1. Who We Are
Still Here ("we", "our", "us") operates the website soimok.com and the Still Here wellness check-in service. We are committed to protecting your privacy and handling your data transparently and lawfully.
2. Data We Collect
2.1 Information You Provide
- Account data: Name, email address, and random access-link tokens with expiry dates. The current implementation does not use passwords.
- Check-in data: Your responses (or non-responses) to scheduled check-ins, including timestamps.
- Emergency contact data: Names, email addresses, and phone numbers of people you designate as emergency contacts. These individuals must consent to being listed.
- Settings & preferences: Check-in frequency, active hours, a timezone setting and a pause flag. Storing a timezone does not prove scheduling has been verified in that timezone.
- Payment data: We do not store your credit card details. Payments are processed by Dodo Payments.
2.2 Information Collected Automatically
- Technical data: IP address, browser type, device information, and access timestamps, collected in server logs for security and operational purposes.
- Cookies and advertising technology: The current account implementation uses an emailed access token. Do not share token-bearing URLs. Hosting requests expose network information to the provider. When advertising is active, Google and authorized advertising partners may use cookies, web beacons, IP addresses, and similar identifiers to deliver and measure ads, prevent fraud, and, where you consent, personalize advertising. Google advertising is currently paused. Before enabling it, we must verify a Google-certified CMP and the required consent controls for the EEA, UK and Switzerland.
3. How We Use Your Data
- To provide the check-in service: dispatching check-ins, processing responses, and escalating to emergency contacts when configured thresholds are met.
- To send transactional emails: access links, contact invitations, check-in prompts and account notifications; successful delivery is not guaranteed.
- To process payments via Dodo Payments.
- To maintain service security: rate limiting, abuse detection, and fraud prevention.
- To comply with legal obligations.
- To support advertising delivery and measurement only after the consent choices required for your location have been collected.
We do not sell account, check-in, or emergency-contact data. We do not send this service data to Google for advertising or use it to build advertising profiles. We do not train machine learning models on your data.
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases:
- Consent: Where processing relies on consent, you may withdraw it by contacting us. Creating an account is not blanket consent to every purpose. Other legal bases can apply to service delivery or required recordkeeping.
- Advertising consent: Where required, advertising storage, measurement, and personalization are based on the choices you make in the consent message. You can refuse or manage these choices there.
- Contractual necessity: Processing your data is necessary to provide the check-in service you signed up for.
- Legitimate interest: Server logs and security measures protect our service and your data from abuse.
5. Data Sharing & Third Parties
We share data only with the following service providers, and only to the extent necessary:
- Cloudflare: Hosts our infrastructure (Workers, D1 database). Service data may be processed by the hosting provider. We do not offer a verified user-selectable storage region. If Cloudflare Web Analytics is enabled at the hosting layer, it also processes website performance and usage measurements.
- Dodo Payments: Processes payments.
- Google Fonts: Fonts requested from Google can expose your IP address and request details to that provider.
- MailChannels: Routes our transactional emails. Email content passes through their servers for delivery.
- Google advertising services and authorized advertising partners: When advertising is active, these parties may process device and online identifiers for ad delivery, measurement, and fraud prevention. Personalized advertising is subject to the consent choices required in your location.
We may disclose data if required by law or in good-faith belief that disclosure is necessary to protect our rights, your safety, or the safety of others.
6. Advertising Choices
Google ad loading is paused. Before advertising resumes, visitors in the EEA, UK and Switzerland must receive the required certified consent message. You can select consent, refuse consent, or manage options in that message. Google may also provide privacy controls so that you can revisit your choices. For more information about how Google uses information from sites that use its services, visit Google's partner sites policy.
7. Emergency Contact Data
When you add emergency contacts, we send them a confirmation notice explaining the nature of the service and their role. They may opt out at any time. We store their contact information solely for the purpose of delivering escalation notifications. Emergency contacts can request deletion of their data by contacting us.
8. Data Retention
- Active account: Data is retained while your account is active.
- Account deletion: Request deletion through the privacy contact below. Automatic deletion within 30 days has not been implemented or verified; cancellation alone does not establish erasure. Applicable legal recordkeeping may require retaining some records, which must be explained when handling a request.
- Server logs: Retention depends on the provider and operational configuration; this site has not verified a universal 90-day maximum.
9. Your Rights
9.1 GDPR Rights (EEA/UK Residents)
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Request limited processing of your data.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: At any time, without affecting the lawfulness of prior processing.
9.2 CCPA Rights (California Residents)
- Right to know: Request disclosure of categories and specific pieces of personal data collected.
- Right to delete: Request deletion of personal data.
- Right to opt out: We do not sell service data. You may still contact us to ask about applicable sale, sharing or advertising opt-out rights.
- Non-discrimination: We will not discriminate against you for exercising CCPA rights.
To exercise any right, email us at privacy [at] soimok [dot] com. We may need proportionate identity verification and will handle the request under applicable requirements. Do not send identity documents or access tokens unless a suitable secure process has been agreed.
10. International Data Transfers
Our infrastructure (Cloudflare, Dodo Payments) operates globally. Data may be transferred to and processed in the United States and other jurisdictions. The applicable transfer arrangements must be confirmed for each provider and purpose; this page does not claim that every contract or certification has been verified. Contact us for information relevant to your data.
11. Children's Privacy
Still Here is not intended for individuals under 18 years of age. We do not knowingly collect data from children. If we learn we have collected data from a child, we will delete it promptly.
12. Security
We implement appropriate technical and organizational measures to protect your data, including HTTPS and token checks in the service implementation. Deployment and provider controls require separate verification. For details, see our Security page. No method of transmission or storage is 100% secure. In the event of a data breach affecting your personal data, we will notify you and relevant authorities as required by law.
13. Changes to This Policy
We will notify you of material changes via email or a prominent notice on our website before the changes take effect. Continued use of the service after changes constitutes acceptance.
14. Contact
For privacy-related inquiries or to exercise your rights:
Email: privacy [at] soimok [dot] com
Response time: Within 30 days (GDPR requirement) or sooner.
You also have the right to lodge a complaint with your local data protection authority.