Skip to content

Privacy Policy

Last updated: July 19, 2026

Online Alarm respects your privacy, and this Privacy Policy (the “Policy”) explains how we handle information about you when you use the website at online-alarm.com (the “Site”).

1. Our Services and the Scope of this Policy

The Site is a browser-based collection of time, timing, and scheduling tools. It includes an alarm clock, an online clock, a world clock, a stopwatch, a countdown timer, event countdowns, a date calculator, an hour calculator, a time zone converter, a study timer, a chess clock, a meeting planner, a “do nothing” timer, and a “time until” countdown, together with a feedback form and optional user accounts (collectively, the “Services”).

How much personal data we process, if any, depends on how you use the Site as a visitor, a registered user, or a premium user. Those roles are described in our Terms of Service, and the data practices for each follow in Section 4.

This Policy describes the source and types of personal data we process, why we process it, our legal grounds, who we share it with, how long we keep it, and your rights and choices.

2. Acknowledgment of the Policy

This Policy is provided to inform you of our data practices. Using the Site does not by itself amount to consent to any processing that requires your consent under applicable law. Where we rely on consent, we ask for it separately, and you are free to decline.

If you do not agree with the practices described here, please do not access the Site or use the Services.

3. Data Controller and Applicable Law

The data controller responsible for your personal data is:

  • Legal Identity: Burak Ozdemir, self-employed (autónomo) registered in Spain
  • Registered Country: Spain
  • Business Address: Calle Puerto 14, 5th floor, 29016, Málaga, Spain.
  • Contact Address: support at online-alarm [dot] com

We are established in Spain, so our processing of your personal data is governed by the EU General Data Protection Regulation (the "GDPR") under its Article 3(1) and by Spain's Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (the "LOPDGDD"). The UK GDPR applies to users in the United Kingdom.

Supervisory Authorities

Our lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, the "AEPD"), at aepd.es. If you are in the EEA, you may also lodge a complaint with the supervisory authority in your own country. If you are in the United Kingdom, you may complain to the Information Commissioner's Office, at ico.org.uk.

4. Data Subjects

What personal data we process, where it is stored, and how it is used depends on how you interact with the Site. Your user status determines each of these.

Visitors

Visitors can use the tools without creating an account. We collect no registration data from you. Your alarms, saved cities, meeting-planner locations, study-timer segment names, tool settings, and similar items are stored locally in your browser using local storage and similar browser storage and are never transmitted to our servers. This local data is tied to your browser and device. It may be lost if you clear your browser data or switch devices or browsers, and you can delete it any time by clearing your browser data for the Site.

Because we have no server-side access to this local data, our processing for visitors is limited to what happens automatically when any device connects to a website: server log data (including IP address and request details, which we keep for security) and cookieless, aggregate analytics through Ahrefs Web Analytics, which does not track individual users.

Registered Users

Registered users create an account by providing an email address, a username, and a password. If social login is offered and you choose it (for example, Google), we receive from that provider the account information you permit through your settings, which may include your name, email address, and profile picture.

Once you sign in, the content needed to sync across your devices, currently your alarms, the cities you save to the world clock and meeting planner and their working hours, and related settings, is transmitted to and stored on our servers (on Laravel VPS infrastructure) so that it is available on each device where you sign in. This content is visible only to you through your account. We do not publish it or make it visible to other users.

Our processing for registered users is broader than for visitors: in addition to server logs and analytics, we process your account registration data, the content you sync to your account, and account-related email such as verification messages, service notifications, and security notices.

When you use alarms while signed in, we also record alarm lifecycle events, such as an alarm firing, being dismissed, or being delayed, together with the alarm's scheduled time, your timezone, and a country-level location derived from your connection. We process this to operate the Service and to produce aggregate, anonymised usage statistics. Our legal basis is our legitimate interest in understanding and improving the Service.

Premium Users

Premium users are registered users who have taken an optional paid subscription to remove advertisements and access additional features. All practices that apply to registered users apply equally to premium users.

