Privacy Policy

Effective Date: July 1, 2026

Welcome to the Privacy Policy for Login AlertX. This policy explains how we collect, use, process, disclose, and protect your personal data when you visit our website at loginalertx.com (the “Website”), purchase our software through WooCommerce, or use the Login AlertX software for Windows and the Login AlertX – Companion mobile app (collectively, the “Services”). We are committed to safeguarding your privacy and ensuring transparency in our data processing practices.

Depending on your location, different privacy frameworks apply. For users in India, we process personal data in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”). For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (“GDPR”), and for California residents, the California Consumer Privacy Act (“CCPA”).

Under the DPDP Act, we act as the Data Fiduciary, you are the Data Principal, and our third-party integrations (like HubSpot, Google, and payment processors) act as Data Processors.

By using our Website or Software, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our services.

1. Consent and Lawful Basis

Under the DPDP Act, we process your personal data based on your free, specific, informed, unconditional, and unambiguous consent, indicated through a clear affirmative action (such as when you purchase our software, submit a contact form, or enable settings in the Software). This Privacy Policy serves as the notice required under Section 6 of the DPDP Act, detailing the purposes and categories of data processed.

You have the right to withdraw your consent to data processing at any time (e.g., by unlinking your mobile app, disabling specific features in the Software, or requesting account deletion). The withdrawal of consent will not affect the lawfulness of any processing carried out before your withdrawal, and may result in the termination of certain features or services.

2. Information We Collect

We collect and process personal data that is necessary, adequate, and relevant for the specified purposes of providing and improving our Website and Software (data minimisation). We collect data in the following ways:

2.1 Website Interactions

  • Personal Information Provided Directly by You:
    • E-commerce Purchases: When you purchase the Software license via WooCommerce, we collect your full name, email address, billing address, phone number, and order details. Payment details (card numbers, UPI credentials, net banking info) are processed securely by our third-party PCI-compliant payment gateways (e.g., Razorpay, PayPal) and are never stored or seen by us.
    • Customer Relations & Support (HubSpot): If you contact us via our contact forms, support tickets, or chat widgets, we use HubSpot as our CRM database. We collect your name, email address, and any details or logs you voluntarily provide in your communication.
  • Automatically Collected Information (Analytics & Tracking):
    • Website Usage & Behavioral Analytics: Through Google Analytics and Microsoft Clarity, we collect anonymized data about your website interactions, including operating system, browser type, device details, IP address (anonymized), clickstreams, page views, and time spent on pages. This helps us understand visitor engagement and improve usability.
    • CRM Tracking: We use HubSpot tracking cookies to identify user sessions and personalize support and marketing communications.
    • Cookies: We use cookies to enhance website function. These include essential cookies (WooCommerce shopping cart), performance cookies (Google Analytics, Microsoft Clarity), and functionality cookies (HubSpot). You can manage cookies via your browser settings or our cookie consent banner.

2.2 Software Usage (Login AlertX for Windows)

The core Login AlertX Windows Service is designed with privacy-first principles. Most monitoring and notification configuration data is stored and processed locally on your machine and is never transmitted to us.

  • Data Transmitted to Our Servers:
    • For license activation, premium validation, and piracy prevention, the Software transmits the following to our secure validation server at loginalertx.com: your license key, registered email address, and your machine name/hardware fingerprint (a unique identifier of your device).
  • Data Processed and Stored Locally (Not Transmitted to Us):
    • Notification Configurations & SMTP: If you configure email notifications, you provide SMTP server details, sender email, sender password, or Google OAuth credentials. These are stored locally and securely (using Windows Credentials Manager or local encryption) on your device. We do not transmit or store these credentials.
    • Webcam Capture: If enabled, the Software captures images using your device’s webcam upon login events. These images are stored in a local directory on your device and attached to notifications sent via your configured SMTP/Google account. We do not collect, view, or store these images.
    • Audio Recording: If enabled, the Software records microphone audio upon login events. These recordings are stored on your device and attached to notifications. We do not collect, view, or store these audio files.
    • System Logs: Operational logs (errors, event detection, license checks) are stored locally in %AppData%\LoginAlertX. They remain on your device and are not shared with us unless you choose to email them for support.
  • Third-Party Geolocation (ip-api.com):
    • To enrich security alerts, the Software fetches your approximate location (city, region, country) based on your public IP address using ip-api.com. This request goes directly to the service provider. The location data is processed locally and included in your alert email, but is not transmitted to or stored by our servers.

2.3 Mobile App (Login AlertX – Companion)

  • Account Pairing: When you pair the Companion app using your licensed email, your mobile device links to your desktop service. Pairing tokens and configurations are stored in the operating system’s secure, encrypted local storage.
  • Push Alerts: We use Firebase Cloud Messaging (FCM) to send push notifications. The alert text containing the event details (e.g., action type, timestamp, IP) is securely sent to your mobile device via FCM over HTTPS/TLS. We do not persist alert notification histories on our servers once they have been delivered to FCM. The mobile app does not access your phone’s camera, microphone, or location.

3. How We Use Your Information

We process your personal data for the following lawful purposes:

  • E-commerce & Licensing: To process transactions, deliver software license keys, manage subscription status, and handle billing via WooCommerce and payment gateways.
  • Customer Support & CRM (HubSpot): To maintain user relations, address technical queries, manage accounts, and process feedback.
  • Website Optimization: To analyze website performance, track conversion rates, diagnose bugs, and improve site layouts (via Google Analytics & Microsoft Clarity).
  • Software Verification: To validate license compliance and unlock premium features.
  • Push Notifications: To deliver instant notifications to paired mobile devices (via FCM).
  • Compliance: To comply with statutory tax laws, billing compliance, and legal authorities.

