Privacy Policy
Last updated 3 August 2026
1.Who this is about
Daymark (“we”, “us”) is a financial forecasting service operated from British Columbia, Canada. This policy covers daymarkhq.com and the application at that domain. It is written to Canada’s PIPEDA and British Columbia’s Personal Information Protection Act.
Questions, requests and complaints all go to support@daymarkhq.com.
2.What we collect, and why
- Your account
- Your name, email address, and whether that address has been verified. Passwords are stored only as a hash — we never hold the password itself, and cannot recover it for you.
- Sessions
- When you sign in we store a session token, its expiry, and the IP address and browser user-agent it was created from. That is what keeps you signed in, and what lets us tell you which sessions are yours if something looks wrong.
- Your workspace
- The figures you type or import, the assumptions you set, and the workspace name, currency and revenue goal. This is the substance of the product and the most sensitive thing we hold.
- Import records
- For each import: the file name, how many rows it had, the column headers found in it, the mapping you confirmed, who ran it and when. The uploaded file itself is read into figures and then discarded — we do not keep a copy of it.
- Billing
- Your Stripe customer and subscription identifiers, the subscription status, and the trial and renewal dates. Card numbers are handled entirely by Stripe and never reach our servers.
- Audit log
- Who did what in a workspace, and when — imports, invitations, role changes, deletions. Deliberately never the financial values themselves.
- Usage recordings
- Microsoft Clarity records how the site is used — pages visited, clicks, scrolling, mouse movement, and your browser, operating system, screen size, approximate location from your IP address and where you arrived from — and replays it as a session. Inside a workspace, the text of the page is masked before it is sent, so the replay shows the layout you saw and what you clicked, not the figures, names or email addresses on it. See clause 5.
Most of that we collect for one purpose: to run the service you signed up for, bill you for it, and support you when it goes wrong. The usage recordings are for one other: to find out which parts of the product people get stuck on, which is difficult to learn any other way from a product this small. There is no advertising anywhere in Daymark, none of this is sold, and none of it is used to build a marketing profile of you.
3.What we can see
Your figures are encrypted in transit and encrypted at rest, but they are not hidden from us. This is a deliberate design decision, and the honest version matters more than a reassuring one: an encryption scheme we could not see through would also make it impossible to reset a password, parse an upload on the server, or work out why your import produced the wrong number.
What we hold ourselves to instead:
- No financial values are written to application logs or error reports.
- Database credentials are least-privilege, and access to production is limited to what is needed to operate it.
- We look at the contents of your workspace only when you ask us for help, when we must to diagnose a fault, or where the law requires it.
- We do not sell your data, share it for marketing, or use your figures to train AI models.
4.Cookies
Ours is one cookie, and it is the session: a signed token that keeps you signed in for up to 30 days, or until you sign out.
Microsoft Clarity sets two more, _clck and _clsk. They hold a random identifier whose only job is to recognise that two page views came from the same browser and the same visit, so a session can be replayed as one session. They are not tied to your account and they carry nothing about you.
There are no advertising cookies. We do not show a consent banner: under Canada’s PIPEDA and BC PIPA we are relying on this page as the notice, which is a judgement we have made rather than a rule we can point at. If you are in the UK or the EU — where analytics cookies generally need consent collected up front, before they are set — then Daymark does not currently do that, and you should read this clause as the disclosure instead. Any tracker-blocking extension stops Clarity, and nothing in the product depends on it working.
5.Who else handles your data
Daymark is built on services that process data on our behalf. Each is bound by its own agreement with us to use it only to provide its service:
- Neon — database
- Stores everything described in clause 2, encrypted at rest. Hosted on AWS in the United States (us-east-2).
- Vercel — application hosting
- Runs and delivers the application, in the United States. Sees requests in transit, including IP addresses.
- Stripe — payments
- Takes and stores your card details, which never reach us, and holds your name, email and billing address under its own privacy policy.
- Resend — email
- Delivers transactional email: verification, password reset, invitations, trial and billing notices. Sees your email address and the contents of those messages.
- Microsoft — usage analytics
- Microsoft Clarity receives the usage recordings described in clause 2, in the United States, under Microsoft's own privacy statement rather than ours. Workspace content is masked in your browser before anything leaves it, so what Clarity holds is the structure of a page and the interactions with it. Microsoft may also use what it collects for its own purposes, including improving its products — that is its arrangement, not something we control or can switch off on your behalf.
- Anthropic — column mapping only
- Daymark first tries to work out an uploaded file's columns from the headers alone. When that is inconclusive, the header row and up to 20 sample rows — including whatever values are in those rows — are sent to Anthropic's API to suggest which column is the date, the amount and the category. Never the whole file. No figure is ever calculated there, and the data is not used to train models. The import screen tells you when a mapping came from this rather than from the headers, and you can change any column it proposes before anything is committed.
6.Where your data is stored, and what that means
Daymark is operated from Canada, but your data is stored and processed in the United States. While it is there it is subject to US law, including lawful requests by US authorities to the providers named above. Canadian privacy law requires that you be told this before you decide to sign up, rather than after.
7.How long we keep it
- While the workspace exists, we keep it. The model is a living document — that is the product.
- Deleting a workspace is a hard delete. The workspace row and everything that hangs off it — models, imports, invitations, memberships, the in-workspace audit log — are removed from the database. Any Stripe subscription on it is cancelled. It cannot be undone, and we cannot get it back for you.
- Deleting your account removes your user record and every session with it, and deletes any workspace you own that has no other members. Workspaces you own that still have other people in them are left until you delete them first.
- Backups may hold a copy for a short window after deletion before they roll off.
- Billing records are kept by Stripe and by us for as long as tax and accounting law requires, regardless of whether the workspace still exists.
8.Your rights
Under PIPEDA and BC PIPA you can ask for access to the personal information we hold about you, ask us to correct it, and withdraw your consent to our holding it. Two of those you do not have to ask for:
- Export. Data & access in your workspace settings downloads everything the workspace holds as a single JSON file — the model, every assumption, who has access, and a record of what has been imported. It works during a trial, while subscribed, and after you cancel.
- Deletion. The workspace owner can delete the workspace outright from the same screen. You can also delete your account from there — that removes your sign-in and any workspace you own that nobody else is in.
For anything else, write to support@daymarkhq.com and we will respond within 30 days. If you are not satisfied with our answer you can complain to the Office of the Information and Privacy Commissioner for British Columbia, or to the Office of the Privacy Commissioner of Canada.
9.Security
Traffic is served over TLS. Passwords are hashed, must be at least 10 characters, and the email address is verified before an account can be used. Every query against your figures resolves your membership of the workspace first, so there is no path that takes a workspace identifier from the browser and trusts it.
No system is perfect. If a breach occurs that creates a real risk of significant harm to you, we will tell you and the relevant privacy commissioner, as the law requires.
10.Children
Daymark is a tool for businesses and is not intended for, or directed at, anyone under 18.
11.Changes to this policy
When this policy changes we update the date at the top. If a change materially affects what we do with your data — a new processor, a new purpose — we will email account holders before it takes effect.
See also the Terms of Service.