In addition, a premium purchase involves a payment transaction handled by our merchant of record, Polar Software, Inc. (polar.sh). We do not receive or store your payment card details or billing address; those are processed by Polar as the seller of record, and the billing relationship for the transaction is between you and Polar. What we store on our servers is your premium status and the start and renewal dates needed to give you access for as long as your subscription is active. If we change our merchant of record, we will update this Policy.

Children

The Site is not directed at children. You must be at least thirteen (13) years old to use it. To create an account, you must also meet the minimum age of digital consent that applies in your country, which in parts of the EEA is higher than thirteen (13) and may be up to sixteen (16). Below the applicable age, you may only use an account with the consent, under the supervision, of a parent or legal guardian who agrees to our Terms of Service.

We do not knowingly collect personal data from a child below the applicable age without that consent. If you believe a child has provided us with personal data without it, please contact us at support at online-alarm [dot] com, and we will take steps to delete it promptly.

5. Sources, Types, Purposes and Legal Bases of Processing

We process personal data in different ways depending on how you use the Site. For each activity below, we give the source and type of data, why we process it, and our legal bases.

Technical Server Logs (all users)

When any device connects to the Site, our server (Nginx) automatically records technical information in log files, including your IP address, browser type, operating system, and the date and time of the request.

We process these logs to keep the Site secure and stable, to detect and prevent attacks and abuse, and to troubleshoot faults. Our legal basis is our legitimate interest in the security and integrity of the Services.

These logs are stored securely, are not used for marketing or analytics, and are accessed only for security investigations, to resolve critical technical faults, or in response to a lawful request from a competent authority. They are held on our Laravel VPS infrastructure and kept only as long as needed for those security purposes; logrotate deletes them automatically after no more than six (6) months.

Content You Use As a Visitor (Local Storage)

When you use the Site as a visitor without signing in, your alarms, saved cities, settings, and similar items are stored locally in your browser. This data stays on your device. We cannot access, see, or store it, and it is not transmitted to us. The only handling that occurs is your own browser reading and writing it locally so the tool works on your device. Because this data does not reach us, we do not process it as a controller, and you can delete it at any time by clearing your browser data for the Site.

Content Synced to Your Account (Registered Users)

When you sign in, the content needed to sync across your devices, currently your alarms, the cities you save to the world clock and meeting planner and their working hours, and related settings, is transmitted to and stored on our servers (Laravel VPS infrastructure) so it is available on each device where you sign in. We process it to provide the sync feature and to maintain your account. This content is visible only to you; we do not publish it or make it available to other users. Our legal basis is the performance of our contract with you, meaning the provision of the account and sync features you asked for. You can delete this data and your account at any time through your profile settings.

Account Registration Data

If you create an account, we collect your email address, username, and password directly from you. Passwords are stored only in hashed form and are never held in plaintext. If social login is offered and you use it (for example, Google), we receive from that provider the information you permit through your settings, which may include your name, email address, and profile picture. After registration, we may process your email address to send a verification message and account-related notices. Our legal bases are performance of our contract with you and, for account security notices, our legitimate interest in protecting accounts. We store this data on our Laravel VPS infrastructure for as long as your account is active. For retention of your account registration data, see Section 9.

Premium Users

If you take a premium membership, the payment itself is handled exclusively by our merchant of record, Polar Software, Inc. (polar.sh), as the seller of record. We do not receive or store your card details or billing address. What we store is your premium status and the start and renewal dates needed to give you access to the premium features. Our legal basis is the performance of our contract with you. Polar processes your payment data as a controller in its own right; see Polar's privacy policy. For retention of your subscription-status data, see Section 9.

Feedback

If you contact us through the feedback form or by email, we process the message and the contact details you provide in order to read and respond. Our legal basis is our legitimate interest in handling inquiries and improving the Site.

Analytics

We use Ahrefs Web Analytics to understand overall Site traffic. The provider operates it without cookies and does not track individual users across sites. To the extent any identifier such as an IP address is handled momentarily to produce aggregate statistics, we rely on our legitimate interest in understanding and improving the Site, and the statistics we retain are aggregated and do not identify you.

