Privacy Policy

Last updated: July 21, 2026

This Privacy Policy describes how doalt ("we", "us", "our") collects, uses, and protects your personal information when you use our service at doalt.io.

1. Information We Collect

Account information: Email address and a cryptographically hashed password (bcrypt). We never store your password in plain text.

Task data: Task labels, due dates, completion status, and timestamps. This data is required for the core functionality of the Service.

Payment information: When you link a payment method, we store your Stripe customer identifier and the last four digits of your card number. Full card numbers, CVV codes, and expiration dates are never stored on our servers. All payment data is processed and stored by Stripe, Inc. in compliance with PCI DSS Level 1 requirements.

Timezone: Automatically detected from your browser to determine your local midnight for charge calculations.

Consent records: When you link a payment method, we log the timestamp, your user ID, and the consent text you agreed to, as required by payment card network rules.

Charge history: A ledger of charges made to your account, including dates, amounts, associated tasks, and the charity that received the donation.

2. Information We Do Not Collect

We do not use analytics trackers, third-party cookies, advertising pixels, or social media integrations. We do not collect location data beyond timezone. We do not collect device fingerprints. We do not sell, rent, or trade your personal data to third parties.

3. How We Use Your Information

We use your information solely to operate the Service: display your tasks, calculate penalties, process charges via Stripe at midnight, maintain your charge ledger, and communicate with you about your account (e.g., receipts, policy changes, support responses).

4. Third-Party Data Sharing

Stripe, Inc.: We share your email address and payment authorization with Stripe to process charges. Stripe's handling of your data is governed by Stripe's Privacy Policy.

We do not share your data with any other third parties unless required by law (e.g., valid court order, subpoena).

5. Data Security

Passwords are hashed using bcrypt with a cost factor of 12. All network traffic is encrypted via TLS 1.2+. Payment processing is delegated entirely to Stripe (PCI DSS Level 1 certified). Database access is restricted to the application server only.

6. Data Retention and Deletion

Your data is retained for as long as your account exists. When you delete your account or request deletion, all personal data — including tasks, ledger history, payment identifiers, and consent records — is permanently removed within 30 days. Stripe customer records are also deleted.

To request data deletion, use the account deletion option in Settings or email [email protected].

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data. To exercise these rights, contact us at [email protected]. We respond within 30 days.

8. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect data from minors.

9. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated via email to the address on your account. The "Last updated" date at the top reflects the most recent revision.

10. Contact

For privacy-related inquiries: [email protected]