TestDino Privacy Policy
Last updated: September 2026
This privacy policy explains how TestDino (Alphabin Technology Consulting) collects, uses and discloses information when you use services via www.testdino.com and app.testdino.com (the "Site").
Security Certifications
TestDino is SOC 2 Type 2 certified, ISO 27001 certified, and GDPR compliant. Our SOC 2 Type 2 audit covers the Security, Availability, and Confidentiality Trust Services Criteria. For details on controls, encryption, infrastructure, and how to request reports under NDA see our Security page.
Personal Information We Collect
This section covers personal information that relates to permitted users of TestDino, such as account holders, dashboard administrators, and team members. Sign-up requires an email address. Paying customers provide billing information as necessary. TestDino collects only the information needed for the interaction. You may decline to provide personal information, though this may prevent certain website activities.
For permitted users, TestDino collects:
- Email (used for login)
- Billing details for paying customers
- Anonymized IP address
- Device type, operating system, and browser type
- Approximate geographic location
- Preferred language
- Referring URL and domain
- Pages visited, with date and time
- Random user ID
Customer Content (Test Data)
Customer Content is the test data that customers upload to TestDino. It is distinct from the personal information above. TestDino processes Customer Content on behalf of the customer as a data processor under our Data Processing Agreement. The customer remains the controller of that data.
When customers send Playwright test results through the @testdino/playwright package or supported CI/CD integrations, Customer Content can include:
- Test names, file paths, and project or spec metadata
- Pass, fail, flaky, and skipped statuses with retry counts
- Error messages, stack traces, and assertion diffs
- Screenshots, videos, and Playwright trace files attached to a test
- Console logs, network logs, and other Playwright artifacts
- CI metadata such as branch, commit SHA, run number, environment, and tags
- Timestamps, durations, and worker or shard identifiers
Customer Content may incidentally contain personal information if a developer captures it in a log, screenshot, or trace. The customer is responsible for what is uploaded. TestDino does not load any tracking script or SDK on customer-owned websites or end-user browsers.
Children's Data
TestDino is a workplace tool and is not directed to children. You must be at least 18 years old to create an account if you are in India, and at least 13 years old (or the age of digital consent in your jurisdiction) elsewhere. We do not knowingly collect personal data from children and we do not track children or show them targeted advertising. If you believe a child has provided us personal data, contact us and we will delete it.
Website Visitors
TestDino collects non-personally-identifying information such as browser type, language preference, referring site, and request date and time to understand visitor usage patterns. We may publish aggregate usage trend reports.
For logged-in users, TestDino collects IP addresses and discloses them under the same circumstances as personal information.
Aggregate visitor statistics, impressions, and clicks may be monitored to improve the service. Aggregate data does not identify individual visitors.
Cookies
A cookie is information a website stores on a visitor's computer that the browser provides upon return. The TestDino marketing site (www.testdino.com) uses cookies for analytics and to remember preferences. The application (app.testdino.com) uses strictly necessary cookies for authentication and session management. Most browsers accept cookies by default. You can set your browser to remove or reject cookies, though certain features may not function without them.
AI Data Processing
TestDino offers AI-powered features that process Customer Content to generate insights such as failure summaries and flake detection. We treat AI processing with the same care as any other handling of Customer Content.
- LLM provider. AI features use Microsoft Azure OpenAI Service and Azure AI Foundry, hosted within our Azure tenant. Customer Content is sent to these services only at the time of inference for the specific feature you are using. They are listed on our Subprocessors page.
- No use for provider training. Microsoft does not use Customer Content sent through Azure OpenAI to train its foundation models, in line with the Azure OpenAI Service terms.
- No TestDino model training by default. We do not train TestDino-owned models on Customer Content by default. If a customer opts in to contribute test data to model training, the scope is documented in writing and the opt-in can be revoked at any time.
- Enterprise opt-out. Enterprise customers can disable AI-powered features for their workspace.
- DPA coverage. AI processing of Customer Content is covered by our Data Processing Agreement.
Legal Bases for Processing
For visitors and users in the European Economic Area, the United Kingdom, or Switzerland, we process personal information on the following legal bases under the GDPR:
- Contractual necessity: to create and operate your account, deliver the service, and provide support.
