Privacy Policy
This Privacy Policy explains how [LEGAL NAME] (“consostack”, “we”) collects, uses, and protects personal data when you use the consostack platform and website. For the hosting of your end-users’ data, where we act as your processor, see the Data Processing Addendum.
1Who we are
The controller of your personal data is [LEGAL NAME], [REGISTERED ADDRESS], company no. [COMPANY ID / IČO]. Privacy questions: [PRIVACY EMAIL].
2Data we collect
Account data
Email address, display name, and a hashed password (if you set one). API keys are stored hashed.
Service data
Project metadata (names, git repository URLs), environment variables and secrets you provide, custom domains, and build & runtime logs generated by your deployments.
Billing data
For paid plans, payments are handled by Stripe. We receive limited billing metadata (plan, status, customer/subscription identifiers); we do not store your card number.
Usage & technical data
Audit logs of actions in your account, IP address, browser/device information, and diagnostic data needed to operate and secure the Service.
3How we use it
- To provide, operate, and secure the Service and your deployments.
- To authenticate you and manage your account, organisation, and API keys.
- To process payments and prevent abuse and fraud.
- To communicate service, security, and billing notices.
- To improve reliability and troubleshoot issues.
4Legal bases (GDPR)
Where GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (security, abuse prevention, improving the Service), legal obligation (tax, accounting), and consent where required (e.g., non-essential cookies).
5Sharing & sub-processors
We do not sell personal data. We share it with service providers who process it on our behalf, including our infrastructure provider ([INFRASTRUCTURE PROVIDER, e.g., Hetzner Online GmbH], EU), payment processor (Stripe), and email provider ([EMAIL PROVIDER]). A current list of sub-processors is in the DPA. We may also disclose data where required by law.
6International transfers
Our infrastructure is located in the European Union. Where a sub-processor transfers data outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, tax, and security obligations. Customer Content is deleted within a reasonable period after account closure. [STATE RETENTION PERIODS].
8Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent. To exercise these rights contact [PRIVACY EMAIL]. You may also lodge a complaint with your supervisory authority (in [JURISDICTION], the [SUPERVISORY AUTHORITY]).
9Security
We use technical and organisational measures including encryption in transit (HTTPS), hashed credentials and API keys, strict per-organisation tenant isolation, and access controls. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
10Cookies
We use strictly necessary cookies to run the console and keep you signed in. See our Cookie Policy.
11Changes
We may update this Policy; material changes will be notified by email or in the Service. The “last updated” date reflects the latest version.
12Contact
Privacy enquiries: [PRIVACY EMAIL], [LEGAL NAME], [REGISTERED ADDRESS].