pwa.today

Privacy Policy

Last updated: 11 August 2026

bitBuilders ("bitBuilders", "we", "us", or "our") operates pwa.today and the related PWA Today services (the "Services"). This Privacy Policy explains how we collect, use, store, and share personal data when you visit pwa.today, create an account, use the PWA Today console, or use our API.

1. Who is responsible for your data?

The data controller is:

bitBuilders
Zekeringstraat 17A
1014 BM Amsterdam
The Netherlands
Email: info@pwa.today

2. Personal data we collect

Depending on how you use the Services, we may collect:

  • Account data: your name, email address, company name, account identifiers, authentication data, passkeys, and account status.
  • Billing data: subscription, purchase, payment status, tax, invoice, and transaction information. Stripe processes payment-card details on our behalf; we do not receive or store your full payment-card number.
  • Application data: domains, hostnames, application names, URLs, verification records, audit configurations, schedules, and API credentials that you create or upload.
  • Audit data: audit requests, selected checks, configuration options, audit status, scores, results, timestamps, and related technical output.
  • Push-notification data: browser push subscription endpoints and keys, notification channels, the related domain, and notification status when you enable audit notifications.
  • Technical and security data: IP address, request time, request path, HTTP method, response status, response size, browser and device information, error information, and security events. Some of this information is recorded automatically in infrastructure and application logs.
  • Communications: messages you send to us at info@pwa.today.
  • Cookie and analytics data: cookie choices and, only if you accept optional analytics cookies, Google Analytics information about how you use the public website and console.

Please do not submit passwords, payment-card details, private keys, or other sensitive information in audit URLs, configuration fields, support messages, or other free-text fields unless the feature specifically asks for it.

3. How we use personal data

  • create, authenticate, and manage your account;
  • provide the Services, including application verification, runtime audits, hosting-related checks, API access, and audit notifications;
  • store and process the application data and configurations that you ask us to process;
  • process purchases, subscriptions, invoices, tax information, and payment-related administration;
  • send service-related messages, including account-confirmation, security, billing, and audit-notification emails;
  • respond to support requests and investigate service problems;
  • protect the Services against fraud, abuse, unauthorised access, and security incidents;
  • monitor, troubleshoot, maintain, and improve the Services;
  • comply with legal, accounting, tax, and regulatory obligations; and
  • establish, exercise, or defend legal claims.

We do not currently send marketing emails. If we introduce marketing communications, we will request any consent required by law and provide an unsubscribe mechanism.

4. Legal bases for processing

Where the EU General Data Protection Regulation (GDPR) applies, we process personal data on the basis of contract performance, legitimate interests, legal obligations, or consent for optional analytics cookies and other processing for which we ask you to opt in. You may withdraw consent at any time.

5. Service providers and sharing

Our service providers process data only as necessary to provide services to us and under appropriate contractual and security arrangements.

  • Amazon Web Services (AWS): hosting, databases, authentication, email delivery, logging, monitoring, storage, and infrastructure.
  • Stripe: payment processing, subscriptions, invoices, and billing administration.
  • Google Analytics: optional analytics, only after you accept optional analytics cookies.
  • Cloudflare Turnstile: signup abuse and bot prevention.

We may disclose personal data when required by law, to protect rights or safety, or in connection with a change in ownership or business structure. We do not sell personal data.

6. International transfers

Service providers may process personal data outside the European Economic Area. Where required, we use an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. Contact us for information about applicable safeguards.

7. Retention

We keep personal data only as long as necessary, unless a longer period is required by law or needed for legal claims, security, fraud prevention, or accounting.

Intended retention periods
Data categoryIntended retention period
Account and profile dataWhile active, then deleted or anonymised within 30 days after closure, except where legally required.
Authentication and passkey dataUntil the account or sign-in method is deleted.
Applications, configurations, and schedulesWhile active, then deleted within 30 days after closure unless needed for legal or security reasons.
Runtime audit records and results90 days after creation, unless a longer period is needed.
Audit-usage and allowance recordsTrial usage remains while the trial account is active and is deleted with account closure; paid-plan usage records are retained until approximately 400 days after the relevant audit-pack or subscription period ends for usage and billing reconciliation.
Push-notification subscriptionsUntil disabled or account closure; inactive subscriptions expire after 90 days without a successful subscription save or refresh. Invalid subscriptions are removed sooner.
API credentials and metadataUntil revoked, replaced, or account closure.
Billing records and invoices7 years after the relevant financial year, or longer where required.
API and infrastructure logsGenerally 30 days for API logs and 14 days for application and worker logs.
Security and administrative logsUp to 12 months.
Support correspondenceUp to 24 months after the matter is closed.

Backups may retain deleted data for a limited period until they expire or are overwritten.

8. Security

We use reasonable technical and organisational measures, including access controls, encryption in transit, restricted infrastructure permissions, secret management, logging, monitoring, and security testing. No internet-based service can be guaranteed to be completely secure.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict processing of your data, object to processing, request portability, and withdraw consent. Contact info@pwa.today. You may also complain to the Dutch Data Protection Authority or another applicable supervisory authority.

10. Cookies and similar technologies

We use necessary cookies to operate and secure the Services. Optional analytics cookies are used only after affirmative consent. The Cookie settings control in the footer lets you change your choice. Advertising cookies are not enabled by us.

11. Children

The Services are intended for people aged 18 or older. We do not knowingly provide accounts to, or intentionally collect personal data from, anyone under 18.

12. Changes to this Policy

We may update this Policy from time to time. We will publish the updated version on pwa.today and update the “Last updated” date. If a change materially affects how we use personal data, we will provide additional notice where required.

13. Contact

Questions, privacy requests, and complaints can be sent to:

bitBuilders
Zekeringstraat 17A
1014 BM Amsterdam
The Netherlands
info@pwa.today