Not open yet — signups haven't started. Join the list for the day they do.
Home/Legal/Privacy policy

Legal

Privacy Policy

Effective date: to be set at launch — this policy is not yet in effect. The version shown here is under legal review and subject to change before go-live.

What we collect, why, who we share it with, and how to ask us to delete it — including how Git and MCP integrations are secured.

The short version: we collect what's needed to run hosting — account and billing information (via Stripe), server logs, and, if you connect one, GitHub and MCP integration data. GitHub App credentials are encrypted at rest; MCP tokens we issue are hashed and shown to you only once. We don't sell personal information, and we don't run advertising trackers. Our infrastructure runs primarily on servers we operate ourselves rather than a general-purpose cloud vendor.

This Privacy Policy explains how personal information is collected, used, disclosed, retained, and protected in connection with lemonadehost.com, the Lemonade Host account dashboard, hosting platform, support channels, deployment tools, APIs, GitHub integration, MCP server, optional add-ons, and related services (collectively, the "Service").

Until a successor entity is identified in an updated version of this Policy, Analytix Media is the current legal operator of the Lemonade Host service and is the controller or business responsible for personal information used for Lemonade Host account administration, billing, security, support, and operations. Lemonade Host is a separate product and brand. Analytix Media is identified solely because it is temporarily acting as the legal operator before the Lemonade Host business is transferred to a dedicated entity.

For personal information contained in or collected through a customer's hosted website and processed only on that customer's instructions, the customer generally acts as the controller or business and Lemonade Host generally acts as a processor, service provider, or contractor. Section 12 explains this distinction.

Questions or privacy requests may be sent to [email protected].

2. Summary

We collect the information reasonably needed to provide and secure a hosting service, process payments, connect authorized repositories and deployment tools, respond to support requests, comply with law, and prevent abuse.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not run third-party advertising trackers. We may use essential cookies or similar technologies for login, session, fraud prevention, preferences, and security.

The Service is hosted primarily on infrastructure owned or controlled by the current Operator. We use third parties for functions such as payments, content delivery and security, GitHub connections, transactional email, error monitoring, optional backup storage, and potentially AI-assisted support.

No method of collection, transmission, or storage is completely secure. You should not upload secrets or regulated data unless the Service and your plan are expressly designed for that use.

3. Personal information we collect before launch

Before paid accounts are available, the waitlist may collect:

  • email address;
  • signup date and source page;
  • consent and delivery records associated with the launch notice; and
  • ordinary request and security log data described below.

The waitlist email address is used to send the launch notification and related essential delivery or suppression processing. It is not automatically enrolled in an ongoing marketing newsletter unless the person separately opts in.

4. Personal information we collect after launch

Depending on how you use the Service, we may collect the following categories.

4.1 Account and identity information

  • email address;
  • account identifier;
  • display name or organization name, if provided;
  • country, region, language, or time zone, if provided or reasonably inferred for service operation;
  • account status, plan, Sites, permissions, and settings;
  • records of acceptance of legal terms and recurring billing consent; and
  • identity or authority information provided when resolving an account, payment, abuse, or ownership dispute.

4.2 Authentication and session information

Authentication may use magic links, one-time codes, passkeys, passwords, GitHub or another OAuth provider, or other methods we make available. We may process:

  • hashed or otherwise protected authentication data;
  • login-link issuance and expiration records;
  • OAuth account identifiers and authorization metadata;
  • session identifiers and essential cookies;
  • login time, IP address, browser or device information;
  • security events, failed attempts, and revocation history; and
  • account recovery and verification records.

We do not receive your GitHub password. If password authentication is offered, passwords should be stored using an industry-standard one-way hashing method rather than in readable form.

4.3 Billing and transaction information

Stripe processes payment-card information. Stripe may collect card details, billing address, tax information, and fraud-prevention data directly. Lemonade Host generally receives and stores:

  • Stripe customer, subscription, invoice, payment, refund, dispute, and payment-method references;
  • card brand, expiration month or year, last four digits, and payment status where made available;
  • billing name, company name, country, postal code, and tax identifiers where needed;
  • plan, Site, add-on, amount, currency, interval, discount, tax, and renewal information; and
  • correspondence about refunds, disputes, chargebacks, and billing support.

We do not intentionally store full payment-card numbers or card security codes on our own servers.

