Privacy Policy
Privacy Policy
Short version: Loginboard collects only the data needed to run your account and deliver the service. We do not sell your data. We do not run advertising. Your work logs belong to you.
1 Who we are
Loginboard ("Loginboard", "we", "us", or "our") operates the website loginboard.com and the Loginboard software-as-a-service application (collectively the "Service"). We are the data controller for personal data collected through the Service.
Contact email for all privacy matters: [email protected]
2 Data we collect
2.1 Data you provide directly
- Account data: name, email address, and password (stored as a bcrypt hash — we never store plaintext passwords).
- Profile data: timezone preference and any optional information you add to your profile.
- Content data: work logs, tasks, subtasks, links, time entries, workspace names, and any text or attachments you enter into the Service.
- Payment data: billing name and payment-card details. Card numbers are processed and stored exclusively by our payment processor, Razorpay; Loginboard stores only a non-sensitive payment reference token and plan status.
- Communications: messages you send to us by email or support channels.
2.2 Data collected automatically
- Log data: IP address, browser type, operating system, referring URL, pages visited, and timestamps — retained for security and abuse-prevention purposes.
- Session data: an encrypted session cookie required for authentication. See our Cookie Policy for details.
- Usage data: feature interactions (e.g. log count, export count) used to enforce plan limits and improve the Service.
2.3 Data from third parties
- OAuth providers: if you sign in with Google or another OAuth provider, we receive the name, email address, and provider user ID disclosed by that provider. We do not receive or store your provider password.
2.4 Data we do NOT collect
- We do not embed third-party advertising or analytics SDKs in the Service interface.
- We do not collect device location, camera, microphone, or contacts data.
- We do not use fingerprinting technologies.
3 How we use your data
We use collected data for the following purposes only:
- Providing the Service: creating and managing your account, displaying your logs and workspaces, processing plan upgrades, and enabling export features.
- Authentication & security: verifying your identity on login, detecting and preventing fraud, abuse, or unauthorised access.
- Plan enforcement: checking usage against the limits of your current plan (Free or Pro).
- Transactional communications: sending receipts, password-reset emails, plan confirmation emails, and essential service notices. These cannot be opted out of while your account is active.
- Product improvement: analysing aggregated, de-identified usage patterns to improve features and fix bugs. We do not build individual behaviour profiles.
- Legal compliance: retaining records as required by applicable law and responding to lawful requests from authorities.
We do not use your content data (logs, tasks, notes) to train machine-learning models or for any purpose beyond operating the Service on your behalf.
4 Legal basis for processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, our legal basis for processing your personal data is:
- Contract performance (Art. 6(1)(b) GDPR): processing necessary to deliver the Service you signed up for — account creation, authentication, and feature delivery.
- Legitimate interests (Art. 6(1)(f) GDPR): security monitoring, fraud prevention, service improvement, and enforcing our Terms of Service, where such interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c) GDPR): compliance with applicable laws, including financial record-keeping and responding to lawful authority requests.
- Consent (Art. 6(1)(a) GDPR): only where you have given explicit, freely withdrawable consent, such as for optional marketing emails (if and when offered).
5 Who we share data with
We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:
5.1 Service providers (sub-processors)
We engage trusted third-party companies to help operate the Service. These sub-processors may access personal data only to perform services on our behalf and are contractually prohibited from using it for any other purpose:
- Cloud hosting & infrastructure: our application and database are hosted on servers provided by Hostinger (Hostinger International Ltd., registered in Cyprus, infrastructure in the EU). Hostinger's privacy policy is available at hostinger.com/privacy-policy.
- Transactional email: password-reset emails and account notifications are sent via Hostinger Email Hosting using our domain loginboard.com, operated on Hostinger's mail infrastructure.
- Payment processing: Razorpay (Razorpay Software Private Limited, India) processes subscription payments. Your card details are transmitted directly to Razorpay and governed by their privacy policy at razorpay.com/privacy. Loginboard stores only a non-sensitive payment reference token and your plan status.
5.2 Legal requirements
We may disclose personal data if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a legal obligation.
5.3 Business transfers
If Loginboard is involved in a merger, acquisition, or sale of all or substantially all of its assets, your data may be transferred as part of that transaction. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
5.4 With your consent
We may share data with third parties in any other circumstance with your prior explicit consent.
6 Data retention
6.1 Active accounts
We retain your personal data for as long as your account is active or as needed to provide the Service.
6.2 Free plan log history
Work logs older than 90 days are automatically purged for Free plan accounts. Pro plan accounts retain unlimited history.
6.3 Account deletion — what happens immediately
When you delete your account, the following personal data is erased immediately and permanently at the moment of deletion:
- Your name and email address
- Your password and authentication credentials
- Connected OAuth identifiers (Google, GitHub)
- Your profile avatar and linked personal identifiers
- IP addresses stored in your activity records
- All active login sessions
Account deletion requires you to confirm your email address at the point of the request, creating a clear record of deliberate, informed intent.
6.4 What we retain after deletion (no personal data)
After your personal data is erased, certain fully anonymised records may be retained indefinitely. These records contain no name, no email address, no IP address, and no information that could identify you. Retention of these records is permitted under GDPR (Recital 26), the Indian DPDP Act 2023, and equivalent privacy laws because they no longer constitute personal data.
Retained anonymised records may include:
- Activity event records (e.g. "a log was created at 09:14 AM") with all personal identifiers removed
- Usage statistics used for service integrity, fraud prevention, and security auditing
These records cannot be used to identify, contact, or profile you in any way.
6.5 Backups
Encrypted database backups are retained for up to 30 days. Backup copies are not used to restore deleted personal data under normal circumstances and are retained solely for disaster-recovery purposes.
7 Your rights
Depending on your location, you may have the following rights regarding your personal data:
Rights under GDPR (EEA / UK / Switzerland)
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion of your personal data, subject to legal retention obligations.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint: lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your EU member state's DPA).
Rights under CCPA (California residents)
- Know: request disclosure of the categories and specific pieces of personal information we have collected about you.
- Delete: request deletion of your personal information (subject to exceptions).
- Opt-out of sale: we do not sell personal information. No opt-out is required.
- Non-discrimination: we will not discriminate against you for exercising any CCPA right.
Rights under Indian DPDP Act, 2023
- Access & correction: request access to, and correction of, your personal data.
- Erasure: request erasure of personal data no longer necessary for the purpose it was collected.
- Grievance redressal: contact our grievance officer at [email protected].
To exercise any of these rights, email us at
[email protected]. We will respond within 30 days. We may ask you to verify your identity before fulfilling a request.
8 Security
We implement reasonable technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- HTTPS/TLS encryption for all data in transit.
- Passwords stored as bcrypt hashes — never in plaintext.
- Access controls limiting data access to personnel who require it.
- Encrypted database backups.
No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. You use the Service at your own risk.
If you believe your account has been compromised, please contact us immediately at [email protected].
9 International data transfers
Loginboard is operated from India. If you access the Service from outside India, your data will be transferred to and processed in India and potentially in the country where our hosting or sub-processor infrastructure is located.
Where we transfer data from the EEA or UK to countries not recognised as providing an adequate level of data protection, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) adopted by the European Commission, or equivalent mechanisms permitted under applicable law.
10 Children
The Service is not directed at children under the age of 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data without parental consent, please contact us at [email protected] and we will take steps to delete such information.
11 Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will notify registered users by email or by a prominent notice within the Service at least 14 days before the change takes effect.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you must stop using the Service and delete your account.