Last updated: March 29, 2026 · We take your privacy seriously.
PushWave ("we", "us", "our") is a web push notification platform. We operate the PushWave service accessible at this domain. For GDPR purposes, PushWave is the data controller of account and usage data. For subscriber data collected on your behalf, you are the data controller and we act as your data processor.
When you register, we collect: name, email address, hashed password, company name (optional), and payment details (processed by Stripe/PayPal — we never store card numbers).
We automatically collect: IP address, browser type, operating system, pages visited, feature usage, and API call logs. This data helps us improve the service and diagnose problems.
When your website visitors subscribe to push notifications, we collect on your behalf: browser push endpoint URL, browser type, OS, device type, country, and language. This is the minimum data required to deliver push notifications.
| Data Type | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Account info | Provide the service | Contract | Until deletion + 30 days |
| Payment data | Process subscriptions | Contract | 7 years (tax law) |
| Usage logs | Security, debugging | Legitimate interest | 90 days |
| Push endpoints | Deliver notifications | Contract / Consent | Until unsubscribed |
| Analytics | Service improvement | Legitimate interest | 2 years |
We never sell your data or use it for third-party advertising.
We share data only with trusted service providers necessary to operate PushWave:
We may disclose data if required by law, court order, or to protect the rights and safety of PushWave and its users.
We retain your account data for as long as your account is active. When you delete your account, we permanently delete all your data within 30 days, except where we are required to retain it for legal or tax purposes (up to 7 years for financial records).
Push subscriber data is deleted when a subscriber unsubscribes, or when you delete your account.
You have the right to:
For EU/EEA residents, see our GDPR page for additional rights and how to exercise them. To make a request, email privacy@pushwave.io. We will respond within 30 days.
We use the following cookies:
We do not use advertising cookies or third-party tracking cookies. We do not participate in cookie-based ad networks.
We protect your data with industry-standard security measures: HTTPS encryption in transit, bcrypt password hashing, parameterized SQL queries to prevent injection attacks, and regular security updates. Sensitive API keys are stored encrypted.
No system is 100% secure. If you discover a security vulnerability, please report it responsibly to security@pushwave.io.
PushWave is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us data, contact us and we will delete it promptly.
For privacy-related questions or to exercise your rights: