Privacy Policy
Last updated: 23 August 2026
1. Who is responsible for your data
The data controller is Hartmire Limited, contact privacy@cloudrelay.ai.
This policy covers data we hold about you, our customer. It does not cover data your own application collects from your visitors — for that you are the controller and we are your processor. See section 8.
2. What we collect, and why
| Data | Why we have it | Legal basis |
|---|---|---|
| Your name and email address | To create your account, sign you in, and contact you about your service | Performance of our contract with you |
| Which plan you chose and your subscription status | To know what you're entitled to and whether the account is current | Performance of contract |
| Your server's details — its identifier, IP address, region | To operate, support, and bill for the service | Performance of contract |
| Server and access logs, including IP addresses | Security, abuse investigation, and diagnosing faults | Our legitimate interest in keeping the service secure |
| Emails you send us | To answer you, and to remember the context next time | Performance of contract |
| Invoices and payment records | Accounting and tax | Legal obligation |
What we do not collect
- Card details. Payment is handled entirely by Stripe on their own pages. Card numbers never reach our servers.
- Passwords. There aren't any. Sign-in is by a single-use link emailed to you, so we have nothing to store or leak.
- Anything you type into an application form beyond what you see. No keystroke logging, no session recording.
- Card details. Never. See above.
3. Cookies and measurement
Our dashboard sets one cookie holding a random session identifier, so that you stay signed in. It is strictly necessary for the service to work and is deleted when you sign out or after 30 days.
We also use Google Tag Manager across our website and dashboard to understand how people find us and whether our advertising works. Tag Manager and the tools loaded through it may set cookies and receive your IP address. It is not loaded on the sign-in confirmation page, because that page's address contains a single-use login token which we will not hand to anyone else.
When someone applies for a free website build, we tell Facebook that an enquiry happened, along with an irreversibly scrambled version of the email address so they can match it to an advert. This is sent from our own server, not by a tracking script in your browser. We do not send your name, your message, or anything about your business.
4. Who else processes your data
| Who | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | Provides the physical servers | Germany / EU |
| Stripe | Payments, card storage, invoices, subscription management | USA and EU |
| Resend | Delivers our emails to you, including sign-in links | USA |
| Namecheap | Domain registration and DNS | USA |
| Google (Tag Manager) | Measuring how people find us and whether our advertising works | USA and EU |
| Meta (Facebook) | Told when an enquiry comes from one of their adverts, with a scrambled email address so they can match it. Sent from our server | USA |
Where a processor is outside the European Economic Area, transfers are made under the European Commission's Standard Contractual Clauses or another approved safeguard. We do not sell your personal data, and we do not share it for advertising.
5. How long we keep it
- Account data — for as long as your account is open, then 30 days after it closes.
- Server logs — up to 90 days.
- Invoices and accounting records — as long as tax law requires, typically 5 years. We cannot delete these on request.
- Support emails — 2 years.
6. Your rights
If you are in the UK or EEA, you have the right to:
- ask what we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data deleted, where we have no overriding legal reason to keep it;
- object to, or ask us to restrict, processing based on legitimate interests;
- receive your data in a portable format;
- complain to your data protection authority.
Email privacy@cloudrelay.ai and we will respond within one month. We will not charge you or make it difficult.
7. Security
Each customer runs on their own isolated virtual server, so one customer's workload cannot reach another's. Access to our management systems is limited to staff who need it and protected by two-factor authentication. Traffic is encrypted in transit with TLS. We have no passwords to breach, because we don't use them.
If a breach affects your personal data and is likely to result in a risk to you, we will notify you and the relevant authority within the time limits the law requires.
8. Data your own application collects
If your app or website collects personal data from your users, you are the controller of that data and we are your processor. We process it only to provide the hosting, and only on your instructions. You are responsible for having your own privacy notice, lawful basis, and consent mechanisms for those users. If you need a written data processing agreement, email privacy@cloudrelay.ai and we'll provide one.
9. Changes
We may change this policy at any time without telling you first. The date at the top of this page always shows when it last changed, so it is worth checking now and again.
10. Contact
Hartmire Limited
privacy@cloudrelay.ai