Privacy Policy
Last updated: July 24, 2026
At DataMatch, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
1.1 Information You Provide
| Data Type | Examples | When Collected |
|---|---|---|
| Account Information | Email address, name, password (hashed) | Registration |
| Payment Information | Payment method details (processed by Stripe) | Subscription or download purchase |
| Communications | Emails, support tickets, feedback | When you contact us |
1.2 Information Collected Automatically
| Data Type | Examples | Purpose |
|---|---|---|
| Usage Data | Pages visited, features used, session duration | Analytics, product improvement |
| Device Information | Browser type, operating system, screen size | Compatibility, optimization |
| IP Address | Approximate geographic location | Security, fraud prevention |
| Cookies | Session ID, preferences, consent choices | Functionality, analytics |
1.3 What We Do NOT Collect
- Contents of your Excel files (processed locally in your browser)
- File names or metadata from your spreadsheets
- Any data within your spreadsheets
2. How We Use Your Information
We use collected information for the following purposes:
- Provide the Service: Create and manage your account, process payments, deliver purchased features
- Improve the Service: Analyze usage patterns to enhance functionality and user experience
- Communicate: Send service updates, respond to support requests, send required legal notices
- Security: Detect and prevent fraud, abuse, and technical issues
- Legal Compliance: Fulfill legal obligations, resolve disputes, enforce agreements
3. Legal Basis for Processing (EEA/UK Users)
If you are in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:
- Contract: Processing necessary to perform our contract with you (e.g., providing the Service)
- Legitimate Interests: Processing necessary for our legitimate interests (e.g., security, fraud prevention), provided your rights are not overridden
- Consent: Where you have given explicit consent (e.g., marketing communications)
- Legal Obligation: Processing necessary to comply with applicable laws
4. Data Sharing and Disclosure
We do not sell your personal data. We may share information in the following circumstances:
4.1 Service Providers
We share data with trusted third parties who help us operate the Service:
- Payment Processing: Stripe (payment information)
- Analytics: Google Analytics (usage data, anonymized)
- Hosting: Vercel (application hosting)
- Database: Neon (account data, encrypted at rest)
4.2 Legal Requirements
We may disclose information if required by law, court order, or to protect the rights, property, or safety of DataMatch, our users, or others.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
5. International Data Transfers
If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers and service providers are located.
For EEA/UK users, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), to protect your data during international transfers.
6. Data Security
We implement industry-standard security measures to protect your information:
- TLS/SSL encryption for data in transit
- AES-256 encryption for data at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication requirements
- Secure password hashing (bcrypt)
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of account + 30 days after deletion request |
| Payment Records | 7 years (tax/legal requirements) |
| Usage Analytics | 26 months |
| Support Communications | 3 years |
8. Your Rights
8.1 All Users
- Access and view your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Withdraw consent at any time
- Object to certain processing activities
8.2 EEA/UK Users (GDPR)
In addition to the above, you have the right to:
- Restrict processing of your data
- Data portability
- Lodge a complaint with your local supervisory authority
8.3 California Residents (CCPA/CPRA)
You have the right to:
- Know what personal information is collected
- Know whether personal information is sold or disclosed
- Opt-out of the sale of personal information (we do not sell your data)
- Access your personal information
- Request deletion of your personal information
- Non-discrimination for exercising your rights
To exercise these rights, email privacy@datamatch.app.
9. Cookies
We use cookies and similar technologies. See our Cookie Policy for details.
10. Children's Privacy
The Service is not directed to children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. Do Not Track
Some browsers have a "Do Not Track" feature. We currently do not respond to DNT signals, but we do honor the Global Privacy Control (GPC) signal where required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on the Service at least 30 days before taking effect.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights:
- Email: privacy@datamatch.app
- Contact page: datamatch.app/contact
- EEA/UK Data Protection inquiries: dpo@datamatch.app