Privacy Policy
Effective September 13, 2026. Operator identity and jurisdiction-specific disclosures must be configured before launch.
What the control plane collects
We process control-plane account and organization details, verification and security events, subscription and invoice references, onboarding subdomain and initial administrator bootstrap data, infrastructure identifiers, support-access records, audit events, and communications. The initial GTM password exists in memory for confirmation and immediate hashing; only the encrypted compatible hash is staged and it is erased after acknowledged bootstrap.
What stays in GTM
Ordinary GTM users, tests, participants, results, payments, uploaded documents, and customer integration settings remain in the customer’s GTM deployment and configured providers. The control plane does not mirror those records. It receives only bounded deployment readiness and aggregate capacity information.
Purposes and legal bases
We use information to provide and secure contracted services, process payments, provision infrastructure, communicate about accounts, prevent abuse, meet legal obligations, improve public documentation and marketing with consent where required, and establish or defend claims.
Providers and disclosures
Depending on configuration, recipients may include DigitalOcean for hosting, Stripe for card and ACH billing, Mailjet for transactional email, a configured helpdesk, GA4/Google Tag Manager for consent-controlled public-site analytics, blockchain RPC/indexer providers for transaction verification, and professional or government recipients when legally necessary. Customers separately configure providers inside GTM.
Analytics
Public marketing, documentation, and support-entry pages may use GA4 or Google Tag Manager under the configured consent policy. Customer account and billing pages do not load advertising or analytics tags. Analytics must exclude passwords, payment data, tenant content, support credentials, signed tokens, and direct identifiers.
Retention
Operational records are retained only for configured security, billing, tax, support, and legal periods. Tenant logical backups are encrypted, normally retained as four weekly copies plus pre-destructive checkpoints, and purged at final deletion. Webhook and replay records are bounded. Some financial or security records may outlast application data when law or disputes require it.
Security
Controls include tenant-scoped database users, encrypted secrets, MFA and recent reauthentication for sensitive operator actions, request signing, replay prevention, least-privilege roles, audit logging, bounded diagnostics, TLS, and restore testing. No system can guarantee absolute security.
Your choices
Account owners may update commercial account data, manage billing, export eligible data during recovery, and request deletion subject to contractual and legal retention. Analytics consent can be withheld where offered. Blockchain records are public and cannot be erased by us.
International transfers and children
Providers may process information in other countries using their applicable safeguards. The service is not directed to children, and customers must not submit children’s information without a valid legal basis.
Contact
The privacy contact, business address, regional rights, appeal process, and regulator information will be populated from owner configuration before live sales.