1. Controller, Operator, And Contact
DWL Accounts is operated by Alpinix LLC. Privacy requests should be sent to privacy
2. Scope And Data Sources
This Privacy Policy applies to DWL Accounts account creation, sign-in, recovery, profile settings, passkeys, email preferences, security events, support, connected-app linkage, entitlement checks, purchases where enabled, billing support, and data-request workflows. Connected apps may publish separate privacy notices for product-specific content, healthcare-adjacent workflows, paid features, analytics, or regulated processing.
Information may come from you, your browser or device, authentication providers such as Google, connected apps, service providers, payment processors, tax processors, email providers, support messages, security logs, cookies, audit logs, and fraud-prevention workflows.
3. Data Categories, Purposes, Legal Bases, Retention, And Sharing
| Category | Examples | Purpose and legal basis | Retention | Shared with |
|---|---|---|---|---|
| Identifiers and account data | Email, name, profile photo, username, user ID, email verification status, account preferences | Create and manage accounts; perform the contract; legitimate interests; consent where required | While the account is active, then deleted or de-identified unless limited retention is needed | Connected apps when linked, hosting/database providers, support providers |
| Authentication and credential data | Password hashes, OAuth IDs, magic-link tokens, reset tokens, session IDs, and passkey status | Authenticate users, recover accounts, prevent abuse; contract, security interests, legal obligations | Tokens expire by design; credential and auth records remain while needed for account access and security | Authentication providers, database providers, hosting providers |
| Passkey and device security data | Credential IDs, public keys, counters, device type, transports, names, timestamps, sign-in signals | Provide passwordless sign-in and account security; contract and legitimate interests | Until deleted by the user, account deletion, or security cleanup, subject to audit and backup limits | Browser/device passkey providers, database and hosting providers |
| Connected-app and entitlement data | App slug, membership status, role, redirect URL, last seen time, permissions, entitlement or subscription status | Link accounts to supported products and enforce access; contract and legitimate interests | While linked or as needed for security, audit, billing, dispute, or legal records | Relevant connected app, hosting/database providers |
| Payment, billing, and commercial information | Processor customer ID, subscription ID, invoice ID, checkout status, plan, price, tax data, billing country/postal code, card brand/last four where provided, refund and dispute status | Process purchases, subscriptions, taxes, receipts, disputes, fraud checks, and accounting; contract, legal obligations, legitimate interests | As needed for the purchase relationship, tax/accounting duties, disputes, fraud prevention, legal obligations, and backup cycles | Payment processors, tax providers, accounting/support providers, connected apps for entitlement status |
| Device, network, session, and security data | IP address in infrastructure logs, app-side IP hashes where used, user agent, cookies, timestamps, audit events, rate-limit signals | Operate, secure, debug, prevent fraud, investigate abuse, and enforce terms; legitimate interests and legal obligations | Shorter operational periods where practical; security, audit, fraud, and legal logs may be retained longer | Hosting, database, DNS/security, email, and security providers |
| Support and request data | Messages, attachments, account identifiers, troubleshooting details, purchase support, legal requests, privacy requests | Respond to requests and resolve issues; contract, consent, legitimate interests, legal obligations | As long as needed for support history, disputes, security, audit, and legal obligations | Email provider, support inboxes, hosting/database providers, relevant connected app where needed |
| Cookies and preferences | Auth.js cookies, sign-out marker, required preference cookies, consent or opt-out records where implemented | Keep users signed in, protect sessions, remember required preferences; contract and security interests; consent where required | Session cookies or documented cookie duration; manual sign-out marker up to 90 days unless changed | Browser, hosting provider, authentication infrastructure |
| Sensitive or regulated information | Account credentials, security logs, limited payment metadata, support content that may include sensitive details if you provide them | Secure accounts, process requests, comply with law; security interests, contract, legal obligations, explicit consent where required | Only as needed for the stated purpose, then deleted or de-identified subject to security, legal, and backup limits | Limited to providers and personnel with a need to process the request |
| De-identified, aggregated, or diagnostic data | Operational metrics, aggregate usage, error counts, de-identified support or security trends | Improve reliability, security, and product planning; legitimate interests | May be retained longer if not reasonably linkable to an identifiable person | Service providers and connected apps in aggregate or de-identified form |
4. Payment Processing And Purchase Privacy
If purchases are enabled, full card numbers, full bank credentials, and payment authentication details should be collected and processed by the payment processor, not by DWL Accounts. DWL Accounts may receive limited payment metadata needed to manage access, subscriptions, receipts, refunds, tax, disputes, fraud prevention, and support.
Payment processors, banks, card networks, wallet providers, app stores, and tax providers may process information under their own terms and privacy notices. DWL Accounts may share account IDs, email, plan, checkout, entitlement, tax, invoice, refund, and dispute information with those providers and with connected apps only as needed for the purchase, compliance, security, or support workflow.
5. Connected-App Sharing And Unlinking
When you link or access a connected app, DWL Accounts may share your user ID, email, display name, avatar, linked-app status, permission or role state, subscription or entitlement status, and security state needed for sign-in, access control, billing, and support. Unlinking may remove access through DWL Accounts but may not delete product records held by the connected app. Contact the connected app or use the data request process for product-specific deletion.
