Privacy Policy
DMARCLoop is committed to providing quality services to you, and this policy outlines our ongoing obligations to you in respect of how we manage your Personal Information.
We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The APPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information. A copy of the Australian Privacy Principles may be obtained from the website of the Office of the Australian Information Commissioner at oaic.gov.au.
1. Who we are
DMARCLoop is a trading name of Visolute Pty Ltd, an Australian company registered in Brisbane, Queensland, Australia. In this policy, "DMARCLoop", "we", "us" and "our" mean Visolute Pty Ltd trading as DMARCLoop.
DMARCLoop is a DMARC monitoring and reporting product, plus a set of free DNS and DMARC tools. This policy covers everything at dmarcloop.com and the services we provide through it. Privacy questions, access and correction requests, and complaints all go to contact at dmarcloop.com.
2. What is Personal Information and why do we collect it?
Personal Information is information or an opinion that identifies an individual. Examples of Personal Information we collect include names, email addresses, billing addresses and payment details. We collect it for the primary purpose of providing our services to you, answering your enquiries, billing you for services you order, and keeping the service secure and available. We may also use it for secondary purposes closely related to that primary purpose, in circumstances where you would reasonably expect such use.
We collect Personal Information through our website at dmarcloop.com, by email, through our contact form, and through our payment processor when you order a paid service. We do not buy contact lists or collect Personal Information from data brokers. Where we collect it, we explain why at the point of collection wherever that is practicable. The specifics are below.
Queries you run through the free tools
When you use the Domain Scan, Domain Checker, DMARC Inspector, SPF Check, DKIM Inspector, DKIM Validator or DMARC Record Wizard, we receive the domain name (and, for DKIM, the selector) you asked about. We log that query string with a timestamp so we can rate-limit abuse and cache results, and we record the same domain, which tool checked it and how the check came out in our analytics (section 2, "Analytics", below) so we can see which kinds of domains the tools are used on. Where you have accepted the analytics cookie, that record is joined to your visitor identifier; otherwise it stands alone. The tools need no account and no sign-in.
Domain names are usually about organisations rather than people, but a lookup on a personal domain can still identify someone — so we treat these logs as Personal Information and apply the retention limits in section 11.
Domain scan reports you ask us to email
The domain scan works without any details from you. If you ask for the full report as a PDF, we collect your email address and the domain you scanned. We use them to generate and email you that report, to notify ourselves that you asked for it (so a person can answer questions about it), and to send you at most one follow-up email a few days later asking whether you need a hand. We do not add you to a mailing list. The report itself is kept on our servers for a short time (see section 11) so the download link in the email keeps working, then deleted.
Files you put through the XML-to-human Converter
The XML-to-human Converter runs entirely in your browser. Aggregate report files you open with it are parsed locally on your own device and are never uploaded, transmitted to us, or stored by us — there is no server involved in that tool at all.
Messages you send us
The contact form collects your name, email address, the topic you pick, and your message. We store that enquiry and email it to ourselves so we can read and reply to it. We use it to answer you and to keep a record of the conversation — not for marketing, unless you separately ask to hear from us. If you ever do join a mailing list of ours, you can unsubscribe at any time by using the unsubscribe link or by writing to us at the address in section 17.
Your account, if you create one
Signing in to the DMARCLoop service means creating an account. We collect your name, email address and the credentials you set, and we keep a record of sign-in activity — timestamps, and where you have enabled multi-factor authentication, the fact that it was used. Account sign-in is handled for us by Kinde, described in section 8; passwords are held by Kinde and are not stored by us.
Billing information, if you order a paid service
If you subscribe to or order a paid DMARCLoop service, we collect the information needed to bill you and to meet our tax and accounting obligations: your name, billing contact details and billing address, your business name and any tax registration details (such as an ABN), the plan and domains you are billed for, and a record of invoices, payments, refunds and chargebacks.
We do not collect, see or store full card numbers. Card details are entered directly with our payment processor, Stripe — see section 7. What comes back to us is a payment token plus non-sensitive details such as the card brand, expiry month and last four digits, which we use to identify the payment method for reconciliation and support.
Technical and security logs
Our content delivery network and web application firewall record standard request data — IP address, user agent, the URL requested, and a timestamp — for security, abuse prevention and rate limiting. Our application logs are deliberately built not to record client IP addresses; the IP stays in the edge access logs, where it is needed for those purposes and nothing else.
Analytics
We measure how the site and the free tools are used with
PostHog, a product-analytics service. Its script
and the data it sends travel through our own domain
(dmarcloop.com/ingest) to PostHog's servers in the
United States. It records page views, referring URLs, an approximate
location derived from your IP address, basic device and browser
information, and page-load performance.
