NDNEWDAY
Back to NEWDAY

Legal

Privacy Policy

Effective Date: July 14, 2026 Last Updated: July 14, 2026
Terms Privacy Disclaimer Refund Policy Cookie Policy Cookie Settings

1. Scope and Operator

This Privacy Policy explains how NEWDAY collects, uses, stores, and shares information when you use the NEWDAY platform. You can contact us at info@newdayapp.net.

2. Information Users Provide

  • Email address, first name, and last name.
  • Password submitted during signup or password changes; NEWDAY stores only a secure password hash.
  • Email verification and password-reset information, including temporary codes and expiry details.
  • Support or contact messages submitted through the platform.
  • Dashboard notes saved locally in your browser, unless a future feature separately transmits them to NEWDAY.

3. Account and Subscription Information

NEWDAY stores account verification status, trial dates, subscription status and plan, Stripe customer and subscription identifiers, Stripe invoice/payment/refund identifiers, and related billing-state information. NEWDAY does not store complete payment-card numbers.

4. Information Collected Automatically

NEWDAY may process IP addresses for security and rate limiting, browser and request technical information available to infrastructure or logs, session activity, platform and API usage, and security or diagnostic logs. NEWDAY does not currently claim to collect precise geolocation or sensitive device fingerprinting data.

5. Browser Storage

For current platform compatibility, NEWDAY stores some values in your browser, including a legacy authentication token, email and name values for display, trial and subscription UI values, theme preference, temporary signup or reset email values, local dashboard notes, and sessionStorage notices.

If you use a shared device, you should log out and protect access to your browser profile.

6. Cookies

NEWDAY uses essential cookies such as newday_session for secure session authentication and newday_csrf for CSRF-token compatibility as the security model evolves. The CSRF token is not described here as fully enforced for every unsafe request. Optional analytics cookies or storage should be used only where consent or permission applies. See the Cookie Policy.

7. How Information Is Used

  • Create and manage accounts.
  • Verify email ownership and authenticate sessions.
  • Provide Simulator and Test Lab access.
  • Administer trials, subscriptions, cancellations, and refunds.
  • Protect security, prevent fraud, and apply rate limits.
  • Respond to support requests.
  • Improve service quality and analytics where consent or permission applies.
  • Comply with legal, accounting, tax, security, and dispute-resolution obligations.

8. Service Providers

NEWDAY may use Stripe for payments, AWS infrastructure and database hosting, Gmail/SMTP for email delivery, PostHog for analytics where enabled and consented, and Redis for internal caching and rate limiting. Redis is used as an internal technical component unless a separately hosted Redis provider is used.

9. Analytics

Cookie Settings provides three optional-tracking choices: Essential Only, Product Analytics, or Analytics with Product Session Replay. Essential cookies remain active for login, security, checkout, and saved preferences. You may accept Product Analytics while rejecting Session Replay, and rejecting optional tracking does not prevent use of NEWDAY. Product Analytics is restricted to approved NEWDAY Production domains and captures only six approved product events: password reset completed, forgot password started, login success, signup started, signup completed, and profile updated.

When Product Session Replay is separately accepted, eligible product-page sessions may be recorded using privacy masking for usability improvement and troubleshooting on /dashboard, /spy, and /indicator-lab. Landing, authentication, legal, billing, profile-form, query-string, hash, and other pages are excluded. Greetings, account details, dashboard notes, profile areas, inputs, Simulator positions and profit/loss values, and Indicator Lab configuration and results are masked or blocked. Email, names, user IDs, form contents, passwords, one-time verification codes, payment identifiers, console logs, canvas content, network timing, headers, request or response bodies, camera, microphone, audio, and clipboard contents are not intentionally recorded. Approved custom events do not intentionally include complete URLs, query strings, or response bodies. Autocapture, automatic pageviews and page-leave events, heatmaps, surveys, application feature flags, exception tracking, and web vitals remain disabled. Session recordings may be retained for up to 30 days. Anonymous technical identifiers may be used to deliver approved events and session replay. You may change either optional choice later through Cookie Settings.

10. Payments

Stripe handles payment-card details on hosted payment or billing pages. NEWDAY stores billing, subscription, payment, and refund identifiers and status information needed to provide access and handle billing issues.

11. Data Sharing

NEWDAY may share information with service providers, where required for legal or safety reasons, or as part of a business transfer. Based on current verified behavior, NEWDAY does not sell personal information and does not share it for unrelated third-party advertising.

12. Security

NEWDAY uses reasonable technical and organizational safeguards, including password hashing, HTTPS, session controls, and restricted infrastructure access. No online service can guarantee absolute security.

13. Retention

NEWDAY retains information while needed for account operation, service delivery, legal, security, accounting, dispute, or business purposes. Verification and reset codes expire. Sessions expire. Billing and refund records may be retained for legal, accounting, tax, or dispute purposes.

14. International Processing

NEWDAY and its providers may process information in Australia, the United States, or other provider locations. Where required, appropriate safeguards should apply, but this policy does not claim a specific transfer mechanism that has not been separately verified.

15. User Rights and Requests

You may request access, correction, or deletion of your personal information by contacting info@newdayapp.net. We may need to verify your identity. Deletion requests may be subject to legal, security, accounting, or dispute-related exceptions. Self-service account deletion is not currently promised.

16. Children

NEWDAY is intended for users aged 18 and over. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information to NEWDAY.

17. Cookies and Choices

See the Cookie Policy for cookies and browser storage. Browser controls may affect platform functionality. Optional analytics is controlled through the consent banner and Cookie Settings.

18. Changes

We may update this Privacy Policy by posting a revised version with updated effective and last-updated dates.

19. Contact

Privacy questions or requests can be sent to info@newdayapp.net.

NEWDAY Contact: info@newdayapp.net