Privacy Policy
Last updated 2026-09-10
This policy describes how Devino Solutions Inc (“we”, “us”) handles data when you use DoDomain — the marketing site, documentation, dashboard, REST API, SDKs, widget, and hosted connect flow. It is scoped to what the product actually does, and it names every service that receives data.
1. Data we collect
- Account data — your name and email address, provided through Google sign-in, Sign in with Apple, or email signup, plus the teams you belong to and your role on each.
- Product data — the domains and DNS records you configure, connect sessions and their verification results, webhook endpoint URLs, and webhook delivery logs (request status and timing, never your users’ page content).
- Usage data — API request and connection counts metered against your plan, plus standard technical logs (IP address, user agent, timestamps) kept for security and rate limiting.
- Billing data — handled by our payment partners; we never see or store full card numbers. We store the plan and subscription state they report to us.
- Support and feedback — what you write in the support form or an error-feedback prompt, a reference id for the submission, and — if you were signed in — your account id and team so we can reply in context.
2. Analytics and error monitoring — exactly what is captured
Product analytics (PostHog), self-hosted at posthog.devino.ca on our own infrastructure. On the marketing site and in the dashboard it records page views, page leaves, and interaction events (clicks and rage-clicks on interface elements — never the text you type into fields). Every event carries the app that produced it, the build version, the environment, the page path, the referring page, and any campaign parameters in the URL. In the dashboard it also records the support and error-feedback submissions described above and “an operation the user saw fail” events, each with the corresponding error-monitoring reference id.
When you sign in, the dashboard links your analytics activity to your internal account id — never your email or name — so that a problem you report can be matched to what happened. The first page you arrived from and the campaign parameters of that first visit are kept as properties of that profile. Visitors who never sign in get no profile. Session replay is off: no recording of your screen, mouse, or keystrokes is made. Your IP address is stored with events.
Error monitoring (Sentry) in the dashboard, API, and hosted connect flow: when something breaks, the error message, stack trace, request path, browser and device details, the build version, and — if you were signed in — your internal account id are sent so we can fix it. DNS record contents and form input are not included.
Google Analytics 4 on the marketing site and documentation only: aggregate page-view and traffic-source measurement, processed by Google. It is not loaded until you accept analytics cookies (section 3).
3. Cookies and browser storage
Essential (always set). The dashboard sets the sign-in session cookie and a short-lived state cookie during sign-in (HttpOnly, Secure, SameSite=Lax); a guest-conversion cookie exists only while a guest account is being upgraded. Your light/dark theme choice is kept in local storage.
Consent choice. The cookie banner stores your answer in a single cookie (dodomain_cookie_consent, one year, shared across dodomain.io and app.dodomain.io) so you are not asked twice.
Analytics (only after you accept). PostHog stores an anonymous identifier in a cookie and local storage; Google Analytics sets its _ga cookies. Until you accept — or if you decline — PostHog runs without storing anything in your browser (events still count the page, but nothing links one visit to the next) and Google Analytics is not loaded at all. No advertising cookies, ever.
4. End users of integrators
When someone connects a domain through an integrator’s product, we process that connection — the domain name, the records to set, provider detection, and verification status — on the integrator’s behalf. Integrators are responsible for their own privacy disclosures to their users. We use this data only to run the connection, never to build profiles.
5. How we use data
- Operating the service — provider detection, DNS verification, webhook delivery, and session handling.
- Metering usage against plan limits and billing paid plans.
- Securing the service — abuse prevention, rate limiting, and debugging.
- Understanding how the product is used, in aggregate, and fixing the problems people report.
- Service communication, such as billing, usage-cap, or security notices.
No advertising, and no automated profiling.
6. Processors and sharing
- Our own servers, fronted by Cloudflare (network edge, TLS, and DNS for dodomain.io) — run the application and database that store the data above.
- Google and Apple — sign-in authentication, when you choose those sign-in methods.
- RevenueCat and Stripe — subscription billing and payment processing.
- Sentry — error monitoring, as described in section 2.
- PostHog — product analytics, self-hosted on our own infrastructure, so analytics data stays with us.
- Google Analytics 4 — aggregate traffic measurement on the marketing site and documentation; data is processed by Google.
- Our transactional email provider — delivers sign-in, team-invitation, support, and billing emails to the address you gave us (Amazon SES infrastructure via our email service).
- Uptimely — runs our public status page and uptime checks; it receives no personal data.
Each processor receives only what it needs for its role. We do not sell personal data, and there are no ad networks. We may disclose data where required by law.
7. Retention
Account data is kept while your account is active. Connection, session, and webhook delivery records are kept for as long as they are needed to operate the service and meter usage. Technical logs rotate on a shorter cycle. Analytics events are retained in our self-hosted PostHog for up to seven years and error reports in Sentry per its default retention. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where law requires longer retention.
8. Security
Data moves over TLS, access to production systems is restricted, and webhooks are signed so your server can verify they came from us. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you without undue delay.
9. Your rights and deleting your data
You can request access to, correction of, export of, or deletion of your personal data. Depending on where you live, you may have additional statutory rights; we honor requests regardless of geography where we reasonably can.
Deleting your account is self-serve: in the dashboard, open Settings → Delete account. Before anything is removed, the page lists exactly what will go — every team you are the only member of, with its apps, domain connections, sessions, and webhook history — and which shared teams you will simply leave, their data staying with the people still on them. Deletion signs you out and cannot be undone.
For anything the self-serve path does not cover — data held about you without an account (for example a support submission you sent while signed out, or analytics tied to a browser), an export, or a correction — email privacy@dodomain.io, or send a request through the support form and choose “Something else”. Either route reaches the team directly and is answered within 30 days.
10. Changes
Updates to this policy are posted here with the date above adjusted. Material changes will be announced in the dashboard or by email before they take effect.
11. Operator and contact
DoDomain is operated by Devino Solutions Inc, Ottawa, Ontario, Canada K1G 5K1. For privacy questions or requests about your data, email privacy@dodomain.io. For anything else, email support@dodomain.io or use the support form.