This Privacy Policy explains how Keyback Systems Ltd. ("Dual Login", "we", "us" or "our") collects, uses, shares and protects information when you visit https://duallogin.com, create an account, or use the Dual Login anti-detect browser and related services (together, the "Services").
We built Dual Login for legitimate business and privacy use. We try to collect as little personal data as we can, keep it only as long as we need it, and never sell it. By using the Services you agree to the practices described here.
1. Information we collect
We collect three kinds of information:
a) Information you give us
- •Account details — your name (or business name), email address and password (stored only as a salted hash).
- •Billing details — processed by our payment provider (see Payment information). We do not store full card numbers on our servers.
- •Support messages — anything you send us by email or through a support form.
- •Team details — if you invite teammates, the names, emails and roles you enter for them.
b) Information we collect automatically
- •Usage data — pages visited, features used, plan limits, and basic diagnostics that help us keep the Services working.
- •Device and log data — IP address, browser type, operating system, and timestamps, collected for security, fraud prevention and troubleshooting.
- •Cookies and similar technologies — see our Cookie Policy.
c) Browser profile data you create
The Services let you create browser profiles, each with its own fingerprint, cookies, local storage and (optionally) a proxy. Where you use the local desktop application, this profile data is stored on your own computer under your control. Where you enable cloud sync, encrypted copies of your profiles are stored so you can access them from other devices. We treat this profile data as confidential and do not inspect its contents except as strictly necessary to operate, secure or debug the sync service, or where required by law.
2. How we use your information
We use information to:
- •Provide, maintain and improve the Services.
- •Create and manage your account, team and subscription.
- •Process payments and send billing notices and receipts.
- •Respond to support requests and communicate service updates.
- •Detect, prevent and investigate fraud, abuse and security incidents.
- •Comply with legal obligations and enforce our terms.
We rely on the following legal bases under the GDPR: performance of a contract (to provide the Services), legitimate interests (to secure and improve the Services and prevent abuse), consent (for non-essential cookies and marketing, where required), and legal obligation (for tax, accounting and lawful requests).
4. Payment information (Stripe)
Payments are handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you pay, your card details are sent directly to Stripe and are not stored on our servers. We receive limited billing information from Stripe — such as the last four digits of your card, card brand, country, and the status of a payment — so we can manage your subscription and show your billing history.
Stripe processes your data as an independent controller for some purposes and as our processor for others, in line with Stripe's own privacy policy. We encourage you to review it.
5. Analytics
We use privacy-respecting analytics to measure traffic and improve the site. Where analytics rely on non-essential cookies or similar identifiers, we ask for your consent first in regions that require it. Analytics data is aggregated and used to understand trends, not to profile individuals.
6. Third-party services
We share personal data only with service providers who help us run the business, under contracts that require them to protect it and use it only for us. These include:
- •Payment processing (Stripe).
- •Cloud hosting and infrastructure providers.
- •Email and support tools for account and service messages.
- •Analytics and error-monitoring tools.
We do not sell your personal information. We may disclose information if required by law, to enforce our agreements, or to protect the rights, safety and property of Dual Login, our users or the public.
7. Data retention
We keep personal data only as long as needed for the purposes described here. Account data is kept while your account is active and for a reasonable period afterward to meet legal, tax and accounting requirements. Billing records are retained as required by law (commonly up to 7 years). Server logs are kept for a limited period for security and troubleshooting. When data is no longer needed, we delete or anonymise it.
8. International transfers
We operate globally, so your information may be processed in countries other than your own, including countries that may not offer the same level of data protection as your home country. When we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. You can request a copy of the safeguards we use by contacting us.
9. Security
We protect your data with encryption in transit (TLS) and at rest for sensitive fields, hashed passwords, access controls, least-privilege practices, and regular review of our systems. Synced browser profiles are encrypted. No method of transmission or storage is perfectly secure, but we work hard to protect your information and to respond quickly if something goes wrong. See our Security Policy for more.
10. Your rights (GDPR)
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:
- •Access the personal data we hold about you.
- •Rectify inaccurate or incomplete data.
- •Erase your data ('right to be forgotten') where applicable.
- •Restrict or object to certain processing.
- •Data portability — receive your data in a portable format.
- •Withdraw consent at any time, without affecting prior processing.
- •Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@duallogin.com. We will respond within the time required by law (usually one month).
11. Your rights (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to and deletion of your personal information, to correct inaccurate information, and to not be discriminated against for exercising your rights. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA. To make a request, email privacy@duallogin.com. We will verify your request before acting on it.
12. Children's privacy
The Services are for business use and are not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the 'Last updated' date and, where appropriate, notify you. Continued use of the Services after changes take effect means you accept the updated policy.
14. Contact us
Questions or requests? Email privacy@duallogin.com or write to Keyback Systems Ltd., Babor Road, Dhaka 1207, Bangladesh. For general support, use support@duallogin.com.