4.4 Site and service metadata

  • Site name and internal identifier;
  • Lemonade Host subdomain and custom domain;
  • DNS and certificate status;
  • plan, billing interval, add-ons, storage, bandwidth, request counts, file counts, and deployment counts;
  • settings, configuration, feature flags, and operational status;
  • creation, modification, suspension, cancellation, and deletion dates; and
  • backup, restore, migration, and continuity-protection metadata.

4.5 Customer Content

We store and serve the files and content you deploy, which may include HTML, CSS, JavaScript, images, fonts, text, code, configuration, and other site assets. Optional features may also process form submissions, structured data, messages, or other information that a customer chooses to collect through a Site.

Customer Content may contain personal information about the customer, website visitors, employees, contractors, clients, or other people. Customers control what they upload and are responsible for having a lawful basis and providing required notices.

We do not routinely read Customer Content for marketing purposes. We may access or automatically analyze it as reasonably necessary to provide the Service, troubleshoot at the customer's request, detect malware or abuse, enforce policies, protect security, comply with law, or restore data.

4.6 Server, request, device, and security logs

Our systems and Cloudflare may automatically process:

  • IP address;
  • timestamp;
  • requested hostname, URL, path, method, protocol, and response status;
  • user agent, browser, operating system, device, and referring page;
  • network, routing, cache, TLS, DNS, firewall, bot, and security information;
  • request size, response size, latency, bandwidth, and error information;
  • approximate geographic region derived from IP address; and
  • identifiers used to detect abuse, fraud, automated traffic, or security incidents.

Logs may relate to visitors of lemonadehost.com, account users, API or MCP clients, and visitors to customer Sites.

4.7 Deployment, GitHub, API, CLI, and MCP information

For deployments and integrations, we may process:

  • deployment time, source, status, actor, commit, branch, file manifest, file hashes, error output, and rollback or restore information;
  • GitHub account, organization, repository, branch, installation, webhook, and commit metadata;
  • GitHub App installation identifiers and, when needed, short-lived installation access tokens or other encrypted integration credentials;
  • an encrypted or otherwise protected webhook secret used to verify GitHub events;
  • API and MCP token identifiers, names, scopes, creation dates, last-used dates, revocation dates, and audit records;
  • one-way hashes of MCP or API tokens that we issue; and
  • commands, files, and instructions submitted through an authorized deployment channel.

We may show a raw MCP or API token only once when it is created. After that, a properly implemented hashed token cannot be retrieved by us and must be replaced if lost.

4.8 Support and communications

We collect information you provide in support tickets, emails, chat, feedback, abuse reports, privacy requests, legal notices, and other communications. This may include contact details, account information, screenshots, files, diagnostic data, and the contents of the message.

Do not send passwords, full card numbers, private keys, raw access tokens, repository secrets, or unnecessary sensitive information in an ordinary support message.

4.9 Abuse, legal, and compliance information

We may collect and preserve information associated with suspected phishing, malware, fraud, infringement, spam, attacks, policy violations, sanctions, legal requests, ownership disputes, and investigations. This may include reports from third parties, evidence, copies of content, logs, correspondence, decisions, and appeal records.

4.10 Optional analytics information

No advertising analytics are intended at launch. We may later use a privacy-focused or self-hosted analytics tool, such as Umami, to understand aggregate use of our own marketing and documentation pages. Before activating a tool that materially changes our practices, we will update this Policy and provide any consent mechanism required by law.

5. Sources of personal information

We collect personal information from:

  • you, when you join the waitlist, create an account, pay, configure a Site, deploy content, contact support, or exercise a right;
  • your organization, administrator, employee, contractor, client, or other Authorized Agent;
  • a customer-authorized AI assistant, script, CLI, API client, or MCP client;
  • GitHub and other integrations you connect;
  • Stripe and other service providers;
  • browsers, devices, servers, networks, Cloudflare, and security systems automatically;
  • visitors who access a customer Site or submit data through an optional feature;
  • abuse reporters, rights holders, law-enforcement agencies, courts, regulators, and other third parties; and
  • publicly available sources where reasonably necessary to investigate abuse, verify ownership, or comply with law.

