symflip

Privacy Policy

This Privacy Policy explains how Symflip (“Symflip”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the Symflip deployment platform and related websites (the “Service”). We act as the data controller for the personal data described here. By using the Service, you agree to this Policy.

1. Information we collect

2. How we use your information

3. Legal bases for processing

Where the GDPR or similar laws apply, we rely on: performance of a contract (to provide the Service you request), legitimate interests (to secure and improve the Service), consent (for non-essential analytics cookies), and legal obligation (for tax and compliance records). You may withdraw consent at any time.

4. How we protect your data

Sensitive credentials — including the SSH keys and project secrets you connect — are encrypted at rest using authenticated encryption before they are stored, and we support rotation of the encryption key. Passwords are stored only as salted hashes. We use transport encryption, access controls, and other safeguards. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, and you are responsible for safeguarding your own credentials and infrastructure.

5. Cookies and analytics

We use cookies and similar technologies to keep you signed in, secure the Service, and measure usage. We use Google Analytics to understand how the Service is used; it may set cookies and collect data such as your IP address and interactions, processed by Google as described in its own privacy policy. You can control cookies through your browser settings and, where required, through our consent controls. Disabling non-essential cookies will not prevent you from using the core Service.

6. How we share information

We do not sell your personal data. We share it only:

7. International transfers

We may process and store data in countries other than yours. Where we transfer personal data internationally, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, where required.

8. Data retention

We retain personal data for as long as your account is active and as needed to provide the Service, then for as long as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where retention is legally required (for example, billing records).

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA/UK have rights under the GDPR, and California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. To exercise any right, contact us at privacy@symflip.com. You may also lodge a complaint with your local data-protection authority.

10. Children’s privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice, such as by email or a notice in the Service, and update the “Last updated” date above.

12. Contact

For privacy questions or requests, contact us at privacy@symflip.com.