Back to site

Privacy Policy

Last updated: 17 August 2026

The short version. DeadlineFox runs countdown deadlines for our customers' email and web campaigns. We hold ordinary account details for the people who buy DeadlineFox. For the contacts our customers run campaigns for, we deliberately hold as little as possible: we never store their email addresses, only an irreversible hash of them, and we do not record IP addresses, build advertising profiles, or track anyone across unrelated websites. This summary is written for clarity and is not a substitute for the full policy below.

1. Who we are

DeadlineFox is operated by [[LEGAL ENTITY NAME]], of [[REGISTERED ADDRESS]]. In this policy, "we", "us" and "our" mean that company, and "the Service" means the DeadlineFox application at app.deadlinefox.com together with the timers, links, and scripts it serves.

If you have a question about anything here, write to [[CONTACT EMAIL]].

2. The two groups of people this policy covers

DeadlineFox handles personal data in two quite different roles, and the difference decides who is responsible for what. Please read the part that applies to you.

3. What we collect from customers

DataWhy we hold it
Name and email addressTo create and sign you in to your account, and to send service email such as password resets and payment receipts.
Password credentialsHandled by our authentication provider. We never see or store your password.
Plan and subscription statusTo give you the features you paid for and enforce plan limits.
Stripe customer referenceTo connect your account to your payments. Card numbers are handled by Stripe and never reach our servers.
Campaign configurationThe campaigns, deadlines, page URLs, and timer designs you create.
Email platform credentialsIf you connect an email platform, its API key is encrypted before storage and is never returned to the browser.
Administrative recordsA log of administrative actions taken on accounts, kept for security and accountability.

4. What we do not collect

This list is as much a part of the design as anything above, so it is worth stating plainly. We do not:

5. What we hold about contacts

When a customer runs a personalized campaign, each contact needs a deadline that is genuinely theirs. Doing that requires recognizing the same person again later, and we do it while holding as little as we can.

DataWhat it actually is
Identifier hashAn irreversible keyed hash (HMAC) of the contact's email address or email-platform contact ID. The original value is never written to our database, and the hash cannot be reversed to recover it.
Visitor tokenA random identifier stored in a cookie so a returning visitor sees the same deadline.
Deadline and timestampsWhen the contact entered the campaign, their original and current deadline, any extension, and the time of a conversion if one is tracked.

A consequence worth spelling out: because only a hash is stored, we cannot produce a list of a customer's contacts, and neither can they. The contacts screen in the app can only confirm whether a value you already know is present. That is a deliberate limit, not an omission.

Campaigns that use a single fixed deadline for everyone, and campaigns that identify returning visitors by cookie alone, create no contact record at all. Nothing personal is stored for those.

6. Cookies

DeadlineFox sets a small number of cookies. None of them are advertising cookies.

CookiePurposeLifetime
ec_sessionIdentifies a returning visitor so their deadline stays consistent across visits and devices. Signed and encrypted, and not readable by JavaScript on the page.Up to 1 year
ec_last, ec_last_timezoneSupports correct deadline display, including the visitor's local time.Up to 1 year
ec_preview, ec_snap, df_pv and relatedUsed only when a customer previews or tests their own campaign. Never set for ordinary visitors.Short-lived
df_ preferencesRemembers a signed-in customer's dashboard choices, such as filters. Account holders only.Up to 1 year

Because the deadline cookie is written by our script domain while the visitor is on our customer's website, browsers treat it as a third-party cookie. Browsers that block third-party cookies will block it. Nothing breaks when that happens: the visitor simply sees the campaign's default behavior instead of a personalized deadline.

7. Who we share data with

We use a small number of service providers to run DeadlineFox. Each one processes data only to provide its service to us. We do not sell data to anyone.

ProviderWhat it does for us
SupabaseDatabase and account authentication
VercelApplication hosting and content delivery
UpstashCaching of deadline state, and background job queueing
StripePayment processing. Stripe handles card details directly; we never receive them.
ResendSending transactional email, such as receipts and password resets
SnapRenderGenerating preview images of customers' own campaign pages

We may also disclose data where the law requires it, or to establish or defend legal claims. If the business is ever sold or reorganized, data may transfer as part of that, and this policy will continue to apply to it.

8. Where data is stored

Data is stored with the providers listed above, in [[HOSTING REGION]]. Some of our providers operate globally, so data may be processed in other countries. Where that involves a transfer out of the UK or the European Economic Area, it is made under the safeguards those laws require, such as the relevant standard contractual clauses.

9. How long we keep it

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, port, or object to our use of your personal data, and to withdraw consent where we rely on it. We honor these requests regardless of where you live. To make one, write to [[CONTACT EMAIL]]. We will not charge you or treat you differently for exercising them.

Two practical notes, so you know what to expect rather than discovering it after you ask:

11. Complaints

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to your data protection regulator, which for our customers in the UK or the EEA is [[SUPERVISORY AUTHORITY]].

12. Security

Data is transmitted over encrypted connections. Email platform API keys are encrypted before they are stored. Contact identifiers are stored only as keyed hashes. The deadline cookie is signed and encrypted, and is not readable by scripts running on the page. No system is perfectly secure, and we do not claim otherwise, but we hold as little as the product allows precisely so that there is less at stake.

13. Children

DeadlineFox is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the product changes. The date at the top always shows the current version, and if a change materially affects customers we will tell them by email rather than relying on them noticing.