Privacy policy

Last reviewed:

This policy explains which personal data we process when you use kauntodaun.com (and contadorparaemail.com, which serves the GIFs of emails already sent) and the Kauntodaun service. In short: we use no analytics or advertising cookies, we do not sell data and we never store your subscribers' email addresses.

Data controller

We process data under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 of 5 December on personal data protection and digital rights (LOPDGDD).

What we process and why

If you use the generator without an account

We store the setup of the timer you create so we can serve the GIF. When you create it we give you an edit key: the key stays in your browser (local storage, hasta.claims) and we only keep a hash of it. Legal basis: providing the service you ask for (GDPR article 6.1.b).

If you create an account

We process your email, your password (stored as a hash, never in plain text), your language, your timers and your team members. Legal basis: the service contract (GDPR article 6.1.b).

If you buy a paid plan

Payments are handled by Stripe. We never see or store your card number; Stripe sends us your subscription status and the details needed to issue the invoice. Legal basis: the contract and tax obligations (GDPR articles 6.1.b and 6.1.c).

When an email with a timer is opened

Every time an email app downloads the GIF we count one impression for that timer, grouped by hour. We use this to show you analytics and to apply plan limits. The impression log does not store the IP address: only the time, the timer and, for evergreen timers, the recipient's hashed identifier. To stop abuse, the engine may rate-limit requests per IP with a short-lived counter that stores the IP as a hash, never in plain text. For each plan's impression limit we count distinct opens with an IP fingerprint: a hash with a key that changes every day, never the IP itself.

In evergreen timers, your email platform adds a recipient identifier to the GIF URL through a merge tag. We never store that identifier as it is: only its hash, to know when that person's countdown started. The full URL, including the identifier, may appear in the access logs of Hostinger's server, which keeps them under its own policy. That's why we recommend using an internal ID from your platform, such as the contact ID, and not the email address or other personal data.

For your subscribers' data, you decide what the timer is used for and we act as a data processor. If you need a signed data processing agreement, write to a.dominguez@theapagency.com.

Technical logs

The server logs technical data for each request (IP address and browser, with the time) for security and to keep the service running. If you use an account, we also store the IP address of each session, of each login link you request and of security changes to the account (audit log). Legal basis: legitimate interest (GDPR article 6.1.f).

Website analytics

We measure how the website is used with our own analytics: no cookies, nothing stored in your browser and no third-party services. It tells us which pages are visited, where visits come from and how many people create a timer, open an account or start a payment. Legal basis: legitimate interest in improving the website (article 6.1.f GDPR).

With each page view, and when you create a timer, copy the code, open an account or start a payment, your browser sends us the page path (from the address we only keep the utm_source, utm_medium and utm_campaign parameters), the domain of the site you came from (not the full address), your browser language and whether the screen is a phone, tablet or computer. To count distinct visitors we compute a fingerprint: a hash of your IP, your browser and our domain with a key that changes every day and is deleted after two days. We do not store the IP or the browser, and one day's fingerprint cannot be linked to another day's.

When you create a timer or an account we also store where you reached that page from (the utm parameters, the referring domain or the page of this site you came from) and the page where you did it. We only look at the page you are on: we do not follow you from page to page.

If your browser sends a Do Not Track or Global Privacy Control signal, nothing is sent. We do not count bots or automated browsers either.

Browser local storage

This data stays in your browser; it goes away when you clear the site's data.

Who else processes data

We do not share data with third parties for advertising. The only transfer outside the European Economic Area is Stripe's, with the safeguards in its data processing agreement.

How long we keep it

Your rights

You can ask for access, correction, deletion, restriction, portability or objection by writing to the privacy contact. We reply within the one-month period set by GDPR article 12. If you think we did not handle your request properly, you can complain to the Spanish Data Protection Agency at aepd.es or to your local authority.

Security

All traffic is encrypted with HTTPS, passwords and timer keys are stored as hashes and database access is limited to the service.

Code copied