Privacy Policy
Effective date: June 3, 2026 · Last updated: June 3, 2026
1. Who we are
dahlke.family ("we," "our," or "us") operates the website at dahlke.family. We provide a private email registration service exclusively for members of the Dahlke family. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website and services.
If you have questions about this policy, contact us at [email protected].
2. Information we collect
Information you provide directly
- Account information: first name, last name, email address, and phone number collected at registration.
- Your chosen email prefix: the part of your @dahlke.family address that you select.
- Password: stored as a one-way cryptographic hash — we cannot recover or read it.
Information collected automatically
- Session data: an encrypted cookie used to keep you logged in. It does not contain personal information beyond a session identifier.
- Server logs: IP addresses and request metadata captured by our hosting infrastructure. These are used for security and debugging and are not used for profiling.
Payment information
We do not collect or store payment card numbers, bank account details, or any other financial credentials. All payments are processed by Stripe, which acts as an independent data controller. Please review Stripe's privacy policy for details on how they handle your payment data. We receive only a Stripe customer ID and subscription status.
3. How we use your information
- To create and manage your @dahlke.family email account.
- To process and manage your subscription through Stripe.
- To send transactional emails (registration confirmation, account activation, billing notices).
- To notify the site administrator of new registrations requiring manual activation.
- To maintain the security and integrity of the service.
- To comply with legal obligations.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Legal bases for processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:
- Contract performance: processing necessary to provide the email service you signed up for.
- Legitimate interests: security logging, fraud prevention, and service improvement.
- Legal obligation: where required by applicable law.
- Consent: where you have explicitly opted in (e.g., future marketing communications, if any).
5. Cookies
We use the following cookies:
- Session cookie (required): an encrypted, HTTP-only cookie that keeps you logged in. It is deleted when you log out or after a period of inactivity. This cookie is strictly necessary for the service to function.
We do not use advertising cookies or third-party tracking cookies. If we add analytics in the future, this policy will be updated and, where required, your consent will be obtained.
6. Analytics
We may add privacy-respecting analytics in the future (such as aggregate page view counts) to help us understand how the service is used. Any analytics tool we adopt will be configured to minimize data collection, will not fingerprint individual users, and will comply with applicable privacy laws. This policy will be updated before any analytics are enabled.
7. Data retention
We retain your personal data for as long as your account is active or as necessary to provide the service. If you cancel your subscription and close your account, we will delete your personal data within 90 days, except where we are required to retain it longer for legal, tax, or fraud-prevention purposes.
Stripe retains payment records according to their own retention policy and applicable financial regulations.
8. Data security
We implement reasonable technical and organizational measures to protect your information, including encrypted HTTPS connections, hashed passwords, and encrypted session tokens. No method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact us immediately at [email protected].
9. Your rights
All users
- Access the personal data we hold about you.
- Correct inaccurate information.
- Delete your account and associated data.
- Cancel your subscription at any time through the billing portal.
EEA / UK residents (GDPR)
In addition to the above, you have the right to:
- Restrict or object to processing of your data.
- Data portability — receive your data in a structured, machine-readable format.
- Lodge a complaint with your local data protection authority.
California residents (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect and how it is used.
- Delete personal information we hold (subject to certain exceptions).
- Opt out of the sale or sharing of personal information — we do not sell or share your data.
- Non-discrimination for exercising your privacy rights.
To exercise any of these rights, email [email protected]. We will respond within 30 days (or 45 days for GDPR requests where an extension is necessary).
10. Third-party services
We use the following third-party services, each governed by their own privacy policy:
- Stripe — payment processing. stripe.com/privacy
11. Children's privacy
Our service is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal information, contact us and we will delete it promptly.
12. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify registered users by email. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
13. Contact
For any privacy-related questions, requests, or concerns, please contact us at:
[email protected]