Privacy Policy

Your privacy matters

This policy explains what data we collect, why we collect it, and how we protect it.

Effective date: May 14, 2025

1. Who We Are

PandaStack is operated by Pandastackio Inc, a company incorporated in Delaware, USA ("PandaStack", "we", "our", or "us"). We provide a cloud platform that lets developers deploy static sites, containers, databases, cron jobs, edge functions, and managed applications.

If you have questions about this policy, contact us at support@pandastack.io.

2. Information We Collect

Account information. When you sign up, we collect your name, email address, and (optionally) a GitHub account connection for OAuth login.

Billing information. Payments are processed by Stripe. We never store full credit card numbers. We receive and store a Stripe customer ID and limited metadata (last 4 digits, card brand, expiry).

Usage data. We collect data about the resources you deploy — project names, deployment configurations, cron schedules, database names — to operate the service on your behalf.

Log and telemetry data. We collect application and infrastructure logs, including IP addresses, HTTP request metadata, error traces, and performance metrics, to maintain service reliability.

Communication data. If you contact support, we retain those communications to resolve your issue and improve our service.

Cookies and local storage. We use cookies for authentication sessions and, where you consent, for analytics. See Section 8 for details.

3. How We Use Your Information

  • Provide, operate, and maintain the PandaStack platform and all products under the PandaStack umbrella (PandaWatch, Sandflare, PandaStack AI, PandaFlow).
  • Process payments and manage your subscription through Stripe.
  • Send transactional emails — deployment alerts, billing receipts, and security notifications.
  • Respond to your support requests and troubleshoot issues.
  • Monitor platform health and detect abuse or security threats.
  • Improve our products through aggregated, anonymised usage analytics.
  • Comply with legal obligations.

We do not sell your personal data to third parties.

4. Data Sharing

We share data only with the following categories of third parties, and only to the extent necessary:

  • Stripe — payment processing and subscription management.
  • Google Cloud Platform — infrastructure hosting (compute, storage, networking).
  • Firebase — web hosting for pandastack.io and static deployments.
  • Mailgun — transactional email delivery.
  • Cloudflare — CDN, analytics, and DDoS protection.
  • GitHub — OAuth authentication and repository integrations (only when you connect your account).

We may also disclose data if required by law, court order, or to protect the rights and safety of PandaStack and its users.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (e.g., billing records retained for 7 years under US tax law).

Deployment logs and infrastructure metrics are retained for up to 90 days and then purged.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Deletion — request that we delete your personal data ("right to be forgotten").
  • Portability — receive your data in a machine-readable format.
  • Objection — object to our processing of your data for direct marketing.
  • Restriction — ask us to limit how we use your data while a dispute is resolved.

To exercise any of these rights, email support@pandastack.io. We will respond within 30 days.

7. Security

We implement industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest, network isolation, role-based access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security, but we take reasonable steps to protect your data.

If you discover a security vulnerability, please report it responsibly to support@pandastack.io.

8. Cookies

We use the following types of cookies:

  • Essential cookies — required for authentication and session management. These cannot be disabled.
  • Analytics cookies — used to understand how users interact with our site (aggregated, anonymised). You may opt out via your browser settings.

We do not use third-party advertising cookies.

9. Children's Privacy

PandaStack is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it promptly.

10. International Transfers

Pandastackio Inc is based in the United States. By using PandaStack, you acknowledge that your data may be transferred to and processed in the United States and other countries where our infrastructure partners operate. We ensure appropriate safeguards are in place for any such transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top and, for material changes, notify you by email or via an in-dashboard notice. Your continued use of the service after a change constitutes acceptance of the updated policy.

12. Contact

For any privacy-related questions or requests, contact us at: support@pandastack.io

Pandastackio Inc
Delaware, USA