Privacy Policy
Last updated August 20, 2026
This policy covers the personal data we hold about you as our customer — the people who hold Nautvia accounts.
It does not cover the personal data inside the stores you host with us: your shoppers' names, addresses and orders. For that data you are the controller and we act on your instructions, which is set out in the Data Processing Agreement.
Who is responsible
The controller of your data is Development Orest Oliinyk, a sole trader registered in Poland (jednoosobowa działalność gospodarcza), of ul. Towarowa 12/407, 35-231 Rzeszów, woj. podkarpackie, Poland. NIP 5170374110, REGON 522540695.
For anything about your data, write to [email protected].
What we collect and why
Your account. Your name, email address, a hash of your password, and — if you enable them — two-factor secrets, recovery codes and passkeys. We need these to give you an account and keep it secure. Legal basis: performance of our contract with you.
Your team. The email addresses of people you invite, and their role. Legal basis: performance of our contract.
Your SSH public keys, so we can give you shell access to your servers. Legal basis: performance of our contract.
Your connected source-control account. When you connect GitHub or GitLab we store your account id and login there, and an access token, so we can read your repository and register deploy webhooks. Legal basis: performance of our contract.
Sign-in and security data. Session records include your IP address and browser user agent. We use your email address and IP address as rate-limiting keys to slow down brute-force attempts. Legal basis: our legitimate interest in keeping accounts secure.
Billing data. Your plan, subscription state, and the brand and last four digits of your card. We never see your full card details — they are entered directly with Stripe. Legal basis: performance of our contract and our legal obligation to keep accounting records.
Operational records. Deployment logs, command output, notifications and error logs produced while running your infrastructure. These can incidentally contain personal data, most often because a command you ran printed some. Legal basis: our legitimate interest in operating and debugging the service.
Messages you send us. If you use the contact form we store your name, email address, the store address you give us, and what you wrote — so we can answer, and so the thread still exists if you come back to it months later. Legal basis: our legitimate interest in responding to enquiries and in following up on them. Nothing you send through it is used for marketing.
Support tickets. When you open a ticket we store what you wrote, your name, and — if you attached one — a reference to the environment or deployment it is about. Tickets belong to your team, so anyone in it can read and answer them. Legal basis: performance of our contract with you.
Password strength check. When you set a password we send the first five characters of its SHA-1 hash to Have I Been Pwned to check whether it appears in a known breach. The full password never leaves our systems and the check cannot identify you. Legal basis: our legitimate interest in account security.
Cookies
Nautvia sets four cookies of its own and none of them track you:
| Cookie | Purpose | Lifetime |
|---|---|---|
nautvia-session |
Keeps you signed in | 2 hours |
XSRF-TOKEN |
Protects forms against cross-site request forgery | Session |
appearance |
Remembers light or dark mode | 1 year |
sidebar_state |
Remembers whether the sidebar is open | 7 days |
Our public pages also load Google Analytics, which sets its own cookies (_ga, _ga_*) to count visits and see which pages people read. It runs on the marketing pages only — the landing page, pricing, documentation and these legal pages.
It does not run anywhere inside your account. Once you are signed in, no analytics script is loaded on any page: your site names, environment names and everything else in the dashboard are never sent to Google.
There is no advertising and no other third-party script on any page.
Who else processes your data
We use these providers. Each processes only what it needs to do its job.
| Provider | What it does | What it receives |
|---|---|---|
| Hetzner Online (Germany) | Runs your servers, volumes and private networks | Server configuration, your team's SSH public key |
| Hetzner Object Storage (Germany) | Stores database backups | Your database dumps |
| Stripe | Payments, invoicing, tax | Your billing details, entered directly with them |
| Cloudflare | DNS for platform domains, and the resolver we use to verify your custom domains | Hostnames and server IP addresses |
| GitHub / GitLab | Source control | Your account id, an access token, repository access |
| Let's Encrypt | TLS certificates | The hostname and the team owner's email address |
| Mailgun (EU region) | Sends account and alert email | Your name, email address, message contents |
| Have I Been Pwned | Breached-password check | A partial, k-anonymised password hash |
| Google Analytics | Counts visits to our public pages — never used inside your account | IP address, page URL, browser and device details |
Where a provider is outside the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses.
We do not sell your data, and we do not share it for advertising.
Where your data is held
Your servers and your database backups are in Falkenstein, Germany, unless you choose another region. Stripe and Cloudflare operate globally.
How long we keep it
| Data | Kept for |
|---|---|
| Account data | Until you delete your account |
| Daily database backups | 7, 14 or 30 days, depending on your plan |
| Manual and imported backups | Until you delete them |
| Deployment and command logs | 90 days, then the log contents are erased |
| Notifications | 90 days |
| Usage records for billing | 90 days |
| Contact form messages | 365 days |
| Support tickets | 365 days after they are closed; open tickets are kept |
| Failed background jobs | 14 days |
| Server application logs | Kept on your own server, rotated by its operating system, and destroyed when you tear the server down |
| Server performance metrics | Not stored by us — read live from our infrastructure provider over a 1- or 7-day window, depending on your plan |
Records we must keep for accounting or tax purposes are kept for as long as the law requires, regardless of the above.
Deleting your account and your infrastructure
Deleting your account from the settings page removes your account records and those of the teams you own.
It does not destroy the servers, volumes and backups held at our infrastructure provider. Those are removed when you tear down your environments. So, to have everything erased:
- Tear down each environment from its page, and delete any manual backups you no longer want; then
- Delete your account, or write to [email protected] and ask us to erase what remains — we will do so within 30 days and confirm when it is done.
We would rather describe this accurately than claim an automatic erasure that does not yet happen.
Your rights
You may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Write to [email protected] and we will respond within 30 days.
If you think we have handled your data wrongly you may complain to the President of the Personal Data Protection Office (UODO) in Warsaw, or to the supervisory authority where you live or work.
Changes
If we change this policy we will update the date at the top and, where the change is significant, tell you by email.