TinyDeploy — Privacy

Log in

Privacy Policy

TinyDeploy · Last updated: 26 Sep 2026

1. What we collect

Account data: your email address (used as the login identifier) and a salted, hashed password — we never store your password in readable form.

Billing data: payment records (plan, amount, status, gateway reference) created when you top up, renew or upgrade. Card numbers and wallet details are handled entirely by the payment gateways (Razorpay / the crypto processor) and never reach our servers.

Deployment data: the server IP, hostname and OS choices you declare when starting a deployment, and the username / password you enter for the freshly installed OS. These credentials are stored encrypted at rest and exist so you can track and re-view your deployment. They describe your freshly installed machine — treat them as you would any server credential.

Operational data: standard request logs (IP, user agent, timestamps) used for rate limiting and abuse prevention.

2. What we do NOT collect

We do not read, scan, or access the contents of your servers. Deployment runs entirely on machines you own or control; our role is limited to serving the image download and tracking progress via tokens your server reports.

3. How we use data

We do not sell or rent personal data. We share data only with the payment processor (to collect payments you initiate) and with hosting/backup storage required to run the service.

4. Retention

Account and transaction records are kept while your account is active, plus the period required by tax/accounting rules for billing records. Deployment records are removed when you delete them from your dashboard. You may request account deletion at any time — contact support from your dashboard.

5. Security

Passwords are stored with PBKDF2 (200,000 iterations, per-user salt). Deployment credentials are encrypted at rest with a server-side key. API and download tokens use cryptographic randomness with strict download limits. See the docs for the security model.

6. Your rights

You may access, correct, or delete your personal data by contacting support from your dashboard. Where required by law (including India's DPDP Act), you may request a copy of your data or withdrawal of consent for processing.

7. Changes

Material changes to this policy will be announced on the site. Continued use after a change means you accept the updated policy.

8. Contact

Privacy questions: contact support from your dashboard or see the about page.