Effective 1 September 2026
Privacy policy
This is a starting draft for friends and family GTM, not a substitute for counsel. We will hire a lawyer after 1,000 subscriptions. Plain language, short.
Who we are
Controller: DataMind Technology. Contact: jeffj@datamind.technology until a privacy@ alias exists.
What we collect
- Account: email address, password hash (Argon2id; we never store the password), encrypted authenticator-app secret, hashed 2FA backup codes.
- Teammates: emails you invite onto the tenant; whether they accepted, last login, last time they used the website app (
/app). - Tenant profile: company name, website.
- Billing: Stripe customer id, subscription id, SKU code. We do not collect or store card numbers, CVC, or billing street address — Stripe Checkout does.
- Product: projects and tickets the tenant creates; MCP API token hashes.
- Waitlist: email, verification time, invite status.
- Technical: session id cookie; security logs (prefer redacted email).
What we do not collect (this epic)
Phone, mailing address, billing address, government IDs, Google/Microsoft profile, or repo file contents. Agents send ticket fields and URIs through the thin MCP, not source dumps.
Why
Provide the Ticketron service, authenticate you, provision a tenant, enforce SKU entitlements, invite teammates, send transactional email (verify, reset, member invite, waitlist invite), and — if you pay — bill via Stripe.
Processors
Stripe (payments). Resend (transactional email). Azure / Databricks Lakebase (hosting and database). Squarespace (domain registrar and DNS). No sale of personal data. No ads network in V0.
Cookies
Essential session cookie only (httpOnly, Secure, SameSite=Lax).
No marketing pixels in V0.
Retention
Account data until the tenant is deleted. A deletion runbook is a later story — for friends and family, contact us to close an account. Waitlist emails: until invite expires or the person asks to be removed. Stripe retains payment data under their policy.
Security
TLS in transit; RLS isolation between tenants; passwords peppered in Key Vault; authenticator-app 2FA (TOTP) before API token reveal; API tokens stored hashed; cards never on our origin.
Your rights
We are US-first for this friends-and-family cohort: access and deletion via email request to jeffj@datamind.technology. If an EU/UK resident signs up, we will need a real GDPR pass (lawful basis, DPA with processors, SCCs). That work is not done — we are not copying GDPR clauses we cannot honor.
Children
Not directed at children under 16 (or 13). No accounts for minors.
Changes
Policy dated . Material changes announced by email to account holders.
Later (not live)
Databricks/Unity Catalog tagging of PII columns, DLP, and a formal retention job are not live. Do not pretend they are.