Privacy

Privacy policy

Draft — not yet reviewed by counsel. This page describes what the product actually does today, so that a lawyer has something factual to work from. Have it reviewed and remove this notice before launch.

What we collect

  • Account data — name, email address, hashed password, two-factor secret.
  • Operational metadata — server names and addresses, application names, repository URLs, deploy history, build logs, and audit entries.
  • Billing data — handled by our payment processor; we store a customer reference, not card numbers.

What we do not collect

Your application's own data — its database contents, uploaded files and customer records — lives on servers in your cloud account. It is not transmitted to or stored by Railyard.

Where it is stored

Operational metadata for the hosted control plane is stored in Canada. Customers on the self-hosted plan run the control plane in their own environment, and none of this metadata reaches us at all.

Who can access it

Members of your team, according to their role. On our side, access is limited to staff who need it for support, and every such access is logged.

Retention and deletion

Deploy logs and audit entries are retained for the life of the account. You can request deletion of your account and its data by writing to hello@railyard.run.