Legal
Data Policy
Last updated: 4 September 2026
This Data Policy explains how data flows through Taxiway: what we process about your account, what stays on the servers you own, who our sub-processors are, and how we keep everything secure. It sits alongside our Privacy Policy and Terms & Conditions.
1. Two kinds of data
Taxiway is a deployment platform: we orchestrate your apps, but they run on infrastructure you own. It helps to think of two distinct kinds of data, with different responsibilities attached.
- Platform data: the data we hold to run the service. Your account details, and the configuration and metadata for your deployments. For this data we are the data controller, and it is covered by our Privacy Policy.
- Your application data: the data your deployed apps and databases create and store, which lives on the servers you connect and own. For this data you are the controller; where our platform handles it on your behalf we act as your data processor.
2. Data we process to run the service
To operate Taxiway we process:
- account and authentication details;
- deployment configuration: repository and service names, build settings, environment variable keys, and the connection details for the servers you link;
- operational logs and metrics needed to deploy, monitor and troubleshoot your services; and
- support requests you send us.
3. Secrets and environment variables
Environment variables and secrets you store are treated as confidential. They are transmitted over encrypted connections, masked whenever they are read back through the dashboard or API, held under access controls, and never used for any purpose other than building and running your deployments.
To be precise about a control we have not yet implemented: environment variable values are not currently encrypted at rest in our database. They are protected by the access controls and infrastructure security described above, not by application-level encryption. We are implementing encryption at rest and will update this policy when it is in place. Until then, please take that into account when deciding what to store, and do not store secrets you are not authorised to process.
4. Where your data lives
Your application data (databases, files, and anything your apps write) resides on the servers you connect and control. Taxiway does not copy or retain that application data beyond what is transiently required to deploy and operate your services. Because you own the underlying infrastructure, you remain in control of where that data physically sits and who your hosting provider is.
5. Sub-processors
We use a small set of trusted providers to deliver the service. Each is bound by contract to appropriate data protection and security obligations:
| Provider | Purpose | Region |
|---|---|---|
| Bunny.net | Marketing website hosting and content delivery | EU (UK/NY/MI storage replicas) |
| Cloudflare | DNS, content delivery and network security | Global (UK/EU edge) |
| Resend | Transactional and account email | USA / EU |
We will give reasonable notice before adding or replacing a sub-processor that handles personal data, so you have the opportunity to object.
6. Security
We protect data with appropriate technical and organisational measures, including:
- encryption of data in transit (TLS) and of secrets at rest;
- hashed credentials and scoped access tokens;
- role-based access controls and the principle of least privilege;
- logging and monitoring of platform activity; and
- regular review of our dependencies and security practices.
No service can guarantee absolute security. If a personal data breach occurs and we are required to, we will notify the ICO within 72 hours and affected users without undue delay.
7. Data retention and deletion
We retain platform data for as long as your account is active. When you delete a service, its configuration and associated platform metadata are removed; when you close your account, we delete or anonymise your platform data within a reasonable period, except where we must keep certain records to meet a legal, accounting or tax obligation, which in the UK is generally six years. Application data on your own servers is yours to retain or delete as you see fit.
8. Your responsibilities
As the controller of your application data, you are responsible for:
- having a lawful basis to process the data your apps handle;
- providing your own privacy notices to, and honouring the rights of, your end users;
- securing and backing up the servers you connect; and
- keeping your account credentials and access tokens safe and only granting access to people who need it.
9. Data processing terms
Where we process personal data on your behalf, we do so only on your documented instructions, keep it confidential, assist you with data subject requests and breach notifications, and delete or return it at the end of our agreement. If you require a separate Data Processing Agreement (DPA) for your records, contact us at support@taxiway.cloud.
10. Changes
We may update this Data Policy as the service evolves. We will update the "last updated" date above and notify you of material changes where appropriate.
Questions about this policy? Email support@taxiway.cloud .