Privacy Policy

Effective date: June 1, 2026

SimpleDMARC ("we", "us", or "our") operates the SimpleDMARC service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the practices described in this Policy.

1. Information We Collect

Account Information: When you register, we collect your name, email address, organization name, and password (stored as a one-way hash).

Domain and DMARC Data: We collect and store domain names you add to the Service, DNS verification tokens, and DMARC aggregate report data (XML reports sent to your designated RUA address). This data is used to provide the monitoring and reporting features of the Service.

Billing Information: Payment details are collected and processed by Stripe. We store only a Stripe customer identifier — we never store full card numbers on our servers.

Usage Data: We may collect information about how you interact with the Service, including IP addresses, browser type, pages visited, and timestamps, for security and analytics purposes.

2. How We Use Your Information

  • To provide, operate, and maintain the Service.
  • To send transactional emails (email verification, password resets, billing receipts).
  • To process payments and manage subscriptions.
  • To detect and prevent fraud, abuse, or security incidents.
  • To comply with legal obligations.
  • To communicate Service updates, changes to these policies, or important notices about your account.

We do not sell your personal information to third parties.

3. Data Sharing

We share your information only with the following categories of service providers who process data on our behalf:

  • Stripe — payment processing and subscription management.
  • Postmark (ActiveCampaign) — transactional email delivery.
  • Amazon Web Services — cloud hosting, storage, and infrastructure.

Each provider is bound by their own privacy and security commitments. We do not share your data with any other third parties except as required by law or to protect the rights and safety of SimpleDMARC or its users.

4. Data Retention

We retain your account information for as long as your account is active, or as needed to provide the Service. DMARC report data is retained for up to 30 days of rolling history in active mode, and may be retained longer in archived form for compliance purposes. You may request deletion of your account and associated data by contacting us at support@aevex.tech.

5. Security

We implement industry-standard security measures including encryption in transit (TLS), hashed password storage (bcrypt), and token-based authentication. No system is completely secure; we cannot guarantee absolute security but we take reasonable steps to protect your data.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Object to or restrict certain processing of your data.
  • Data portability (receive your data in a machine-readable format).

To exercise any of these rights, contact us at support@aevex.tech. We will respond within 30 days.

7. Cookies

We use a single session cookie ("access_token") to authenticate your session. This cookie is HTTP-only and is deleted when you log out. We do not use third-party tracking or advertising cookies.

8. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice in the Service. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

10. Contact

If you have questions or concerns about this Privacy Policy, please contact us at support@aevex.tech.