# MTDT Privacy Policy

> What MTDT does with personal information about the people who visit its websites, hold an account and use the platform — what is collected, who it is shared with, and how long it is kept.

Last updated 25 August 2026

**Download:** [PDF](https://docs.mtdt.io/legal/mtdt-privacy-policy.pdf) · [Markdown](https://docs.mtdt.io/legal-information/privacy-policy.md)

## 1. Who We Are and What This Policy Covers

This policy explains what we do with personal information about the people who visit our
websites, create an MTDT account, use the platform, or get in touch with us.

MTDT is owned and operated by **Shiny Friday Deployment Club LLC**, 30 N Gould St # 43289,
Sheridan, WY 82801, United States. That company decides what personal information is collected
and why, and is the data controller wherever you are. "MTDT", "we" and "us" mean that company.
"You" means the person the information is about.

The platform is developed and supported from the European Economic Area by **Propeller Plan
Sp. z o.o.**, KRS 0000899016, Święty Marcin 29/8, 61-806 Poznań, Poland, acting on our
instructions. It is listed among the providers in Section 4.

**What this policy does not cover.** MTDT backs up and deploys the contents of the Salesforce
orgs, Git repositories and issue trackers you connect to it. Personal data inside those systems
belongs to you, and we handle it only on your instructions. That processing is governed by our
[Data Processing Agreement](https://docs.mtdt.io/docs/legal-information/dpa), not by this policy.

## 2. What We Collect

**Information you give us**

- Account details: your name, email address, and — if you sign in through Google or your
  organization's single sign-on provider — the account identifier that provider gives us.
- Billing details: the customer and subscription identifiers Stripe creates for you. Your card,
  billing address and tax identifiers are entered with Stripe and held by Stripe. We never
  receive or store card numbers.
- Anything you write to us: support requests, sales enquiries, and text you type into the
  platform, such as the name you give a deployment.

**Information we record as you use the Services**

- Sign-in and security events: timestamps, IP address, and multi-factor authentication events.
- An audit log of actions taken in your team, so administrators can see who did what.
- Product analytics: which pages and features are used, and technical details about your browser
  and device. Web addresses are stripped of identifiers before they are recorded.
- Website analytics on mtdt.io and docs.mtdt.io, including approximate location derived from your
  IP address.
- On the mtdt.io marketing website only: recordings of the visit — pages, clicks, scrolling and
  mouse movement — and measurement of whether an advertisement led you to us. Neither happens in
  the application or in the documentation.

We do not ask for, or deliberately collect, special categories of personal data such as health,
biometric or political information. We do not collect precise location from your device.

## 3. Why We Use It

- **To provide the Services** — creating and securing your account, running what you ask the
  platform to do, taking payment, and supporting you. *Basis: performance of our contract with you.*
- **To keep the Services working and safe** — diagnosing faults, investigating abuse, keeping
  audit records, and understanding how the product is used so we can improve it.
  *Basis: our legitimate interests in operating and improving a secure service.*
- **To market to you** — sending product news to people who have asked for it, and measuring how
  our websites perform. *Basis: your consent, which you can withdraw at any time.*
- **To meet legal obligations** — accounting, tax, and responding to lawful requests.
  *Basis: compliance with a legal obligation.*

## 4. Who We Share It With

We do not sell personal information for money. Section 7 explains how US state privacy
laws treat the advertising cookies on our websites.

We use the following providers, and they receive only what they need to do their job:

| Provider | What it does | Where |
|---|---|---|
| Hetzner Online GmbH | Hosts the platform and its databases | Germany |
| Stripe | Takes payments; holds the card and billing details you enter | United States |
| PostHog | Product analytics | European Union |
| Google | Tag Manager and Analytics on mtdt.io and docs.mtdt.io | United States |
| Microsoft | Clarity, which records visits to the mtdt.io website | Ireland, with onward transfer to the United States |
| LinkedIn | Advertising and conversion measurement on the mtdt.io website | United States |
| Salesforce | The chat widget on the mtdt.io website | United States |
| Tilda | Publishes the mtdt.io website | United Arab Emirates |
| Better Stack | Collects application logs and monitors uptime | European Union; provider in the United States |
| Propeller Plan Sp. z o.o. | Develops and supports the platform | Poland |
| Slack | Delivers internal operational notifications | United States |
| Amazon Web Services | Delivers transactional email | United States |

We also share personal information with our professional advisers, with authorities where the
law requires it, and with a buyer if the business is sold — in which case this policy continues
to apply until you are told otherwise.

