OnlyDMARC
  • Home
  • Features
  • Why DMARC
  • Pricing
  • Docs
  • Sign In
  • Start Free Trial
Legal

Privacy Policy

Last updated: 1 January 2025  ·  Effective: 1 January 2025

Plain-English summary: We collect only what we need to provide the service. We never sell your data. You can request deletion at any time. The full detail is below.
Contents
  • 1. Who we are
  • 2. Data we collect
  • 3. How we use your data
  • 4. Legal basis
  • 5. Sharing & disclosure
  • 6. Data retention
  • 7. Security
  • 8. International transfers
  • 9. Your rights
  • 10. Cookies
  • 11. Children
  • 12. Changes to this policy
  • 13. Contact us

1. Who we are

OnlyDMARC Ltd ("OnlyDMARC", "we", "us", "our") is a company registered in New Zealand and the Cayman Islands. We operate the OnlyDMARC platform — a DMARC aggregation and monitoring service — accessible at onlydmarc.com and related sub-domains.

We act as a data controller in respect of personal data we collect directly from you (e.g. your account details). We may act as a data processor where we handle data on your behalf as part of delivering the service (e.g. processing DMARC report data that relates to your email infrastructure).

2. Data we collect

Account & registration data

When you create an account we collect your name, work email address, company name, and a hashed password. If you upgrade to a paid plan we also collect billing contact details. We do not store full card numbers — payments are processed by our PCI-DSS compliant payment provider.

Usage and service data

We collect information about how you use the platform including pages visited, features used, search queries within the app, and configuration changes. This helps us improve the product and troubleshoot issues.

DMARC report data

To deliver the core service, we ingest, parse, and store the DMARC aggregate (RUA) and forensic (RUF) reports sent to the receiving addresses we provision for you. This data typically contains sending IP addresses, authentication results, and message counts — it generally does not contain personal data about your end users, but may vary depending on your senders.

Technical and log data

We automatically collect IP addresses, browser type, device type, referring URLs, and access timestamps in server and application logs. Logs are retained for up to 90 days for security and debugging purposes.

Communications

If you contact us by email or via the in-app contact form, we retain that correspondence to help resolve your query and improve our support processes.

3. How we use your data

  • Providing, maintaining and improving the OnlyDMARC service
  • Authenticating you and keeping your account secure
  • Processing payments and managing billing
  • Sending transactional emails (account confirmation, alerts, invoices)
  • Sending product updates and security tips (you can opt out at any time)
  • Detecting and preventing fraud, abuse, and security incidents
  • Complying with legal obligations
  • Conducting anonymised, aggregated analytics to understand usage patterns

4. Legal basis for processing (UK/EU)

Where UK GDPR or EU GDPR applies, we process your data under the following legal bases:

  • Contract performance — processing necessary to deliver the service you have signed up for.
  • Legitimate interests — for security monitoring, fraud prevention, product analytics, and improving our service, where these do not override your rights.
  • Legal obligation — where we must process data to comply with applicable law.
  • Consent — for optional marketing communications. You may withdraw consent at any time.

5. Sharing & disclosure

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

  • Sub-processors: We use carefully vetted third-party infrastructure providers (cloud hosting, email delivery, payment processing, monitoring). A current list of sub-processors is available on request.
  • Your organisation: If you access OnlyDMARC via an organisational account, your account owner and administrators can access your data within the platform.
  • Legal requirements: We may disclose data if required by a court order, law enforcement request, or other legal obligation, and will endeavour to notify you where permitted.
  • Business transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred. We will give reasonable notice and ensure equivalent protections are maintained.

6. Data retention

We retain your account data for as long as your account is active. If you close your account, we delete or anonymise your personal data within 90 days, unless we are required to retain it longer for legal, tax, or fraud-prevention purposes.

DMARC report data is retained in accordance with your chosen plan. You may configure retention periods within the platform settings. Reducing retention will permanently delete older data.

7. Security

We take appropriate technical and organisational measures to protect your data, including encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, regular security assessments, and incident response procedures. See our Security page for more detail.

No transmission over the internet is 100% secure. If you have reason to believe your data has been compromised, please contact us immediately at security@onlydmarc.com.

8. International data transfers

Our infrastructure is hosted in the European Economic Area (EEA). Where we use sub-processors outside the EEA, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent UK mechanisms under the UK GDPR.

9. Your rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data ("right to be forgotten").
  • Restriction — ask us to restrict processing in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any right, contact us at privacy@onlydmarc.com. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority — in the UK this is the Information Commissioner's Office (ICO).

10. Cookies

We use cookies and similar tracking technologies for authentication, security, preferences, and analytics. The key cookies we set are described below.

Types of cookies we use

Strictly necessary cookies are essential for the Service to function and cannot be disabled. They include authentication tokens, session identifiers, and CSRF tokens. No personal profiling is performed with these cookies.

Functional cookies remember your preferences to provide a more personalised experience — for example, your preferred theme, dashboard layout, or notification settings. These can be disabled but may affect the quality of the experience.

Analytics cookies help us understand how visitors use our marketing website. This data is aggregated and anonymised. These are optional and require your consent.

Cookie list

Name Category Duration Purpose
od_session Necessary Session Authenticates your session. Deleted when the browser is closed.
od_csrf Necessary Session CSRF protection token to prevent cross-site request forgery attacks.
od_remember Necessary 30 days Persistent login token when "Remember me" is selected.
od_prefs Functional 1 year Stores UI preferences such as theme, timezone, and layout settings.
od_consent Necessary 1 year Records your cookie consent choices.
od_anon_id Analytics 90 days Anonymous identifier used for aggregate analytics. Does not identify individuals.

Managing your cookie preferences

When you first visit OnlyDMARC, you will be presented with a cookie consent banner allowing you to choose which optional cookies to accept. You can update your preferences at any time via your account settings. You may also control cookies through your browser settings — note that disabling strictly necessary cookies will prevent you from signing in.

Instructions for managing cookies: Chrome, Firefox, Safari, Edge.

11. Children

Our service is intended for professional use and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify you via email or an in-app notice. Continued use of the service after changes take effect constitutes acceptance of the revised policy.

13. Contact us

If you have any questions or concerns about this policy or our data practices, please contact our Data Protection Officer:

OnlyDMARC Ltd
Email: privacy@onlydmarc.com
Postal address: Please think of the environment and don't send pieces of paper packed inside a package of other paper to people.

OnlyDMARC

Powerful DMARC aggregation and monitoring. Built for teams that care about email security without the complexity.

Product
  • Features
  • Pricing
  • Documentation
  • Status
Company
  • Why DMARC
  • About
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • Security

© 2026 OnlyDMARC Ltd. All rights reserved.

Made with for email security engineers