This policy explains how purpl LLC, a limited liability company registered in Wyoming, USA ("purpl", "we", "us"), handles personal data when you use Subsecond: the websites at subsecond.io and app.subsecond.io, the Subsecond application, and our emails and support channels (together, the "Service"). This policy is incorporated into and forms part of our Terms of Service; by using the Service you agree to both.
The short version: we collect the minimum needed to run a paid product: your email, a display name you choose, your saved scanner configurations, your billing status, and security records of your sign-ins and scanner sessions (section 1). We do not sell or share your data for advertising, run ad trackers, or profile your behavior across sites. We use service providers to host the Service, send email, and take payments; we may email you about Subsecond (you can opt out of anything that is not a service notice); and we disclose data only when this policy says so or the law requires it.
1. Data we collect
We collect data in three ways: you give it to us, your browser sends it automatically, and our payment processor sends it to us.
- Account data: your email address, a display name you choose, and (once, at signup) how you heard about us.
- Content you create: saved scan filters, layouts, views, columns, and alert preferences. These are stored so your workspace follows you across devices.
- Billing data: your subscription or trial status and Stripe reference identifiers (customer, subscription, and checkout session IDs). Payments are processed entirely by Stripe on Stripe's own pages; we never receive or store your full card number or security code. Stripe sends us payment event notifications so we can activate and maintain your access, which may include limited billing details such as card brand, the last four digits of the card, and billing country. Stripe's handling of your payment details is described in Stripe's privacy policy. If you buy the 30-day trial, we also keep a hashed record that your email address has used it (a keyed hash derived with a secret key, so it cannot be turned back into your address) to prevent repeat trials (section 7).
- Sign-in and session records: each time you sign in successfully, and each time the app opens a live scanner connection, we record: your IP address; an approximate location derived from that IP address (country and, where available, region and city) using the geolocation headers our hosting and security provider, Cloudflare, attaches to the request; basic browser and device information your browser sends in its request headers (the User-Agent string and, at sign-in, your Accept-Language preference); and the time of the sign-in or the start and end time of the scanner connection (from which its duration follows) and why the connection ended. This location is approximate, city level at best, and is never GPS-level or device location; we do not ask your device for its location. We keep these records for 13 months (section 7) and use them only to prevent fraud and abuse, secure your account, detect account sharing, and establish evidence if a charge is disputed (section 2). We do not log your individual page views or what you do inside the scanner.
- Security and technical data: when you request a sign-in code, we record the IP address of the request to prevent abuse; these records are automatically deleted after approximately 48 hours. Our servers and hosting providers also keep standard technical logs of requests to the Service (the data your browser sends automatically, such as IP address, browser type, the pages or endpoints requested, timestamps, and response status) for operations, debugging, and security.
- Communications: if you email support@subsecond.io or reply to one of our emails, we keep the correspondence (your address and what you wrote) so we can help you and keep a record of what was agreed.
We do not collect passwords (sign-in uses one-time email codes), real names, postal addresses, phone numbers, government identifiers, or any brokerage or trading account information. Subsecond displays market data; it never connects to your brokerage. We do not buy personal data about you from data brokers or other third parties.
We do not collect biometric identifiers, health or medical information, precise (GPS-level) geolocation (the only location data we hold is the approximate, IP-derived location described above), financial account numbers, or information about your race, ethnicity, religion, sexual orientation, immigration status, or union membership. Subsecond is not a financial institution, broker, or adviser, and your saved scans are not financial account data.
2. How we use data
We use personal data for the following purposes. For users in the EEA, UK, and Switzerland, the legal basis for each is shown in parentheses (see section 10).
- to provide and operate the Service, including authenticating you and syncing your saved configurations (performance of our contract with you);
- to process payments, manage subscriptions and trials, and handle billing questions and disputes via Stripe (performance of contract; legal obligations);
- to send transactional email: sign-in codes and important service, security, or billing notices (performance of contract; legal obligations);
- to tell you about Subsecond (new features, changes, tips, and offers) by email, with an opt-out in every such message (legitimate interests; consent where the law requires it, see section 3);
- to prevent fraud and abuse and secure the Service and your account, including rate-limiting sign-in attempts, detecting account sharing and enforcing the one-live-connection-per-account rule, enforcing our Terms of Service and data-provider restrictions, and establishing evidence of who used an account, from where, and when if a charge is disputed or charged back. This is what the sign-in and session records in section 1 are for (legitimate interests; legal obligations where applicable);
- to monitor, troubleshoot, and improve the Service, for example reviewing server logs after an outage or support tickets to fix a bug (legitimate interests);
- to understand, in aggregate, where customers heard about Subsecond and how the Service is used (legitimate interests);
- to comply with legal obligations such as tax, accounting, and lawful requests from authorities, and to establish, exercise, or defend legal claims (legal obligations; legitimate interests).
