1. Overview & Commitment
We are committed to protecting your privacy and treating customer data with transparency and respect. This Privacy Policy details how we collect, utilize, store, and safeguard your personal data when you use our SaaS applications, API services, and websites.
2. Information We Collect
- Account Information: Name, email address, authentication credentials, and organization profile.
- Payment Details: Billing address, tax identifiers, and transaction history. Sensitive card tokens are processed directly by certified payment gateways and never touch our edge servers unencrypted.
- Usage Telemetry & Logs: API requests, edge latency metrics, browser user agent, IP address, and error reports.
3. How We Use Your Data
We process your information to provide and operate the Service, authenticate sessions, enforce role-based access control, invoice subscriptions, defend against DDoS attacks and bots (via Turnstile), and send essential system notifications. We do not sell or monetize personal data.
4. Cloudflare Edge & Data Hosting
Our infrastructure is built natively on Cloudflare Workers, Cloudflare D1 (distributed SQLite), and Cloudflare R2 (S3-compatible object storage). Data is encrypted in transit using TLS 1.3 and at rest with AES-256. Routing is optimized to keep compute and query processing as close as possible to your physical region.
6. Data Retention & Deletion
We retain customer data for as long as your workspace account remains active. When an organization owner deletes a workspace, all associated records in D1 and files in R2 are immediately decoupled and irreversibly purged within 30 days, except where legal compliance mandates retention.
7. Your Rights (GDPR & CCPA)
Under European GDPR and California CCPA regulations, you have the right to access your personal data, rectify inaccuracies, request erasure ("right to be forgotten"), restrict processing, and export your workspace data in a portable machine-readable format.
9. Security Safeguards
We implement defense-in-depth architecture: signed URLs, column-level AES-256-GCM encryption for third-party API credentials, rate-limiting sliding windows, Turnstile bot verification, and scoped organization RBAC access guards.
10. Contact Privacy Team
For questions regarding data processing or to exercise your GDPR rights, contact our Data Protection Officer at privacy@yourdomain.com.