- Legitimate interests: to secure our service against abuse, prevent fraud, improve product reliability, and operate our business, where those interests are not overridden by your rights.
- Legal obligation: to comply with tax, audit, and other applicable legal requirements.
- Consent: for optional activities such as marketing communications and non-essential cookies, where we ask for it. You can withdraw consent at any time.
For users in India, where consent is the basis for processing under the Digital Personal Data Protection Act, 2023, we ask for it separately for each purpose, and withdrawing it is as easy as giving it: through your account settings or by writing to the Grievance Officer named below. The purposes are:
- Service delivery: operating your account and the features you use. Necessary for the service, so not consent-based.
- Support: answering your requests and troubleshooting your account.
- Product analytics: understanding how the product is used so we can improve it. You can opt out separately.
- Marketing: product news and offers. You can opt out separately at any time.
For Customer Content, the customer is the data controller and TestDino acts as a processor on the customer's instructions under our Data Processing Agreement.
Protection of Information
TestDino discloses personal information and Customer Content only to employees, contractors, and subprocessors that (i) need it to process the data on TestDino's behalf or to provide the services, and (ii) have agreed in writing not to disclose it to others. Where data is transferred outside your home country, we rely on the legal mechanisms described under International Data Transfers below.
TestDino does not rent or sell personal information. We disclose it only in response to subpoenas, court orders, or governmental requests, or where we believe in good faith that disclosure is reasonably necessary to protect the property or rights of TestDino, third parties, or the public.
We take reasonable technical and organizational measures to protect personal information and Customer Content against unauthorized access, use, alteration, or destruction.
Subprocessors
Our current third-party subprocessor list is published at testdino.com/subprocessors. Each subprocessor is contractually limited to the purpose described and is bound by confidentiality obligations.
Each subprocessor publishes its own privacy notice — check their site directly for details. To subscribe to notifications of subprocessor changes, email support@testdino.com.
International Data Transfers
Personal information and Customer Content may be transferred to, stored in, or processed in countries other than your own, including the United States and the European Union, depending on the Azure region used.
For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable). The relevant clauses are incorporated into our Data Processing Agreement.
Data Retention
We retain Customer Content for as long as your subscription remains active, in line with the retention window for your plan. Once data exceeds the applicable retention period, it is deleted automatically on a rolling basis.
Account and billing records are retained while the account is active and for a limited period after closure to satisfy legal, tax, and audit requirements. After that period, personal information associated with the account is deleted or anonymized.
TestDino retains data according to your subscription tier, covering automation artifacts, test data, and manual test records. These records are automatically deleted once their applicable retention period ends.
For detailed plan-specific retention periods and storage limits, please refer to our Data Retention documentation.
Account Inactivity and Data Deletion
If an account remains inactive for 60 days after plan cancellation, TestDino may delete the account and all associated personal data. Users receive notification before deletion and can prevent it by logging in or contacting support.
You can request account deactivation or deletion at any time by contacting support. After deletion, some information may be retained to prevent fraud, troubleshoot problems, assist investigations, enforce our Terms of Service, or comply with legal requirements. The retention period for these records is described under Data Retention.
Your Privacy Rights
Depending on where you live, you have specific rights regarding your personal information: under the GDPR in the European Economic Area and the United Kingdom, under state privacy laws in the United States, and under the Digital Personal Data Protection Act, 2023 in India. The two sections that follow set out the United States and India rights in detail. Our GDPR page covers Europe.
Subject to applicable law, you may have the right to:
- Request access to a copy of the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of your personal information
- Request that we restrict or object to certain processing
- Request a portable copy of your information
- Withdraw consent where we rely on consent as a legal basis
We will not discriminate against you for exercising any of these rights.
To exercise a right, contact support@testdino.com. We verify requests by confirming control of the email address on the account, and may ask for further information where the request concerns data we cannot link to that address. An authorized agent may submit a request on your behalf with your written permission, which we will ask to see. We respond within the time required by the law that applies to you.