Marketing Email

We do not send marketing or promotional email. The only emails we send are transactional: verification, security, and service notices related to your account.

6. Third-Party Service Providers and Recipients

To run the Site securely and reliably, we work with the providers below. Some act as our processors on our instructions; others, namely Polar as our merchant of record, any sign-in provider you choose, and Google as our advertising partner, act as controllers in their own right for their part of the processing, under their own privacy policies.

Laravel VPS (Hosting)

Laravel VPS provides the hosting infrastructure on which the site runs. For all users, it processes server logs (IP address, browser type, operating system, and timestamp). For registered and premium users, it also stores account data (email address, username), synced content, and subscription status. The Laravel VPS servers are located in the United States. Laravel VPS acts as our processor. Our legal basis is the performance of a contract and legitimate interest. For details on how Laravel VPS handles data, please refer to Laravel's privacy policy.

Cloudflare (Security and Delivery)

Cloudflare helps protect the Site from malicious activity and speeds up content delivery. It may process your IP address and technical device data to distinguish between real human visitors and malicious bots or automated attacks. Cloudflare is a US-based service, and data may be processed in the United States. Our legal basis is our legitimate interest in the security and integrity of the Service. Cloudflare sets its own retention periods; please refer to Cloudflare's privacy policy for details.

Google AdSense (Advertising)

We show advertising to non-premium users through Google AdSense. Google uses cookies and similar identifiers to serve ads and processes online identifiers, including cookie IDs, device identifiers, and IP addresses, to display ads, prevent fraud, and cap how often you see a given ad and, if you agree, to personalize ads based on your browsing. Our legal basis is your consent. This processing happens only if you consent through the ad consent banner on the Site. We use Google's integrated Consent Management Platform (CMP); you can change your ad preferences or withdraw consent at any time through the ad settings overlay on the Site or a similar mechanism made available. Withdrawing consent does not affect processing carried out before you withdrew it, and after withdrawal Google will no longer use your data for personalized advertising on this Site. For details on how Google handles this data, please refer to Google's privacy policy.

Polar Software, Inc. (polar.sh) (Merchant of Record)

Premium payments are processed by Polar as our merchant of record and the registered seller, which is responsible for processing the transaction and collecting applicable taxes. We do not receive or store your card details or billing address, and your billing relationship for the payment is with Polar. Polar acts as a controller for the payment data it processes. Our legal basis for our related processing (storing your premium status to give you access) is performance of our contract. We reserve the right to change our Merchant of Record at any time, in which case we will update this Policy accordingly. For details on how Polar handles your payment data, please refer to polar.sh's privacy policy.

7. Cookies

Our Own Cookies

We do not set any first-party cookies for tracking or analytics. Where we need to remember a strictly necessary choice, such as your consent preference or your signed-in session, we use the minimum browser storage required for that function, and we describe it here.

Name Purpose Type Party Duration
online-alarm-session Keeps you signed in during a session Strictly necessary First party 2 hours
XSRF-TOKEN Enhances visitor browsing security by preventing cross-site request forgery Strictly necessary First party 2 hours
remember_web_* Keeps you signed in across browser sessions Strictly necessary First party 400 days
sidebar_collapsed Remembers whether you collapsed the navigation sidebar Functional (preference) First party 1 year

Third-Party Cookies

As mentioned above, Google AdSense may set cookies and similar identifiers to serve and measure ads on this Site and across the web, as described in Section 6.

You can opt out of personalized advertising by visiting Google's Ad Settings. To understand how Google processes data through its partners, visit Google's Partner Policy page.

