Privacy Policy
DMARCLoop is committed to providing quality services to you, and this policy outlines our ongoing obligations to you in respect of how we manage your Personal Information.
As a small business we are not currently required to comply with the Privacy Act 1988 (Cth), but we choose to follow the Australian Privacy Principles (APPs) it contains anyway, because they describe how personal information ought to be handled. The APPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information. A copy of the Australian Privacy Principles may be obtained from the website of the Office of the Australian Information Commissioner at oaic.gov.au.
1. Who we are
DMARCLoop is a trading name of Visolute Pty Ltd, an Australian company registered in Brisbane, Queensland, Australia. In this policy, "DMARCLoop", "we", "us" and "our" mean Visolute Pty Ltd trading as DMARCLoop.
DMARCLoop is a DMARC monitoring and reporting product, plus a set of free DNS and DMARC tools. This policy covers everything at dmarcloop.com and the services we provide through it. Privacy questions, access and correction requests, and complaints all go to contact at dmarcloop.com.
2. What is Personal Information and why do we collect it?
Personal Information is information or an opinion that identifies an individual. Examples of Personal Information we collect include names, email addresses, billing addresses and payment details. We collect it for the primary purpose of providing our services to you, answering your enquiries, billing you for services you order, and keeping the service secure and available. We may also use it for secondary purposes closely related to that primary purpose, in circumstances where you would reasonably expect such use.
We collect Personal Information through our website at dmarcloop.com, by email, through our contact form, and through our payment processor when you order a paid service. We do not buy contact lists or collect Personal Information from data brokers. Where we collect it, we explain why at the point of collection wherever that is practicable. The specifics are below.
Queries you run through the free tools
When you use the Domain Scan, Domain Checker, DMARC Inspector, SPF Check, DKIM Inspector, DKIM Validator or DMARC Record Wizard, we receive the domain name (and, for DKIM, the selector) you asked about. We log that query string with a timestamp so we can rate-limit abuse and cache results, and we record the same domain, which tool checked it and how the check came out in our analytics (section 2, "Analytics", below) so we can see which kinds of domains the tools are used on. Where you have accepted the analytics cookie, that record is joined to your visitor identifier; otherwise it stands alone. The tools need no account and no sign-in.
Domain names are usually about organisations rather than people, but a lookup on a personal domain can still identify someone — so we treat these logs as Personal Information and apply the retention limits in section 11.
Domain scan reports you ask us to email
The domain scan works without any details from you. If you ask for the full report as a PDF, we collect your email address and the domain you scanned. We use them to generate and email you that report, to notify ourselves that you asked for it (so a person can answer questions about it), and to send you at most one follow-up email a few days later asking whether you need a hand. We do not add you to a mailing list. The report itself is kept on our servers for a short time (see section 11) so the download link in the email keeps working, then deleted.
Files you put through the XML-to-human Converter
The XML-to-human Converter runs entirely in your browser. Aggregate report files you open with it are parsed locally on your own device and are never uploaded, transmitted to us, or stored by us — there is no server involved in that tool at all.
Messages you send us
The contact form collects your name, email address, the topic you pick, and your message. We store that enquiry and email it to ourselves so we can read and reply to it. We use it to answer you and to keep a record of the conversation — not for marketing, unless you separately ask to hear from us. If you ever do join a mailing list of ours, you can unsubscribe at any time by using the unsubscribe link or by writing to us at the address in section 17.
Your account, if you create one
Signing in to the DMARCLoop service means creating an account. We collect your name, email address, the password you set and, if you choose to give it, a phone number. Passwords are stored only as a one-way hash — we cannot read yours back. We keep a record of sign-in activity (timestamps, the IP address and browser used, and whether two-factor authentication was used) to keep your account secure. If you sign in with a third-party account such as Google or Microsoft, or through your organisation's single sign-on, that provider tells us your name and email address; we do not receive your password for it.
Billing information, if you order a paid service
If you subscribe to or order a paid DMARCLoop service, we collect the information needed to bill you and to meet our tax and accounting obligations: your name, billing contact details and billing address, your business name and any tax registration details (such as an ABN), the plan and domains you are billed for, and a record of invoices, payments, refunds and chargebacks.
We do not collect, see or store full card numbers. Card details are entered directly with our payment processor, Stripe — see section 7. What comes back to us is a payment token plus non-sensitive details such as the card brand, expiry month and last four digits, which we use to identify the payment method for reconciliation and support.
