Privacy Policy
What we collect, what we do not, and who else touches it.
Last updated
The short version
We collect what we need to run your account and nothing else. We do not sell personal data, we do not run advertising, and we do not track you across other websites.
The filings PAGAlert indexes are public records published by California's Department of Industrial Relations. We did not gather them from individuals and we do not enrich them with anything from elsewhere.
What we collect from you
Only these:
- Your email address and password, held by our authentication provider — we never see the password itself
- Your name and company name, if you choose to give them
- The entities you ask us to monitor, and the notes, tags and statuses you write against cases
- Your billing details, held by Stripe — card numbers never reach our servers
- Ordinary server logs: IP address, timestamp and the page or endpoint requested
- If you send an Enterprise enquiry: your name, work email, company and message, kept to reply to you and as a record of the enquiry
Your notes are yours
Notes, tags and case statuses are private to your account. They are not shown on the public directory, not shared with other customers, and not used to improve anything outside your own account. Database-level access rules enforce this, not just application code.
We can technically read them, because we operate the database. We do not access them except to support you, to comply with the law, or to protect the service.
If your firm needs a data processing agreement covering the notes and other data you enter, email support@pagalert.com and we will provide ours.
Analytics and monitoring
We use privacy-friendly page analytics that set no cookies and build no cross-site profile. We do not use session recording anywhere in the product; the logged-in pages show case names and private notes, and recording them would be a compliance problem dressed up as a debugging tool.
We use an error-monitoring service that receives stack traces when something breaks. It is configured not to send request bodies, cookies or session tokens.
Who else processes your data
We keep this list short deliberately, and it is complete:
- Supabase — database and authentication
- Fly.io — the API and the collection worker
- Vercel — the website and web application
- Stripe — payments and subscription billing
- Resend — transactional and alert email
- Sentry — error monitoring
- Cloudflare — DNS, the email forwarding for our support address, and Turnstile, the bot check on sign-up, sign-in and password reset
Email you receive
Alert email carries a one-click unsubscribe link, and we honour it immediately. You can also change or switch off alerts per monitored entity from your settings.
Account email — password resets, billing notices, and notice of a material change to these terms — is not something you can unsubscribe from while the account is open, because it is how we reach you about the account itself.
If mail to your address hard-bounces or you mark us as spam, we stop sending our email to it — including alerts — and record that we have. The app shows a notice on every page while that is in force. Contact support to undo it.
How long we keep things
Account data, including your notes and tags, is kept while the account is open and deleted within 30 days of you deleting the account.
Public filing records are kept indefinitely — they are public records, and the case timeline is only useful because it is long.
Server logs are kept for 30 days. Delivery records for alerts are kept for 12 months so we can answer questions about what was or was not sent.
Database backups, and our providers' logs (email delivery and error monitoring, for example), can hold a copy a little longer than these periods, until they expire on their own schedules.
Your rights, and how to use them
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, by emailing support@pagalert.com. We will respond within 30 days.
California residents have specific rights under the CCPA, including the right to know what we collect and the right to delete it. We do not sell personal information, so there is nothing to opt out of on that front.
PAGAlert is offered only to businesses based in the United States and is not directed at people in the European Union or the United Kingdom, so this policy is written for US law — California's in particular — rather than the GDPR.
If a filing on the public directory names you personally — which happens to sole proprietors, because the employer name in a PAGA filing is sometimes a person's own name — write to us and we will consider removing that page from the public site. See our collection practices page for how that works.
Security
Data is encrypted in transit and at rest. Access between customer accounts is separated at the database level rather than only in application code. API keys and webhook secrets are stored so that they cannot be read back after creation.
If you believe you have found a security problem, email support@pagalert.com before disclosing it publicly, and we will work with you.