8. Sharing of Personal Data

We do not sell, rent, or trade your personal data with third parties for their marketing purposes. We share personal data only in the following circumstances:

  • Our hosting provider, Laravel VPS, stores and processes technical data (including IP addresses and server logs) and, for registered and premium users, account data, synced content, and subscription status solely to run the infrastructure the Site depends on. Our security and delivery provider, Cloudflare, processes IP addresses and technical device data solely to protect the Site against malicious traffic and attacks. Both act as our processors, and our legal bases are performance of contract and legitimate interest.
  • If you consent to advertising, Google processes advertising data to serve and measure ads, as described in Section 6 and Section 7. This happens only if you consent through the ad consent banner.
  • If you take a premium membership, your chosen plan and an account identifier are passed to Polar Software, Inc. (polar.sh) to start the transaction. Your card details and billing address are entered directly with Polar and are never transmitted to or stored by us. Polar acts as a controller for the payment data it handles.
  • Content you sync to your account is visible only to you. We do not display it publicly, rank it, or make it available to other users.
  • Our authorized contractors or developers may access technical logs where necessary to investigate security threats or resolve critical faults, on the basis of our legitimate interest. They are bound by confidentiality obligations and may act only on our instructions.
  • If we go through a business transition such as a merger, acquisition, or sale of assets, your personal data may be among the assets transferred. We will tell you through the Site or by email before it takes effect, and we will require the acquiring party to honor this Policy or to give you notice and choices consistent with it.
  • We may disclose personal data to courts, law enforcement, or government authorities where required by a lawful request, court order, or legal process, on the basis of compliance with a legal obligation. Where we are legally able to, we will try to notify you before disclosing.
  • We may use and disclose personal data where necessary to protect the security and integrity of the Services and to enforce our Terms of Service, on the basis of our legitimate interest.

9. International Transfers and Data Retention

Where your data is processed

We are established in Spain. Some of our service providers are located outside the EEA, principally in the United States: Laravel VPS (hosting), Cloudflare (security and delivery), Google (advertising, if you consent), and Polar (payment, as merchant of record). As a result, personal data, including server logs and, for registered and premium users, account data and synced content, may be transferred to and processed in the United States.

Transfers from the EEA and the UK

For users in the EEA and the UK, we transfer personal data to these providers on the basis of the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) under GDPR Art. 46, and, where a provider is certified, the EU-US Data Privacy Framework. These provide appropriate safeguards for your data. You can ask us for information about the safeguards that apply, using the contact details in Section 15.

Data Retention Periods

Technical Server Logs (IP addresses and access data) are retained for no longer than six (6) months and then deleted automatically using logrotate on our Laravel VPS infrastructure.

Local Storage Visitor Content (alarms, saved cities, settings held in local storage) is stored only on your device. We set no retention period because we do not hold it; it stays on your device until you delete it or clear your browser data.

Registered User Account Data and Synced Content (email address, username, alarms, saved cities, and settings) are kept for as long as your account is active. When you delete your account, we permanently delete this data from our servers within thirty (30) days, apart from anything we must retain by law.

Alarm Lifecycle Events (alarm firing, dismissal, and delay events, together with the alarm's scheduled time, your timezone, and a country-level location) are kept for as long as your account is active, like the rest of your account data. They are deleted when you delete your account.

Premium Subscription Status (subscription plan identifier and active/inactive status) is kept for as long as your subscription or account is active. After account deletion, cancellation, or termination by us for cause, we retain it for one hundred and twenty (120) days to handle potential payment disputes and chargebacks, then delete it permanently. Card details and billing addresses are never stored by us; they are held by Polar as the merchant of record.

Analytics via Ahrefs are aggregated and contain no personal data, and we may keep them for historical traffic analysis.

10. Security

We use organizational, technical, and administrative measures designed to protect your personal data against unauthorized access, destruction, alteration, or misuse. We work with providers such as Cloudflare to defend the Site against denial-of-service (DDoS) attacks, malicious bots, and unauthorized access.

If you use the Site as a visitor, your data stays in your browser's local storage and is not held on our servers, so its security depends on the security of your own device. For registered users, account data and synced content are held on our Laravel VPS infrastructure, and access is limited to authorized personnel. We do not store payment card details; payment is handled by our merchant of record, Polar. Access to server logs is limited to authorized personnel and used only for troubleshooting and security investigations.

No method of transmission or storage is completely secure, so while we work to protect your data, we cannot guarantee absolute security.

