Privacy Policy

Effective Date: August 14, 2026 | Version 2.4

1. Scope & Legal Roles

This Privacy Policy explains how DiffFlow LLC ("DiffFlow", "Company", "we", "us", or "our") collects, processes, stores, and protects personal data when you access our website (diffflow.com), utilize our software applications, interact with our REST APIs, or subscribe to our automated website change monitoring services (collectively, the "Service").

Under the General Data Protection Regulation (GDPR) (EU) 2016/679, the UK Data Protection Act 2018, and California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA):

  • DiffFlow as Data Controller: We act as Data Controller regarding account credentials, billing identifiers, communication records, platform telemetry, and security audit logs generated by users who register on our platform.
  • DiffFlow as Data Processor / Service Provider: We act as Data Processor regarding monitored target URLs, custom CSS selectors, Document Object Model (DOM) snapshots, and diff payloads processed strictly upon Customer instructions.

2. Categories of Data We Collect

We collect and process the following categories of data strictly to provide, maintain, and secure the Service:

A. Account & Identity Data

Full name, business email address, company/organization name, and salted cryptographic password hashes (Argon2id). We never store plaintext passwords.

B. Billing & Payment Data

Payment card transactions are processed directly by our PCI-DSS Level 1 compliant processor, Stripe, Inc. DiffFlow stores only non-sensitive tokens, Stripe Customer IDs, billing addresses, and invoice histories. We do not store Primary Account Numbers (PAN) or CVV codes.

C. Monitor Configurations & Alert Routing

Target URLs, CSS selector expressions, polling frequencies, filter expressions, and alert delivery destinations (email addresses, mobile numbers for SMS delivery, webhook URLs, Slack/Discord webhook credentials).

D. Crawl Cache & Diff Data

Sanitized HTML extracts, SHA-256 content hashes, and structured differential change records. Our normalization engine automatically purges transient session tokens, script tags, and advertising scripts prior to diff calculation.

E. Technical & Telemetry Data

Internet Protocol (IP) addresses, browser user-agent headers, API authentication tokens, request timestamps, response latencies, and worker error traces used for security monitoring, Server-Side Request Forgery (SSRF) defense, and DDoS mitigation.

3. Legal Bases for Processing (GDPR Art. 6)

We process personal data only when lawful under applicable data protection regulations:

  • Performance of Contract (Art. 6(1)(b)): Fulfilling our contractual commitments to execute automated polling, compute diffs, dispatch notifications, manage subscriptions, and process payments.
  • Legitimate Interests (Art. 6(1)(f)): Protecting our infrastructure against abuse, detecting malicious scraping, enforcing SSRF controls, mitigating fraud, and maintaining platform uptime.
  • Legal Obligation (Art. 6(1)(c)): Complying with financial recordkeeping, statutory tax reporting, and valid law enforcement disclosures.
  • Consent (Art. 6(1)(a)): Delivering non-essential communications or voluntary feedback surveys (consent may be revoked at any time).

4. Storage Technologies & Cookies

DiffFlow does not deploy third-party advertising cookies or cross-site tracking pixels. We use browser localStorage strictly for authentication token persistence (JSON Web Tokens) and UI preferences (such as cookie consent choices and theme settings). This storage remains on your device and is transmitted solely in secure API request headers to our authenticated endpoints.

5. Third-Party Sub-Processors

We engage vetted third-party service providers ("Sub-processors") to support platform operations. All sub-processors are bound by strict Data Processing Agreements (DPAs) with standard contractual clauses:

Sub-processorPurposeLocationTransfer Mechanism
Stripe, Inc.Payment processing & subscription billingUnited StatesEU-US DPF / Standard Contractual Clauses (SCCs)
Cloudflare, Inc.Edge DNS, TLS termination, email dispatchGlobal / USAEU-US DPF / Standard Contractual Clauses (SCCs)
Twilio, Inc.SMS critical alert delivery (optional)United StatesEU-US DPF / Standard Contractual Clauses (SCCs)
Neon Inc.Encrypted PostgreSQL cloud database hostingUnited States / EUStandard Contractual Clauses (SCCs)

We do not sell, rent, monetize, or trade your personal data to any third party under any circumstances.

6. Data Retention & Deletion Schedules

  • Active Accounts: Account data and monitor configurations are retained for the duration of your active subscription.
  • Account Deletion: When an account is deleted via the dashboard, all active monitors, notification routes, and authentication tokens are immediately revoked and permanently deleted from production databases within thirty (30) days.
  • Historical Diff Records: Change snapshots and diff records are retained for thirty (30) days on free accounts and up to ninety (90) days on paid accounts, after which raw snapshot payloads are automatically pruned.
  • Financial & Invoicing Records: Billing and tax transaction histories are retained for seven (7) years to satisfy statutory tax obligations.

7. Your Privacy Rights (GDPR & CCPA/CPRA)

Depending on your jurisdiction, you possess specific statutory rights regarding your personal data:

  • Right of Access & Portability: Request a structured, machine-readable export of all personal data held about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal records.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data when no longer necessary for contractual or legal purposes.
  • Right to Restrict Processing: Request temporary restriction of data processing during dispute resolution.
  • Right to Object: Object to processing based upon legitimate interests or direct communications.
  • California CPRA Non-Discrimination: We will not discriminate against you in pricing, service availability, or feature access for exercising your privacy rights.

To exercise any of these rights, submit your request to [email protected]. We verify requests against account credentials and respond within thirty (30) calendar days.

8. Technical & Organizational Security Measures (TOMs)

DiffFlow implements enterprise-grade technical and organizational safeguards:

  • Encryption: All network communication is encrypted in transit using TLS 1.3 with strict HTTP Strict Transport Security (HSTS). Data at rest is encrypted using AES-256.
  • SSRF Hardening: Outbound scraping requests pass through custom DNS pre-flight verification to block private address spaces (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, and RFC 4193 IPv6 subnets).
  • Password Protection: Passwords are protected using Argon2id with unique, randomly generated salts.
  • Edge Security: Strict Content Security Policy (CSP) headers and Subresource Integrity (SRI) hashes prevent code injection.

9. Children's Privacy

The Service is an enterprise and developer tool intended strictly for users aged 18 and older. We do not knowingly collect personal data from individuals under 16 years of age. If we learn that a minor has provided personal data, we will immediately purge such data from our systems.

10. Policy Amendments & Contact Details

We may update this Privacy Policy periodically. Material changes will be communicated via email to registered account holders or highlighted on our platform at least fourteen (14) days before taking effect.

For questions, Data Protection Officer (DPO) inquiries, or regulatory notices, contact our Data Privacy Team:

DiffFlow Privacy & Data Protection

Email: [email protected]

Security Reports: [email protected]

Stop missing the signal.

Create your first monitor