This Privacy Policy explains how Postflight ("we", "us", "our") collects, uses, discloses, and protects personal data in connection with our websites, dashboard, status pages, APIs, MCP endpoints, client scripts, and related services (the "Service").
Postflight is currently operated by its founder as a sole proprietorship, pending incorporation. Upon formation of a successor legal entity, that entity will assume responsibility for personal data held under this Policy, and we will update this Policy to reflect its details.
We are committed to handling personal data in accordance with applicable data protection laws, including, where applicable, the EU/UK General Data Protection Regulation (GDPR) and the data protection laws of the jurisdictions in which we operate.
1. The two roles we play
Postflight handles data in two distinct capacities:
- As a controller
- For data about you — the person who signs up, administers an account, or visits our website — we decide how and why the data is processed. Sections 2–4 primarily concern this data.
- As a processor / data intermediary
- The Service ingests logs, metrics, telemetry, and error data from applications you connect. That data belongs to you and may incidentally contain personal data about your end users (for example, IP addresses or identifiers appearing in logs). For that data, you are the controller and we process it only on your instructions to provide the Service. If you need a data processing agreement (DPA), contact us at [email protected].
If you are an end user of an application monitored by Postflight and have questions about that application's data practices, please contact the application's operator — they control that data.
2. Data we collect
- Account and profile data
- Name, email address, and authentication identifiers, collected via our identity provider when you sign up or log in; organization/workspace names; plan and billing status.
- Connection and configuration data
- OAuth tokens and metadata for platforms you connect (e.g. Vercel, Railway, Fly.io, Netlify, or a Kubernetes cluster), project and deployment identifiers, repository metadata, journey definitions, notification channel configuration (e.g. a Slack or Discord webhook), and status page settings.
- Operational data from your connected systems (processed on your behalf)
- Deployment events, build and deploy metadata, logs, metrics, error reports, console and network telemetry captured by client scripts you install, and the results of automated checks and journey runs. We do not intentionally collect end-user personal data through these channels, but such data may appear incidentally in logs and error payloads you route to us. You are responsible for scrubbing data at the source that you are not permitted to share.
- Usage and device data
- How you interact with the Service (features used, pages viewed, actions taken), approximate location derived from IP address, browser and device type, and diagnostic logs about the Service itself. We use this for security, product analytics, tier-limit metering, and billing.
- Payment data
- If you purchase a paid plan, payments are handled by a payment processor; we receive limited information (such as plan, transaction status, and partial card details) but do not store full card numbers.
- Communications
- Messages you send us (support requests, feedback) and related metadata.
- Cookies and similar technologies
- We use cookies and similar technologies that are necessary for authentication and session management, and optionally for analytics. You can control non-essential cookies through your browser or, where required, through a consent mechanism.
We do not knowingly collect data from children under 18; the Service is not directed at them.
3. How we use data
We use personal data to:
- provide, operate, secure, and maintain the Service, including authentication, monitoring your connected applications, running checks, detecting incidents, and delivering notifications;
- power AI-assisted features such as incident diagnosis, change correlation, and agent hand-off — operational data may be sent to AI model providers acting as our sub-processors for this purpose;
- publish the public status pages you configure (only the information you choose to expose);
- meter usage against plan limits, manage billing, and prevent abuse;
- respond to support requests and communicate with you about the Service, including service and security notices;
- send product updates and marketing communications where permitted — you can opt out at any time;
- analyze and improve the Service, using aggregated or de-identified data where feasible;
- comply with legal obligations and enforce our Terms of Service.
Legal bases (where GDPR applies): performance of a contract (providing the Service), legitimate interests (security, product improvement, business communications), consent (where required, e.g. certain cookies or marketing), and legal obligation.
We do not sell personal data, and we do not use your Customer Data to train generalized AI models.
5. International transfers
We operate from Sri Lanka, and our infrastructure and service providers may store or process data in other countries (including the United States and the European Union). Wherever data is transferred, we take steps to ensure it receives a comparable standard of protection and, where the GDPR applies, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
6. Retention
We keep personal data only as long as needed for the purposes above:
- Account data: for the life of your account and a reasonable period afterwards for legal, billing, and security purposes.
- Operational data (logs, telemetry, check results): for the retention window associated with your plan, after which it is deleted or de-identified on a rolling basis.
- OAuth tokens: until you disconnect the platform or delete your account, at which point they are revoked and deleted.
- Billing records: as required by tax and accounting law.
When you delete your account, we delete or de-identify your personal data and Customer Data within a reasonable period, except where retention is required by law or for backup cycles, in which case data remains protected until purged.
7. Security
We implement administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit, encrypted storage of credentials and tokens, tenant isolation, least-privilege access controls, and logging and monitoring of our own systems. No method of transmission or storage is completely secure; if we become aware of a data breach affecting your personal data that meets applicable notification thresholds, we will notify you and the relevant authorities as required by law.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- access the personal data we hold about you and information about how it has been used or disclosed;
- correct inaccurate or incomplete data;
- delete your data or your account;
- port data you provided to us in a machine-readable format;
- object to or restrict certain processing, including direct marketing;
- withdraw consent where processing is based on consent, without affecting prior processing;
- complain to the data protection authority in your jurisdiction — for example, your local supervisory authority in the EU/UK.
To exercise these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law and may need to verify your identity first.
If your personal data appears in Customer Data controlled by one of our customers, we will refer your request to that customer and support them in responding, as required by law.
9. Do Not Track and similar signals
Our Service does not currently respond to browser Do Not Track signals. Where legally required, we honor recognized opt-out preference signals for applicable jurisdictions.
10. Changes to this Policy
We may update this Policy from time to time. For material changes we will provide reasonable advance notice by email or in-product notice. The "Last updated" date at the top reflects the latest revision. Your continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
11. Contact us
Privacy contact — Postflight. Email: [email protected]
Questions about this document? Email [email protected].