1. Who operates DriftWatch
DriftWatch operates DriftWatch and controls the account, commercial, support, and service-operation data described here. Contact the support address published on the live service with privacy questions or requests.
2. Data we collect
- Account and identity data, including name, email, authentication records, workspace membership, role, and preferences.
- Customer configuration and content, including monitored URLs, page labels, portfolios, selectors, noise rules, snapshots, extracted text, diffs, notes, decisions, reports, recipient details, responses, and user-supplied branding.
- Delivery and integration data, including email and Slack destinations, encrypted webhook credentials, delivery status, API-key metadata, and client-portal activity.
- Commercial data, including selected plan, billing cadence, payment-provider customer, subscription, Checkout, invoice, payment, refund, and lifecycle identifiers. DriftWatch does not receive or store full payment-card numbers.
- Technical and usage data, including timestamps, HTTP status, run duration, errors, security and rate-limit records, feature activity, acquisition source, and campaign attribution.
3. Public scans and monitored pages
Anonymous market scans fetch the public website you submit. Public scan page contents are discarded after analysis; DriftWatch retains the bounded result, URL, reliability evidence, and acquisition metadata for up to 30 days so the result can be opened, emailed, or claimed into an account.
Account monitors retain page snapshots, extracted text, and change evidence needed to compare later checks and produce reports. Deleting a monitor removes its monitor-owned snapshots and changes. Some independently frozen reports, decisions, delivery evidence, or billing records can remain when required to preserve an artifact you created or meet a legal or operational obligation.
4. How we use data
- Provide, operate, secure, troubleshoot, and support DriftWatch.
- Fetch selected public pages and detect, interpret, and deliver changes.
- Authenticate users, enforce roles and plan limits, and prevent abuse.
- Process purchases, subscriptions, refunds, and account communications.
- Measure reliability, product adoption, and commercial attribution.
- Comply with law, resolve disputes, and protect users, the service, and third parties.
DriftWatch does not sell personal information or use it for targeted advertising.
5. AI processing
The configured AI provider receives bounded material needed for a requested output. For change summaries, this can include the page name, public URL, category, and a truncated meaningful-text diff. Analyst features use bounded retained evidence and citations. DriftWatch currently uses OpenAI for production AI processing when the operator selects the OpenAI launch configuration. Provider responses are validated and can fall back to deterministic output when a request fails.
Do not place secrets or unnecessary personal information in monitored public pages, labels, notes, prompts, or integration payloads.
6. When data is shared
Data is shared only as needed with:
- Render and PostgreSQL infrastructure used to host and store the service.
- Stripe or Lemon Squeezy, depending on the active checkout provider, for payments, subscriptions, invoices, customer portals, and refunds.
- Resend for authentication links and service email.
- OpenAI for the bounded AI processing described above.
- Google when you choose Google authentication.
- Slack, webhook endpoints, report recipients, and portals you deliberately configure.
- Professional advisers, authorities, or transaction parties when legally necessary.
Providers may process data in other countries under their own legal safeguards and service terms.
7. Cookies and local storage
DriftWatch uses essential session, authentication, security, link-access, and attribution storage needed to operate the service and preserve a requested journey. It does not use third-party advertising cookies. Your browser can block storage, but authentication and protected workflows may stop working.
8. Retention and deletion
Retention depends on the record and purpose. Public scan results are retained for up to 30 days; Analyst inquiries are pruned after 365 days; short-lived credentials, security buckets, delivery attempts, check history, incidents, and activity records follow bounded schedules described in the product. Workspace content is generally retained while the account remains active, and subscription history may remain available after cancellation so service can resume.
You can delete individual monitors and other supported artifacts in the service. To request account or workspace deletion, access, correction, restriction, portability, or an objection, contact the support address published on the live service. The operator may retain limited tax, payment, fraud, security, dispute, and legal records after a request where required or permitted by law.
9. Security
DriftWatch uses access controls, tenant-scoped authorization, bounded inputs and outputs, hash-only public bearer credentials, signed webhooks, security headers, and encryption of sensitive integration credentials before database storage. No service can guarantee absolute security. Report a suspected security issue to the support address published on the live service.
10. Rights, children, and changes
Depending on where you live, you may have legal rights over personal data and may complain to a local data-protection authority. DriftWatch is a business service and is not directed to children under 16. The operator does not knowingly collect a child's data through an account.
Material policy changes will be posted here with a new effective date. These privacy terms are part of the Terms of Service, and payment returns are described in the Refund Policy.