6. How we use personal information

We may use personal information to:

  • create, authenticate, administer, secure, and support accounts;
  • process purchases, renewals, taxes, refunds, disputes, and chargebacks;
  • host, store, cache, back up, restore, deploy, and serve Customer Content;
  • connect GitHub repositories and process authorized deployments;
  • issue, verify, scope, rotate, and revoke tokens;
  • configure custom domains, DNS, SSL, and related features;
  • provide transactional email, receipts, magic links, renewal notices, policy notices, and security alerts;
  • measure storage, bandwidth, requests, deployments, and other resource use;
  • monitor availability, diagnose errors, maintain systems, and improve reliability;
  • provide customer support and, if enabled, AI-assisted support;
  • detect, investigate, prevent, and respond to fraud, abuse, malware, phishing, spam, attacks, and unauthorized access;
  • enforce our Terms, Acceptable Use Policy, Refund Policy, and technical limits;
  • protect customers, visitors, the public, our systems, and third parties;
  • comply with contracts, tax obligations, sanctions, court orders, legal process, and other laws;
  • establish, exercise, or defend legal claims;
  • complete a merger, financing, reorganization, sale, assignment, or transfer of the Lemonade Host business; and
  • perform other uses disclosed at the time of collection or authorized by you.

We do not use Customer Content to create advertising profiles. We do not intentionally use private Customer Content to train a publicly available general-purpose AI model without a separate, clear opt-in.

Where a law requires a legal basis, we generally rely on:

  • Contract: processing needed to create an account, process a purchase, host a Site, deploy files, provide an integration, or respond to a service request.
  • Legitimate interests: securing and improving the Service, preventing fraud and abuse, measuring resource use, communicating about the Service, protecting legal rights, and operating a hosting business, balanced against individual rights.
  • Legal obligation: tax, accounting, sanctions, consumer, privacy, law-enforcement, court, and regulatory requirements.
  • Consent: waitlist signup, optional marketing, certain cookies or analytics, or another use where consent is requested. Consent may be withdrawn for future processing, but withdrawal does not make earlier lawful processing unlawful.
  • Vital interests or public interest: only in unusual circumstances where applicable law permits or requires it.

When we process personal information solely on a customer's documented instructions as a processor, the customer is responsible for identifying its legal basis.

8. Cookies and similar technologies

We may use cookies, local storage, session identifiers, and similar technologies that are necessary or reasonably useful for:

  • account login and session continuity;
  • magic-link, OAuth, passkey, and authentication flows;
  • security, fraud detection, load balancing, and abuse prevention;
  • saving language, interface, or consent preferences;
  • checkout and payment processing; and
  • measuring essential technical performance.

These technologies may be set by us or service providers such as Cloudflare, Stripe, or an authentication provider.

We do not intend to use third-party advertising cookies or pixels at launch. If we add optional analytics, advertising, or another nonessential technology, we will update disclosures and provide a consent or opt-out tool where required.

A browser's "Do Not Track" setting is not a uniform legal or technical standard. Where applicable law requires recognition of a legally valid opt-out preference signal, we will honor it for activities to which it applies. Because we do not sell or share personal information for cross-context behavioral advertising, an advertising opt-out should not be necessary for our current practices.

9. Service providers and subprocessors

We disclose personal information to providers that perform services for Lemonade Host. They may process information only for permitted purposes under their contracts, instructions, and applicable law.

Confirmed or planned provider categories include:

  • Stripe: payment processing, subscription billing, fraud prevention, invoices, refunds, and disputes. Stripe receives payment and billing information directly.
  • Cloudflare: DNS, content delivery, caching, SSL/TLS, tunnel connectivity, bot management, DDoS mitigation, firewall, and network security. Cloudflare processes request and network information for Lemonade Host and customer Sites.
  • GitHub: OAuth sign-in where offered, GitHub App repository connections, webhooks, and repository-based deployments selected by the customer.
  • Backblaze B2: off-site backup storage only for customers who purchase or activate the optional Continuous Protection feature, unless otherwise disclosed.
  • A transactional email service provider: delivery of magic links, one-time codes, receipts, renewal notices, security alerts, and service messages. The specific provider may be Postmark, Resend, Amazon SES, or another provider selected before or after launch.
  • An error-monitoring and diagnostics provider: collection and analysis of application errors, stack traces, performance data, and limited technical context. The provider may be Sentry or another provider.
  • An AI model or support-automation provider: processing of support-chat content or support prompts if an AI-assisted support feature is enabled. The provider may be Anthropic, OpenAI, or another provider. We will disclose the use at the point of interaction and configure or contract for appropriate business data controls before enabling it.
  • Professional advisers and operational vendors: accountants, attorneys, security consultants, insurers, and other providers that need limited information to perform a legitimate service.

