Privacy Policy

Privacy PolicyLast updated August 2, 2026

StackShift is an infrastructure control plane. To provide the service, we process account information, workspace and project metadata, deployment records, operational signals, billing records, and support communications.

We publish only practices that are supported by the current product and backend implementation. Where a retention period, processor, or legal right has not been verified, this page does not invent one.

1

Information we process

  • Account and authentication records such as your name, email address, password representation, sessions, team membership, and access permissions.
  • Workspace, project, stack, application, database, domain, deployment, build, runtime, configuration, log, metric, and resource-status information needed to operate your workloads.
  • Technical request and session metadata such as IP address, user-agent information, timestamps, request paths, and security or audit events.
  • Subscription, transaction, invoice, usage, and payment-provider reference information. Payment providers handle payment data according to their own terms.
  • Support and communication information that you send to StackShift, including email, bug reports, feedback, and business enquiries.
2

How we use information

  • To create accounts, authenticate users, manage teams, enforce permissions, and protect sessions.
  • To deploy, provision, monitor, troubleshoot, recover, and otherwise operate projects, stacks, applications, databases, and related platform resources.
  • To provide billing, usage reporting, support, diagnostics, fraud prevention, abuse prevention, security operations, and auditability.
  • To investigate incidents, enforce platform rules, respond to lawful requests, and protect StackShift, customers, and third parties.
3

Operational access and workloads

4

Secrets and sensitive configuration

  • Selected stored credentials and sensitive configuration values are encrypted when the platform encryption key is configured for that storage path; this is not a claim that every stored data field is encrypted by the same mechanism.
  • Secret values are masked in product surfaces where masking is implemented and should not be placed in logs, screenshots, support messages, or chat prompts.
  • Customers are responsible for rotating credentials that may have been exposed outside the platform.
5

Sharing and service providers

6

Retention and deletion

7

Your choices and requests

  • Update account information, revoke sessions, remove credentials, and delete supported resources through the product where those controls are available.
  • Contact us to request access, correction, export, or deletion of personal information. We may verify the request and apply operational or legal limits.
  • Manage non-essential browser storage or marketing communication preferences where the relevant controls are available.
8

Contact