Effective August 15, 2026
Privacy policy
This policy explains how Nazar Adamovych, the operator of RenewalDock ("RenewalDock," "we," "us," or "our"), collects, uses, discloses, and retains personal information when you use our business renewal-reminder service.
1. Our role
We control account, billing, support, security, and first-party product-usage information. For recipient addresses and other personal information an account holder enters into a renewal record, the account holder decides why and how that information is used and instructs RenewalDock to process it. Account holders are responsible for their notices, permissions, and lawful basis for those instructions.
2. Information we collect
- Account information: name, work email, optional business name, timezone, password hash, email-verification status, and opaque session identifiers.
- Renewal information: titles, categories, dates, optional location or jurisdiction labels, responsible-owner names, internal work-progress status and next action, reminder and fallback-contact email addresses, reminder schedules, notes, recurrence settings, history, and optional reference links.
- Billing information: Stripe customer and subscription identifiers, selected billing interval, plan, subscription status, paid-term dates, consent records, and limited event identifiers. Stripe receives payment and billing-address details; we do not receive full card numbers.
- Communications: verification, reset, reminder, fallback, and billing-email delivery identifiers and status; and the name, email, topic, and message submitted through support.
- Security and diagnostics: timestamps, route and request results, errors, deployment identifiers, and stable one-way hashes derived from limited request attributes such as an IP address and email or user identifier for rate limiting. Unexpected-error alerts intentionally exclude URLs, headers, form values, and user content.
- First-party product events: signup, test-reminder request, renewal creation, CSV import, Pro-comparison, checkout, and subscription events, together with limited context such as selected template, product entry point, entry-page label, plan interval, legal-policy version, and UTM source, medium, or campaign labels.
- Aggregate acquisition counts: daily totals of eligible marketing-page impressions, grouped by an internal page label and cleaned UTM source, medium, campaign, and template labels. These totals are not linked to an account, session cookie, IP address, referrer, browser or device identifier, or full user-agent string. Request headers are examined transiently to avoid counting framework prefetches and obvious automated traffic, but are not retained in the acquisition-count table.
We collect this information directly from users, automatically when the service is used, and from providers such as Stripe, Resend, and our hosting infrastructure.
When you use the public renewal-tracker builder or CSV cleaner, your browser reads the values or selected file and generates the download locally; RenewalDock does not receive those values, the file, or its contents. In an authenticated Free or Pro import, the browser likewise previews the CSV locally, but sends the original file to RenewalDock after you explicitly confirm the import. It is parsed in server memory and is not retained as an uploaded file. Fields from accepted import rows become renewal records under this Policy.
3. Information you should not submit
RenewalDock is designed for operational metadata, not sensitive document storage. Do not submit passwords, full payment-card data, Social Security or government identification numbers, protected health information, biometric data, bank credentials, or other specially regulated or highly sensitive information. Use an access-controlled document system for authoritative files.
4. How we use information
- create, authenticate, secure, and support accounts;
- store renewal records and send the operational reminder and fallback notices selected by account holders;
- process subscriptions, document recurring-billing consent, provide billing notices, prevent fraud, and maintain accounting records;
- answer support, privacy, security, and legal requests;
- measure first-party product operation and improve reliability and usability;
- detect abuse, enforce our agreements, establish or defend legal claims, and comply with law.
Where a legal basis is required, we rely on performance of our agreement, legitimate interests in operating and securing a business service, compliance with legal obligations, and consent where the law requires it.
5. How we disclose information
We disclose only information reasonably needed for the purpose to:
- Railway: application hosting, managed PostgreSQL, deployment, and operational logs;
- Resend: verification, password-reset, reminder, billing, support, and operational email delivery;
- Stripe: checkout, subscription billing, customer portal, payment processing, fraud prevention, and billing records;
- GitHub: source control and scheduled calls to protected operational endpoints; and
- Hostinger: domain registration, DNS, and business-email services.
We may also disclose information when reasonably necessary to comply with law or valid legal process, protect people or rights, investigate abuse, or complete a financing, reorganization, acquisition, or sale of the service subject to appropriate confidentiality protections.
We do not sell personal information, share it for cross-context behavioral advertising, disclose it for third-party direct marketing, or use renewal content to train generative-AI models.
6. Cookies and tracking
RenewalDock uses one essential, secure, HTTP-only cookie to maintain an authenticated session. Account-linked first-party product events and aggregate page-impression totals are stored in our database as described above. Aggregate impression counting does not set a cookie or assign a visitor identifier. We do not currently use third-party advertising cookies, browser fingerprinting, or cross-site behavioral trackers. If that changes, we will update this policy and provide any choice required by law before activating non-essential tracking.
7. Retention
- Account, renewal, delivery, and first-party product records are generally kept for the life of the account and removed when the account is deleted, subject to the exceptions below.
- Session records expire after 30 days and expired records are removed by a scheduled cleanup. Used or long-expired verification and reset-token records are removed after 30 days.
- Rate-limit records are removed after their short operational window, generally within 48 hours.
- Aggregate acquisition-count rows are kept for up to 400 days and then removed by scheduled cleanup.
- Stripe webhook identifiers may be kept for up to two years to prevent duplicate processing and investigate billing events.
- Support communications, security records, and legal-request records are retained only as reasonably needed for the request, dispute, security issue, or legal obligation.
- Stripe and other providers retain payment, tax, fraud, and delivery records under their policies and legal obligations.
Deleting an account removes the user and account-linked content from the active RenewalDock database after billing is safely canceled. Limited billing, tax, fraud-prevention, legal, or security records may remain where required or reasonably necessary. Provider systems may retain residual copies through normal backup or deletion cycles.
8. Security
Safeguards include salted password hashing, opaque server-side sessions, encrypted transport, account-scoped access checks, same-origin mutation checks, signed Stripe webhooks, server-only credentials, rate limiting, minimized error alerts, scheduled data cleanup, and a written security and incident-response process. No system can guarantee absolute security. Report suspected unauthorized access through the contact form using the Security issue topic.
9. Your choices and privacy rights
You can edit account and renewal information, remove recipients, export active renewals, manage billing, and delete your account from Settings. You may also request access, correction, deletion, or a portable copy and may object, restrict processing, withdraw consent, or appeal a decision where applicable law provides that right.
Submit a request through our contact form using the Privacy request topic. Describe the account email and request without sending identity documents unless we specifically ask for a secure verification method. We may verify identity and authority, including for an authorized agent, and may retain the request record as required by law. You may appeal a denial by replying to our response with "Privacy appeal."
10. International processing
RenewalDock is operated from New York, United States. Our providers may process information in the United States and other countries where they or their subprocessors operate. Those countries may have different privacy laws. Where required, we use provider commitments and contractual safeguards for transfers.
11. Children
RenewalDock is a business service for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. Contact us if you believe a child submitted information.
12. Changes to this policy
We may update this policy as the service, providers, or law changes. We will post the effective date and provide reasonable advance notice if a change materially expands how we use personal information, and we will request consent where required.
13. Contact
RenewalDock is operated by Nazar Adamovych, sole proprietor, 31 Queens Way, Apt 10, Camillus, New York 13031, United States. Submit privacy, security, or legal requests through our contact form.