Privacy Policy

Last updated August 20, 2026

This policy covers the personal data we hold about you as our customer — the people who hold Nautvia accounts.

It does not cover the personal data inside the stores you host with us: your shoppers' names, addresses and orders. For that data you are the controller and we act on your instructions, which is set out in the Data Processing Agreement.

Who is responsible

The controller of your data is Development Orest Oliinyk, a sole trader registered in Poland (jednoosobowa działalność gospodarcza), of ul. Towarowa 12/407, 35-231 Rzeszów, woj. podkarpackie, Poland. NIP 5170374110, REGON 522540695.

For anything about your data, write to [email protected].

What we collect and why

Your account. Your name, email address, a hash of your password, and — if you enable them — two-factor secrets, recovery codes and passkeys. We need these to give you an account and keep it secure. Legal basis: performance of our contract with you.

Your team. The email addresses of people you invite, and their role. Legal basis: performance of our contract.

Your SSH public keys, so we can give you shell access to your servers. Legal basis: performance of our contract.

Your connected source-control account. When you connect GitHub or GitLab we store your account id and login there, and an access token, so we can read your repository and register deploy webhooks. Legal basis: performance of our contract.

Sign-in and security data. Session records include your IP address and browser user agent. We use your email address and IP address as rate-limiting keys to slow down brute-force attempts. Legal basis: our legitimate interest in keeping accounts secure.

Billing data. Your plan, subscription state, and the brand and last four digits of your card. We never see your full card details — they are entered directly with Stripe. Legal basis: performance of our contract and our legal obligation to keep accounting records.

Operational records. Deployment logs, command output, notifications and error logs produced while running your infrastructure. These can incidentally contain personal data, most often because a command you ran printed some. Legal basis: our legitimate interest in operating and debugging the service.

Messages you send us. If you use the contact form we store your name, email address, the store address you give us, and what you wrote — so we can answer, and so the thread still exists if you come back to it months later. Legal basis: our legitimate interest in responding to enquiries and in following up on them. Nothing you send through it is used for marketing.

Support tickets. When you open a ticket we store what you wrote, your name, and — if you attached one — a reference to the environment or deployment it is about. Tickets belong to your team, so anyone in it can read and answer them. Legal basis: performance of our contract with you.

Password strength check. When you set a password we send the first five characters of its SHA-1 hash to Have I Been Pwned to check whether it appears in a known breach. The full password never leaves our systems and the check cannot identify you. Legal basis: our legitimate interest in account security.

Cookies

Nautvia sets four cookies of its own and none of them track you:

Cookie Purpose Lifetime
nautvia-session Keeps you signed in 2 hours
XSRF-TOKEN Protects forms against cross-site request forgery Session
appearance Remembers light or dark mode 1 year
sidebar_state Remembers whether the sidebar is open 7 days

Our public pages also load Google Analytics, which sets its own cookies (_ga, _ga_*) to count visits and see which pages people read. It runs on the marketing pages only — the landing page, pricing, documentation and these legal pages.

It does not run anywhere inside your account. Once you are signed in, no analytics script is loaded on any page: your site names, environment names and everything else in the dashboard are never sent to Google.

There is no advertising and no other third-party script on any page.

Who else processes your data

We use these providers. Each processes only what it needs to do its job.

Provider What it does What it receives
Hetzner Online (Germany) Runs your servers, volumes and private networks Server configuration, your team's SSH public key
Hetzner Object Storage (Germany) Stores database backups Your database dumps
Stripe Payments, invoicing, tax Your billing details, entered directly with them
Cloudflare DNS for platform domains, and the resolver we use to verify your custom domains Hostnames and server IP addresses
GitHub / GitLab Source control Your account id, an access token, repository access
Let's Encrypt TLS certificates The hostname and the team owner's email address
Mailgun (EU region) Sends account and alert email Your name, email address, message contents
Have I Been Pwned Breached-password check A partial, k-anonymised password hash
Google Analytics Counts visits to our public pages — never used inside your account IP address, page URL, browser and device details

Where a provider is outside the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses.

We do not sell your data, and we do not share it for advertising.

Where your data is held

Your servers and your database backups are in Falkenstein, Germany, unless you choose another region. Stripe and Cloudflare operate globally.

How long we keep it

Data Kept for
Account data Until you delete your account
Daily database backups 7, 14 or 30 days, depending on your plan
Manual and imported backups Until you delete them
Deployment and command logs 90 days, then the log contents are erased
Notifications 90 days
Usage records for billing 90 days
Contact form messages 365 days
Support tickets 365 days after they are closed; open tickets are kept
Failed background jobs 14 days
Server application logs Kept on your own server, rotated by its operating system, and destroyed when you tear the server down
Server performance metrics Not stored by us — read live from our infrastructure provider over a 1- or 7-day window, depending on your plan

Records we must keep for accounting or tax purposes are kept for as long as the law requires, regardless of the above.

Deleting your account and your infrastructure

Deleting your account from the settings page removes your account records and those of the teams you own.

It does not destroy the servers, volumes and backups held at our infrastructure provider. Those are removed when you tear down your environments. So, to have everything erased:

  1. Tear down each environment from its page, and delete any manual backups you no longer want; then
  2. Delete your account, or write to [email protected] and ask us to erase what remains — we will do so within 30 days and confirm when it is done.

We would rather describe this accurately than claim an automatic erasure that does not yet happen.

Your rights

You may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Write to [email protected] and we will respond within 30 days.

If you think we have handled your data wrongly you may complain to the President of the Personal Data Protection Office (UODO) in Warsaw, or to the supervisory authority where you live or work.

Changes

If we change this policy we will update the date at the top and, where the change is significant, tell you by email.