TODO(legal): confirm the controller entity name, registered address, and registration number below before this page leaves draft status.
This Privacy Policy explains what personal data Webstead collects, why, and what rights you have over it. It applies to webstead.app and the Webstead dashboard (together, the "Service").
The data controller is [legal entity name — TODO], registered in Lithuania at [registered address — TODO]. Contact us about privacy matters at support@webstead.app.
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, password (hashed, never stored in plain text), display name | You, at registration |
| GitHub integration data | OAuth access token (encrypted at rest), repository/branch names you choose to deploy | You, via GitHub OAuth |
| Build configuration | Environment variables you set for a build (encrypted at rest), build logs | You, via the dashboard |
| Deployment data | Canister IDs, deployment history, site URLs, custom domains | Generated by the Service |
| Payment data | Top-up purchase records, plan tier | You and Stripe, Inc. (we do not store full card numbers) |
| Visitor form submissions | Content submitted through forms embedded on sites you host | Your site's visitors, via the Service |
| Support communications | Messages sent through our contact form or by email | You |
| Technical/log data | IP address, timestamps, and similar request metadata, retained briefly for security and rate-limiting (for example, to prevent abuse of the contact form and login) | Automatically, from your browser |
We do not use third-party analytics or advertising trackers on webstead.app — see our Cookie Policy for the complete (short) list of cookies we set.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and securing your account, providing the Service you signed up for | Performance of a contract |
| Processing cycle top-up payments | Performance of a contract |
| Responding to support requests | Performance of a contract / legitimate interest |
| Preventing abuse (rate-limiting, fraud prevention, spam filtering on the contact form) | Legitimate interest |
| Sending service emails (deploy failures, low-cycles warnings, security notices) | Performance of a contract / legitimate interest |
| Complying with legal obligations (e.g., tax records for payments) | Legal obligation |
Where we ever rely on consent (for example, optional marketing communications, if we introduce them), you can withdraw it at any time.
We share data only as needed to run the Service:
{yoursite}.webstead.app) and, if you use one, your custom domain's DNS.We do not sell personal data.
Because the Service publishes content to a public blockchain network, some data — specifically, the content of sites you choose to publish, and their public canister identifiers — is inherently visible to the network's node operators and, once served, to the public internet. This is a structural property of the Internet Computer, not a Webstead choice, and it means that content you publish is not held in the same way as data in a conventional private database. Account data (your email, password hash, encrypted tokens, private build configuration) is not published on-chain — only the built site content you choose to deploy is.
We retain account and deployment data for as long as your account is active, plus a reasonable period afterward to comply with legal obligations (such as tax records for payments) and resolve disputes. If you delete a site, we remove it from the network and stop serving it, subject to the blockchain caveat in Section 3. If you delete your account, we delete or anonymize personal data within a reasonable period, except where retention is legally required.
If you're in the EU/EEA or UK, you have rights under the GDPR (and equivalent rights in most other jurisdictions), including the right to:
To exercise any of these rights, email support@webstead.app. If you're in Lithuania, your supervisory authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI) — vdai.lrv.lt. If you're elsewhere in the EU/EEA, you may also contact your own national data protection authority.
Our infrastructure and service providers may process data outside your country of residence, including outside the EU/EEA. Where that happens, we rely on appropriate safeguards recognized under GDPR (such as Standard Contractual Clauses) with those providers.
We encrypt sensitive data at rest (including GitHub OAuth tokens and build environment variables) and in transit (TLS). No system is perfectly secure, and we can't guarantee absolute security, but we design the Service to minimize what's exposed and to whom — for example, environment variables are only ever decrypted for the duration of a build.
The Service is not directed at children under 16, and we don't knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we'll remove it.
We'll update the "Last updated" date above when this policy changes, and post a notice for material changes.
Questions about this policy or your data: support@webstead.app or our contact page.