Privacy Policy
Last updated: [DATE]
1. Who we are
[Company name AB], [Street address, postcode, city, Sweden], [Org. no. 559XXX-XXXX] ("we", "us") is the data controller for the personal data processed through Do Not Miss Anything (the "Service"). Contact for privacy questions or to exercise your rights: privacy@donotmissanything.com. For data your organization enters about its own people and work, your organization is the controller and we process it on its behalf, as set out in our Terms of Service.
2. What we collect
- Account data: name, email address, hashed password.
- Content you create: tasks, task descriptions, comments, chat messages, and photos attached to tasks.
- Organization/workforce data: if your organization uses the Planner module, this includes resource names, scheduling/assignment data, and (if your account is linked to a resource) which jobs you're booked on and for how long.
- Technical data: your IP address is stored briefly (up to 1 hour) to prevent signup abuse, then deleted automatically.
- If your organization connects Microsoft Business Central: job/project and customer reference data imported from your organization's Business Central tenant.
- Billing data, if your organization buys a paid plan: the billing contact's name and email, company name, subscription and invoice history. Card details are entered directly with Stripe; we only see the card brand and last four digits.
Usage analytics: we use Vercel Web Analytics to count page views (page URL, referrer, country, browser and device type). It sets no cookies and does not identify you — a visitor is only distinguished by a hash that is discarded daily. We also use Vercel Speed Insights, which measures anonymous page-load performance (e.g. load times) the same cookieless way. We do not use advertising or tracking cookies.
3. Why we process it, and on what legal basis
- To provide the Service (account creation, task/list management, notifications) — necessary to perform our contract with you or your organization (Art. 6(1)(b) GDPR).
- To send email notifications about missed tasks, weekly digests, or planner alerts — based on your organization's/your use of those features, which you can be removed from by your list/organization admin.
- To prevent abuse (signup rate limiting) — legitimate interest (Art. 6(1)(f)).
- To understand which pages are used, in aggregate, so we can improve the Service (anonymous page-view analytics) — legitimate interest (Art. 6(1)(f)).
- To bill paid subscriptions — necessary to perform our contract (Art. 6(1)(b)).
4. Who we share it with
- Supabase (database, authentication, and file storage hosting).
- Vercel (application hosting, and cookieless page-view and performance analytics).
- Resend (transactional email delivery for notifications and digests).
- Stripe (subscription payments — only if your organization buys a paid plan; card details go directly to Stripe and are never stored by us). Stripe also uses payment data as an independent controller, for example for fraud prevention and to meet its legal obligations, as described in Stripe's privacy policy.
- Microsoft Business Central — only if your organization has connected this integration, and only to import job/customer reference data, not to send your personal data to Microsoft.
We do not sell personal data, and do not share it for advertising purposes.
5. How long we keep it
Account and content data is kept for as long as your account exists. When you delete your account, your owned lists, tasks, messages, and attachments are permanently deleted. Signup-abuse-prevention data (IP addresses) is deleted automatically within an hour. Demo sandboxes are deleted automatically after 24 hours. Invoices and billing records are kept for as long as Swedish bookkeeping law requires (currently seven years), even if the account is deleted.
6. Your rights
Under GDPR, you have the right to:
- Access a copy of your personal data — download it any time from Account settings.
- Correct inaccurate data — editable directly in Account settings.
- Erase your data — delete your account any time from Account settings. This is permanent and cannot be undone.
- Object to or restrict certain processing, and data portability.
- Lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se.
7. Cookies
We use only strictly necessary cookies required to keep you signed in (session cookies) and, briefly during a Business Central connection, short-lived cookies to secure that login flow. We do not use analytics or advertising cookies, so no cookie consent banner is shown — Swedish/EU law does not require consent for cookies that are strictly necessary to provide a service you've requested.
8. Where your data is stored and transferred
Our database and file storage are hosted in the EU. Some of our providers process data outside the EU/EEA, including in the United States: our application servers (Vercel), payment processing (Stripe) and email delivery (Resend). Such transfers are protected by the EU–US Data Privacy Framework where the provider is certified, and otherwise by the European Commission's Standard Contractual Clauses. Contact us for a copy of the relevant safeguards.