Technical and security logs
Our content delivery network and web application firewall record standard request data — IP address, user agent, the URL requested, and a timestamp — for security, abuse prevention and rate limiting. Our application logs are deliberately built not to record client IP addresses; the IP stays in the edge access logs, where it is needed for those purposes and nothing else.
Analytics
We measure how the site and the free tools are used with a product-analytics service. Its
script and the data it sends travel through our own domain (dmarcloop.com/ingest)
to our analytics provider's servers. It records page views, referring URLs, an approximate
location derived from your IP address, basic device and browser information, and page-load
performance.
We also record a small number of named events so we can see which parts of the site are actually used: that a tool was run and what severity the result was, that a generated record was copied, that an aggregate report was opened in the converter, that the contact form was submitted, which call-to-action link was clicked, and your cookie choice. What you type into a tool is never sent from your browser — not the DKIM key you paste, not the name or contents of a report file you open, and not your name, email address or message. Query strings are stripped from every page address before it is reported, so a shared result link does not carry the domain in it into analytics either. Separately, our tools service records the domain a check was run on, as described under "Queries you run through the free tools" above.
Whether the analytics sets a cookie depends on where you are — see section 6. Without the cookie it counts you using a daily-rotating hash of your IP address and browser that cannot be reversed to you and does not persist between days.
There is no Google Analytics, no advertising network, no social widget and no cross-site tracking anywhere on this site. We do not sell or share analytics data. Our analytics provider processes it on our behalf and under our instructions only.
3. Sensitive Information
Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
We do not seek or require sensitive information to provide any part of DMARCLoop, and we ask that you do not include it in contact form messages or support correspondence. If we do come to hold sensitive information, it will be used by us only:
- For the primary purpose for which it was obtained;
- For a secondary purpose that is directly related to the primary purpose;
- With your consent; or where required or authorised by law.
4. Third Parties
Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties — for example, billing and payment method details passed back to us by Stripe when you pay for a service, or your details supplied by a colleague who arranges a service on your organisation's behalf. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.
This site links to external websites, including the RFC and standards documents referenced throughout our FAQ and tools. We do not guarantee the content, links or privacy practices of any third party site, even where we have linked to it.
5. How we use your information
- To run the free tools and return results to you.
- To provide, support and administer any paid service you order, including sending service and billing notices.
- To reply to enquiries you send us.
- To take payment, issue invoices, and keep financial records.
- To keep the service available and secure — rate limiting, blocking abuse, investigating faults.
- To understand aggregate usage so we can improve the tools and the documentation.
- To meet legal, tax and regulatory obligations.
We do not sell Personal Information, and we do not disclose it to third parties for their own marketing.
6. Cookies
This site sets at most two cookies, both first-party, both on
.dmarcloop.com so they also apply to the DMARCLoop app:
-
The analytics cookie (its name begins with
ph_) — set by our analytics script. It holds a random visitor identifier so we can tell a returning visitor from a new one and, if you go on to create an account, connect what you did on this site to it. It lasts one year. -
Your cookie choice (
dl_consent) — remembers whether you accepted or declined the analytics cookie, for six months, so we do not ask again.
If you are in the European Economic Area, the United Kingdom or Switzerland,
or if we cannot tell where you are, the analytics cookie is not set until you accept it in the
banner. Declining keeps the site fully usable: the analytics then works without a cookie,
counting you only as an anonymous, daily-rotating visitor. You can change your mind by
clearing the dl_consent
cookie, after which the banner appears again.
Everywhere else the analytics cookie is set from your first page view, on the basis described here. If your browser sends a Global Privacy Control signal we treat it as declining, wherever you are.
We set no advertising cookies and no third-party cookies. The free tools, the FAQ and the contact form all work normally whatever you choose.
7. Payments and Stripe
We use Stripe to process payments. When you enter card or other payment details to order a service, those details go directly to Stripe over an encrypted connection — they are not submitted to, routed through, or retained by DMARCLoop's servers.
Stripe handles that information as an independent controller of it in its own right, so your payment information is also subject to Stripe's privacy policy, which you can read at stripe.com/privacy. Among other things, Stripe uses payment and device data for fraud detection and to meet its own legal and regulatory obligations, and it may process and store that data outside Australia — including in the United States and the European Union. If you have questions about what Stripe does with your data specifically, that policy is the authoritative source, not this one.
Separately from Stripe, we keep our own billing and transaction records (invoices, amounts, dates, plan) because Australian tax and corporations law requires us to.
