Legal
Privacy Policy
Last updated: 27 July 2026
This Privacy Policy explains how Symflip (“Symflip”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the Symflip deployment platform and related websites (the “Service”). We act as the data controller for the personal data described here. By using the Service, you agree to this Policy.
1. Information we collect
- Account information. Your email address and a securely hashed form of your password. We never store your password in plain text.
- Billing information. For paid plans, your plan, billing status, and transaction records. Payments are processed by a third-party payment processor; we receive limited billing details (such as the last four digits of a card and billing country) but do not store full card numbers.
- Connection and deployment data. Information you provide to run deployments — repository URLs, server hostnames and usernames, SSH keys, and project secrets — along with deployment metadata such as release identifiers, timestamps, statuses, and deploy logs.
- Usage and device data. Log data such as IP address, browser type, pages viewed, and actions taken, collected automatically when you use the Service.
- Cookies and analytics. We use strictly necessary cookies for authentication and security, and analytics cookies to understand usage. See “Cookies and analytics” below.
2. How we use your information
- to provide, operate, and secure the Service, including connecting to your servers and performing deployments you initiate;
- to authenticate you and protect against fraud, abuse, and unauthorized access;
- to process payments, manage subscriptions, and send billing and transactional messages;
- to provide support and respond to your requests;
- to analyze and improve the Service and develop new features; and
- to comply with legal obligations and enforce our Terms of Service.
3. Legal bases for processing
Where the GDPR or similar laws apply, we rely on: performance of a contract (to provide the Service you request), legitimate interests (to secure and improve the Service), consent (for non-essential analytics cookies), and legal obligation (for tax and compliance records). You may withdraw consent at any time.
4. How we protect your data
Sensitive credentials — including the SSH keys and project secrets you connect — are encrypted at rest using authenticated encryption before they are stored, and we support rotation of the encryption key. Passwords are stored only as salted hashes. We use transport encryption, access controls, and other safeguards. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, and you are responsible for safeguarding your own credentials and infrastructure.
5. Cookies and analytics
We use cookies and similar technologies to keep you signed in, secure the Service, and measure usage. We use Google Analytics to understand how the Service is used; it may set cookies and collect data such as your IP address and interactions, processed by Google as described in its own privacy policy. You can control cookies through your browser settings and, where required, through our consent controls. Disabling non-essential cookies will not prevent you from using the core Service.
6. How we share information
We do not sell your personal data. We share it only:
- with service providers who process data on our behalf — such as cloud hosting, our payment processor, and analytics providers — under contracts that limit their use of the data;
- to comply with law, respond to lawful requests, or protect the rights, safety, and property of Symflip, our users, or others;
- in connection with a merger, acquisition, or sale of assets, in which case we will notify you of any change in control of your data; and
- with your consent or at your direction.
7. International transfers
We may process and store data in countries other than yours. Where we transfer personal data internationally, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, where required.
8. Data retention
We retain personal data for as long as your account is active and as needed to provide the Service, then for as long as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where retention is legally required (for example, billing records).
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA/UK have rights under the GDPR, and California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. To exercise any right, contact us at privacy@symflip.com. You may also lodge a complaint with your local data-protection authority.
10. Children’s privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide notice, such as by email or a notice in the Service, and update the “Last updated” date above.
12. Contact
For privacy questions or requests, contact us at privacy@symflip.com.