4. How We Share Your Information

We do not sell, rent, or trade your personal data. We share your information only with authorized Data Processors under strict data processing agreements that restrict usage to the services they perform for us. These include:

  • WooCommerce: Processes transaction data and manages store administration.
  • HubSpot: Processes CRM database entries, contact submissions, and support interactions.
  • Payment Gateways (Razorpay, PayPal): Safely execute payment processing. They receive payment data directly.
  • Google Analytics & Microsoft Clarity: Process anonymized site visitor metrics.
  • ip-api.com: Queries public IP addresses to output approximate location metadata within user alerts.
  • Firebase Cloud Messaging (FCM): Routes real-time push alerts to paired companion apps.
  • Legal Compliance: We may disclose personal data if required by a court of law, statutory authority, or government regulations to protect the legal rights, safety, and property of our company or our users.

5. Data Storage and Security

  • Website & Cloud Storage: Personal data related to orders, licenses, and CRM entries is stored on secure databases hosted on our servers and WooCommerce/HubSpot secure cloud platforms, protected by industry-standard encryption, firewalls, and strict access controls.
  • Local Software Storage: Local configurations, SMTP data, webcam photos, audio recordings, and logs reside in %AppData%\LoginAlertX on the Data Principal’s device, protected by the device’s system security.
  • Mobile Companion App: Pairing credentials and preferences are encrypted within the Android/iOS secure storage directory.
  • Security Standards: We implement HTTPS/TLS encryption for all data in transit. While we strive to employ best-in-class administrative, organizational, and physical security measures, no system is 100% secure, and we cannot guarantee absolute security.

6. Data Retention and Erasure

We retain personal data only for as long as necessary to fulfill the purposes of processing, or as required by applicable tax, accounting, and legal requirements.

  • Order and Financial Data: Retained for the duration of the software subscription and as mandated by financial regulations (typically 7 years).
  • HubSpot CRM Records: Retained as long as you maintain an active account or communication channel with us.
  • License Keys: Retained until the license expires or is terminated.
  • Local Device Data: Retained locally on your machine. All temporary files (captured images, audio) are deleted dynamically by the Software after notification dispatch. Other data is removed upon software uninstallation.

Upon expiration of the retention period or receipt of a valid erasure request, we will securely delete or anonymize the personal data, unless retention is legally mandated.

7. Rights of the Data Principal (Under the DPDP Act)

If you are a user in India, the DPDP Act grants you the following statutory rights regarding your personal data:

  • Right to Access: Obtain a summary of the personal data we process about you, the purposes of processing, and the identities of third parties with whom your data has been shared.
  • Right to Correction, Completion, and Erasure: Request correction of inaccurate data, completion of incomplete records, or erasure of data that is no longer necessary for the purpose of collection (unless legal retention is required).
  • Right to Withdraw Consent: Withdraw your consent to data processing at any time.
  • Right to Nominate: Nominate another individual to exercise your rights on your behalf in the event of death or physical/mental incapacity.
  • Right to Grievance Redressal: Raise questions, concerns, or grievances regarding our data practices with our Grievance Officer.

8. Duties of the Data Principal

Under the DPDP Act (Section 15), Data Principals are obligated to comply with the following duties when submitting information or exercising rights:

  • You must not impersonate another individual when providing personal data.
  • You must not suppress or misrepresent material facts when providing personal data or filing requests.
  • You must not register false or frivolous grievances or complaints.

9. Grievance Redressal Mechanism

If you have questions, concerns, or wish to exercise your rights as a Data Principal under the DPDP Act, you may contact our designated Grievance Officer:

Email: [email protected]
Response Timeline: We will acknowledge receipt of your grievance within 48 hours and attempt to resolve it within the statutory period of 30 days (or as prescribed under the DPDP Act rules).

If you are not satisfied with the resolution provided by our Grievance Officer, you have the right to file a complaint with the Data Protection Board of India (DPBI) in the prescribed manner.

10. Data Breach Management

We take security breaches seriously. In the event of a personal data breach impacting your information, we will notify the Data Protection Board of India (DPBI) and the affected Data Principals (users) in accordance with the procedures, guidelines, and timelines mandated under the DPDP Act.

11. Children’s Privacy

Our Services are not intended for individuals under 18 years of age. Under the DPDP Act, processing of children’s data (minors under 18) requires verifiable consent of a parent or guardian. We do not knowingly collect personal data from minors, nor do we perform behavioral tracking or targeted advertising directed at children. If we discover we have inadvertently collected data of a minor without parental consent, we will delete it immediately.

12. International Data Transfers

Our primary servers are hosted in the United States. If you are accessing our Services from outside the United States (including India), your personal data may be transferred across borders. We ensure that all such cross-border transfers comply with the provisions of the DPDP Act and other relevant global data transfer mechanisms, ensuring your data is protected under equivalent security standards.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in our software, website, or legal compliance mandates. When updates are published, we will revise the “Effective Date” at the top of the policy. We encourage you to review this document periodically.

14. Contact Us

For general support, licensing help, or questions about this policy (unrelated to formal grievances), please contact us at:

When contacting us, please include relevant context (e.g., license serial key, order details) to assist with your request. For Software troubleshooting, you may attach operational logs from your local %AppData%\LoginAlertX directory.

Scroll to Top