01Who we are

DMARCmetric ("we", "us") operates the DMARC monitoring service at dmarcmetric.com. We are the data controller for the personal data described in this policy.

The data controller is Digiport OÜ, registered at Viru väljak 2, Tallinn 10111, Estonia. Estonia is a member state of the European Union, so the GDPR applies directly. The accountable contact for any privacy question is [email protected].

02What data we process

Account data

When you create an account we process the information you give us:

Billing data. Payments for paid plans are processed by Stripe; card details are entered on Stripe's hosted checkout and billing pages and never touch our servers — we never see, transmit or store a card number. We hold only billing metadata: your workspace's plan, its Stripe customer and subscription identifiers, and subscription status.

DMARC aggregate-report data

The core of the service is parsing the aggregate (RUA) DMARC reports that mail providers send about messages claiming to be from your domains. These reports are third-party-generated telemetry — we do not create them; receiving mail operators (Google, Microsoft, Yahoo and so on) generate and send them. For each sending source in a report we store the structured rows:

Aggregate reports carry no message content — no bodies, no subject lines, no recipient addresses. This is a property of the RUA format itself: reporters never send that data, so it never reaches us. See also Security and privacy at DMARCmetric and How long is my data kept?

03Why we process it & legal basis

We process the data above only to provide the service you signed up for:

We frame this policy around the GDPR and rely on the following legal bases:

04Sub-processors

We use a small set of infrastructure providers to run the service. We do not sell your data or share it with advertisers.

ProviderPurposeLocation / note
Hetzner Application & database hosting Germany (EU) — the service and your data run on Hetzner infrastructure in Germany.
Cloudflare CDN, TLS termination and edge protection Web traffic passes through Cloudflare's edge and is TLS-encrypted between your browser and the service.
Postmark Transactional email delivery Delivers our verification, password-reset and opt-in digest emails. Receives the recipient address and email content needed to send.
Stripe Subscription billing & payment processing Processes payments for paid plans. Receives the billing details you enter on Stripe-hosted pages (name, email, billing address, card); we receive only non-card billing metadata back.
MaxMind GeoLite2 Offline IP-geolocation dataset Not a live service. We load the GeoLite2 dataset into our own PostgreSQL database and resolve a sender's IP to a country with a local SQL lookup. Sender IP addresses are never sent to MaxMind (or any third-party geolocation service) at lookup time.

Cloudflare Turnstile (a bot-challenge widget) is integrated in our codebase but currently dormant, so no data flows to it today. If we re-enable it, it operates under the Cloudflare entry above and we will update this note accordingly.

05Data retention

Report data is retained according to your workspace's plan. Since the launch of paid plans (reflected in the "last updated" date above), dashboards and exports read at most your plan's retention window — currently 30 days of history on the Free plan and one year on Starter — and a scheduled job physically deletes stored report data only once it is older than your plan's window plus a 60-day grace period (roughly 90 days of storage on Free, about 14 months on Starter). The grace period means upgrading immediately reveals still-stored history. The purge covers report rows, the plain-English summaries derived from them, and alerts; forensic failure samples have their own fixed 30-day window.

Existing workspaces are notified before the first scheduled deletion runs — nothing quietly vanishes from accounts that predate these windows.

Deletion on request is always available:

For the full detail, see How long is my data kept?

06International transfers

Your account and report data are hosted in Germany (EU) on Hetzner infrastructure. Web requests are served through Cloudflare's global edge network, which may route or terminate TLS at edge locations outside your country; report processing and storage remain on our EU hosting.

Our primary hosting is in the EU (Hetzner, Germany). Where a sub-processor (for example Cloudflare or Postmark) may process personal data outside the EEA, such transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) and equivalent safeguards. As noted under Sub-processors, sender IP addresses are never sent to MaxMind — IP-to-country resolution is a local lookup inside our own database, so no IP data is transferred to a geolocation service.

07Your rights

Under the GDPR you have the right to:

To exercise any of these, email [email protected] from your account's address and a human will handle it.

08Cookies

We use one first-party cookie: an essential session cookie set when you sign in. It is flagged Secure (only ever sent over HTTPS) and is backed by a server-side session record, so signing out revokes it immediately. There is no token stored in your browser for a rogue script to steal.

We use no analytics, advertising or tracking cookies. Because the only cookie we set is strictly necessary to run the service, no cookie-consent banner is required — there is nothing non-essential to consent to.

09Security

We describe only what is true today. DMARCmetric does not currently hold SOC 2 or ISO 27001 certification, and we make no such certification claims. See Security and privacy at DMARCmetric for the fuller picture.

10Changes & contact

We may update this policy as the product evolves; the "last updated" date at the top reflects the current version. For any privacy question, to exercise your rights, or to request deletion, contact [email protected].