Priostack ("we", "our", "us") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how you can control it.
1. Information We Collect
- Account data: email address and hashed credentials when you sign up.
- API usage data: request logs, credit consumption, and process instance metadata associated with your API key.
- Payment data: billing is handled entirely by Stripe. We never store your card number or CVV.
- Analytics: anonymous page-view counts, browser type, and referring URL. No personally identifiable information is used for analytics.
2. How We Use Your Data
- To provide and maintain the Priostack API service.
- To send transactional emails (account creation, top-up receipts).
- To detect abuse and protect the security of the platform.
- To improve the product via aggregated, anonymised usage statistics.
3. Data Sharing
We do not sell, rent, or share your personal data with third parties except:
- Stripe, for payment processing (Stripe Privacy Policy).
- Reddit Ads Pixel — used for campaign conversion tracking on Reddit. Tracks pageviews and signup conversions. Reddit Privacy Policy.
- Facebook/Meta Pixel — used for retargeting campaigns on Facebook and Instagram. Tracks pageviews. Meta Privacy Policy.
- LinkedIn Insight Tag — used for LinkedIn campaign analytics and conversion tracking. Tracks pageviews and professional audience insights. LinkedIn Privacy Policy.
- Google Analytics / Google Ads (gtag.js) — used for traffic analytics and Google Ads conversion tracking. Tracks pageviews, events, and conversions. Google Privacy Policy.
- PostHog — used for session replay and product analytics (opt-in, requires cookie consent). Masks all sensitive form inputs. PostHog Privacy Policy.
- When required by law or to protect the rights and safety of our users.
4. Data Retention
Account data is retained for as long as your account is active. You may request deletion at any time by emailing privacy@priostack.com. Process instance data (BPMN logs) is stored for 90 days by default.
5. Cookies
We use only essential session cookies. The dashboard stores a short-lived session token in localStorage - not your raw API key. This token expires in 30 minutes and is automatically refreshed while you are active. We do not use tracking or advertising cookies.
6. Security
All data is transmitted over HTTPS (TLS 1.2+). API keys are hashed and never stored in plain text. Our servers are hardened and firewall-protected.
7. Your Rights
If you are located in the EU/EEA, you have the right to access, rectify, erase, or port your personal data under GDPR. Contact us at privacy@priostack.com.
8. Changes to This Policy
We may update this policy from time to time. We will notify you by email if changes are material. Continued use of the service constitutes acceptance of the revised policy.
9. Contact
Questions? Email privacy@priostack.com.
v1.5.86