We do not use your data for automated decision-making that has legal or similarly significant effects on you, and we do not build advertising profiles.
3. Email from us
- Service email: sign-in codes, receipts and billing notices, security alerts, and notices about changes to the Service or these documents. You cannot opt out of these while you have an account, because the Service cannot work without them.
- Product and marketing email: we may occasionally email the address on your account about Subsecond: new features, changes, tips, and offers. Every such email includes an unsubscribe link, and you can also opt out at any time by emailing support@subsecond.io. We process opt-outs promptly and within the time required by law (currently 10 business days under CAN-SPAM). We do not use purchased or third-party advertising lists, and we do not send marketing email on behalf of anyone else.
Where the law requires consent for product or marketing email (for example, in parts of the EEA and UK beyond the "existing customer" rule), we will ask for it at signup or before the first such email, and you can withdraw it at any time without affecting the Service.
4. Cookies and similar storage
- Authentication cookie: an essential, HttpOnly session cookie that keeps you signed in for up to 30 days. Blocking it will prevent sign-in.
- Preference cookie: remembers whether the app sidebar is open (7 days). No personal data.
- Cloudflare Turnstile: the CAPTCHA on our sign-in page, provided by Cloudflare for security. It may set its own strictly necessary cookies to distinguish humans from bots; Cloudflare's use of this data is described in Cloudflare's privacy policy.
- Session storage: short-lived, tab-scoped flags (for example, remembering that you left for Stripe checkout). Cleared when the tab closes.
We use no advertising cookies and no cross-site tracking. On our marketing site (subsecond.io) we measure visits with Cloudflare Web Analytics, a cookieless tool that counts page views, referrers, and page-load timings without cookies, local storage, or fingerprinting, and builds no visitor profiles. We do not currently use any cookies or similar technologies that require your consent, which is why you see no cookie banner. If we later add privacy-respecting analytics or error-tracking tools that process personal data, we will update this section and section 5 before they go live and, where the law requires, ask for your consent first.
What we do not use. We do not use session-replay or screen-recording tools, keystroke or mouse-movement logging, heat maps, chat or form-field interception, tracking pixels, fingerprinting, or third-party advertising or social-media tags and SDKs (such as the Meta Pixel, Google Ads or Analytics tags, or TikTok pixels) anywhere on the Service. We do read the standard headers your browser sends with every request (such as User-Agent), as described in section 1, but we do not run scripts that probe your device to build a fingerprint. Other than our hosting and security providers acting on our behalf (section 5), no third party reads or intercepts your interactions with the Service. Apart from the technical logs and support correspondence described in section 1, we do not record your communications. If we ever add analytics or error-tracking tools, we will disclose them in this section first.
Do Not Track and Global Privacy Control. Because we do not track you across other websites and do not sell or share personal data for advertising, there is nothing for a "Do Not Track" or "Global Privacy Control" browser signal to switch off; we treat any such signal as a request not to be tracked, which is already our default for everyone.
5. Who we share data with
We never sell or rent personal data, and we do not share it with advertisers, ad networks, or data brokers. We disclose personal data only in the following cases.
Service providers. Companies that process data on our behalf and on our instructions, under data processing agreements that restrict them to providing their service to us. Today they are:
- Stripe: payment processing, invoicing, and the billing portal (USA).
- Amazon Web Services (SES): delivery of sign-in codes and our other emails (USA).
- Cloudflare: hosting, content delivery, DNS, security including the Turnstile CAPTCHA, and Web Analytics on the marketing site (global network, US-based).
- Oracle Cloud Infrastructure: the servers and database that run the Service (US East).
We may add or replace providers that perform these kinds of functions (hosting, email delivery, payments, security, support tooling, analytics, or error monitoring) as the Service evolves; when we do, we aim to update this list promptly. Our market data providers receive no personal data about you.
