Daymark
Legal

Privacy Policy

Last updated 2 August 2026

In short
We hold your financial figures in an ordinary database and we are able to read them — that is what makes password reset, import parsing and actually helping you possible. We do not sell them, we do not use them to train AI models, and we do not run advertising or analytics trackers. Your data is stored in the United States. You can export everything or delete it outright, at any time, from Data & access in your workspace settings.

1.Who this is about

Daymark (“we”, “us”) is a financial forecasting service operated from British Columbia, Canada. This policy covers daymarkhq.com and the application at that domain. It is written to Canada’s PIPEDA and British Columbia’s Personal Information Protection Act.

Questions, requests and complaints all go to support@daymarkhq.com.

2.What we collect, and why

Your account
Your name, email address, and whether that address has been verified. Passwords are stored only as a hash — we never hold the password itself, and cannot recover it for you.
Sessions
When you sign in we store a session token, its expiry, and the IP address and browser user-agent it was created from. That is what keeps you signed in, and what lets us tell you which sessions are yours if something looks wrong.
Your workspace
The figures you type or import, the assumptions you set, any saved scenarios, and the workspace name, currency and revenue goal. This is the substance of the product and the most sensitive thing we hold.
Import records
For each import: the file name, how many rows it had, the column headers found in it, the mapping you confirmed, who ran it and when. The uploaded file itself is read into figures and then discarded — we do not keep a copy of it.
Billing
Your Stripe customer and subscription identifiers, the subscription status, and the trial and renewal dates. Card numbers are handled entirely by Stripe and never reach our servers.
Audit log
Who did what in a workspace, and when — imports, invitations, role changes, deletions. Deliberately never the financial values themselves.

We collect all of it for one purpose: to run the service you signed up for, bill you for it, and support you when it goes wrong. There is no advertising, no third-party analytics and no tracking anywhere in Daymark.

3.What we can see

Your figures are encrypted in transit and encrypted at rest, but they are not hidden from us. This is a deliberate design decision, and the honest version matters more than a reassuring one: an encryption scheme we could not see through would also make it impossible to reset a password, parse an upload on the server, or work out why your import produced the wrong number.

What we hold ourselves to instead:

  • No financial values are written to application logs or error reports.
  • Database credentials are least-privilege, and access to production is limited to what is needed to operate it.
  • We look at the contents of your workspace only when you ask us for help, when we must to diagnose a fault, or where the law requires it.
  • We do not sell your data, share it for marketing, or use your figures to train AI models.

4.Cookies

One cookie, and it is the session: a signed token that keeps you signed in for up to 30 days, or until you sign out. There are no advertising cookies, no analytics cookies and no third-party trackers, so there is no consent banner to click through.

5.Who else handles your data

Daymark is built on services that process data on our behalf. Each is bound by its own agreement with us to use it only to provide its service:

Neon — database
Stores everything described in clause 2, encrypted at rest. Hosted on AWS in the United States (us-east-2).
Vercel — application hosting
Runs and delivers the application, in the United States. Sees requests in transit, including IP addresses.
Stripe — payments
Takes and stores your card details, which never reach us, and holds your name, email and billing address under its own privacy policy.
Resend — email
Delivers transactional email: verification, password reset, invitations, trial and billing notices. Sees your email address and the contents of those messages.
Anthropic — column mapping only
Daymark first tries to work out an uploaded file's columns from the headers alone. When that is inconclusive, the header row and up to 20 sample rows — including whatever values are in those rows — are sent to Anthropic's API to suggest which column is the date, the amount and the category. Never the whole file. No figure is ever calculated there, and the data is not used to train models. The import screen tells you when a mapping came from this rather than from the headers, and you can change any column it proposes before anything is committed.

6.Where your data is stored, and what that means

Daymark is operated from Canada, but your data is stored and processed in the United States. While it is there it is subject to US law, including lawful requests by US authorities to the providers named above. Canadian privacy law requires that you be told this before you decide to sign up, rather than after.

7.How long we keep it

  • While the workspace exists, we keep it. The model is a living document — that is the product.
  • Deleting a workspace is a hard delete. The workspace row and everything that hangs off it — models, scenarios, imports, invitations, memberships, the audit log — are removed from the database. It cannot be undone, and we cannot get it back for you.
  • Deleting your account removes your user record and every session with it.
  • Backups may hold a copy for a short window after deletion before they roll off.
  • Billing records are kept by Stripe and by us for as long as tax and accounting law requires, regardless of whether the workspace still exists.

8.Your rights

Under PIPEDA and BC PIPA you can ask for access to the personal information we hold about you, ask us to correct it, and withdraw your consent to our holding it. Two of those you do not have to ask for:

  • Export. Data & access in your workspace settings downloads everything the workspace holds as a single JSON file — the model, every assumption, who has access, and a record of what has been imported. It works during a trial, while subscribed, and after you cancel.
  • Deletion. The workspace owner can delete the workspace outright from the same screen.

For anything else, write to support@daymarkhq.com and we will respond within 30 days. If you are not satisfied with our answer you can complain to the Office of the Information and Privacy Commissioner for British Columbia, or to the Office of the Privacy Commissioner of Canada.

9.Security

Traffic is served over TLS. Passwords are hashed, must be at least 10 characters, and the email address is verified before an account can be used. Every query against your figures resolves your membership of the workspace first, so there is no path that takes a workspace identifier from the browser and trusts it.

No system is perfect. If a breach occurs that creates a real risk of significant harm to you, we will tell you and the relevant privacy commissioner, as the law requires.

10.Children

Daymark is a tool for businesses and is not intended for, or directed at, anyone under 18.

11.Changes to this policy

When this policy changes we update the date at the top. If a change materially affects what we do with your data — a new processor, a new purpose — we will email account holders before it takes effect.

See also the Terms of Service.