Privacy

What we hold, and what we don't.

Your email address, your settings, and dated copies of public pages you asked us to watch. That is close to the whole list.

The short version

  • We hold your email address, your workspace settings, and dated copies of the public pages you asked us to watch.
  • We do not sell personal data, and there are no advertising trackers on this site.
  • Payment happens at Stripe. We never see or store your card details.
  • Ask for deletion and it is real: one command removes your account and every row attached to it. That behaviour is covered by an automated test, not a promise.

Who is responsible

DeltaChime is run by Prav Durgani in the United Kingdom. For UK and EU data protection law he is the data controller for everything described here.

Every privacy request goes to prav@deltachime.io. There is nobody else to route it to, which is the one advantage of a one-person company.

What we hold

Your email address
Used to sign you in, send your briefs, and answer you when you write. It comes from you at sign-up.
Workspace settings
The competitors you named, the pages in each Source Pack, and your delivery preferences.
Captured pages and evidence
Dated copies of the public pricing and plan pages you asked us to watch, the SHA-256 hash of each copy, and the differences between them. This is what every claim in your brief points to.
Briefs and delivery records
The briefs we produced for you, and a log of what was sent where and when, so we can show a brief went out and never send the same one twice.
Subscription status
Your plan, whether it is active, and Stripe's identifiers for the subscription. Not your card.
Sample-brief requests
If you ask for a free sample brief: the email address and competitor domains you gave, any note you wrote, and a one-way hash of your IP address used to rate-limit the form.
Server logs
Cloudflare records requests to the site so faults and abuse can be investigated. Short-lived, and not used to build a profile of you.

The pages we capture are company commercial pages. Now and then one carries a person's name — a quote, a contact line. We do not go looking for it, do not index it, and do not build a profile of anyone from it.

What we do not hold

  • Card numbers. Stripe handles payment from end to end and we never receive them.
  • Anything behind a login on a competitor's site. We only read pages anyone can open.
  • Advertising or cross-site tracking data. Nothing here is shared with data brokers or ad networks, and personal data is never sold.
  • Special category data. DeltaChime watches company pricing pages; it has no reason to hold anything about anyone's health, beliefs or politics, and it does not.

Why we are allowed to hold it

Running your account
Contract. Without your email address and your competitor list there is no brief to send.
Keeping it working and safe
Legitimate interests: debugging, preventing abuse of the forms, and making sure the same brief is not delivered twice.
Sample-brief requests
Legitimate interests, and you asked for it. Tell us to delete it and we do, straight away.
Billing and tax records
Legal obligation. Financial records have to be kept for a period set by UK tax law, whatever else is deleted.

Cookies and analytics

Signing in sets a session cookie, handled by Clerk. It is what keeps you signed in. That is the only cookie the product needs.

The only analytics on this site is Cloudflare Web Analytics. It sets no cookies, does not fingerprint you and does not follow you between sites, which is why there is no banner here asking you to accept tracking.

There is no Google Analytics, no advertising pixel, no session recording and no heatmap on this site.

Who else touches your data

Six suppliers, named honestly: five the product cannot run without, and one that sits on the operator's side and receives nothing about you. It is listed anyway, because a supplier you cannot see is a supplier you cannot check.

Cloudflare
Hosts and serves the site, keeps the short-lived server logs, and provides the cookieless analytics.
Neon
Runs the Postgres database where your account, settings, captures, evidence and briefs live.
Clerk
Handles sign-in. Holds your email address and your session.
Stripe
Takes payment and holds your card details. We see the subscription, never the card.
Resend
Delivers the email. Sees your address and the contents of your brief.
Slack
The operator's own alert channel: scheduler health, and chimes from the operator's own workspace. There is no customer Slack connection in DeltaChime, so nothing of yours — no brief, no chime, no address — ever reaches it.

Several of these are US companies, so some processing happens outside the UK. Each publishes a data processing agreement with the standard contractual clauses and the UK addendum, and that is the basis those transfers rely on. If this list changes, it changes here.

How long we keep it

While your account is active we keep your captures and change history, because that continuous record is the product. How much of it you can browse depends on your plan: 90 days on Solo, 365 days on Pro.

Delete your account and everything attached to it goes within 30 days: competitors, Source Packs, captures, evidence, Chimes, briefs, delivery records and feedback.

Billing records stay longer where tax law requires it. Sample-brief requests are deleted whenever you ask.

Your rights

UK and EU data protection law gives you the right to get a copy of what we hold, correct it, delete it, take it elsewhere in a portable format, and object to how it is being used.

One email covers all of them: prav@deltachime.io. You get an answer within 30 days and usually a great deal sooner. There is no charge and you do not have to justify the request.

Deletion is not a soft flag here. A single command removes a user and every row belonging to them in one transaction — competitors, Source Packs, captures, Chimes, briefs, delivery logs, feedback — and it either completes or rolls back entirely. An automated test proves one customer's data disappears while another customer's is left untouched.

If something goes wrong

If a breach puts your data at risk you get an email: what happened, what was affected, and what has been done about it. Where the law requires it, the Information Commissioner's Office is told within 72 hours.

The security boundary we work inside

Complaints

Write to prav@deltachime.io first — it is the fastest route to a fix, and it reaches the person who can make it.

If that does not satisfy you, you can complain to the Information Commissioner's Office in the UK, or to your national data protection authority if you are in the EU.

ico.org.uk

Changes to this notice

A material change gets an email at least 14 days before it takes effect. A small correction just changes the date at the top.

The rest of the agreement