consostackpreview
Legal

Privacy Policy

Effective: [EFFECTIVE DATE]Last updated: [EFFECTIVE DATE]
Template notice for the operator (remove before publishing): product-grounded template, not legal advice. Fill every [PLACEHOLDER] and have it reviewed by qualified counsel in [JURISDICTION] before publishing.

This Privacy Policy explains how [LEGAL NAME] (“consostack”, “we”) collects, uses, and protects personal data when you use the consostack platform and website. For the hosting of your end-users’ data, where we act as your processor, see the Data Processing Addendum.

1Who we are

The controller of your personal data is [LEGAL NAME], [REGISTERED ADDRESS], company no. [COMPANY ID / IČO]. Privacy questions: [PRIVACY EMAIL].

2Data we collect

Account data

Email address, display name, and a hashed password (if you set one). API keys are stored hashed.

Service data

Project metadata (names, git repository URLs), environment variables and secrets you provide, custom domains, and build & runtime logs generated by your deployments.

Billing data

For paid plans, payments are handled by Stripe. We receive limited billing metadata (plan, status, customer/subscription identifiers); we do not store your card number.

Usage & technical data

Audit logs of actions in your account, IP address, browser/device information, and diagnostic data needed to operate and secure the Service.

3How we use it

4Legal bases (GDPR)

Where GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (security, abuse prevention, improving the Service), legal obligation (tax, accounting), and consent where required (e.g., non-essential cookies).

5Sharing & sub-processors

We do not sell personal data. We share it with service providers who process it on our behalf, including our infrastructure provider ([INFRASTRUCTURE PROVIDER, e.g., Hetzner Online GmbH], EU), payment processor (Stripe), and email provider ([EMAIL PROVIDER]). A current list of sub-processors is in the DPA. We may also disclose data where required by law.

6International transfers

Our infrastructure is located in the European Union. Where a sub-processor transfers data outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7Retention

We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, tax, and security obligations. Customer Content is deleted within a reasonable period after account closure. [STATE RETENTION PERIODS].

8Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent. To exercise these rights contact [PRIVACY EMAIL]. You may also lodge a complaint with your supervisory authority (in [JURISDICTION], the [SUPERVISORY AUTHORITY]).

9Security

We use technical and organisational measures including encryption in transit (HTTPS), hashed credentials and API keys, strict per-organisation tenant isolation, and access controls. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

10Cookies

We use strictly necessary cookies to run the console and keep you signed in. See our Cookie Policy.

11Changes

We may update this Policy; material changes will be notified by email or in the Service. The “last updated” date reflects the latest version.

12Contact

Privacy enquiries: [PRIVACY EMAIL], [LEGAL NAME], [REGISTERED ADDRESS].

Terms of Service → Cookie Policy → DPA / GDPR →