Teks kabijakan basa Inggris
Kabijakan iki saiki mung kasedhiya ing basa Inggris. Teks basa Inggris sing dadi acuan nganti terjemahan sing wis ditliti diterbitake.
Scope and roles
This Privacy Policy explains how Seedbox LC. collects, uses, discloses, and protects personal data when you visit runenv.dev or use the hosted Runenv service.
This Policy applies to website visitors, account holders, workspace owners, team members, invited users, billing contacts, and people who contact us about the service.
For account management, website operations, billing, analytics, security, and support, Seedbox LC. generally acts as the data controller or business. For workspace content that customers upload or configure in Runenv, including secrets and collaboration records, Seedbox LC. generally acts as a processor or service provider on the customer’s instructions.
Personal data we collect
- Account and profile data, such as your name, email address, profile image, authentication records, encrypted password or sign-in metadata, session data, and optional two-factor authentication settings.
- Invitation and collaboration data, such as invited email addresses, inviter identity, organization and project membership, roles, comments, guides, audit entries, and shared workspace activity.
- Customer content and workspace records, such as encrypted secret values, shared credentials, snapshots, configuration snippets, change requests, personal overrides, project names, environment names, and metadata that customers choose to upload.
- Billing and commercial data, such as subscription plan, billing cycle, price, currency, Paddle customer or subscription identifiers, transaction status, and cancellation or renewal state. Payment card details are processed by our payment provider rather than stored by us.
- Device, network, and service usage data, such as IP address, timestamps, browser or app metadata, user agent, security events, rate-limit signals, webhook delivery history, and service token usage metadata.
- Website diagnostics and analytics data, including crash or error telemetry and website interaction information collected through tools we use to operate and improve the service, such as Sentry and Microsoft Clarity where enabled.
- Integration data when you connect third-party services, such as OAuth provider identifiers, integration targets, encrypted access tokens, webhook destinations, and synchronization status for providers like GitHub, Vercel, Netlify, or chat platforms you configure.
How we obtain personal data
We collect personal data directly from you when you create an account, sign in, purchase a plan, invite others, configure a workspace, contact us, or connect an integration.
We also receive personal data from other people and systems, including when a workspace administrator invites you by email, when you sign in through an identity provider, when a billing processor sends subscription events, or when a customer configures integrations or webhooks that include personal data.
How we use personal data
- To provide, secure, maintain, and improve Runenv and its website, APIs, billing, collaboration, and support functions.
- To authenticate users, manage accounts, administer organizations and projects, and enforce permissions, plan limits, and workspace settings.
- To send service communications, including sign-in notices, invitation emails, account confirmations, subscription notices, and security or operational alerts.
- To process payments, prevent fraud, maintain service reliability, investigate misuse, and protect the rights, safety, and property of Runenv, our customers, and others.
- To comply with legal obligations, enforce our agreements, respond to lawful requests, and resolve disputes.
- To analyze product usage and diagnose errors so we can improve usability, performance, security, and stability.
Legal bases for processing
Where European, UK, Swiss, or similar data protection laws apply, we rely on one or more legal bases depending on the context: contract necessity, legitimate interests, consent, and legal obligation.
- Contract necessity: to provide accounts, subscriptions, authentication, invitations, billing, and requested product features.
- Legitimate interests: to secure the service, prevent abuse, improve reliability, perform internal analytics, and communicate with customers about the operation of the service.
- Consent: where required for optional communications or certain analytics and tracking practices.
- Legal obligation: where we must retain, disclose, or process information to comply with law, accounting requirements, or lawful requests.
International data transfers
Runenv and its providers may process personal data in countries other than your own. Where required, we use appropriate safeguards for cross-border data transfers, such as contractual protections and provider commitments designed for international transfers.
If your organization has specific residency, transfer, or regulated-workload requirements, contact us before relying on the service for those use cases.
Retention
We retain personal data for as long as reasonably necessary to provide the service, maintain security, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods depend on the type of data and the context in which it was collected.
- Account and subscription records are generally retained while your account is active and for a reasonable period afterward for compliance, audit, and dispute resolution.
- Invitations, audit records, webhook histories, and other workspace metadata may remain while required for workspace operations, security, and customer records.
- When you delete an account or workspace, primary production records may be removed or deactivated, but limited records and backup copies may remain until they are overwritten or no longer needed for legitimate business or legal purposes.
Security
We use technical and organizational measures intended to protect personal data and customer content. These measures may include encryption at rest for secrets, hashed long-lived tokens, access controls, authentication safeguards, session management, and rate limiting.
No internet service or storage system is completely secure, and we cannot guarantee absolute security. You are also responsible for securing your own endpoints, credentials, exported files, integrations, and team access policies.
Your rights and choices
- You can access and update certain profile information from your account settings.
- You can request deletion of your account, subject to workspace ownership and legal retention constraints.
- Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to appeal certain decisions where applicable.
- If we rely on consent for a specific processing activity, you may withdraw that consent at any time, although that will not affect processing already carried out before withdrawal.
- To make a privacy request, contact [email protected]. We may need to verify your identity before completing a request.
Children
Runenv is not directed to children and is not intended for use by anyone under 16 years of age. If you believe a child has provided us personal data, contact us so we can investigate and take appropriate action.
Automated decision-making and profiling
Runenv does not currently use automated decision-making or profiling as defined by GDPR Article 22. Our systems may use automated rules for rate limiting, security event detection, and usage monitoring, but these rules do not produce decisions with legal or similarly significant effects on you.
If we introduce automated decision-making in the future, we will update this Policy and provide appropriate safeguards under applicable law.
Do Not Track signals
There is currently no universal technology standard for recognizing or responding to Do Not Track (DNT) browser signals, so we do not currently recognize or respond to DNT signals. If an industry standard is established in the future, we may update this Policy accordingly.
Changes to this Policy and contact information
We may update this Privacy Policy from time to time to reflect changes in the service, our vendors, our legal obligations, or our data practices. When we do, we will update the effective date and post the revised version on this page.
If you have questions about this Privacy Policy, privacy rights, or our data practices, contact [email protected].