EZCheck

Loading...

Privacy Policy

This policy explains what data EZCheck collects, why we collect it, and how we keep it safe. We try to collect as little as possible.

Last updated:

1. What we collect

  • Account data. Email address, username, display name, and a hashed password (we never store the plaintext). Optional avatar if you upload one.
  • Content you create. Checklists, items, titles, pin / completion state, and timestamps.
  • Technical data. Standard web logs (IP address, user agent, request path, status code, timestamp) and a session cookie for keeping you signed in.
  • Email delivery metadata. When we send you a verification, password reset, or notification email, we keep a short delivery log (recipient, timestamp, status).

We do not embed third-party advertising SDKs or cross-site behavioural trackers in the Service.

2. Why we collect it

  • To create and authenticate your account.
  • To store, display, and sync your checklists across devices.
  • To send you transactional email (verify email, reset password).
  • To detect abuse, debug errors, and keep the Service secure.
  • To comply with applicable law.

3. Cookies & local storage

EZCheck only uses cookies and local storage that are strictly necessary for the Service or that remember your interface preferences. We do not use advertising cookies, cross-site trackers, or third-party analytics.

3.1 How to control them

Because we only use strictly-necessary and first-party preference cookies, there is no opt-in toggle to disable them in-app — turning them off would break sign-in, language switching, or theme persistence. You can still:

  • open Cookie settings in the footer to clear your preference cookies on this device, or sign out to clear all cookies in one click;
  • clear all EZCheck cookies and local storage from your browser's site-data settings;
  • block first-party cookies for this domain in your browser settings (the site will then ask you to sign in on every visit and reset your language & theme);
  • sign out from the in-app menu, which clears your session cookie immediately;
  • delete your account from in-app settings, which removes server-side data and invalidates all your sessions.

3.2 Full inventory

Here is every cookie and local-storage key EZCheck may set in your browser. We'll update this list whenever we add or change one.

Required for sign-in, security, and core UI bootstrap. The Service cannot function without these.

NameTypeProviderPurposeDuration
next-auth.session-token / __Secure-next-auth.session-tokenCookieAuth.js (first-party)Keeps you signed in across requests. Without it the site cannot recognise your session.Session, refreshed up to 30 days; cleared on sign-out.
next-auth.csrf-token / __Host-next-auth.csrf-tokenCookieAuth.js (first-party)Protects sign-in and form submissions from cross-site request forgery (CSRF).Session.
next-auth.callback-url / __Secure-next-auth.callback-urlCookieAuth.js (first-party)Stores the URL to return to after a successful sign-in.Session.
ezcheck-cookie-noticeCookieEZCheck (first-party)Records that you have dismissed the cookie notice banner so we don't show it again.1 year.

Remember UI choices like language and theme. First-party only; never used for cross-site tracking.

NameTypeProviderPurposeDuration
ezcheck-localeCookieEZCheck (first-party)Remembers your interface language (Chinese / English) so the server can render the right copy on first paint.1 year.
checklist-themeCookieEZCheck (first-party)Remembers your theme preset (light / dark / accent) so the right colours render before the app boots.1 year.
ezcheck-localeLocal storageEZCheck (first-party)Mirrors the locale cookie so your language preference survives if cookies are cleared by the OS.Until you clear browser data.
checklist-theme-preset · checklist-theme-preset:user:<id>Local storageEZCheck (first-party)Stores theme preferences globally and per signed-in user, so each account keeps its own theme.Until you clear browser data.

4. How we share data

We share data only with vendors strictly necessary to operate the Service:

  • a cloud hosting provider for application servers and the PostgreSQL database;
  • a transactional email provider to deliver verification and reset emails.

We do not sell your personal data. We do not share your checklist content with anyone other than people you explicitly choose to share with from inside the app.

5. Data retention

Your account and content are kept for as long as the account is active. When you delete your account, your account record and checklists are scheduled for deletion. Backups containing your data are rotated within a reasonable window and then permanently removed.

6. Your rights

You can, at any time:

  • view, edit, or delete individual checklists and items in-app;
  • change your display name, password, and email address;
  • delete your entire account from the in-app settings;
  • contact us at support@thaktive.com to request a copy of, correction of, or deletion of your personal data.

Depending on where you live (e.g. EEA / UK under GDPR, California under CCPA), you may have additional rights such as objecting to processing or lodging a complaint with a supervisory authority.

7. International transfers

Our hosting providers may store and process data in regions outside your country of residence. We rely on industry-standard safeguards and our vendors' contractual commitments for cross-border data transfers.

8. Security

We use HTTPS/TLS in transit, hashed passwords, scoped session tokens, and apply security updates regularly. No system can guarantee absolute security; please choose a strong, unique password.

9. Children

The Service is not directed to children under 13 (or the age of digital consent in your jurisdiction). If you believe a child has provided us personal information, please contact us so we can delete it.

10. Changes to this policy

We may update this policy from time to time. The “Last updated” date above reflects when the latest version took effect. Material changes will be highlighted on this page.

11. Contact

Privacy questions or data requests? Email support@thaktive.com, or use the contact page. The data controller is Thaktive International Limited.

Privacy Policy|EZCheck