// legal

Privacy Policy

Last updated: July 31, 2026

1. Overview

customer.log ("we", "us") provides a real-time event logging and notification service for founders and small teams. This Privacy Policy explains what personal data we collect, why we collect it, how it is shared, and the rights and controls you have over it. It covers (a) visitors to our website, (b) account holders who use our service, and (c) the visitors to our customers' websites whose data is processed through the customer.log SDK.

2. Data controller and contact

customer.log is the data controller for the personal data collected when you use our website and dashboard. For event data logged through the customer.log SDK on your website, you are the data controller and we act as a data processor on your behalf. Questions, requests, and complaints can be sent to privacy@getcustomerlog.com and will be answered within 30 days. The data protection officer can be reached at the same address.

3. Data we collect

Account data — your name, email address, authentication provider, and account settings when you register. Event data — the events you log through the SDK or API, including channel, title, message, metadata, tags, and notification preferences. Billing data — event counts used for usage-based billing; we do not store full payment card numbers. Usage data — aggregated counts of events and feature usage for service health and billing. Analytics data — see the Cookies section below.

4. Cookies and similar technologies

Essential: a session cookie ("accessToken") keeps you signed in and is strictly necessary; a local storage entry ("customer_log_consent") records your cookie preference; and Vercel provides website analytics used for our legitimate interest in understanding site performance. Consent-based: with your consent we may store a random visitor identifier ("customer_log_uid" in local storage) and run visitor/page-view tracking. We do not use advertising cookies or share data with advertising networks. You can change your consent at any time with the control below.

5. Legal basis for processing (GDPR)

We process account data and event data to perform the contract you enter into when you register (Art. 6(1)(b)) and to provide the service you request. We process website analytics from Vercel on the basis of our legitimate interests (Art. 6(1)(f)) in operating and improving the website. Non-essential visitor tracking cookies are processed only on the basis of your consent (Art. 6(1)(a)), which you may withdraw at any time without affecting other services. For the customer.log SDK, our customers are responsible for establishing their own lawful basis (typically consent) before deploying it.

6. How we use your data

We use your data to deliver and maintain the service: storing and displaying your events, delivering notifications to the channels you configure (Slack webhook, email), generating AI summaries and digests, billing based on event volume, and responding to support requests. We also aggregate website usage to understand and improve the product. We never sell your personal data, including under CCPA/CPRA.

7. AI processing

When you enable AI summaries and digests, event data is sent to Google's Gemini API to generate structured highlights and narrative summaries. Events are processed only to produce summaries and are not used to train external models. You can disable AI features at any time, which stops further processing.

8. Third-party services and subprocessors

The service relies on the following providers, which process data only as needed to run their part of the service: Firebase (authentication), MongoDB Atlas (data storage), Resend (email delivery), Google Gemini (AI summaries), Slack (via webhooks you configure), Vercel (website hosting and, with your consent, web analytics), and geoip-lite (a local, offline IP-to-country lookup). A current list of subprocessors is available on request.

9. International data transfers

Your data is processed by providers located in the United States, the European Economic Area, and elsewhere. When personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the data protection framework certifications of our providers, to protect your data.

10. SDK visitor data

When the customer.log SDK is installed on your website, it may store a random visitor identifier in the visitor's browser and transmit page-view and path information together with a country inferred from the visitor's IP address. You are the data controller for that data. You must disclose the use of customer.log in your own Privacy Policy and, where required, obtain consent before the SDK runs. We provide this disclosure text and a consent pattern in our SDK documentation.

11. Data retention and deletion

Event data is retained while your project is active. You can delete individual events from your dashboard, and deleting your account removes your projects, events, and usage records. Analytics data is retained for as long as needed to understand website usage and is deleted on request. Backup copies are purged according to our retention schedule. You may exercise your deletion rights at any time by contacting us.

12. Security

Event ingestion is authenticated with per-project API keys, sessions are protected with JWT and HTTP-only cookies, and access to our infrastructure is restricted. No system is fully immune to compromise, but we apply reasonable technical and organizational safeguards appropriate to the sensitivity of the data.

13. Your data protection rights

Depending on your jurisdiction (including under GDPR and CCPA/CPRA), you have the right to access, correct, export, delete, or restrict the processing of your personal data, to object to processing, and to withdraw consent at any time. California residents may also request information about how their data is disclosed and may opt out of any "sale" or "sharing" of personal information — we do not sell or share personal information. To exercise any right, email privacy@getcustomerlog.com or use the account deletion option in your dashboard. We will respond within 30 days and will not discriminate against you for exercising your rights.

14. Data processing for our customers

For event data that our customers log through the SDK, we act as a data processor. Our customers are responsible for the lawfulness of their processing, and we process only in accordance with their instructions and our Terms of Use. A Data Processing Agreement (DPA) incorporating standard GDPR terms is available on request.

15. Children's privacy

The service is intended for founders and teams operating a business and is not directed to children. We do not knowingly collect personal data from children under 16 (or under 13 in jurisdictions where that threshold applies). If you believe a child has provided us personal data, contact us and we will delete it.

16. Changes to this policy

We may update this policy as the service evolves or the law changes. Material changes will be announced in the changelog and, where required, by email to account holders. The date at the top of this page reflects the last revision, and continued use after changes take effect constitutes acceptance.

17. Contact

Questions about this policy can be sent to privacy@getcustomerlog.com.

We care about your privacy

We use essential cookies to keep you signed in. We only ask for consent to use non-essential tracking cookies (visitor and page-view tracking). We never sell your data. Read our Privacy Policy and Terms of Use.