The providers that process personal data from the systems **you** connect are a different list,
published at [Subprocessors](https://docs.mtdt.io/docs/legal-information/subprocessors).

## 5. Where It Is Processed

The platform runs in the European Union, on infrastructure operated by Hetzner Online GmbH in
Falkenstein, Germany. The company that operates it is established in the United States, and
several of the providers above are outside the European Economic Area; where personal data
reaches them, the transfer is protected by a lawful transfer mechanism — the European
Commission's Standard Contractual Clauses or, for providers certified under it, the EU–US
Data Privacy Framework.

## 6. How Long We Keep It

We keep account and billing information for as long as you have an account, and afterwards only
for as long as we need it — to finish billing, to meet accounting and tax rules, or to establish
or defend a legal claim.

Application logs are kept for three days and monitoring metrics for thirty days, after which
they are deleted. Product analytics is kept for one year, and recordings of visits to the
marketing website for thirty days. Website analytics is kept for two months at the event level
and up to fourteen months for the visitor record, which starts over if you visit again. After
that it survives only as aggregate figures that identify no one.

The audit record of actions taken in your team is kept for longer. Its purpose is to let your
administrators and us look back at what was done and by whom, and that purpose only works if
the record outlasts the event.

## 7. Your Rights

You can ask us to give you a copy of your personal information, correct it, delete it, restrict
or object to how we use it, or send it to another provider. Where we rely on your consent, you
can withdraw it at any time; that does not affect anything we did before you withdrew it.

Write to **mtdt@mtdt.io** and we will answer within the time the law allows. If you are in the
EEA, the UK or Switzerland and you think we have got it wrong, you can also complain to your
national data protection authority.

If you live in California or another US state with a privacy law, you have comparable rights to
know, delete and correct, and to opt out of targeted advertising. We do not sell personal
information for money, but the advertising cookies described below may count as "sharing" or
targeted advertising under those laws. Refuse those cookies, or email us, and we will act on it.

## 8. Cookies and Tracking

Some cookies are needed to sign you in and keep the platform working; without them it does not
function. The rest are optional:

- On docs.mtdt.io we ask before loading anything. Google Analytics runs only if you accept, and
  the "Cookie settings" link in the footer lets you change your answer at any time. Refusing
  also clears the cookies Google has already set.
- On the mtdt.io marketing website we run more: Google Analytics, the LinkedIn advertising tag,
  and Microsoft Clarity, which records the visit. The banner there tells you they are in use.
  This is the marketing website only — none of it runs in the application.
- In the application we use PostHog for product analytics. It records which features are used;
  it does not record your screen.

You can also refuse or delete cookies in your browser. Doing so may break parts of the platform
that depend on them.

## 9. Security

We take the security of this data seriously: access to production systems is limited to people
who need it, data is encrypted in transit, and secrets are held in a dedicated
vault. The measures set out in Appendix 2 of our
[Data Processing Agreement](https://docs.mtdt.io/docs/legal-information/dpa) describe the
platform as a whole and apply here too. No service can promise that it will never be breached,
and we do not.

## 10. Children

The Services are for business use and are not intended for anyone under 18. We do not knowingly
collect personal information from children. If you believe a child has given us information,
write to mtdt@mtdt.io and we will delete it.

## 11. Changes

We may update this policy. When we do, we will change the "Last updated" date above and publish
the new version here.

## 12. Contact

- Privacy and data protection: mtdt@mtdt.io
- Everything else: info@mtdt.io
- Support: support@mtdt.io
