Private beta
Privacy notice
Last updated September 3, 2026
Scope
This notice describes the current DataFast private-beta web application, analytics collector, and optional revenue integrations. It is a factual product notice, not a claim of regulatory certification. A formal retention schedule and complete self-service deletion workflow are not yet available.
Account and sign-in data
DataFast stores the name and email used for an account, email-verification state, and authentication-provider links. Google sign-in can also provide a profile image. Login sessions may record an IP address and user agent for account access and security. Magic-link delivery uses the submitted email address, and request limits are stored to control repeated authentication attempts.
Passwords and authentication tokens are not included in customer account exports. OAuth tokens are encrypted before database storage.
Website analytics data
Customer-installed trackers can send the page URL, referrer, event time, event name, and customer-configured event properties. The collector adds the DataFast site ID, receipt time, and country when Cloudflare supplies one.
In anonymous mode, the collector uses the request IP address and user agent only to derive a site-specific visitor identifier that rotates daily; the raw values are not written to analytics events. Persistent 30-day attribution is enabled only after the customer website records explicit visitor consent. A customer controls which event properties its website sends and should not send unnecessary personal data.
Revenue and Stripe data
The Revenue API can store transaction identifiers, amount, currency, time, optional metadata, and attribution identifiers. An optional read-only Stripe App connection imports payment, refund, and subscription facts needed for revenue reporting. The analytics projection does not store Stripe customer email, address, or payment-method details.
Stripe also processes DataFast plan checkout and billing. Connecting a customer's Stripe business account is optional and separate from paying for DataFast.
Service providers
The current product uses Vercel for the web application, Neon for PostgreSQL, Cloudflare for event collection and queues, Tinybird for analytics, and Stripe for billing and optional revenue sync. When enabled, Resend delivers magic links and Google provides Google sign-in. Each provider handles data needed for its part of the service under its own terms.
Retention, export, and deletion
The beta does not currently run a uniform time-based purge for account, analytics, revenue, or provider-reconciliation records. A retention policy must be approved before general availability.
Signed-in customers can download a limited relational account inventory from the account privacy page. It excludes raw Tinybird analytics, revenue payloads, and security credentials, so it is not presented as a complete portability or subject-access export.
Self-service deletion is not yet offered because complete removal must coordinate PostgreSQL, Tinybird, Stripe relationships, sessions, and pending operational records. No account data is changed by viewing either privacy page.
Open authenticated account privacy tools