Our primary application infrastructure and database are intended to be self-hosted on servers owned or controlled by the Operator rather than hosted by a general-purpose cloud infrastructure vendor. Standard backups may replicate to a second server owned or controlled by the Operator.

We may change providers as the Service evolves. Describing a provider by function allows us to replace it without rewriting the entire Policy, but we will update the provider name and the Last Updated date when a change materially affects privacy practices or where law requires identification.

10. Customer-connected AI assistants and external tools

A customer may connect an external AI coding assistant, agent, editor, script, or other tool to our MCP server or API using a scoped token. That external tool is selected, instructed, and controlled by the customer.

When the customer's tool sends a deployment command or files to Lemonade Host:

  • we process the command, files, token identifier, scope, logs, and related metadata needed to perform and secure the deployment;
  • the external tool provider processes information under its own terms and privacy policy;
  • the external tool provider is not our service provider or subprocessor merely because the customer instructed it to connect to Lemonade Host; and
  • the customer is responsible for deciding what information to provide to the tool and whether its use is lawful and secure.

Customers should not place raw MCP tokens, secrets, personal data, or confidential content into an AI prompt unless they understand the external provider's handling of that information.

11. AI-assisted Lemonade Host support

If Lemonade Host offers an AI-assisted support feature, that is different from a customer-connected deployment tool. In the support feature, we may send the support message and limited relevant account or diagnostic context to an AI provider to help generate, summarize, classify, or route a response.

Before enabling that feature, we intend to:

  • identify that AI assistance is being used at the point of interaction;
  • limit the information sent to what is reasonably needed;
  • avoid sending raw payment-card data, passwords, private keys, or raw access tokens;
  • use available business or enterprise privacy settings;
  • prohibit use of the submitted content to train a public model unless the user separately and clearly opts in; and
  • establish an appropriate retention and deletion configuration.

Users should review AI-generated support and should not rely on it as legal, security, financial, or other professional advice.

12. Customer Sites and allocation of privacy responsibilities

12.1 Lemonade Host as controller or business

We generally determine the purposes and means of processing account, billing, security, abuse-prevention, service analytics, support, and legal-compliance information. For those activities, Lemonade Host and the Operator act as a controller or business.

12.2 Lemonade Host as processor, service provider, or contractor

When we process personal information contained in Customer Content or collected through a customer Site solely to provide hosting or an optional customer-configured feature, the customer generally determines why the information is collected and how it is used. The customer is generally the controller or business, and Lemonade Host is generally a processor, service provider, or contractor.

In that role, we process information to provide the Service, secure it, prevent abuse, follow documented customer instructions, and comply with law. We do not sell that information or use it for cross-context behavioral advertising.

12.3 Customer obligations

Each customer is responsible for:

  • publishing an accurate privacy notice for its Site;
  • identifying the customer as the party responsible for visitor data;
  • obtaining legally required consent for forms, cookies, scripts, communications, and analytics;
  • providing a lawful basis for processing;
  • limiting collection to what is necessary;
  • responding to visitor rights requests;
  • selecting and contracting with third-party tools;
  • avoiding regulated or sensitive data that the Service is not designed to handle; and
  • notifying us when our assistance is reasonably needed to fulfill a lawful request.

If a static Site uses client-side JavaScript to send information directly from a visitor's browser to a customer-selected third party, that third party may receive the data without it being stored by Lemonade Host, apart from ordinary network or security logs. The customer is responsible for disclosing and governing that transfer.

If Lemonade Host provides an upgraded feature that receives or stores form submissions or other visitor data, the feature description and any additional data-processing terms may apply.

13. Other disclosures of personal information

We may disclose personal information:

  • to service providers and subprocessors described above;
  • to an account owner, organization administrator, or Authorized Agent consistent with account permissions;
  • at your direction or with your consent;
  • to investigate abuse, fraud, infringement, security incidents, ownership disputes, or violations;
  • to comply with law, regulation, subpoena, warrant, court order, sanctions, or other valid legal process;
  • when reasonably necessary to protect rights, safety, property, users, visitors, the public, or the Service;
  • to establish, exercise, or defend legal claims;
  • to accountants, attorneys, insurers, auditors, and professional advisers; or
  • in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale, assignment, or transfer of all or part of the Lemonade Host business.