6. Service Providers And Processors
| Provider category | Current provider or status | Role |
|---|---|---|
| Hosting and deployment | Vercel | Hosts the Next.js app and may process request, deployment, and operational logs. |
| Database and storage | Supabase Postgres/Storage | Stores account, auth, passkey, email preference, app linkage, audit, and related account records. |
| Email delivery | Resend or configured email provider | Sends verification, password reset, magic link, security, billing, receipt, and optional update emails. |
| Authentication provider | Google OAuth where selected | Provides Google sign-in profile data when you choose that method. |
| Payment processing | Payment processor used at checkout when enabled | Processes payment methods, subscriptions, invoices, taxes, refunds, chargebacks, fraud checks, and limited billing metadata. |
| DNS/security infrastructure | Cloudflare where configured for domain routing or security | May process DNS, request, firewall, or security metadata if enabled for the domain. |
| Analytics/session replay | Not currently used by DWL Accounts unless separately disclosed | Provider operational logs may still exist for hosting, security, payment, and debugging. |
| Error logging | No separate client error logging service is currently disclosed | Runtime and provider logs may be retained by infrastructure services. |
7. Privacy Choices, U.S. State Rights, And International Rights
Depending on where you live and how the law applies, you may request access, correction, deletion, export, portability, objection, restriction, withdrawal of consent, appeal, non-discrimination, limitation of sensitive information, or authorized-agent handling. We may verify your identity and authority and may deny or limit requests where permitted by law, including for security, fraud prevention, legal obligations, taxes, payment disputes, chargebacks, audit logs, backups, trade secrets, privileged information, or another person's rights.
EU, UK, Swiss, or other international users may have rights to lodge a complaint with a supervisory authority. DWL Accounts is operated from the United States. EU/UK representative and data protection officer requirements should be reassessed if offering scope, user geography, processing scale, sensitive data, or regulated workflows change.
9. Cookies And Similar Technologies
DWL Accounts uses essential cookies and similar storage for authentication, session protection, sign-out state, CSRF protection, required preferences, and account security. Refusing essential cookies may prevent sign-in, purchases, account security, or connected-app access from working.
| Cookie or technology | Purpose | Typical duration |
|---|---|---|
authjs.*, __Secure-authjs.*, and __Host-authjs.* | Auth.js session, callback, and security state | Session or Auth.js configured session duration |
dwl_manual_sign_out | Fresh reauthentication after manual sign-out | Up to 90 days unless changed or cleared |
dwl_privacy_choices and required consent records where used | Remember required account, privacy, display, or compliance preferences | Until changed, expired, or cleared |
| Payment processor cookies where checkout is embedded or redirected | Fraud prevention, checkout security, payment authentication, and payment-session continuity | Set by the payment processor under its policies |
| Analytics, advertising, retargeting, or session replay cookies | Not currently used by DWL Accounts unless separately disclosed | Not applicable |
10. Security And Breach Notice
DWL Accounts is designed to use HTTPS, secure cookies, Auth.js sessions, Argon2id password hashes, WebAuthn passkeys, server-side service access, restricted client access to sensitive account tables, audit logs, provider access controls, backups, and monitoring where available. No system is perfectly secure. We will investigate suspected incidents and notify affected users, regulators, payment processors, or connected apps where required by applicable law or provider rules.
11. Health, Sensitive Data, And AI Training
DWL Accounts itself is an identity and account portal. Do not send health information, government IDs, payment details, credentials, private keys, or other sensitive information through general support unless necessary for the request. Healthcare-adjacent connected apps must provide product-specific privacy notices before collecting health information. DWL Accounts does not claim HIPAA compliance unless a separate reviewed implementation and agreement state so.
Account data, support data, connected-app linkage data, payment metadata, and uploaded content are not used to train AI models unless that use is clearly disclosed and consented to in a product-specific notice or another valid legal basis applies.
12. Internal Access, Retention, Backups, And Logs
Access to account data is limited to authorized personnel and service providers with a legitimate need. Account profiles, authentication records, passkeys, support messages, connected-app records, purchase records, payment metadata, tax records, backups, and security logs are retained only as needed for the purposes described in this Policy, then deleted or de-identified unless security, fraud prevention, payment disputes, chargebacks, tax, accounting, legal, backup, audit, or dispute needs require longer retention. Backups and provider logs are not deleted instantly everywhere.
13. International Transfers
DWL Accounts is operated from the United States. Information may be processed in the United States and other locations where service providers, payment processors, connected apps, or support providers operate. Where required, appropriate safeguards are used for international transfers, such as adequacy decisions, standard contractual clauses, provider transfer frameworks, or other legally recognized mechanisms.
14. Children
DWL Accounts is not directed to children under 13 and does not knowingly collect personal information from children under 13. A parent or guardian may contact privacy
15. Automated Decisions And Fraud Controls
DWL Accounts may use automated or rule-based controls for authentication, rate limits, fraud prevention, payment-risk signals, spam prevention, security alerts, entitlement checks, and abuse detection. These controls are used to protect the Service and users. DWL Accounts does not currently make solely automated decisions that produce legal or similarly significant effects on users unless a product-specific notice states otherwise.
16. Changes To This Policy
Material changes may receive email, in-app, checkout, or Portal notice and may require renewed acknowledgement, consent, or preference choices where appropriate. The version, effective date, and last-updated date at the top identify the current policy.