Privacy Policy

Our privacy policy and how we use your data

Last updated: 4 August 2026

The short version

We don’t sell your data, we run no advertising or cross-site trackers, and watching a shared demo is cookieless by default. The rest of this page is the detail: exactly what we store, why, and how to have it removed. It is written to match what the product does, not a template.

Two audiences are covered differently. Creators have an account and record, edit, and share demos. Viewers open a shared link — no account, and by default never personally identified.

Who we are

DemoMate is an interactive product-demo platform operated by DATAMESH DM CLOUDTECH LLP, a limited liability partnership registered in India (“DemoMate”, “we”, “us”). Questions about this policy go to [email protected].

Watching a demo is anonymous by default

If you only open a shared demo, we never identify you. We record aggregate, demo-level analytics — which steps were reached, completions, and call-to-action clicks. To attribute events within a single viewing session we generate a random session identifier in the browser’s memory. It is not a cookie, is never written to durable storage, and is discarded when the session ends, so it cannot recognise you on a later visit or across other sites.

We do not store your IP address, User-Agent, referrer, or request headers with these events. An IP address is used only to rate-limit abuse of the analytics endpoint, is never logged, and is hashed before it reaches storage — what is kept is a salted digest we cannot reverse, not the address. This is the same anonymous-by-default stance as privacy-first analytics like Plausible and Fathom, and reflects regulator guidance (e.g. the French CNIL) that genuinely anonymous, cookieless measurement needs no consent banner.

We honour opt-out signals. If your browser sends Global Privacy Control (GPC) or Do Not Track (DNT), we record nothing for your session. A demo link can also carry ?analytics=0 to disable measurement explicitly.

When a viewer becomes identified

You are only linked to personal data when you provide it, through one of three paths:

  • Submitting a form inside a demo (for example a lead-capture step).
  • Unlocking an email-gated demo — the creator required an email before the demo plays.
  • Opening a personalised link a creator sent with your details encoded in the URL (?u. parameters).

We do not verify this information — a viewer can type any email, and a personalised link carries whatever the creator put in it. Once given, that email and any form answers become a leadbelonging to the creator who owns the demo. For lead data the creator is the controller and DemoMate acts as a processor on their behalf. Creators can also forward demo view events — including any identity a viewer has provided — to webhook endpoints they configure; what happens to that data is governed by the creator's own privacy practices.

Cookies we set

We set no advertising or cross-site tracking cookies. On a shared demo we may set two strictly-necessary cookies, and only after a viewer unlocks an email-gated demo:

  • dm_gate_{id}— an HttpOnly access token that remembers a gate was passed, so the viewer isn’t re-prompted. Expires after 24 hours.
  • dm_gate_email_{id} — holds the email the viewer entered so the player can label their session. It is deliberately readable by the demo page (not HttpOnly) for that reason.

Full details are in our Cookie Policy.

Creator account data

To run your account we store what it needs — your name, email, organisation, and authentication credentials — managed through our authentication layer (Better Auth). Paid plans are billed through Paddle, our merchant of record; we never see or store your full card number, which Paddle handles directly.

Who else processes your data

A small set of vendors runs parts of the service, each processing data only to provide its function to us:

  • Cloudflare R2 — hosting for demo assets and published demo HTML.
  • Sentry — application error monitoring.
  • Resend — transactional email delivery.

Paddle acts as the merchant of record for every purchase: it is the seller and an independent controller of your payment and tax data, not a processor acting on our behalf.

How long we keep it

  • Deleted demos move to trash and are permanently purged, with their hosted assets, after 30 days.
  • Leads can be deleted by the creator at any time from the leads view; deleting a lead removes the associated viewer identity records and the copies held in our CRM and webhook delivery queues. A queued push also stops holding what the viewer typed the moment it succeeds — the contents are erased in the same write that marks the delivery done — and terminal queue rows are purged after 30 days. What we cannot reach is anything that has already left us, such as a notification email your team received or a record already pushed to a CRM you connected.
  • Form submissions (the answers typed into an in-demo form) are stored with the demo they belong to, not the lead — they remain until the demo itself is deleted and purged.
  • Account deletion — to close an account and remove its data, contact [email protected].

Your rights

You can ask us to access, correct, export, or delete your personal data, and to object to certain processing — email [email protected]. We answer within 30 days.

We are established in India, so our processing is governed by the Digital Personal Data Protection Act, 2023. If we do not resolve your request, you may complain to the Data Protection Board of India. Which additional statutory rights you hold depends on where you are: if you are in the EU/EEA or the UK, the GDPR and UK GDPR give you rights of access, rectification, erasure, portability, and objection, and you may complain to your local supervisory authority; if you are in California, the CCPA gives you rights of access and deletion and the right to opt out of the sale of personal information — we do not sell personal information. Whichever applies, the same address above reaches us.

Children

DemoMate is a business tool, not directed to children. We do not knowingly collect personal data from anyone under 18.

Changes and contact

We may update this policy as the product evolves; material changes appear here with a new “last updated” date. Privacy questions: [email protected]. General support: [email protected]. To report a demo that violates our terms, see Report abuse.