We also record a small number of named events so we can see which parts of the site are actually used: that a tool was run and what severity the result was, that a generated record was copied, that an aggregate report was opened in the converter, that the contact form was submitted, which call-to-action link was clicked, and your cookie choice. What you type into a tool is never sent from your browser — not the DKIM key you paste, not the name or contents of a report file you open, and not your name, email address or message. Query strings are stripped from every page address before it is reported, so a shared result link does not carry the domain in it into analytics either. Separately, our tools service records the domain a check was run on, as described under "Queries you run through the free tools" above.
Whether PostHog sets a cookie depends on where you are — see section 6. Without the cookie it counts you using a daily-rotating hash of your IP address and browser that cannot be reversed to you and does not persist between days.
There is no Google Analytics, no advertising network, no social widget and no cross-site tracking anywhere on this site. We do not sell or share analytics data. PostHog processes it on our behalf and under our instructions; its own privacy policy is at posthog.com/privacy.
3. Sensitive Information
Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
We do not seek or require sensitive information to provide any part of DMARCLoop, and we ask that you do not include it in contact form messages or support correspondence. If we do come to hold sensitive information, it will be used by us only:
- For the primary purpose for which it was obtained;
- For a secondary purpose that is directly related to the primary purpose;
- With your consent; or where required or authorised by law.
4. Third Parties
Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties — for example, billing and payment method details passed back to us by Stripe when you pay for a service, or your details supplied by a colleague who arranges a service on your organisation's behalf. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.
This site links to external websites, including the RFC and standards documents referenced throughout our FAQ and tools. We do not guarantee the content, links or privacy practices of any third party site, even where we have linked to it.
5. How we use your information
- To run the free tools and return results to you.
- To provide, support and administer any paid service you order, including sending service and billing notices.
- To reply to enquiries you send us.
- To take payment, issue invoices, and keep financial records.
- To keep the service available and secure — rate limiting, blocking abuse, investigating faults.
- To understand aggregate usage so we can improve the tools and the documentation.
- To meet legal, tax and regulatory obligations.
We do not sell Personal Information, and we do not disclose it to third parties for their own marketing.
6. Cookies
This site sets at most two cookies, both first-party, both on
.dmarcloop.com so they also apply to the DMARCLoop app:
-
The analytics cookie (its name begins with
ph_) — set by PostHog. It holds a random visitor identifier so we can tell a returning visitor from a new one and, if you go on to create an account, connect what you did on this site to it. It lasts one year. -
Your cookie choice (
dl_consent) — remembers whether you accepted or declined the analytics cookie, for six months, so we do not ask again.
If you are in the European Economic Area, the United Kingdom
or Switzerland, or if we cannot tell where you are, the
analytics cookie is not set until you accept it in the banner. Declining
keeps the site fully usable: the analytics then works without a
cookie, counting you only as an anonymous, daily-rotating visitor.
You can change your mind by clearing the dl_consent
cookie, after which the banner appears again.
Everywhere else the analytics cookie is set from your first page view, on the basis described here. If your browser sends a Global Privacy Control signal we treat it as declining, wherever you are.
We set no advertising cookies and no third-party cookies. The free tools, the FAQ and the contact form all work normally whatever you choose.
7. Payments and Stripe
We use Stripe to process payments. When you enter card or other payment details to order a service, those details go directly to Stripe over an encrypted connection — they are not submitted to, routed through, or retained by DMARCLoop's servers.
Stripe handles that information as an independent controller of it in its own right, so your payment information is also subject to Stripe's privacy policy, which you can read at stripe.com/privacy. Among other things, Stripe uses payment and device data for fraud detection and to meet its own legal and regulatory obligations, and it may process and store that data outside Australia — including in the United States and the European Union. If you have questions about what Stripe does with your data specifically, that policy is the authoritative source, not this one.
Separately from Stripe, we keep our own billing and transaction records (invoices, amounts, dates, plan) because Australian tax and corporations law requires us to.
8. Authentication and infrastructure providers
Two other providers handle Personal Information on our behalf, in addition to the hosting and payment providers already described.
Kinde — authentication
We use Kinde to run sign-up, sign-in and session management for the DMARCLoop service. When you create an account or sign in, your name, email address, credentials and sign-in activity are processed and stored by Kinde on our behalf. Passwords are held by Kinde, hashed — we never receive or store your password, and neither we nor Kinde can read it back. Kinde also processes technical data about the sign-in attempt itself, such as IP address, device and browser, in order to detect suspicious sign-ins. Kinde's own privacy policy is at kinde.com/privacy-policy.