8. Service providers
Like most online services, we rely on other companies to run DMARCLoop. Besides Stripe (section 7), the kinds of provider that handle Personal Information on our behalf are:
- Hosting and infrastructure — the servers, databases and storage the site, the tools and the DMARCLoop service run on, including aggregate report processing;
- Content delivery and security — the network this site is served through, which also provides the web application firewall and the anti-spam check on our forms;
- Email delivery — sending account, report and billing emails, and receiving the DMARC reports you direct to us;
- Product analytics — as described in section 2.
Each of them processes Personal Information only on our behalf and under our instructions, only as far as the service they provide needs it, and not for their own purposes. Our providers change from time to time, so rather than list them here we will tell you who they currently are, and where they process data, if you ask us at contact at dmarcloop.com.
9. Disclosure of Personal Information
Your Personal Information may be disclosed in a number of circumstances, including the following:
- To the service providers we need to run DMARCLoop (section 8) and to Stripe (section 7), and only as far as they need it;
- To third parties where you consent to the use or disclosure;
- Where required or authorised by law.
We may also disclose information where it is needed to establish or defend a legal claim, or to prevent a serious threat to someone's life, health or safety. If our business or assets are ever sold or restructured, information held about customers may transfer to the acquirer, who would remain bound by this policy until they notify you otherwise.
10. Overseas storage
Most of our service providers are based outside Australia, so Personal Information we hold is stored and processed overseas — principally in the United States, and for some providers in other countries, including the European Union. We choose providers that protect Personal Information to a standard comparable to this policy. By using DMARCLoop you consent to that disclosure to overseas recipients for the purposes set out in this policy. Ask us and we will tell you which countries apply to your information.
11. Retention, destruction and de-identification
When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify it. In practice:
- Cached DNS results — expire automatically, typically within minutes to hours.
- Tool query and application logs — retained for up to 12 months, then deleted automatically.
- Emailed domain scan reports (the PDF files) — deleted automatically 30 days after they are generated. The record that you requested one (your email address and the domain) is kept so we can answer follow-up questions, and deleted on request.
- Edge access and security logs — retained for one month.
- Analytics events — retained by our analytics provider for as long as we use it; the anonymous daily identifier used without a cookie cannot be linked back across days. Ask us and we will delete the events attached to your visitor identifier or account.
- Billing and transaction records — kept for a minimum of seven years, as Australian tax and corporations law requires.
12. Security of Personal Information
Your Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorised access, modification or disclosure. All traffic to this site is served over HTTPS. The site enforces a strict Content Security Policy; the only third-party script it loads is an anti-spam check, on the contact and scan pages. Access to production systems is restricted and least-privilege, and payment card data never reaches our infrastructure at all.
No system is perfectly secure, but if we ever have a data breach likely to cause serious harm, we will tell the people affected promptly — what happened, what information was involved and what we are doing about it — following the approach of the Notifiable Data Breaches scheme.
13. Access to your Personal Information
You may access the Personal Information we hold about you and update and/or correct it, subject to certain exceptions. You can also ask us to delete it where we are not required to keep it. If you wish to access your Personal Information, please contact us in writing at contact at dmarcloop.com. We will respond within a reasonable period — normally 30 days.
We will not charge any fee for your access request, but may charge an administrative fee for providing a copy of your Personal Information. In order to protect your Personal Information we may require identification from you before releasing the requested information.
If you are in the United Kingdom or the European Economic Area, you may also have rights under the UK GDPR or GDPR — including access, rectification, erasure, restriction, portability and objection. The same address handles those requests.
14. Maintaining the quality of your Personal Information
It is important to us that your Personal Information is up to date. We will take reasonable steps to make sure that your Personal Information is accurate, complete and up-to-date. If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.
15. Children
DMARCLoop is a tool for email and DNS administrators. It is not directed at children, and we do not knowingly collect Personal Information from anyone under 16.
16. Policy updates
This Policy may change from time to time and is available on our website. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle Personal Information, we will tell account holders by email before it takes effect.
17. Privacy policy complaints and enquiries
If you have any queries or complaints about our Privacy Policy, please contact us at:
Visolute Pty Ltd, trading as DMARCLoop
Brisbane, Queensland, Australia
contact at dmarcloop.com
We will acknowledge your complaint and aim to resolve it within 30 days. If you are in the United Kingdom or the European Economic Area and are still not satisfied, you can also complain to your local data protection authority.