www.mailyreminder.app (the "Site") is owned and operated by The Maily Reminder
Team, who act as the data controller and can be contacted at
dev@mailyreminder.app.
Purpose
The purpose of this privacy policy (this "Privacy Policy") is to inform users of
our Site of the following:
- The personal data we will collect;
- Use of collected data;
- Who has access to the data collected;
- The rights of Site users; and
- The Site's cookie policy.
This Privacy Policy applies in addition to the terms and conditions of our Site.
GDPR
For users in the European Union, we adhere to Regulation (EU) 2016/679 of the
European Parliament and of the Council of 27 April 2016, known as the General
Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we
adhere to the GDPR as enshrined in the Data Protection Act 2018.
Consent
By using our Site, users agree that they consent to the conditions set out in
this Privacy Policy and to the collection, use, and retention of the data listed
herein.
Where the legal basis for processing your personal data is your consent, you may
withdraw that consent at any time. Withdrawing your consent will not make
processing we completed before the withdrawal unlawful.
You can withdraw your consent by contacting us at
dev@mailyreminder.app.
You may also withdraw consent by cancelling your subscription and deleting your
account, after which we will delete or anonymize your personal data in
accordance with this Privacy Policy.
Legal Basis for Processing
We collect and process personal data about users in the EU and UK only when we
have a legal basis for doing so under Article 6 of the GDPR. We rely on the
following legal bases:
- Contract — processing is necessary to perform our contract with
you, namely to provide the service you sign up for, including delivering daily
emails, tracking goals and milestones, and processing your subscription;
- Consent — you have provided your consent to the processing of
your data for one or more specific purposes; and
- Legitimate interests — processing is necessary for our legitimate
interests, provided these are not overridden by your interests or fundamental
rights and freedoms. Our legitimate interests include securing and maintaining
the Site, preventing fraud and abuse, processing payments, operating the referral
system, and analyzing usage to improve and develop the service.
Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy
Policy. We will not collect any additional data beyond the data listed below
without notifying you first.
Data Collected Automatically
When you visit and use our Site, we may automatically collect and store the
following information:
- IP address;
- Hardware and software details; and
- Clicked links.
Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our
Site:
- First and last name;
- Email address;
- Payment information; and
- User-entered goal content.
This data may be collected using the following methods:
- Through Google Single Sign-On when users sign in;
- Through information users enter directly on the Site; and
- Through our payment processor when users subscribe.
How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this
Privacy Policy or indicated on the relevant pages of our Site. We will not use
your data beyond what we disclose in this Privacy Policy.
The data we collect automatically is used to operate and secure the Site,
process payments, prevent fraud, and improve the service.
The data we collect when the user performs certain functions is used to provide
the service, deliver daily emails, process subscriptions, and operate the
referral system.
Who We Share Personal Data With
Employees
We may disclose user data to any member of our organization who reasonably needs
access to it to achieve the purposes set out in this Privacy Policy.
Third Parties
We may share user data with the following third parties:
- Stripe;
- Google; and
- Resend.
The data shared with each is as follows: payment information is shared with
Stripe; authentication information, including name and email address, is shared
with Google; and email addresses are shared with Resend.
This data is shared for the following purposes: to process payments (Stripe), to
authenticate users through single sign-on (Google), and to deliver our daily
emails (Resend).
Third parties will not be able to access user data beyond what is reasonably
necessary to achieve the given purpose. Each of these third parties maintains
its own privacy policy governing how it handles your data.
Other Disclosures
We will not sell or share your data with other third parties, except in the
following cases:
- If the law requires it;
- If it is required for any legal proceeding;
- To prove or protect our legal rights; and
-
To buyers or potential buyers of this company in the event that we seek to
sell the company.
If you follow hyperlinks from our Site to another site, please note that we are
not responsible for and have no control over their privacy policies and
practices.
International Data Processing
Some of the third parties we use, including Stripe, Google, and Resend, may
process your data on servers located outside your country of residence,
including outside the European Union and United Kingdom. Where we transfer
personal data outside the EU or UK, we take reasonable steps to ensure it is
protected by appropriate safeguards, such as standard contractual clauses or
transfers to jurisdictions recognized as providing adequate protection.
How Long We Store Personal Data
User data will be stored until the purpose the data was collected for has been
achieved. You will be notified if your data is kept for longer than this period.
How We Protect Your Personal Data
We take reasonable measures to protect user data. Access to our services is
secured through Google Single Sign-On, so we do not store user passwords.
Payment information is handled entirely by our payment processor, Stripe, and is
not stored on our servers. Data transmitted to and from our Site is encrypted in
transit using industry-standard TLS/HTTPS. We limit access to personal data to
what is necessary to operate the service.
While we take all reasonable precautions to keep user data secure, no method of
transmission over the Internet or electronic storage is completely secure, and
we cannot guarantee absolute security.
Data Breach Notification
In the event of a data breach affecting your personal data, we will take
reasonable steps to notify affected users and any relevant supervisory
authorities where required by law, within the timeframes required under the
GDPR, and to mitigate the impact of the breach.
Your Rights as a User
Under the GDPR, you have the following rights:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restrict processing;
- Right to data portability; and
- Right to object.
Children
The minimum age to use our Site is 13 years of age. We do not knowingly collect
or use personal data from children under 13 years of age. If we learn that we
have collected personal data from a child under 13, that data will be deleted as
soon as possible. If a child under 13 has provided us with personal data, their
parent or guardian may contact us using the details below.
How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know whether we have collected your personal data, how we
have used it, whether we have disclosed it and to whom, if you would like your
data to be deleted or modified in any way, or if you would like to exercise any
of your other rights under the GDPR, please contact us here:
The Maily Reminder Team dev@mailyreminder.app Do Not Track Notice
Do Not Track ("DNT") is a privacy preference that you can set in certain web
browsers. We do not track the users of our Site over time and across third-party
websites and therefore do not respond to browser-initiated DNT signals. We are
not responsible for and cannot guarantee how any third parties who interact with
our Site and your data will respond to DNT signals.
Cookie Policy
A cookie is a small file, stored on a user's hard drive by a website. Its
purpose is to collect data relating to the user's browsing habits. You can
choose to be notified each time a cookie is transmitted. You can also choose to
disable cookies entirely in your internet browser, but this may decrease the
quality of your user experience.
We use the following types of cookies on our Site:
- Functional cookies — used to remember the selections you make
on our Site so that your selections are saved for your next visit; and
- Third-party cookies — created by a website other than ours. We
use third-party cookies for authentication and secure sign-in through Google Single
Sign-On, and for payment processing and fraud prevention through Stripe.
Modifications
This Privacy Policy may be amended from time to time in order to maintain
compliance with the law and to reflect any changes to our data collection
process. When we amend this Privacy Policy we will update the "Effective Date"
at the top of this Privacy Policy. We recommend that our users periodically
review our Privacy Policy to ensure they are notified of any updates. If
necessary, we may notify users by email of changes to this Privacy Policy.
Complaints
If you have any complaints about how we process your personal data, please
contact us using the details in the Contact Information section so that we can,
where possible, resolve the issue. If you feel we have not addressed your
concern satisfactorily, you have the right to lodge a complaint with a
supervisory authority. Users in the EU may contact the data protection authority
in their country of residence, and users in the UK may contact the Information
Commissioner's Office (ICO).
If you have any questions, concerns, or complaints, you can contact us at:
The Maily Reminder Team dev@mailyreminder.app