Privacy Policy
Version: 2025-09-01
Who we are
PlayOnDay (“we”, “us”, “our”) builds a lightweight web app for creating and enjoying personal video playlists.
Scope of this notice
This notice explains what data we process on our website and forms. The application itself currently does not store user accounts or viewing data. In future phases we plan to add accounts, progress sync, and a marketplace; see Future features.
Data we collect now (website & forms)
- Contact / signup form: first name, last name, email, purpose (newsletter / cooperation / delete data), optional phone and comment.
- Marketing consent (newsletter): a checkbox recording your consent decision.
- Technical & security: IP address (server logs), anti-bot token (Cloudflare Turnstile) used only to verify the submission.
How we use your data & legal bases (GDPR/UK GDPR)
- Newsletter updates — to send you emails after you opt in. Legal basis: your consent.
- Cooperation enquiries — to respond to messages and plan collaboration. Legal basis: legitimate interests and/or pre-contractual steps.
- Delete-my-data requests — to verify and process your request. Legal basis: legal obligation and/or your rights under data protection law.
- Security & anti-abuse — to protect forms and infrastructure (e.g., Turnstile). Legal basis: legitimate interests.
Retention
We keep personal data only as long as necessary for the purpose collected and then delete or anonymise it. As a rule of thumb, contact form submissions are retained for operational needs and records of consent, then removed within our configured retention window (currently 365 days). You can ask us to delete your data at any time; we will honour valid requests unless we must keep certain records by law.
Sharing & processors
We don’t sell your personal data. We work with trusted service providers to host the website, protect forms, send emails, and store data securely. These providers process data on our instructions and under contract. Today this includes:
- Security/anti-bot: Cloudflare Turnstile (validates that a submission is human).
- Hosting/database & infrastructure: cloud hosting provider(s) used to run our site and store submissions.
- Email delivery (if used): an email service to send messages and notifications.
Cookies & similar tech
We currently use essential cookies/tech needed to operate forms and security. We do not run analytics or advertising cookies at this time. If this changes, we will update this notice and present choices.
Your rights
Subject to law, you can request access, rectification, erasure, restriction, objection, and data portability. Where we process based on consent (e.g., newsletter), you can withdraw consent at any time — this won’t affect prior lawful processing. To exercise your rights, contact us. You can also lodge a complaint with your local supervisory authority.
Security
We apply reasonable technical and organisational measures to protect data (e.g., TLS, anti-forgery, origin checks, anti-bot verification, access controls). No system is 100% secure; please contact us immediately if you suspect misuse.
International transfers
Our service providers may process data in other countries. When data leaves the EEA/UK, we rely on appropriate safeguards (e.g., Standard Contractual Clauses) as required by law.
Children
Our website and upcoming app are intended for adult users. We do not knowingly collect personal data from children.
Future features (what will change when they launch)
- User accounts & sign-in: we will process login email and password (stored in hashed form) and basic account details to run the service.
- Progress: we will store progress per playlist/video (e.g., playlist ID, video index, elapsed time) so you can resume where you left off.
- Playlists & sharing: we will store links and metadata you add to manage your playlists and share them with other registered users.
- Marketplace & payments: purchases will be handled by a payment provider (e.g., Stripe/PayPal). We won’t receive full card details; we’ll get transaction metadata (status, amount, product) to fulfil your order. We’ll update this section and link the provider’s privacy notice before launch.
Changes to this notice
We may update this notice as our service evolves. We’ll change the version at the top and, where appropriate, provide additional notice. Please check back from time to time.
Contact
Contact us: using this form
Website: PlayOnDay.com
Mobile app — what we collect now
The PlayOnDay mobile app is designed to work with minimal data. Today we do not require an account and we do not run in-app analytics. The app:
- Opens original videos from platforms like YouTube or Vimeo in a web view or the system browser. Those platforms may process your data under their own privacy notices.
- Saves lightweight settings on your device (e.g., theme, last opened playlist, last video index/time) so you can resume quickly. This stays on your device and is not sent to our servers.
- Does not access your contacts, photos, camera, microphone, precise location, or Bluetooth.
On-device storage (app)
The app stores small pieces of data locally (e.g., playlist ID, video index, elapsed time, UI preferences). You can clear this via your device settings or by uninstalling the app. If you later sign in (see below), selected items may sync to your account.
Device permissions
- Network access — required to open video links and load thumbnails.
- Notifications (optional, if you enable reminders) — used to nudge you about the next video in a playlist. You can turn notifications off at any time in system settings.
- Background tasks — used only to schedule local notifications; we do not track your location or activity in the background.
- Not requested — camera, microphone, contacts, photos/media, precise location.
Crash reports & analytics (app)
We currently do not collect crash logs or analytics in the app. If we later integrate a provider (e.g., App Center / Firebase Crashlytics) to improve stability, we will update this notice and list the provider here, including what data is sent and retention.
Third-party content in the app
PlayOnDay doesn’t host videos or content. When you open a video or a page, you interact directly with its source (e.g., YouTube/Vimeo/www page). Your use of those services is governed by their terms and privacy notices. We encourage you to review them.
Security in the app
We use secure connections (TLS) and platform protections. If sign-in is enabled in a future release, authentication tokens will be stored securely by the OS (e.g., Keychain/Keystore) and cleared on sign-out or uninstall.
Mobile app — future features (when launched)
- Accounts & sync — if you create an account and sign in, the app will sync your playlists and progress to our servers so you can resume across devices. Legal basis: contract / legitimate interests.
- Sharing — if you share a playlist with another registered user, we’ll process the recipient’s account identifier to deliver access.
- In-app purchases/marketplace — handled by a payment provider (e.g., App Store/Google Play or Stripe). We receive transaction metadata (no full card details) to fulfil your order. We’ll list the provider and link their privacy notice before launch.
- Push notifications (optional) — if enabled, your device’s push token will be used to send reminders. You can opt out at any time.
Retention for account data will follow our Retention rules (currently 365 days for form submissions) and specific service needs; details will be added here on launch.
Uninstall & deletion
Uninstalling the app removes on-device data. If you have an account or previously submitted forms, you can request server-side deletion any time via this form. We will honour valid requests unless we must retain certain records by law.