United States State Privacy Rights
If you live in a state with a comprehensive privacy law, including California (CCPA and CPRA), Virginia, Colorado, Connecticut, Utah, Texas, and others, you have the right to know what personal information we collect, to access it, to correct it, to delete it, to receive a portable copy, and to opt out of targeted advertising and of the sale of personal information. TestDino honors these rights for every United States resident, whichever state you are in.
We do not sell or share your personal information for cross-context behavioral advertising as those terms are defined under California law, and we do not use or disclose sensitive personal information for purposes other than providing the service.
Notice at collection
The categories of personal information we collect, where each comes from, why we collect it, and how long we keep it:
| Category | Examples | Source | Purpose | Retention |
|---|---|---|---|---|
| Identifiers | Name, email address, account ID, IP address | You, your device | Account creation, sign-in, security, support | Life of the account, plus a limited period after closure (see Data Retention) |
| Commercial information | Plan, billing details, invoices, payment status | You, our payment processor | Billing, tax, and audit compliance | As required for tax and audit obligations after the account closes |
| Internet activity | Pages visited, referring URL, device and browser type, approximate location, preferred language | Your device, cookies | Product analytics, reliability, security | Aggregated or deleted per the analytics retention in Data Retention |
| Professional information | Organization name, role, workspace membership | You, your organization's admin | Team workspaces, permissions, invoicing | Life of the workspace membership |
Customer Content is not listed above because we process it as a service provider on the customer's instructions, for the retention window of the customer's plan.
Your Rights Under Indian Law (DPDP Act 2023)
Alphabin Technology Consulting is a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 for the personal data it decides the purposes of processing for. If you are in India, you have the right to:
- Access: a summary of the personal data we process about you and the processing activities involved.
- Correction and erasure: correction of inaccurate data, completion of incomplete data, and erasure of personal data no longer necessary for the purpose it was collected for.
- Grievance redressal: a readily available means to register a grievance, which we will resolve within the period prescribed under the Act and its Rules.
- Nomination: to nominate another individual to exercise your rights in the event of your death or incapacity.
Where we process personal data on the documented instructions of a customer (for example, personal data contained in test artifacts your employer uploads), we act as a Data Processor. Direct your request to that customer and we will support them in fulfilling it.
You may exercise these rights, or withdraw consent previously given, by writing to our Grievance Officer below. Withdrawing consent does not affect processing carried out before withdrawal. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Grievance Officer
Under the Information Technology Act, 2000 and its Rules, and the Digital Personal Data Protection Act, 2023, our Grievance Officer is:
Pratik PatelAlphabin Technology Consulting
1100 Silver Business Point, VIP Circle, Utran, Surat, Gujarat 394105, India
Email: grievance@testdino.com
We acknowledge grievances within 24 hours and resolve them within 15 days, or any shorter period notified under applicable Rules.
Promotional Communications
You may opt out of promotional emails or texts by following the instructions in those messages or by contacting us. We honor opt-outs within 10 business days. If you opt out, TestDino continues to send transactional messages about your account, billing, security, and ongoing business relations, which are not promotional.
Data Processing Agreement
TestDino is GDPR compliant. Customers processing personal data through TestDino should request and sign our Data Processing Agreement. Send an email to support@testdino.com requesting the agreement, complete it, and return a signed copy. We will return a counter-signed copy within 10 business days.
For supplemental information on our GDPR program, see our GDPR page.
Business Transfers
If TestDino or substantially all its assets are acquired, or if the company goes out of business or enters bankruptcy, user information would be transferred as an asset. You acknowledge that such transfers may happen, and that an acquirer may keep using personal information under this policy.
Privacy Policy Changes
TestDino may update this Privacy Policy from time to time. Material changes will be communicated through the service or by email where appropriate. Continued use of the service after the effective date of an updated policy constitutes acceptance.
Dispute Resolution
Alphabin Technology Consulting is established in India. Disputes arising out of or relating to this Privacy Policy are subject to the laws of India, without regard to its conflict-of-law principles. For users in the European Economic Area, you also have the right to lodge a complaint with your local Data Protection Authority.
Terms of Service
For more information on terms of use, see the full Terms of Service.
Contact Us
For privacy policy questions, contact support@testdino.com.