Privacy Policy
Last updated: 2026-05-11
This Privacy Policy explains what information Nano-BaaS ("we", "us") collects, how we use it, and your rights regarding that information. It applies to anyone using the Service at nanobaas.io.
1. Information we collect
- Account data — your email address, username, and a hashed password when you sign up.
- Imported data — the contents of any Google Sheet or CSV you import into the Service.
- Usage data — API request counts, audit log entries (action, timestamp, API key used), and basic technical metadata such as IP address and user agent.
- Billing data — if you upgrade, Stripe processes your payment. We store your Stripe customer ID and subscription status; we never see or store your card details.
2. How we use it
- To operate the Service — provisioning datasets, serving APIs, enforcing quotas.
- To communicate with you — verification emails, password resets, important account notices.
- To improve the Service — aggregate usage analysis, debugging, capacity planning.
- To meet legal obligations and prevent abuse.
3. Sharing
We do not sell your personal data. We share data only with the service providers necessary to run Nano-BaaS — for example, our hosting provider, our email provider, and Stripe for billing. We may disclose data when required by law.
4. Data location and retention
Your imported datasets and account information are stored on servers we operate. We retain your data for as long as your account is active. If you delete your account, we delete associated datasets and audit log entries within a reasonable period, except where retention is required by law.
5. Security
We use industry-standard measures to protect your data — encrypted transport (HTTPS), hashed passwords, and access controls. No system is perfectly secure; you are responsible for keeping your account credentials confidential.
6. Your rights
You may have rights to access, correct, export, or delete your personal data depending on your jurisdiction. To exercise any of these rights, contact us at hello@kodestack.io. If you are in the UK, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
7. Cookies
We use cookies only as required for session management and CSRF protection. We do not use third-party advertising or tracking cookies.
8. Changes
We may update this Privacy Policy from time to time. Material changes will be communicated by email or via the Service.
9. Contact
Questions about your data or this policy? Contact us at hello@kodestack.io.