Privacy policy
Effective 1 October 2026.
NotifyBell is operated by Altix Code Ltd, a company registered in the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data we collect when you use our website and dashboard (the “Service”), what we collect and process on your behalf when your own backend publishes notifications and your users receive them through the NotifyBell embed, why, how long we keep it, who we share it with, and the rights you have over it. It applies to the marketing site, the dashboard, the API, and the embeddable widget.
Two different roles are in play throughout this policy, and they matter: for data about you and your NotifyBell account, Altix is the data controller. For data about the people who receive notifications through your app (your “Subscribers” — your own end-users, identified by an identifier your backend assigns), you are the data controller and Altix is a data processor acting only on your instructions — see “When we process data on your behalf” below.
1. Data we collect about you
When you sign up and use the Service, we collect:
- Account details — your email address, an optional name, your organisation name, and a salted, irreversibly hashed copy of your password. We never store or have access to your actual password.
- Team and permission data — if your account has more than one person on it, we store each member’s email, role, who invited them, and when, so an account owner or admin can manage access.
- Billing information — your subscription plan, status, and renewal date. Card and payment details are collected and held by Stripe, our payment processor; we only ever receive a subscription and customer identifier from them, never your card number.
- Support and account communications — anything you send us by email, including transactional email we send you (password resets, email verification, team invitations, billing receipts).
- Usage and security logs — sign-in timestamps, and a security audit log of membership actions on your account (invitations, role changes, removals, and account deletion requests), each tagged with the actor’s email and the time it happened.
- Technical data — standard web server and request logs (IP address, user agent, timestamps) generated when you use the dashboard or API, kept briefly for security and abuse prevention.
2. When we process data on your behalf
NotifyBell exists to store and deliver notifications your own backend publishes, to your own users, through an API key and an embeddable widget you add to your product. When your backend publishes a notification or registers a Subscriber, and when a Subscriber reads or interacts with it through the embed, we process the following on your behalf, as your processor, under your instructions (which are to operate the Service as described in our documentation):
- Subscriber identifiers — the identifier your backend assigns to that user (we never generate our own), and, only if your backend chooses to supply them, an email address and a display name.
- Notification content — the title, body text, category, optional action link, and priority of each notification your backend publishes, plus whether and when a Subscriber has read or seen it.
- Preferences — which notification categories a Subscriber has opted out of, so a publish correctly skips them.
- Activity timestamps — the last time a Subscriber read or received something, used only to measure monthly-active Subscribers against your plan and to show you that count.
This data can include personal data about your users, depending entirely on what your backend sends us and what notification content you choose to publish — a notification title you write yourself may itself contain personal data about the recipient or a third party, and that is your choice and your responsibility as controller, not ours. We do not read, moderate, or make any product decision based on the content of a notification; it passes through unchanged other than being stored and delivered.
The connection between the embed and your backend is authenticated with a short-lived, signed subscriber token, minted by your backend using a per-app signing key that we seal at rest (AES-256-GCM) and never expose to a browser. A compromised token grants access to exactly one Subscriber’s own inbox, nothing else.
3. Why we process it
- To provide, maintain, and secure the Service — operating your dashboard and API, storing and delivering notifications in real time, enforcing plan limits, and preventing abuse.
- To bill you, via Stripe, for a paid subscription you chose.
- To communicate with you about your account, including emails necessary to operate it (verification, password resets, team invitations, billing receipts) and, if you have not opted out, occasional product updates.
- To maintain a security audit trail of who did what on your account, so account owners and admins can review activity and we can investigate suspected compromise.
- To comply with our legal and accounting obligations, including tax law.
4. Who we share it with
We do not sell personal data. We share it only with the processors needed to run the Service, each bound by contract to use it solely to provide their service to us:
- Stripe, Inc. — payment processing and subscription billing. Stripe never receives Subscriber data; it only ever sees your own account and billing details.
- Resend (via its SMTP relay) — delivery of our own transactional email to you (account holders and team members). Subscriber data is never sent through this channel; notification delivery to your users happens through the embed and API, not email.