Legal, safety, and enforcement. We may disclose data if we believe in good faith it is necessary to comply with a law, regulation, subpoena, court order, or other legal process; to respond to lawful requests from public authorities; to enforce our Terms of Service or data-provider obligations; to detect, prevent, or address fraud, abuse, security incidents, or payment disputes; or to protect the rights, property, or safety of purpl, our users, or the public. In particular, if a charge is disputed or charged back, we may provide account records, including the sign-in and session records described in section 1 (IP address, approximate location, browser information, and sign-in and connection times), to Stripe and, through Stripe, to the card network as evidence. Sign-in and session records are not otherwise shared with anyone and are never sold. We may also share data with our professional advisers (lawyers, accountants, auditors, insurers) under confidentiality obligations.
Business transfers. If purpl is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of its assets, your data may be transferred as part of that transaction. The recipient will be bound by this policy with respect to data collected under it until it gives you notice of any changes.
With your direction. If you ask us to share something with a third party (for example, to send a receipt to your accountant), we will.
6. Aggregate and de-identified data
We may create and use aggregated or de-identified information (statistics that cannot reasonably be linked to you, such as how many users run a given type of scan or which signup channels are most common) for any lawful purpose, including operating, improving, and marketing the Service, and we may keep it after your account is deleted. We maintain such data in de-identified form, do not attempt to re-identify it, and require anyone we share it with to do the same.
7. How long we keep data
The periods below are targets we operate to; they are approximate and subject to the exceptions that follow.
- Sign-in code records, including the requesting IP address: automatically deleted approximately 48 hours after creation.
- Payment webhook records: approximately 30 days.
- Sign-in and session records (section 1): 13 months from the date of each record, after which they are automatically deleted.
- Server and security logs: for a limited period needed for operations and security, after which they are deleted or rotated.
- Support correspondence: for as long as needed to resolve the matter and keep a record of it.
- Account data and your saved configurations: until you delete your account, when they are erased immediately (below).
- Billing records: as long as required for tax, accounting, and dispute-handling obligations (generally up to 7 years).
- Trial-use record: if you buy the 30-day trial, a hashed record that your email address has used it (derived with a secret key, so it cannot be turned back into your address), kept to prevent repeat trials.
Deleting your account. You can delete your account yourself at any time: in the app, open Account settings, choose Delete account, and type DELETE to confirm. This is available to every account, including one that never finished signing up or never paid. Deletion takes effect immediately and cannot be undone: we erase your email address, your display name, and all of your saved layouts, views, and filters (your signup-source answer and the suffix of your account handle are kept in de-identified form, section 6); sign you out on every device; and send a confirmation to the email address that was on the account. If your subscription is set to renew, you must cancel it in the billing portal before you can delete the account; a subscription already set to end at the period end, or a 30-day trial in progress, does not block deletion, but any remaining paid time is forfeited and not refunded (Terms Sections 7 and 16). If your account is suspended you cannot sign in, so email support@subsecond.io from your account email and we will delete it without undue delay. The same email address can sign up again later; that creates a new account with no history.
After deletion we keep only the following. Billing records: the Stripe customer, subscription, and charge history, as our payment and tax audit trail, for the period in the list above; on our side they are no longer tied to a name or email address. We do not delete the customer record that Stripe itself holds; Stripe's own retention governs it. Sign-in and session records (section 1): IP address, approximate location, browser details, and sign-in and connection times, for up to 13 months after deletion (each record is deleted 13 months after it was made), for fraud prevention and to defend chargebacks and payment disputes, and then deleted. Trial-use record: if the account used the 30-day trial, the hashed record described above that the email address has used it; it is derived with a secret key, cannot be turned back into the address, is not linked to the deleted account, and is kept to prevent repeat trials (fraud prevention, section 2). Terms-acceptance record: that the account accepted a particular version of our Terms of Service, and when. It is not tied to a name or email address and is kept with the billing records, for the same period. We may also keep records needed to resolve an open dispute, chargeback, or legal claim, or the minimum needed to enforce a ban or prevent repeat abuse; and de-identified data (section 6). Residual copies may remain in routine backups for a limited period before being overwritten.
8. Security
We protect data by holding as little of it as possible. We store no passwords, security questions, Social Security or government ID numbers, driver's license numbers, card or financial account numbers, medical information, or biometric data. Sign-in uses short-lived one-time codes stored only as keyed hashes and deleted after approximately 48 hours; session cookies are HttpOnly and Secure; sign-in endpoints are rate-limited and protected by CAPTCHA; all traffic is encrypted in transit with TLS; card data never touches our servers; and access to production data is limited to the people who need it to run the Service.
