Privacy Policy
uls-tracker is a U.S.-based service. This policy explains what personal data we collect, why we collect it, who else processes it, and how you get rid of it.
Last updated: 6 September 2026
Who we are
The Service is independently operated in Texas under the name Ice Code Studio. Privacy questions: [email protected].
What we collect
Data you give us
- Email address — required. It is both your identity and the delivery channel: sign-in is by magic link, and alerts and digests go to the same address. We do not ask for a name, callsign, or address.
- Watchlist — the callsigns you choose to track and what kind of change you want to hear about.
- Notification preferences — digest frequency, which alert types are enabled.
- Payment details — entered directly into Stripe, never into our servers. We store only Stripe's customer and subscription identifiers plus your plan status and renewal date. We never see or store your card number, CVC, or bank details.
Data generated by using the Service
- Session cookie — a single first-party cookie holding an opaque session token, set after you click a magic link. It is strictly necessary to keep you signed in. We use no advertising or cross-site tracking cookies.
- Sign-in tokens — short-lived, single-use, expire after 15 minutes.
- API keys — if you create one, we store a hash of it, not the key itself, so requests can be attributed to your account and rate-limited.
- Server logs — ordinary request logs (IP address, timestamp, path, user agent) kept for security, abuse prevention, and debugging.
- Email delivery events — deliveries, bounces, and complaints reported back by our email provider, so we can stop mailing addresses that reject us.
What we do not collect
No advertising SDKs, no cross-site trackers, no fingerprinting, no behavioural profiles. The one analytics script we load is Cloudflare Web Analytics, which is cookieless, sets no identifiers, and reports only aggregate page-load metrics (page URL, referrer, country, browser) to Cloudflare, listed as a subprocessor below. We do not buy personal data about you from anyone and we do not sell or rent your data to anyone.
Note that the callsign and licensee records displayed on the Service come from the FCC's public Universal Licensing System. That is U.S. government public data about licence holders — it is not collected from you, and we cannot remove it at our discretion. Corrections have to go through the FCC.
Why we use it
- To sign you in and keep you signed in (magic links, session cookie).
- To provide the features you asked for — watchlists, alerts, digests, exports, API access.
- To take payment and manage your subscription.
- To keep the Service secure and enforce rate limits and tier caps.
- To send necessary service messages — billing failures, security notices, material changes to these policies.
We send no marketing email. Alert and digest email can be turned off entirely, or per alert type, in notification settings. Turning email off does not close your account.
Third-party processors
We keep the list short on purpose. Each of these receives only what it needs to do its job:
- Stripe (payments) — receives your email address and the card details you enter into Stripe's own hosted form, and returns customer/subscription identifiers to us. Stripe acts as an independent controller for fraud prevention and its own compliance obligations.
- Postmark (transactional email) — receives your email address and the contents of sign-in links, alerts, and digests in order to deliver them, and reports delivery status back to us.
- Cloudflare (CDN, DNS, TLS, DDoS protection) — proxies requests to the Service and therefore processes connection metadata such as IP address and user agent in transit.
- Nocix (dedicated server hosting, Kansas City, Missouri, USA) — runs the application and the database.
- Google (Gmail) (contact and support mail) — receives whatever you send to our contact address, and our replies.
These are the processors we rely on today. If we add one, this list changes with it and the "last updated" date moves.
How long we keep it
- Account, watchlist, preferences — for as long as your account exists.
- Sessions — expire 30 days after sign-in, or immediately on sign-out. An expired session is cleared the next time it is checked, not on a fixed schedule.
- Sign-in tokens — invalid after 15 minutes or as soon as used, whichever comes first. The spent token record itself is not purged; it stays in the database attached to your account.
- Server logs — nginx access and error logs on the server are rotated daily and kept 14 days. Application logs go to the system journal, which is capped by disk size rather than a fixed number of days.
- Billing records — retained by us and by Stripe for as long as U.S. tax and accounting rules require, even after you close your account.
Your choices
- Access and export — your watchlist is visible and exportable from your account settings. Email us for anything else we hold about you.
- Correction — you can change your notification preferences yourself. To change the email address on your account, email us. FCC record errors have to be corrected at the FCC.
- Deletion — there is no self-service delete yet. Email [email protected] and we will delete your account — email address, watchlist, preferences, API keys, and sessions — within 30 days. Billing records we are legally required to keep are retained as above.
- Email opt-out — turn digest email off entirely, or turn individual alert types off, in notification settings.
Depending on where you live, applicable law may give you additional privacy rights. We accept access, correction, and deletion requests from all users at [email protected].
Security
All traffic is served over HTTPS. Session cookies are HTTP-only and restricted to this site. Sign-in links are single-use and short-lived, and we store no passwords, so there is no password database to leak. No system is perfectly secure; if we discover a breach affecting your data we will notify affected users by email.
Children
The Service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
Changes to this policy
We will post updates here and move the "last updated" date. Material changes are announced by email to registered users before they take effect.
Contact
Privacy questions, access requests, or deletion requests: [email protected]. See also our terms of service.