Privacy Policy
Last updated: July 3, 2026
This Privacy Policy describes how Push Notification Service ("we", "us", or "our") collects, uses, and shares information when you use our service.
1. Our Two Roles
We process personal data in two distinct capacities:
- As a controller of the data of our own customers — the account holders who sign up, manage sites, and pay for the Service.
- As a processor of the data of our customers' website visitors ("subscribers"). When a visitor subscribes to push notifications on a customer's site, the customer is the controller of that data and we process it only on their instructions to provide the Service. A Data Processing Agreement (DPA) covering this processing is available to customers on request via our contact page.
If you are a subscriber receiving notifications from a website that uses our Service, that website's operator is responsible for your data; please consult their privacy policy. You can unsubscribe at any time via the unsubscribe link in any notification or your browser's site-permission settings.
2. Information We Collect
Account Information (as controller)
When you create an account we collect your name, email address, and (via Stripe) billing information. We never store full card numbers — payment data is handled entirely by Stripe.
Subscriber Push Data (as processor)
To deliver notifications on our customers' behalf, we store each subscriber's browser push endpoint (a unique URL issued by the browser vendor), its encryption keys, any tags the customer assigns, and optional coarse metadata (browser, operating system, locale). We treat push endpoints as pseudonymous personal data: they do not directly identify a person, but they are unique identifiers and we protect them accordingly. We do not collect subscribers' names, email addresses, or browsing history, and we do not track subscribers across sites.
Usage Data
We collect aggregate statistics about notification delivery (sent, delivered, clicked counts) to power dashboard analytics. Click-through counting is anonymous — we count clicks per notification and store no per-user click history. We log API requests (IP address, endpoint, timestamp) for security and debugging; these logs are retained for up to 90 days and are not sold or shared.
3. How and Why We Use Information
- To provide, secure, and improve the Service (performance of our contract with you; our legitimate interests)
- To process payments and manage subscriptions (performance of contract)
- To send transactional emails — invitations, billing receipts, payment-failure and security notices (performance of contract)
- To detect and prevent abuse, spam, and security incidents (legitimate interests; legal obligation)
- To comply with legal obligations
Subscribers' push subscriptions are created only after they grant permission through their browser's native prompt (consent, obtained by the site owner). We do not sell personal data, we do not use it for advertising, and we do not "sell" or "share" personal information as those terms are defined by the California Consumer Privacy Act.
4. Sharing & Subprocessors
We share data only with the providers needed to run the Service:
- Stripe — payment processing. We share the minimum necessary (email, billing details); Stripe's privacy policy governs the data it collects.
- Browser push services — notifications are delivered through infrastructure operated by browser vendors (e.g., Google FCM, Mozilla Autopush, Apple Push). Subscribers' endpoints are transmitted to these services solely to deliver notifications; payload contents are encrypted end-to-end per the Web Push standard.
- Infrastructure — the Service is hosted on Google Cloud Platform servers located in the United States.
We may also disclose information if required by law, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to previously collected data). We will notify customers before adding subprocessors that handle subscriber data.
5. International Transfers
If personal data is transferred outside the jurisdiction where it was collected, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and their UK and Swiss equivalents where applicable). Details are set out in our DPA.
6. Data Retention
- Account data — retained while your account is active, and deleted within 30 days of a verified deletion request or account termination, except where law requires longer retention (e.g., invoices).
- Push subscriptions — deleted when a subscriber unsubscribes, when the browser signals the endpoint is dead (HTTP 404/410), or when the customer deletes the subscriber or the site.
- API and security logs — up to 90 days.
- Aggregate statistics — retained as anonymous counts with no personal data.
7. Security
We use TLS for all connections, store API keys only as SHA-256 hashes, encrypt per-site signing keys at rest, sign all unsubscribe and click-through links, and enforce per-site origin checks on subscription collection. If we become aware of a personal-data breach affecting you or your subscribers, we will notify affected customers without undue delay and in accordance with applicable law.
8. Your Rights
Depending on your jurisdiction (including under the GDPR and CCPA), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. To exercise them, contact us; we respond within 30 days. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local supervisory authority. Subscriber requests should be directed to the website operator (the controller); we assist our customers in fulfilling them as required by our DPA.
9. Children
The Service is a business tool, is not directed to children, and requires account holders to be at least 18. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
10. Cookies
The marketing site (this site) sets no tracking or analytics cookies. The dashboard uses a session cookie to keep you logged in and a CSRF token cookie for security — both strictly necessary. We use no third-party analytics or advertising cookies anywhere.
11. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes we will notify account holders by email in addition to posting the new policy here with an updated "Last updated" date.
12. Contact
Questions about this Privacy Policy or our data practices? Contact us.