Privacy Policy
Last updated: 13 July 2026
This policy describes our current practices for the Nudgely marketing website (nudgelyapp.com) and the Nudgely application (app.nudgelyapp.com). It is not legal advice. If you need a formal DPA or jurisdiction-specific addendum, contact us.
1. Who we are
Nudgely ("we", "our" or "us") provides recurring task reminder software for teams. We operate:
- The marketing site at nudgelyapp.com
- The application at app.nudgelyapp.com
Privacy questions: mark@nudgelyapp.com.
2. Scope and roles
This policy covers personal information we process as operator of Nudgely.
- Account holders and marketing visitors: we determine how we collect and use your information to run the website, accounts, billing and support.
- Recipient data inside a customer workspace: when a customer uploads recipient names and emails, schedules nudges, or receives completion comments and attachments, that customer decides what to send and why. We process that information to provide the service to the customer. Customers are responsible for having a lawful basis to email recipients and to use Nudgely with their content.
3. Information we collect
3.1 Account and company information
When you register or manage a workspace we may collect:
- Name, email address and password (hashed)
- Email verification and password-reset status
- Company profile details (name, industry, size, website, contact email, timezone, logo, optional brand colour)
- Team membership, roles and invite details
- Theme and similar product preferences stored with your session
- Billing-related identifiers from Stripe (customer and subscription IDs, plan, status). Card details are handled by Stripe and are not stored in our application database
3.2 Nudge and task information
- Nudge content (name, description, schedule, timezone, reminder policy, approval settings, pause and skip dates)
- Recipient names and email addresses supplied by the customer
- Occurrence and send metadata (scheduled time, send attempts, overdue and reminder state)
- Completion comments, optional file attachments, approval status and related timestamps
- Snooze choices and expiry for completion links
- Per-company recipient unsubscribe preferences
3.3 Information from recipients (no account required)
Recipients who open a completion or unsubscribe link may provide or generate:
- Optional comments and uploaded evidence files
- Snooze selections
- Unsubscribe confirmations for a specific company
- Technical data such as IP address and user agent associated with completion or related activity
3.4 Marketing site and contact information
- Contact form submissions (name, email, company, message)
- Cookie and analytics data described in section 8 (only where you consent to analytics)
3.5 Automatically collected technical information
- Device, browser and operating system details
- IP address and approximate location derived from IP
- App usage events needed to operate dashboards, notifications and security controls
- Error and diagnostic data (for example via Sentry)
- Email delivery events such as bounces and complaints used for suppression
- Audit and admin activity logs where our platform operators investigate issues (including limited impersonation by site admins, which is recorded)
4. How we use information
- Create and secure accounts, verify email and reset passwords
- Provide the workspace: nudges, teams, templates, analytics, exports, branding and settings
- Send transactional emails (verification, invites, password reset, nudge reminders with calendar attachments, completion notices, admin digests, billing notices)
- Process subscriptions, plan changes, invoices and payment failures through Stripe
- Enforce plan limits, history retention and team freeze behaviour
- Show in-app notifications (for example completions, invites and payment issues)
- Honour per-company unsubscribe preferences and skip suppressed addresses
- Respond to support and contact requests
- Monitor reliability and security, prevent abuse and debug faults
- Analyse marketing-site usage in aggregate when analytics consent is given
- Comply with law and enforce our terms
We do not sell personal information.
5. Emails and recipient choices
Nudgely sends service emails that are required to operate the product. These are not marketing newsletters. Examples include account verification, invites, nudge reminders, completion notifications, company admin digests (if enabled) and billing notices.
Nudge reminder emails include a completion link, an ICS calendar attachment where applicable, and per-company unsubscribe options (including List-Unsubscribe where supported). Unsubscribing stops reminders from that company's workspace; it does not remove an account holder's login or billing emails.
If an address hard-bounces or generates a complaint, we may suppress further sends to protect deliverability.
6. Service providers
We use processors to run Nudgely. They only receive what is needed for their role:
- Vercel for hosting the marketing site and application
- Supabase / PostgreSQL for application database hosting (including Prisma Accelerate where used) and object storage for company logos and completion attachments
- Stripe for subscription billing and the customer portal
- Resend for transactional email delivery and bounce or complaint webhooks
- Sentry for application error monitoring
- Google Analytics, Microsoft Clarity, Umami and Vercel Analytics / Speed Insights for marketing-site analytics when you accept analytics cookies. The application also uses Umami and Microsoft Clarity to understand product usage
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition or asset sale (with appropriate protections).
7. Data security
We use technical and organisational measures appropriate to a multi-tenant SaaS product, including:
- Encrypted transport (HTTPS)
- Hashed passwords and session-based authentication
- Role-based access inside companies and teams
- Tokenized completion and unsubscribe links for recipients
- Separation of billing card data with Stripe
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
8. Cookies and analytics
Essential cookies and storage are needed for the site and app to function (for example authentication sessions, security, theme preference and remembering your cookie choice). These run without an analytics opt-in.
Analytics cookies and similar technologies on the marketing site load only if you choose Accept analytics on the cookie banner. They currently include:
- Google Analytics
- Microsoft Clarity (including session insights)
- Umami
- Vercel Analytics and Speed Insights
You can change your mind later using Cookie preferences in the site footer. Declining analytics does not stop essential browsing. Browser settings can also block cookies, which may affect some features.
9. Retention
We keep personal information while your account is active and as needed to provide the service, resolve disputes and meet legal or accounting obligations.
- Nudge history retention in-product depends on your plan (for example Free retains a limited window; higher plans retain longer or indefinitely). Older instances may be deleted automatically when the retention window ends.
- Billing records may be retained longer where tax or financial rules require it.
- Backups and logs are kept for a limited operational period then overwritten or deleted.
- Contact form messages are kept as needed to respond and improve support.
When information is no longer required, we delete or anonymise it where practicable.
10. International transfers
Nudgely and its providers may process information in Australia and other countries (for example where hosting, email, billing or analytics infrastructure is located). If you access Nudgely from another country, your information may be transferred across borders to operate the service.
11. Your rights and choices
Depending on where you live, you may have rights to access, correct, update, delete or restrict certain personal information, or to complain to a regulator. For Australian users, you may make a request under the Australian Privacy Principles.
You can also:
- Update profile and company details in the app settings where available
- Manage cookie analytics preferences on the marketing site
- Use per-company unsubscribe links in nudge emails if you are a recipient
- Ask us to delete an account (subject to billing and legal retention needs)
To exercise privacy rights, email mark@nudgelyapp.com. We may need to verify your identity before responding. If you are a recipient and your data was uploaded by a customer organisation, we may redirect your request to that organisation where they control the relevant records.
12. Children's privacy
Nudgely is intended for business and workplace use. It is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps.
13. Third-party links and content
The site or app may link to third-party sites (for example Stripe's customer portal or documentation). Their privacy practices are governed by their own policies. Completion pages may display a customer's logo and brand colour on eligible plans; that branding is controlled by the customer.
14. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date will change when we post revisions. Material changes may also be communicated in the product or by email where appropriate. Continued use after an update means you acknowledge the revised policy.
15. Contact
Nudgely
Privacy and support: mark@nudgelyapp.com
Marketing site: nudgelyapp.com
Application: app.nudgelyapp.com