Privacy Policy

Last updated: August 5, 2026

Before launch

The highlighted values below are placeholders. Replace the data controller and the contact address with the real ones, and confirm the list of processors matches the services actually in production.

Dayling Pulse watches websites, not people. We collect the least we can get away with, we never sell it, and there are no advertising or analytics trackers on this site. This page explains what we hold, why, and what you can ask us to do with it.

The data controller is [legal entity, address]. For anything in this policy, write to privacy@dayling.example — placeholder address, to be replaced before launch.

1. What we collect

  • Account details — your name and email address, and a hashed password or the identifier of the provider you signed in with. These are held by Neon Auth, our identity service.
  • Your monitored sites — the address of each site and the name you gave it.
  • Check results — what each scan found: response status and time, certificate expiry, pages crawled, broken links, technical SEO signals, the resulting score, and the alerts derived from them.
  • Your preferences — whether you want email alerts, from which severity, and whether you want a weekly summary.
  • Billing details — your plan, subscription status and period end, plus the customer identifier our payment provider gives us. We never see or store your card number.
  • Technical logs — the ordinary server records our hosting provider keeps, including IP addresses, used to keep the service running and secure.

We do not ask for anything about your website’s own visitors, and our checks read only pages that are already public.

2. Why we hold it, and on what basis

  • To provide the service you signed up for — running checks, showing history, sending the alerts you asked for. Legal basis: performance of a contract.
  • To take payment and meet our accounting obligations. Legal basis: contract, then legal obligation.
  • To keep the service secure and abuse-free, and to fix what breaks. Legal basis: our legitimate interest in running a working service.
  • To send occasional service emails about changes that affect you. Legal basis: contract, or your consent for anything promotional — which you can withdraw at any time.

3. Who else processes it

We use a small number of providers, each bound by a data processing agreement and each doing exactly one job:

  • Neon — our PostgreSQL database and the Neon Auth identity service. Holds your account, sites, check results and settings. Hosted in the European Union.
  • Stripe — subscription payments. Receives your email address and payment details directly; we receive back only the plan, the status and a customer identifier.
  • Our email provider — delivers alert and account emails, and therefore sees your email address and the content of those messages.
  • Our hosting provider — runs the application and keeps the technical logs described above.

We do not sell personal data and we do not share it for advertising. We disclose it only when the law requires us to.

4. Where it is stored

Your account and your check data are stored in the European Union. Some providers may process limited data outside the EU; where they do, the transfer relies on the European Commission’s standard contractual clauses or an adequacy decision.

5. How long we keep it

  • Check history and reports are kept for the window your plan includes — 30 days on the free plan, up to two years on the larger ones — and older records are deleted automatically.
  • Account details, sites and settings are kept while your account exists.
  • When you close your account, your sites, scans and alerts are deleted with it. Backups roll off within 30 days.
  • Invoices and payment records are kept for as long as tax law requires, typically ten years.

6. Cookies

We set one cookie: the session cookie that keeps you signed in. It is strictly necessary, so there is no consent banner to click. There are no analytics, advertising or third-party tracking cookies on this site.

7. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. You can also withdraw any consent you gave, without it affecting what came before.

Most of this is a click away in the app: your account screen exports and deletes your data directly. For anything else, write to privacy@dayling.example and we will answer within one month. If you are not satisfied, you can complain to your national data protection authority.

8. Security

Traffic is encrypted in transit, passwords are hashed by our identity provider, and access to production data is limited to the people who need it. No system is perfect; if a breach ever affects your data, we will notify you and the relevant authority as the law requires.

9. Changes to this policy

We will update this page when what we do changes, and we will email you before a change that materially affects you takes effect. The date at the top always tells you which version you are reading.