⚠️ Draft — not legal advice. This document is a placeholder and must be reviewed by qualified counsel before launch.

Privacy Policy

Last updated: 2026-04-17

1. Data We Collect

We collect the minimum data needed to provide the Services:

  • Account data: email, name, hashed password, OAuth profile info.
  • Billing data: tokenised payment methods (via Stripe — we never see raw card numbers), invoices, and transaction logs.
  • Service data: metadata about the cloud resources you provision (IPs, regions, plans) and operational logs.
  • Telemetry: IP, user-agent, and request timestamps retained for 90 days for security and abuse prevention.

2. How We Use It

We use your data to deliver the Services, bill you, provide support, and comply with legal obligations. We do not sell your data.

3. Subprocessors

We share data with the following subprocessors:

  • Stripe — payment processing
  • Vultr / other upstream providers — compute provisioning
  • Neon — database hosting
  • Vercel — web hosting
  • Resend — transactional email

A current list is available on request at privacy@ewang.cloud.

4. Your Rights

Depending on your jurisdiction (GDPR, CCPA, etc.), you may have rights to access, correct, delete, or port your personal data. Contact us to exercise them.

5. Retention

We keep account data for the life of your account plus 12 months. Financial records are retained for 7 years for tax compliance.

6. Security

We use TLS in transit, encryption at rest, and strict access controls. No system is perfect — if you discover a vulnerability, please email security@ewang.cloud.

7. Contact

Questions? Email privacy@ewang.cloud.