Privacy Policy

Last updated: 8 October 2025

Who we are
NoDCC (“we”, “us”) provides tools and guides to help you avoid dynamic currency conversion (DCC).

What this policy covers

This explains what personal data we process, why, for how long, and your rights under GDPR (EEA/UK) and CPRA/CCPA (California).

Data we collect (minimal by design)

  • Essential technical data: IP address, device/browser info, basic request logs (to deliver pages, prevent abuse).

  • Preferences you set: language, country, calculator inputs (stored locally on your device via localStorage; not sent to us).

  • Analytics (optional): anonymized page analytics to improve the site (IP anonymization and no cross-site tracking when possible).

  • Contact form: if you write to us, we process the content you submit to reply.

We do not create user accounts, track people across sites, or buy/sell personal data.

Purposes & legal bases (GDPR)

  • Provide the service (essential cookies/local storage; server logs) — Legitimate interests / Contract-like necessity.

  • Security & abuse preventionLegitimate interests.

  • Usage analytics (if enabled via consent) — Consent.

  • Respond to messagesLegitimate interests / Consent (you initiated contact).

  • Legal complianceLegal obligation.

Cookies & local storage

  • Essential: remember UI choices; keep the app working offline/PWA.

  • Analytics (optional): traffic measurement.
    You can manage consent via the cookie banner. Blocking non-essential cookies won’t break the core calculator.

Data sharing

  • Hosting/CDN: to serve the site fast and securely.

  • Analytics: privacy-respecting analytics provider.

  • Error monitoring (if used): to fix crashes.

  • FX data sources: we query public FX APIs; your personal data is not required for these calls.

We require processors to follow data-protection terms. We do not sell personal data.

International transfers

Service providers may process data outside your country. Where required, we use SCCs/UK IDTA or equivalent safeguards.

Data retention

  • Server logs: typically ≤ 30–90 days unless needed for security/legal reasons.

  • Contact form messages: as long as needed to resolve your request; then archived or deleted.

  • Local storage on your device: until you clear your browser data.

Your rights (GDPR/UK GDPR)

You can request access, rectification, deletion, restriction, portability, or object to processing of your personal data. You may withdraw analytics consent anytime via the cookie settings. You also have the right to complain to your local Data Protection Authority.

California (CPRA/CCPA)

We do not sell or share personal information for cross-context behavioral advertising. You may request access, deletion, and correction via our Contact form.

Children

The site is for general audiences and not directed to children under 13 (or under 16 in the EEA/UK).

Security

We use reasonable technical and organizational safeguards. No method is 100% secure.

Changes

If we change this policy, we’ll update the “Last updated” date and post the new version here.

Contact
For any privacy request, use the Contact form on this website.