MTDT Privacy Policy
Last updated 25 August 2026
1. Who We Are and What This Policy Covers
This policy explains what we do with personal information about the people who visit our websites, create an MTDT account, use the platform, or get in touch with us.
MTDT is owned and operated by Shiny Friday Deployment Club LLC, 30 N Gould St # 43289, Sheridan, WY 82801, United States. That company decides what personal information is collected and why, and is the data controller wherever you are. "MTDT", "we" and "us" mean that company. "You" means the person the information is about.
The platform is developed and supported from the European Economic Area by Propeller Plan Sp. z o.o., KRS 0000899016, Święty Marcin 29/8, 61-806 Poznań, Poland, acting on our instructions. It is listed among the providers in Section 4.
What this policy does not cover. MTDT backs up and deploys the contents of the Salesforce orgs, Git repositories and issue trackers you connect to it. Personal data inside those systems belongs to you, and we handle it only on your instructions. That processing is governed by our Data Processing Agreement, not by this policy.
2. What We Collect
Information you give us
- Account details: your name, email address, and — if you sign in through Google or your organization's single sign-on provider — the account identifier that provider gives us.
- Billing details: the customer and subscription identifiers Stripe creates for you. Your card, billing address and tax identifiers are entered with Stripe and held by Stripe. We never receive or store card numbers.
- Anything you write to us: support requests, sales enquiries, and text you type into the platform, such as the name you give a deployment.
Information we record as you use the Services
- Sign-in and security events: timestamps, IP address, and multi-factor authentication events.
- An audit log of actions taken in your team, so administrators can see who did what.
- Product analytics: which pages and features are used, and technical details about your browser and device. Web addresses are stripped of identifiers before they are recorded.
- Website analytics on mtdt.io and docs.mtdt.io, including approximate location derived from your IP address.
- On the mtdt.io marketing website only: recordings of the visit — pages, clicks, scrolling and mouse movement — and measurement of whether an advertisement led you to us. Neither happens in the application or in the documentation.
We do not ask for, or deliberately collect, special categories of personal data such as health, biometric or political information. We do not collect precise location from your device.
3. Why We Use It
- To provide the Services — creating and securing your account, running what you ask the platform to do, taking payment, and supporting you. Basis: performance of our contract with you.
- To keep the Services working and safe — diagnosing faults, investigating abuse, keeping audit records, and understanding how the product is used so we can improve it. Basis: our legitimate interests in operating and improving a secure service.
- To market to you — sending product news to people who have asked for it, and measuring how our websites perform. Basis: your consent, which you can withdraw at any time.
- To meet legal obligations — accounting, tax, and responding to lawful requests. Basis: compliance with a legal obligation.
4. Who We Share It With
We do not sell personal information for money. Section 7 explains how US state privacy laws treat the advertising cookies on our websites.
We use the following providers, and they receive only what they need to do their job:
| Provider | What it does | Where |
|---|---|---|
| Hetzner Online GmbH | Hosts the platform and its databases | Germany |
| Stripe | Takes payments; holds the card and billing details you enter | United States |
| PostHog | Product analytics | European Union |
| Tag Manager and Analytics on mtdt.io and docs.mtdt.io | United States | |
| Microsoft | Clarity, which records visits to the mtdt.io website | Ireland, with onward transfer to the United States |
| Advertising and conversion measurement on the mtdt.io website | United States | |
| Salesforce | The chat widget on the mtdt.io website | United States |
| Tilda | Publishes the mtdt.io website | United Arab Emirates |
| Better Stack | Collects application logs and monitors uptime | European Union; provider in the United States |
| Propeller Plan Sp. z o.o. | Develops and supports the platform | Poland |
| Slack | Delivers internal operational notifications | United States |
| Amazon Web Services | Delivers transactional email | United States |
We also share personal information with our professional advisers, with authorities where the law requires it, and with a buyer if the business is sold — in which case this policy continues to apply until you are told otherwise.
The providers that process personal data from the systems you connect are a different list, published at Subprocessors.
5. Where It Is Processed
The platform runs in the European Union, on infrastructure operated by Hetzner Online GmbH in Falkenstein, Germany. The company that operates it is established in the United States, and several of the providers above are outside the European Economic Area; where personal data reaches them, the transfer is protected by a lawful transfer mechanism — the European Commission's Standard Contractual Clauses or, for providers certified under it, the EU–US Data Privacy Framework.
6. How Long We Keep It
We keep account and billing information for as long as you have an account, and afterwards only for as long as we need it — to finish billing, to meet accounting and tax rules, or to establish or defend a legal claim.
Application logs are kept for three days and monitoring metrics for thirty days, after which they are deleted. Product analytics is kept for one year, and recordings of visits to the marketing website for thirty days. Website analytics is kept for two months at the event level and up to fourteen months for the visitor record, which starts over if you visit again. After that it survives only as aggregate figures that identify no one.
The audit record of actions taken in your team is kept for longer. Its purpose is to let your administrators and us look back at what was done and by whom, and that purpose only works if the record outlasts the event.
7. Your Rights
You can ask us to give you a copy of your personal information, correct it, delete it, restrict or object to how we use it, or send it to another provider. Where we rely on your consent, you can withdraw it at any time; that does not affect anything we did before you withdrew it.
Write to mtdt@mtdt.io and we will answer within the time the law allows. If you are in the EEA, the UK or Switzerland and you think we have got it wrong, you can also complain to your national data protection authority.
If you live in California or another US state with a privacy law, you have comparable rights to know, delete and correct, and to opt out of targeted advertising. We do not sell personal information for money, but the advertising cookies described below may count as "sharing" or targeted advertising under those laws. Refuse those cookies, or email us, and we will act on it.
8. Cookies and Tracking
Some cookies are needed to sign you in and keep the platform working; without them it does not function. The rest are optional:
- On docs.mtdt.io we ask before loading anything. Google Analytics runs only if you accept, and the "Cookie settings" link in the footer lets you change your answer at any time. Refusing also clears the cookies Google has already set.
- On the mtdt.io marketing website we run more: Google Analytics, the LinkedIn advertising tag, and Microsoft Clarity, which records the visit. The banner there tells you they are in use. This is the marketing website only — none of it runs in the application.
- In the application we use PostHog for product analytics. It records which features are used; it does not record your screen.
You can also refuse or delete cookies in your browser. Doing so may break parts of the platform that depend on them.
9. Security
We take the security of this data seriously: access to production systems is limited to people who need it, data is encrypted in transit, and secrets are held in a dedicated vault. The measures set out in Appendix 2 of our Data Processing Agreement describe the platform as a whole and apply here too. No service can promise that it will never be breached, and we do not.
10. Children
The Services are for business use and are not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, write to mtdt@mtdt.io and we will delete it.
11. Changes
We may update this policy. When we do, we will change the "Last updated" date above and publish the new version here.
12. Contact
- Privacy and data protection: mtdt@mtdt.io
- Everything else: info@mtdt.io
- Support: support@mtdt.io