- Cloudflare, Inc. (Turnstile) — bot and abuse protection on our public sign-up, sign-in, and password-reset forms. Cloudflare sees only what is needed to score a form submission as human or automated; it does not see Subscriber data.
- Hetzner Online GmbH — our infrastructure host, where our servers and database physically run (EU-located).
Issued invoices are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company. This is an internal system we operate ourselves, not a third party.
Some of these processors are located outside the European Economic Area. Where that is the case, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.
We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Altix, our customers, or others.
5. How long we keep it
- Account data, and the Subscriber, notification and preference data processed on your behalf, are kept for as long as your account is active. NotifyBell does not currently age out old notifications automatically — if you need a fixed retention window for notification content or Subscriber records, apply it from your own backend (for example by not re-publishing to a Subscriber you consider stale, or by removing an app you no longer use) until an automatic retention setting ships.
- If you delete your account, every app, Subscriber, notification, preference and API key it holds, and every team member’s access, are removed immediately and permanently — see “Deleting your account”.
- Invoices already issued remain in our invoicing system independently of your account, for as long as Cyprus tax and accounting law requires us to keep financial records (currently up to seven years).
- Security audit log entries are retained after an account is deleted, because the point of a security log is to survive the event it may need to explain; entries are kept for as long as needed for security, fraud-prevention, and legal purposes.
- Server and request logs are kept briefly (typically a few weeks) and then deleted or anonymised.
6. Deleting your account
Account owners can permanently delete their account from Settings at any time. Doing so:
- Cancels any active subscription immediately — you are not billed again, and lose access right away rather than at the end of the billing period.
- Permanently deletes every app on the account, every Subscriber, notification and preference it holds, and every API key issued to it.
- Removes every team member’s access to the account immediately.
- Records that the deletion happened, in a log entry that is not deleted with the account (see above).
- Does not affect invoices already issued, which remain in our invoicing system under our legal retention obligations, independently of the deleted account.
This action cannot be undone. The dashboard asks you to type your account’s name to confirm before it proceeds. Because Subscriber data is yours to control, you may also stop sending us new Subscriber data at any time simply by stopping your own integration — you do not need to delete the whole account to do that.
7. Cookies
Our own website and dashboard use a single strictly necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies on our site. The embeddable widget does not set cookies on your users’ browsers; it authenticates with the short-lived subscriber token your backend issues, held in memory by the embed for the life of the page.
8. Your rights
If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Correct inaccurate data.
- Erase your data, including by deleting your account yourself as described above.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent, where processing relies on it (for example, optional product-update emails).
- Lodge a complaint with your local data protection authority — for Cyprus, the Office of the Commissioner for Personal Data Protection.
To exercise any of these rights, email privacy@altixcode.com. If your request concerns data about a Subscriber rather than your own NotifyBell account — for example, a request from one of your users to see or delete the data we hold about them on your behalf — we will direct it to you, the Customer, who is the controller for that data and the right party to handle it, unless you have instructed us otherwise. We will of course assist you in fulfilling that request, including by deleting a named Subscriber’s records on your instruction.
9. Security
Passwords are hashed with bcrypt and never stored in plain text. Invite, password-reset, email-verification and API-key credentials use single-use or revocable, cryptographically random tokens that are hashed (SHA-256) at rest — we hold no value that lets us, or anyone who reads our database, reconstruct your API key or a live reset link. Each app’s signing key is sealed at rest with AES-256-GCM and never reaches a browser. Traffic to the Service, the API, and the embed is encrypted in transit with TLS. Access to production infrastructure is restricted to the people who need it to operate the Service.
10. Children
The Service is intended for businesses and developers integrating it into their own products, and account registration is not directed at, or knowingly used to collect account data from, children under 16. Where your own application serves Subscribers who are children, you remain the controller responsible for the lawfulness of that processing, including any parental-consent obligations that apply to you.
11. Changes to this policy
If we make a material change to this policy, we will notify account owners by email and update the effective date above before the change takes effect.
12. Contact
Altix Code Ltd (Cyprus). For any question about this policy or your data, email privacy@altixcode.com.