Legal
Privacy Notice
Last Updated: July 23, 2026
Dang! Payoff is built on a simple idea: you type in your own numbers, and we do not sell personal information for money. It's a scoreboard, not a data grab. This notice explains what we collect, why, and what you can do about it.
1. What We Collect, and Why
Account information — your email address and sign-in records. You sign in using a magic link or a one-time code we email you, or with Google Sign-In. Source: you, Google if you choose Google Sign-In, and records generated when you use the Service. Purpose: signing you in, receipts, renewal reminders, security, and legal notices. Required to have an account.
Your plan data — the information you enter and calculations derived from those inputs, including creditor labels, balances, APRs, minimum payments, due days, payments, corrections, commitments, strategies, journey names, and projections. We use it to operate the planning features, store and display your plan, secure and troubleshoot the Service, and provide support when you ask. We do not use it for advertising, sell it for money, disclose it to advertising platforms, or use it for third-party profiling. Required for the Service to work.
Achievement cards — generated from your real progress. Shared only when you choose to share them.
Subscription and billing data — plan, status, trial dates, and transaction records. Payments are processed by Stripe; we never receive or store your full card number.
Technical and security data — our service providers and systems may record information such as IP address, browser and device type, operating system, timestamps, pages or application routes requested, session and authentication events, error and diagnostic records, and security logs. We use this information to deliver and secure the Service, diagnose problems, prevent abuse, and maintain reliable operations. We do not collect precise GPS location. Our providers may infer an approximate region from an IP address for security, routing, tax, or fraud-prevention purposes.
Consent state — your cookie/tracking choice, stored on your device (see the Cookie & Tracking Notice).
Support communications — if you email us, we keep the thread to help you.
The planning features do not connect to your bank, import bank transactions, or retrieve credit reports. Stripe separately processes the payment information you provide at checkout. You type in what you choose to type in.
2. What We Never Do
- We do not sell personal information for money.
- We do not disclose your debt-plan content — creditor names, balances, APRs, due dates, payments, strategies, projections — to advertising platforms.
- We do not use your plan data to train AI models.
- No marketing pixels are currently active on the Service. If we later activate advertising technology on our public marketing pages, we will update this notice and the Cookie & Tracking Notice BEFORE activation, and it will apply only with the consent controls described there.
3. Service Providers
We use service providers to operate the Service. They receive the information needed for their functions and handle it under applicable contracts and law. Our current providers include Supabase (database and authentication hosting), Vercel (web hosting), Resend (email delivery), Upstash/QStash (background jobs), Google (our support, legal, and privacy email service; optional Google Sign-In; and Google profile-image delivery), and jsDelivr (delivery of browser software libraries). When paid plans are enabled, Stripe processes payments. Stripe may also process payment information for fraud prevention, disputes, compliance, and its own legal obligations, as described in Stripe's privacy notice.
We may also disclose information when required by law, to protect users, the Service, or legal rights, or as part of a merger, financing, acquisition, reorganization, or asset sale, subject to applicable confidentiality and notice requirements.
4. Retention
Plan data. Kept while your account is active.
Deleting your account. When you request deletion, we schedule it to complete seven days later and you can cancel the request at any point during those seven days. This waiting period exists only to protect you from an accidental or regretted deletion; it is unrelated to how long backups are kept. When the seven days elapse and the deletion runs, your account and plan data are removed from active production systems.
Backups. Backups are a separate mechanism. After deletion completes, limited copies of your data may still exist in routine backups until those backups are overwritten on our providers' normal cycle — currently a rolling seven-day window on our database provider's plan. Provider backup schedules and configurations can change. Backups are used for service recovery, not to fulfill requests to restore an individually deleted account.
Technical, security, and authentication records. Kept according to provider schedules — currently seven days on our database provider's plan — and otherwise as reasonably necessary to secure, operate, and troubleshoot the Service.
Support communications. Kept as long as reasonably necessary to respond to you, maintain appropriate records of the issue, and meet legal obligations.
Billing, tax, fraud-prevention, legal, and assent records. Kept for up to 7 years as required for accounting, tax, payment, dispute, enforcement, and legal purposes.
Legal holds. We may retain limited information longer when required by law or reasonably necessary to establish, exercise, or defend legal claims.
5. Your Controls (available to everyone, regardless of where you live)
- Export your data anytime (Account → Privacy & data → Export).
- Correct anything by editing it in the app.
- Delete your account and data (Account → Privacy & data → Delete).
- Cookie/tracking choice — change anytime (Cookie settings).
- Email choices — transactional email (receipts, sign-in links, legal notices) comes with the Service; marketing email, if we ever send it, will be separate opt-in with a working unsubscribe honored within 10 business days.
Depending on your state of residence, you may have additional legal rights (access, correction, deletion, portability, opt-outs). We honor the Global Privacy Control browser signal as an opt-out signal. To exercise any right or ask questions: privacy@dangpayoff.com. We respond within the time applicable law requires (and aim for 45 days regardless).
6. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include encrypted connections, encryption at rest for our database provider's stored data, access restrictions, and controlled write paths for sensitive records. No system can be guaranteed completely secure.
If a security incident triggers a legal notification obligation, we will provide notices as applicable law requires. For Florida residents, Florida law generally requires notice no later than 30 days after determining that a qualifying breach occurred, subject to statutory investigation, law-enforcement-delay, and harm-assessment provisions.
7. Children
The Service is for adults 18+. We do not knowingly collect information from anyone under 18; if we learn we have, we will delete it and close the account.
8. United States Only
The Service is intended for U.S. residents and is operated from the United States.
9. Changes
We'll update this notice as the Service evolves and give notice of material changes before they take effect.
10. Contact
Dang Apps LLC · privacy@dangpayoff.com · 3206 NE 2nd Ave, Suite 3028, Miami, FL 33137