Skip to content
Back to Diff Stage

Privacy notice

Updated: 6 October 2026.

Who we are

Kim Ward, a sole trader trading as Diff Stage, United Kingdom, is responsible for our account, billing and support information. Address: 58 Upperfield Road, Maltby, Rotherham, S66 8BG. Contact: support@diffstage.com.

For personal data in evidence uploaded by a customer, we process it on that customer's instructions to host and review their browser tests. The customer decides what to record and why. If you appear in a recording, contact that customer first; you can also contact us to help route your request.

What we collect

  • Accounts and teams: your name, email, password hash, GitHub account ID, team memberships, roles and invitations. These come from you, GitHub sign-in or your team administrator.
  • Repositories and evidence: repository details and visibility, integration identifiers, branches, commit hashes, pull-request numbers and titles, test names, review notes, baseline decisions, videos, posters and diagnostic telemetry. These come from your team, CI uploads and GitHub. Recordings and telemetry may contain screen contents, URLs, console output, network details and personal data captured by your tests.
  • Billing and usage: purchaser contact details, billing name and address, agreed terms, invoices, subscription/payment status and identifiers, plan limits and storage usage. These come from you, Stripe and our service. Payment details go through Stripe's hosted checkout; we do not receive your full card number. Billing is currently in test mode: do not enter real payment details.
  • Service and support: evidence-view history for signed-in team members, session information, IP addresses and browser/request details where logged, errors and support correspondence. These come from using the service or contacting us.

Account and authentication details are needed to provide account access; billing details are needed for billing functions. Without them we may be unable to provide those functions. Please use synthetic test data and avoid uploading secrets or sensitive personal information. We do not automatically redact recordings.

Why we use it

For information we control ourselves, we use these UK GDPR legal bases:

  • Contract: providing your account and requested service, administering your subscription and answering related support requests when you are the contracting customer.
  • Legitimate interests: administering customer teams and authorised access, showing review progress, keeping the service reliable and secure, preventing abuse, responding to enquiries and resolving disputes. This also covers service administration involving team members who are not personally the contracting customer.
  • Legal obligations: keeping records required for accounting, tax and other applicable legal duties.

The customer's own purposes and legal basis apply to personal data in their uploaded evidence. This notice does not give us blanket consent to use it for other purposes. We do not sell personal data or use uploaded evidence for advertising. We do not make solely automated decisions with legal or similarly significant effects on people.

Sharing and suppliers

Team members can see information according to their access permissions. Public evidence can be viewed without signing in by anyone with the link. Evidence for private connected repositories requires a verified account belonging to the owning team. Protected GitHub projects also restrict access after disconnection. A private storage bucket does not make all evidence private.

Authorised GitHub publication shares evidence links, review descriptions and, for public evidence, previews in repository discussions. Copies held by GitHub or other viewers may remain after deletion from Diff Stage.

We use:

  • Laravel Cloud for application hosting and database services, including its infrastructure providers.
  • Cloudflare R2, provisioned through Laravel Cloud, for video and poster storage.
  • GitHub for optional sign-in, repository integration and authorised evidence publication.
  • Stripe for hosted checkout, subscription management and billing records.
  • Cloudflare SMTP for account verification, password resets, team invitations and billing emails.
  • Cloudflare Email Routing and Google's Gmail for support email: messages to support@diffstage.com are forwarded to the operator's Gmail mailbox. Please avoid sending recordings, secrets or sensitive attachments by email.

GitHub, Stripe and Google also process information for their own services under their privacy policies: GitHub, Stripe and Google.

The operator and suppliers may access data as needed for administration, support and security. We may share relevant information with advisers or authorities where required by law or necessary to establish or defend legal claims.

Where information is processed

Our application and database are configured in London, United Kingdom. The private evidence bucket has EU jurisdiction. These settings do not confine all supplier access, support, logs or other processing to those regions. Our suppliers, including GitHub, Stripe, Cloudflare and Google, operate internationally and may process information outside the UK, including in the United States.

The protection applicable to a transfer depends on the provider and processing involved. UK adequacy regulations and contractual safeguards, such as standard contractual clauses with a UK Addendum, are available mechanisms where applicable; we do not claim every supplier operation is covered by the same mechanism. Contact support@diffstage.com for information about a particular transfer and the applicable safeguards.

How long we keep it

  • Ordinary evidence: runs become eligible for pruning 30 days after creation. Pruning removes their videos, posters and associated run records. Runs containing approved baselines, or baselines referenced by comparisons created within the last 30 days, can be kept longer. Eligibility is not a guarantee of deletion at exactly 30 days.
  • Accounts, teams and integration details: kept while needed to provide the service. Account closure may require support where team ownership or billing remains unresolved.
  • Billing records: kept as needed for accounting, tax obligations and handling payments or disputes, separately from evidence retention.
  • Support and logs: kept for as long as needed to resolve enquiries, diagnose problems, protect the service or handle a specific legal claim.
  • Database recovery copies: the recovery window is seven days. This does not promise recovery of deleted video objects, or a fixed deletion period for every supplier's backup or operational copy.

Cancelling billing or disconnecting GitHub does not delete evidence. Authorised team administrators can delete runs using the application controls. Contact us for other deletion requests. We cannot directly erase copies independently held by other people or services.

Security and cookies

We use HTTPS, password and upload-token hashing, team access checks and private object storage with temporary video delivery links. Keep delivery links private when sharing private evidence. No system can guarantee absolute security.

We use session and security cookies for sign-in and request protection. The application does not currently include advertising or analytics trackers. GitHub and Stripe apply their own cookie practices when you visit their services.

Your rights and contact

Depending on the circumstances, you can request access, correction, deletion, restriction or a portable copy of your personal information, and object to processing based on legitimate interests. If processing relies on consent, you can withdraw it without affecting earlier lawful processing.

Email support@diffstage.com. We may need to verify your identity and clarify the request. Requests are normally free and answered within one month; we will explain any lawful extension. For customer-controlled evidence, we help the customer respond. Requests for copies or deletion can be handled through support; this notice does not promise a self-service export tool.

You can complain to the UK's Information Commissioner's Office (ICO), whether or not you contact us first.

We update this notice when our processing changes and will draw material changes to your attention where appropriate.