Privacy Policy

Effective September 13, 2026. Operator identity and jurisdiction-specific disclosures must be configured before launch.

What the control plane collects

We process control-plane account and organization details, verification and security events, subscription and invoice references, onboarding subdomain and initial administrator bootstrap data, infrastructure identifiers, support-access records, audit events, and communications. The initial GTM password exists in memory for confirmation and immediate hashing; only the encrypted compatible hash is staged and it is erased after acknowledged bootstrap.

What stays in GTM

Ordinary GTM users, tests, participants, results, payments, uploaded documents, and customer integration settings remain in the customer’s GTM deployment and configured providers. The control plane does not mirror those records. It receives only bounded deployment readiness and aggregate capacity information.

Purposes and legal bases

We use information to provide and secure contracted services, process payments, provision infrastructure, communicate about accounts, prevent abuse, meet legal obligations, improve public documentation and marketing with consent where required, and establish or defend claims.

Providers and disclosures

Depending on configuration, recipients may include DigitalOcean for hosting, Stripe for card and ACH billing, Mailjet for transactional email, a configured helpdesk, GA4/Google Tag Manager for consent-controlled public-site analytics, blockchain RPC/indexer providers for transaction verification, and professional or government recipients when legally necessary. Customers separately configure providers inside GTM.

Analytics

Public marketing, documentation, and support-entry pages may use GA4 or Google Tag Manager under the configured consent policy. Customer account and billing pages do not load advertising or analytics tags. Analytics must exclude passwords, payment data, tenant content, support credentials, signed tokens, and direct identifiers.

Retention

Operational records are retained only for configured security, billing, tax, support, and legal periods. Tenant logical backups are encrypted, normally retained as four weekly copies plus pre-destructive checkpoints, and purged at final deletion. Webhook and replay records are bounded. Some financial or security records may outlast application data when law or disputes require it.

Security

Controls include tenant-scoped database users, encrypted secrets, MFA and recent reauthentication for sensitive operator actions, request signing, replay prevention, least-privilege roles, audit logging, bounded diagnostics, TLS, and restore testing. No system can guarantee absolute security.

Your choices

Account owners may update commercial account data, manage billing, export eligible data during recovery, and request deletion subject to contractual and legal retention. Analytics consent can be withheld where offered. Blockchain records are public and cannot be erased by us.

International transfers and children

Providers may process information in other countries using their applicable safeguards. The service is not directed to children, and customers must not submit children’s information without a valid legal basis.

Contact

The privacy contact, business address, regional rights, appeal process, and regulator information will be populated from owner configuration before live sales.