11. Your Data Protection Rights

The legal framework and the authorities that apply to you are described in Section 3. In short, the GDPR governs our processing because we are established in Spain and offer the Site to people in the EEA, and the UK GDPR applies to users in the United Kingdom.

Subject to the conditions and exceptions in the applicable law, you have the following rights.

Your right to access: You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data together with information about the categories, purposes, retention, and recipients.

Your right to rectification: You have the right to request correction or completion of your personal data if it is inaccurate or incomplete.

Your right to erasure ("right to be forgotten"): You have the right to request deletion of your personal data in certain circumstances, such as where the data is no longer necessary for the purpose for which it was collected or where you withdraw consent. We may be unable to comply fully where retention is required by applicable law or where a retention period set out in Section 9 has not yet expired. Please note that for data stored in your browser's local storage as a visitor, we have no server-side access and cannot erase it for you; you can remove it by clearing your browser data. For server-stored account data, you can request erasure or delete your account through the Site's settings.

Your right to restriction of processing: You have the right to request that we restrict processing of your personal data in certain situations, such as where you contest the accuracy of the data or object to our processing on legitimate interest grounds.

Your right to data portability: Where we process your personal data by automated means on the basis of your consent or the performance of a contract, such as your account details and synced content, you have the right to receive that data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.

Your right to object to processing: You have the right to object to processing of your personal data where we rely on legitimate interest as our legal basis, on grounds relating to your particular situation. You may object to processing for direct marketing at any time.

Your right to withdraw consent: Where we process your personal data on the basis of your consent (including consent to personalized advertising through Google AdSense) you have the right to withdraw that consent at any time through the relevant control. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Your right not to be subject to solely automated decision-making: You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects concerning you. We do not make such decisions.

Your right to lodge a complaint: If you are not satisfied with how we handle your data, please contact us first so we can try to resolve it. You also have the right to complain to a supervisory authority. Our lead authority is the Spanish AEPD (aepd.es); if you are in the EEA you may also complain to the authority in your own country, and if you are in the UK, to the Information Commissioner's Office (ico.org.uk).

Notice to United States Residents

If you are a resident of California or another US state with comprehensive privacy legislation, you may have specific rights, including to know the categories of personal information we collect and the purposes and to access or delete your personal information, to correct inaccurate information, and to opt-out of the “sharing” of personal information for cross-context behavioral (targeted) advertising. We do not sell your personal information for money. Where we show personalized advertising through Google AdSense, that may be treated as “sharing” under some state laws, and you can opt out through the Google Consent Management Platform. To exercise any of these rights, contact us at support at online-alarm [dot] com. We will not discriminate against you for exercising them.

12. Exercising Your Data Protection Rights

We handle rights requests in line with the GDPR: we respond without undue delay and within one (1) month of receipt, extendable by a further two (2) months for complex or numerous requests, in which case we tell you within the first month. If we cannot complete a request within that period, we will tell you within it and give an expected date. If we refuse a request, we will explain why within that period.

You can exercise your rights by contacting us at support at online-alarm [dot] com. We may ask you to verify your identity before we act so that we do not disclose your data to someone else. Requests are free of charge. Where a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or decline to act, as the applicable law allows, and we will explain that decision.

13. Updates to this Policy

We may update this Policy to reflect legal, technical, or business changes. When we do, we post the revised version and update the “last updated” date at the top.

For minor changes that do not materially affect your rights or how we process your data, posting the updated Policy is the notice. For material changes, including changes to the categories of data we collect, the purposes, the legal bases, the recipients, or your rights, we will give registered users reasonable advance notice by email before the changes take effect. Where the change involves processing that requires your consent, we will ask for that consent separately rather than treating your continued use as agreement.

Continued use of the Site after an update means you are aware of the current Policy. It does not, by itself, amount to consent to any processing that the law says requires your separate consent.

14. Language

The governing language of this Policy is English. Any translations provided are for reference only, and the English version prevails in the event of a conflict. Communications about this Policy will be in English unless we agree otherwise.

15. Contact Information

If you have any questions or complaints about this Policy, or if you wish to exercise your rights, please contact us in writing at support at online-alarm [dot] com.