Legal
Privacy Policy
Last updated 28 August 2026.
Plain-language draft
This page is written in plain English so you can actually read it, and it has not been reviewed by a lawyer. It is not final legal advice. Treat it as a description of how the business actually handles data, due for a proper legal review before it's relied on.
Got a cold email from us?
Start at section 3, "Where we got your details if we emailed you first" — it explains exactly what we have, where it came from, and how to make us delete it.
1. Who we are
InspectPlay is operated by DAPDEV Software Solutions OÜ, Sepapaja 6, 15551 Tallinn, Estonia. We're the data controller for the personal data described on this page. Because we're established in the EU, GDPR applies to how we process personal data regardless of where you're located. Contact us about privacy at [email protected].
2. What we collect
Account data. When you sign up: your business name and email address. That's the whole signup form.
Data you enter to run the software. The clients, sites, equipment, inspections and photographs you enter as you use InspectPlay. This is your business data; we process it on your behalf to run the service, we don't use it for our own purposes.
Technical logs. Standard request logs — IP address, browser type, timestamps, and similar technical detail — generated automatically by our hosting infrastructure for security and troubleshooting.
Billing data. Payment is handled entirely by Stripe. We don't see or store your card details — Stripe tells us your plan and payment status, nothing more.
3. Where we got your details if we emailed you first
If you're reading this because you received an email from us and you don't have a InspectPlay account, here is exactly what happened.
What we collected: your name, business email address, business address, and certification number.
Where it came from: a professional directory of playground safety inspectors, in which inspectors list themselves to be contacted about third-party work — not from you directly.
Why we're allowed to: our lawful basis under GDPR Article 6(1)(f) is legitimate interests — specifically, reasonable business-to-business outreach to inspectors who may be interested in software built for their trade. We only use these details to send a small number of relevant emails; we don't sell or share this list.
Your right to object: you can object to this processing at any time, for any reason, under GDPR Article 21. We will stop.
To object or be erased: reply to the email, or write to [email protected] asking us to delete your details. We'll confirm once it's done, normally within a few days.
4. How we use data, and on what basis
- Running your account and the service — necessary to perform our contract with you.
- Billing — necessary to perform our contract with you, via Stripe.
- Sending transactional email (sign-in links, receipts, service notices) — necessary to perform our contract with you, via Resend.
- Security and troubleshooting logs — our legitimate interest in keeping the service working and secure.
- Prospective-customer outreach — our legitimate interest in reasonable B2B marketing, described in section 3.
We don't sell personal data to anyone, and we don't use your business data — your clients, sites or inspections — for anything other than running the service for you.
5. Cookies
InspectPlay sets one cookie: a session cookie that keeps you signed in after you click your sign-in link. It's essential to the service, marked HttpOnly and Secure, and expires after 30 days or when you sign out. We don't set any analytics, advertising or tracking cookies, and we don't use any third-party tracking pixels or scripts on this site.
6. Who we share data with
We use a small number of subprocessors to run InspectPlay. We don't sell data to anyone, and we don't share it beyond what's needed to run the service:
- Cloudflare — hosting, database (D1) and file storage (R2) for the application and everything in it.
- Stripe — payment processing and billing.
- Resend — delivery of sign-in links, receipts and service emails.
Aerial imagery shown in the app comes from public government sources, not from any of the subprocessors above.
7. International transfers
We're based in Estonia, in the EU. Cloudflare, Stripe and Resend are all US-headquartered providers that may process data outside the EU/EEA as part of delivering their service to us. Where that happens, we rely on their Standard Contractual Clauses and other GDPR-recognized safeguards for the transfer.
8. How long we keep data
- Account and business data — for as long as your account is active, plus 30 days after cancellation so you can export or recover it, then deleted.
- Prospective-customer directory details (section 3) — until we've made contact and you either respond, convert to a customer, or ask us to stop; otherwise removed from our outreach list on a routine basis.
- Technical logs — kept for a limited period for security purposes, then deleted automatically.
9. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify it if it's inaccurate.
- Erase it, subject to any legal reason we may need to keep it.
- Object to processing based on legitimate interests, including outreach.
- Restrict processing in certain circumstances.
- Port your data to another provider in a common format.
To exercise any of these, email [email protected]. You also have the right to complain to a supervisory authority. In Estonia that's the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). If you're located elsewhere in the EU/EEA, you can also complain to your own country's data protection authority.
10. Security
We rely on Cloudflare's infrastructure for hosting, encrypt traffic to the app in transit, and limit access to production data to what's needed to run the service. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data.
11. Children
InspectPlay is a business tool for professional inspectors. It isn't directed at children, and we don't knowingly collect personal data from anyone under 18.
12. Changes to this policy
If we make a material change to how we handle personal data, we'll update this page and, where the change affects you directly, email the address on your account.
13. Contact
For any privacy question or request: [email protected]. See also our Terms of Service.