|---|---|---|
| Cloudflare | Hosting, databases, file storage, queues, account and alert e-mail, DNS lookups for checks | EU and US |
| Hetzner | Analytics database | Germany |
| Twilio | Text messages: the mobile number and the message text | US |
| Stripe | Payments; we never see card numbers | EU and US |
We also keep database backups with a separate storage service.
The keyword tools request search data from DataForSEO and from Apple’s App Store and Apple Ads services. They receive keywords, countries, platforms and app IDs, not data about you. To check domain expiry dates, we query public registry (RDAP) servers with the domain name. To show website icons, our server requests them from DuckDuckGo’s icon service with the domain name, so your browser does not contact it.
When personal data goes to a provider outside the European Economic Area, the transfer relies on the EU–U.S. Data Privacy Framework or the European Commission’s standard contractual clauses in the provider’s data processing terms.
How long we keep data
| Data | Kept |
|---|---|
| Account, projects and settings | While your account exists |
| Sessions | Up to 30 days |
| Sign-in protection records | About 20 minutes |
| Uptime checks and incidents | 365 days |
| Alert contacts, consent records and delivery logs | Until you remove the contact or close your account |
| One-time codes | 10 minutes, as a hash |
| Payments and credit history | As long as accounting and tax law requires |
| Customer analytics data | Until the customer deletes the project |
| Daily visitor ID random values | 48 hours |
| Beta requests | 180 days |
When you close your account, we delete its data, except records that the law tells us to keep. Backups expire on their own schedule.
Your rights
You have the right to access your personal data, to correct it, to have it deleted, to restrict or object to its processing, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time; this does not affect processing before the withdrawal.
Write to support@data.dad. We answer within one month. We may ask you to confirm that the request comes from you.
Complaints
You can complain to the Czech supervisory authority, the Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, or to the authority in the EU country where you live or work. We ask you to contact us first, so we can try to fix the problem.
Changes
We publish changes to this policy on this page with a new date. If a change is important, we tell account holders by e-mail before it takes effect. See also the Terms of Service.