1. Who we are
Vaibhav Gupta, a sole trader trading as ArtifactDeploy (“ArtifactDeploy”, “we”, “us”) operates https://artifactdeploy.com and the related Service and is the controller of the personal data described here. Contact us about privacy at [email protected].
2. Data we collect
Data you give us
- Account data: your email address and password. Passwords are hashed by our authentication provider; we never see them in plain text.
- Artifacts: the content, titles and settings of files you deploy. Don’t include personal data in public Artifacts unless you intend it to be public.
- Support messages: anything you send when you email us.
Data created when you use the Service
- API keys and connected apps: keys and OAuth access tokens are stored only as one-way SHA-256 hashes, plus their names, creation date, last-used time and deploy counts. For apps you connect by signing in, we store the app’s name and redirect address.
- Usage records: deployments, deletions and view counts for each deployment.
- Technical data: IP address, browser type and request logs processed by our hosting provider for security, abuse prevention and reliability.
Payment data
Payments are handled entirely by Paddle. We do not receive or store your card details. Paddle shares with us your subscription status, plan, a customer ID and your email address so we can activate your plan.
3. How we use it, and our legal bases
- To provide the Service — creating your account, hosting your Artifacts, authenticating API requests (performance of a contract).
- To bill you — activating and managing subscriptions through Paddle (contract, legal obligation).
- To keep the Service safe — preventing abuse, fraud and attacks, and enforcing our Terms (legitimate interests).
- To communicate with you — service emails such as verification, password reset, receipts and important changes (contract, legitimate interests). We don’t send marketing email without your consent.
We do not sell your personal data, and we do not use your Artifacts to train AI models.
4. Cookies
We use only strictly necessary cookies and local storage to keep you signed in to the dashboard. We do not use advertising or cross-site tracking cookies. Paddle may set its own cookies during checkout, as described in Paddle’s privacy notice.
5. Who we share data with
We use these service providers (“processors”), bound by contracts that limit how they can use your data:
| Provider | Purpose |
|---|---|
| Supabase | Authentication and database (account, API key hashes, deployment records) |
| Cloudflare | Website hosting, CDN, file storage (R2) and serving deployments |
| Paddle | Checkout, payments, invoicing and tax — Paddle is our Merchant of Record |
| Zoho Mail | Sending account emails such as verification and password reset |
We may also disclose data if required by law, to respond to valid legal requests, or to protect the rights and safety of our users and others.
6. International transfers
Our providers may process data outside your country, including in the United States and the European Union. Where required, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. How long we keep data
- Account data and Artifacts: while your account is active. Deleting a deployment removes its file immediately. You can delete your whole account at any time in Dashboard → Settings, which removes your deployments, keys and account data immediately, apart from brief backup retention.
- Billing records: as long as tax and accounting laws require (typically up to 7 years), held by Paddle and us.
- Security logs: kept for a limited period, normally no more than 90 days.
8. Your rights
Depending on where you live (for example under the GDPR, UK GDPR, India’s DPDP Act or California law) you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent. Email [email protected] to exercise these rights — we reply within 30 days. You also have the right to complain to your local data-protection authority.
9. Security
We use HTTPS everywhere, hash passwords and API keys, restrict access to production systems, and rely on reputable infrastructure providers. No system is perfectly secure, so please use a strong, unique password and keep API keys private.
10. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes
We will post any changes to this policy on this page with a new “last updated” date, and email account holders about significant changes.