We may disclose aggregated or deidentified information that cannot reasonably be linked to an individual. We will not attempt to reidentify data that applicable law requires us to maintain as deidentified.

14. International processing and transfers

Lemonade Host is operated from the United States, and primary systems are intended to be located in the United States. Information may therefore be transferred to and processed in the United States and other countries where providers operate.

Privacy laws in those countries may differ from the laws where you live. Where the EEA, UK, Switzerland, or another jurisdiction requires a transfer mechanism, we will use an applicable mechanism or take other required steps before making a restricted transfer, such as contractual safeguards, an adequacy framework, or another legally recognized method.

Customers that use the Service to process personal information from multiple countries are responsible for determining whether their own use requires a data processing addendum, transfer assessment, representative, local storage, or other compliance measure.

15. Retention

We retain personal information only for as long as reasonably necessary for the purposes described, including service delivery, security, dispute resolution, tax, accounting, legal compliance, and enforcement. Actual retention can vary based on the data, account status, backup cycles, legal holds, investigations, and technical constraints.

Our intended baseline schedule is:

  • Waitlist email: until the launch notice is sent, the person asks for deletion, or a short delivery and suppression period ends; ordinarily no more than 30 days after the launch message unless needed to honor an unsubscribe or legal obligation.
  • Ordinary server and request logs: generally up to 30 days, except when retained longer for security, abuse, fraud, legal, or billing purposes.
  • Authentication, deployment, API, CLI, and MCP audit logs: generally up to 30 days, with relevant records retained longer when needed to investigate compromise, abuse, or a dispute.
  • Active account information: while the account is active and generally up to 30 days after closure, except for records that must or may be retained longer.
  • Customer Content on active systems: while the Site is active; after deletion or termination, removal from primary systems generally occurs promptly or within 30 days, subject to technical and legal exceptions.
  • Standard backup copies: generally age out through the applicable backup cycle. The ordinary operational target may be shorter, such as approximately seven days, but residual copies may remain for up to 30 days. Backup availability is not guaranteed.
  • Continuous Protection backups: for the retention period described for that add-on, subject to technical, contractual, and legal exceptions.
  • GitHub integration identifiers and retrievable secrets: until the connection is revoked, disconnected, or no longer needed, then deleted from active systems promptly; short-lived access tokens expire through their normal lifecycle, and encrypted residual copies of longer-lived secrets may remain until backup cycles expire.
  • MCP or API token hashes: until revoked, expired, deleted, or the account is closed, then removed from active systems promptly, subject to backup cycles and security records.
  • Billing, invoice, tax, refund, and dispute records: for the period required or reasonably advisable under tax, accounting, payment, and legal rules, which may be several years.
  • Subscription-consent and legal-acceptance records: for at least the period required by applicable automatic-renewal and contract law. For California transactions, the intended minimum is three years or one year after the contract ends, whichever is longer.
  • Support communications: generally up to 24 months after the matter is closed, unless a shorter period is practical or longer retention is needed for security, abuse, legal, billing, training-quality review, or repeated issues.
  • Abuse, security incident, legal hold, and litigation records: for as long as reasonably necessary to investigate, protect the Service, comply with law, or establish, exercise, or defend claims.

Deletion from active systems does not always mean immediate deletion from immutable logs, encrypted backups, fraud systems, provider records, or records we are legally permitted or required to retain.

16. Security

We use administrative, technical, and physical safeguards intended to protect personal information. Depending on the feature, safeguards may include access controls, network filtering, encryption in transit, encryption at rest for retrievable credentials, one-way hashing for issued tokens, scoped permissions, secret rotation, logging, backups, and security monitoring.

GitHub App private keys and other retrievable integration secrets should be encrypted at rest. Short-lived GitHub access tokens should be generated and discarded through their normal lifecycle. MCP or API tokens issued to customers should be hashed at rest and displayed only once. Dashboard controls should allow customers to revoke GitHub connections and tokens.

No security measure is perfect. We cannot guarantee that unauthorized access, loss, alteration, disclosure, hardware failure, software defects, attacks, or other incidents will never occur. Customers remain responsible for securing their own devices, email, repositories, code, credentials, Authorized Agents, and backups.