No method of transmission over the internet or of electronic storage is 100% secure. We use reasonable safeguards appropriate to the data we hold, but we cannot guarantee security, and you use the Service at your own risk. Because sign-in is by one-time code sent to your email address, the security of your Subsecond account depends on the security of your email account and devices: keep them protected (strong password, two-factor authentication), do not forward or share sign-in codes, and tell us at support@subsecond.io right away if you suspect unauthorized access. To the fullest extent permitted by law, we are not responsible for access to your account or data that results from a compromise of your email account or devices, or from your sharing a sign-in code or session. If a security incident affects your personal data, we will notify you and any relevant authority where and as required by applicable law.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, to withdraw consent where processing is based on consent, and to not be discriminated against for exercising these rights. Regardless of where you live, you can always: change your display name and saved configurations in the app; unsubscribe from product email (section 3); manage your subscription in the billing portal; and delete your account yourself in the app (section 7).
To exercise any other right, email support@subsecond.iofrom your account email address; that is how we verify the request. If we cannot verify a request that way, we may ask for additional information that matches what we hold, and we may decline requests we cannot verify. An authorized agent may submit a request on your behalf if they provide your signed permission; we may also confirm the request with you directly. We aim to respond within 30 days and in any event within the time required by applicable law (one month, extendable, under the GDPR/UK GDPR; 45 days, extendable, under California law), and will tell you if we need more time and why. Requests are free, but we may charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive, as the law allows.
10. Users in the EEA, UK, and Switzerland
Controller. purpl LLC, Wyoming, USA, is the controller of your personal data. Contact: support@subsecond.io.
Legal bases. We rely on:
- Performance of a contract (Art. 6(1)(b)): account, sign-in, saved configurations, billing, service email;
- Legal obligation (Art. 6(1)(c)): tax and accounting records, responding to lawful requests;
- Legitimate interests (Art. 6(1)(f)): securing the Service and preventing fraud and abuse, including keeping the sign-in and session records described in section 1 (IP address, approximate location, browser information, and sign-in and connection times) for 13 months to detect account sharing and unauthorized access and to evidence payment disputes; troubleshooting and improving the Service; aggregate statistics; enforcing our Terms and defending legal claims; business transfers; and sending existing customers email about similar products and services with an opt-out (the "soft opt-in"). You can object to processing based on legitimate interests at any time (section 9); we will then stop unless we can show compelling legitimate grounds that override your interests, or we need the data to establish, exercise, or defend legal claims;
- Consent (Art. 6(1)(a)): product or marketing email where consent is required, and any future optional analytics that requires it. You can withdraw consent at any time without affecting the lawfulness of earlier processing.
Your rights. Access, rectification, erasure, restriction, data portability, objection (including an absolute right to object to direct marketing), and withdrawal of consent, as set out in section 9. You also have the right to lodge a complaint with your local supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority of the member state where you live or work.
Why we need the data. Providing your email address and completing payment are necessary to create and keep an account; without them we cannot provide the Service. All other data is optional or generated by your use of the Service.
Transfers. We are established in the United States and process data there; see section 13.
11. California residents (CCPA/CPRA)
This section applies to California residents and serves as our notice at collection. It applies to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies to purpl.
Categories of personal information
In the preceding 12 months we have collected the following categories of personal information, as defined in the CCPA, from the sources and for the purposes described in sections 1 and 2:
- Identifiers: email address, display name, IP address, Stripe customer ID, and, if you buy the trial, a keyed hash of your email address (not reversible) recording that the trial was used. Source: you; your browser; Stripe. Retention: section 7.
- Customer records / commercial information: subscription and trial status, purchase history (via Stripe references), how you heard about us, support correspondence. Source: you; Stripe. Retention: section 7.
- Internet or network activity: sign-in and session records described in section 1 (IP address, browser and device information from request headers, sign-in times, and scanner connection start and end times); server and security logs described in section 1; cookie and session-storage data described in section 4; saved scanner configurations. Source: your browser and your use of the Service. Purpose: operating and securing the Service, preventing fraud and account sharing, and evidence in payment disputes. Retention: section 7 (sign-in and session records: 13 months).