Hivelocity — backend compute and processing
We use Hivelocity for some of our backend compute and data processing — the server capacity behind parts of the DMARCLoop service, including aggregate report processing. Personal Information handled by those workloads is stored and processed on servers Hivelocity provides to us. Hivelocity supplies and maintains the underlying infrastructure and data centre; it does not use your information for its own purposes.
9. Disclosure of Personal Information
Your Personal Information may be disclosed in a number of circumstances, including the following:
- To the service providers we need to run DMARCLoop, and only as far as they need it — Amazon Web Services (hosting, storage, logging and outbound email delivery), Stripe (payment processing and fraud prevention, as described in section 7), Kinde (authentication) and Hivelocity (backend compute and processing), both as described in section 8, Cloudflare (the network this site is served through) and PostHog (analytics, section 2);
- To third parties where you consent to the use or disclosure;
- Where required or authorised by law.
PostHog (product analytics, section 2) and Cloudflare (serving this site, and the Turnstile anti-spam check on the contact form) also process data on our behalf and appear in the same list.
We may also disclose information where it is needed to establish or defend a legal claim, or to prevent a serious threat to someone's life, health or safety. If our business or assets are ever sold or restructured, information held about customers may transfer to the acquirer, who would remain bound by this policy until they notify you otherwise.
10. Overseas storage
Our site, API, databases and logs run on Amazon Web Services
infrastructure in the United States (the us-east-1
region). Our Hivelocity servers are located in Hivelocity's data
centres, which are principally in the United States. Analytics data
is held by PostHog in the United States. Stripe and Kinde each
process data in the United States and elsewhere. This means
Personal Information we hold is stored and processed overseas, and by
using DMARCLoop you consent to that disclosure to overseas recipients
for the purposes set out in this policy.
11. Retention, destruction and de-identification
When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify it. In practice:
- Cached DNS results — expire automatically, typically within minutes to hours.
- Tool query and application logs — retained for up to 12 months, then deleted automatically.
- Emailed domain scan reports (the PDF files) — deleted automatically 30 days after they are generated. The record that you requested one (your email address and the domain) is kept so we can answer follow-up questions, and deleted on request.
- Edge access and security logs — retained for one month.
- Analytics events — retained by PostHog for as long as we keep the account; the anonymous daily identifier used without a cookie cannot be linked back across days. Ask us and we will delete the events attached to your visitor identifier or account.
- Billing and transaction records — kept for a minimum of seven years, as Australian tax and corporations law requires.
12. Security of Personal Information
Your Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorised access, modification or disclosure. All traffic to this site is served over HTTPS. The site enforces a strict Content Security Policy; the only third-party script it loads is Cloudflare Turnstile, on the contact and scan pages. Access to production systems is restricted and least-privilege, and payment card data never reaches our infrastructure at all.
No system is perfectly secure, but if we ever have a data breach likely to cause serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
13. Access to your Personal Information
You may access the Personal Information we hold about you and update and/or correct it, subject to certain exceptions. You can also ask us to delete it where we are not required to keep it. If you wish to access your Personal Information, please contact us in writing at contact at dmarcloop.com. We will respond within a reasonable period — normally 30 days.
We will not charge any fee for your access request, but may charge an administrative fee for providing a copy of your Personal Information. In order to protect your Personal Information we may require identification from you before releasing the requested information.
If you are in the United Kingdom or the European Economic Area, you may also have rights under the UK GDPR or GDPR — including access, rectification, erasure, restriction, portability and objection. The same address handles those requests.
14. Maintaining the quality of your Personal Information
It is important to us that your Personal Information is up to date. We will take reasonable steps to make sure that your Personal Information is accurate, complete and up-to-date. If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.
15. Children
DMARCLoop is a tool for email and DNS administrators. It is not directed at children, and we do not knowingly collect Personal Information from anyone under 16.
16. Policy updates
This Policy may change from time to time and is available on our website. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle Personal Information, we will tell account holders by email before it takes effect.
17. Privacy policy complaints and enquiries
If you have any queries or complaints about our Privacy Policy, please contact us at:
Visolute Pty Ltd, trading as DMARCLoop
Brisbane, Queensland, Australia
contact at dmarcloop.com
Tell us first so we can try to put it right. If you are still not satisfied with how we have handled your Personal Information or your request, you can complain to the Office of the Australian Information Commissioner — oaic.gov.au.