17. Privacy rights and requests

Depending on where you live and which law applies, you may have the right to:

  • know or access personal information we hold;
  • receive information about categories, sources, purposes, and recipients;
  • correct inaccurate personal information;
  • delete personal information, subject to exceptions;
  • obtain a portable copy;
  • restrict or object to certain processing;
  • withdraw consent for future processing;
  • opt out of sale, sharing, or targeted advertising where applicable;
  • limit certain uses of sensitive personal information where applicable;
  • appeal a denied request where applicable; and
  • complain to a privacy or data-protection authority.

Submit a request to [email protected]. State the account email and the right you want to exercise. We may need to verify identity and authority before responding. Verification may include access to the account email, authentication to the account, transaction information, or other proportionate steps.

An authorized agent may submit a request where law permits, but we may require proof of authorization and direct verification with the individual.

We may deny or limit a request where permitted, including when we cannot verify identity, the information belongs to another person, deletion would impair security or legal rights, retention is legally required, or the request is manifestly unfounded, excessive, fraudulent, or outside the scope of applicable law.

We will not unlawfully discriminate against a person for exercising a privacy right.

18. California privacy information

The California Consumer Privacy Act, as amended, applies only to businesses that meet statutory criteria and to certain service providers, contractors, and recipients. Whether every CCPA obligation applies to Lemonade Host may depend on the current Operator's size, data volume, relationships, and activities.

To the extent the CCPA applies, this Policy describes the categories of personal information collected, sources, business or commercial purposes, categories of recipients, retention approach, and rights request method.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 16.

Even where a particular statutory right does not legally apply, we may choose to honor a reasonable access, correction, or deletion request when doing so is feasible, secure, and consistent with our obligations.

19. EEA, UK, and Swiss information

Where applicable, individuals in the EEA, UK, or Switzerland may have rights to access, correction, deletion, portability, restriction, objection, and withdrawal of consent, and may lodge a complaint with a competent supervisory authority.

If we rely on legitimate interests, you may request information about the balancing of those interests. If we rely on consent, withdrawal applies prospectively.

If Lemonade Host actively targets or materially expands service to these jurisdictions, additional measures may be required, including a data processing addendum, transfer terms, records of processing, a representative, or other local compliance steps. This Policy does not itself represent that every enterprise or regulated-customer requirement has been completed.

20. Automated processing and decisions

We may use automated systems to detect spam, attacks, malware, abnormal resource use, payment risk, or policy violations; prioritize support; route abuse reports; and identify technical errors.

These systems may temporarily block a request, deployment, Site, payment, or login. Where applicable law grants a right relating to a decision based solely on automated processing that has legal or similarly significant effects, you may request information or human review by contacting [email protected].

AI-assisted support may generate or suggest responses, but users should not treat those responses as professional advice. We do not intend to make employment, credit, housing, insurance, health, or similarly high-impact decisions about individuals through the Service.

21. Children and age restriction

The Service is not directed to children or minors. Account holders must be at least eighteen (18) years old.

We do not knowingly collect personal information directly from a person under 13 through a Lemonade Host account. If we learn that a minor created an account or submitted personal information without valid authorization, we may suspend the account and delete the information, subject to legal and security exceptions.

Customers may not use the Service to intentionally collect children's personal information unless they independently satisfy all applicable consent, notice, security, and other legal requirements and the applicable Lemonade Host feature is expressly approved for that use. The base Service is not designed for children's regulated data.

22. Changes to this Policy

We may update this Policy as the Service, providers, features, laws, or business structure change. The Last Updated date will identify the current version.

If a change materially affects how active account information is used, we will provide notice as required by law, which may be by email, account notice, or another appropriate method. A provider-name update that does not materially change the purpose or type of processing may be made by updating the provider list and date.

If the Lemonade Host business is transferred to a dedicated entity, this Policy will be updated to identify the new controller or business and any resulting changes to governing contacts, locations, or providers.

23. Contact

Privacy questions and requests:

[email protected]

For account security, do not include passwords, full card numbers, private keys, or raw access tokens in an ordinary email.

Related

The rest of the legal pages

Terms of service

What the service includes, how billing and deployments work, and how disputes are resolved.

Acceptable use policy

The limits and rules that keep a 99¢ site healthy for everyone.

Refund policy

The 30-day guarantee on a new site, and how billing disputes are handled.

Pricing

Every plan, every interval, on one page.

Get on the list

Join the list and we'll email you just once — that's the only thing we use your address for.

Join the list