- Geolocation data: an approximate location (country and, where available, region and city) derived from your IP address by our hosting provider, Cloudflare, at sign-in and when you connect to the scanner. This is not precise geolocation as the CCPA defines it: it cannot locate you within a radius of 1,850 feet and we do not access your device's location. Source: your browser's connection, via Cloudflare. Purpose: fraud prevention, security, detecting account sharing, and evidence in payment disputes. Retention: 13 months (section 7).
Beyond the approximate, IP-derived location above, we do not collect geolocation data; we do not collect biometric information, professional or employment information, education information, or inferences used to build a profile about you. We do not collect or use sensitive personal information other than the one-time sign-in codes (stored hashed, deleted after approximately 48 hours) used solely to authenticate you, which is a permitted purpose that does not give rise to a right to limit.
Disclosure, sale, and sharing
We disclose each category above to the service providers listed in section 5 for the business purposes described there. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We have no actual knowledge that we sell or share the personal information of consumers under 16. Because we do not sell or share, we do not offer an opt-out link; we treat Global Privacy Control signals as described in section 4.
Your California rights
- Right to know: the categories and specific pieces of personal information we collected, the categories of sources, the purposes, and the categories of third parties to whom we disclosed it. You may make this request up to twice in any 12-month period.
- Right to delete: you can delete your account yourself at any time in the app (section 7), subject to the exceptions in the CCPA (for example, completing a transaction, security and fraud prevention, legal obligations), which mirror the retention exceptions in section 7.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing and right to limit use of sensitive personal information: not applicable, because we do not sell, share, or use sensitive personal information beyond the permitted purpose above.
- Right to non-discrimination: we will not deny you service, charge a different price, or provide a different level of quality because you exercised these rights.
Submit requests by email to support@subsecond.io from your account email. We verify requests by matching the sending address (and, where needed, additional details) with our records; we cannot act on requests we cannot verify. We aim to confirm receipt within 10 business days and to respond within 45 days, extendable once by a further 45 days with notice, as the CCPA provides. An authorized agent may submit a request for you if they provide your signed written permission or a power of attorney; we may also ask you to verify your identity with us directly. We do not offer financial incentives in exchange for personal information.
12. Other US state privacy laws
Residents of other US states with comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah, Texas, and Oregon) may have similar rights to access, correct, delete, and port their data and to opt out of targeted advertising, sales, and profiling. We do not engage in targeted advertising, sales, or profiling. To exercise a right, follow section 9; to appeal a decision on your request, reply to our response and we will reconsider it and tell you the outcome.
13. International transfers
We are a US company, and data is processed and stored in the United States, including by the service providers in section 5. If you use the Service from outside the US, your data is transferred to and processed in the US, which may not provide the same level of data protection as your home jurisdiction. Where required (for example, for EEA, UK, and Swiss users), transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum, and our service providers' own transfer mechanisms.
14. Links to other sites and services
The Service links to third-party sites and services we do not operate, for example Stripe's checkout and billing portal, our providers' privacy policies, and external resources in our content. Their privacy practices are governed by their own policies, not this one, and we are not responsible for them. Review a third party's policy before providing it with data.
15. Children
The Service is for adults and is not directed to anyone under 18, and in particular not to children under 13 within the meaning of the US Children's Online Privacy Protection Act. We do not knowingly collect data from minors; if we learn that a minor has created an account, we will delete the account and its data promptly. If you believe a minor has provided us data, contact us.
16. Disclaimer and limitation
This policy describes our data practices as of the effective date; it is not a warranty of any particular security outcome. It is incorporated into our Terms of Service, and, to the fullest extent permitted by law, the Terms' disclaimer of warranties, limitation of liability and release, indemnification, governing law, informal-resolution step, and binding individual arbitration and class-action waiver (Terms Sections 13–15, 18 and 19) apply to any claim or dispute relating to this policy or to our collection, use, or protection of your data. Nothing in this section limits rights that applicable data-protection law gives you and that cannot be waived.
17. Changes to this policy
We may update this policy as the Service evolves. For material changes, we will notify you before they take effect by email to the address on your account or by a notice in the Service; notice is deemed given when sent or posted. Other changes take effect when posted here. The effective date above always reflects the current version, and we encourage you to review this page periodically. Continued use of the Service after a change takes effect means the updated policy applies to you.
18. Contact
purpl LLC (Wyoming, USA)
Email: support@subsecond.io