Beta
Features Recipes Pricing FAQ
Get started free
Features Recipes Pricing FAQ Get started free

Legal

Data Policy

Last updated: 29 June 2026

This Data Policy explains how data flows through Taxiway: what we process about your account, what stays on the servers you own, who our sub-processors are, and how we keep everything secure. It sits alongside our Privacy Policy and Terms & Conditions.

1. Two kinds of data

Taxiway is a deployment platform: we orchestrate your apps, but they run on infrastructure you own. It helps to think of two distinct kinds of data, with different responsibilities attached.

  • Platform data: the data we hold to run the service. Your account details, billing, and the configuration and metadata for your deployments. For this data we are the data controller, and it is covered by our Privacy Policy.
  • Your application data: the data your deployed apps and databases create and store, which lives on the servers you connect and own. For this data you are the controller; where our platform handles it on your behalf we act as your data processor.

2. Data we process to run the service

To operate Taxiway we process:

  • account and authentication details;
  • subscription and billing records (via Stripe);
  • deployment configuration: repository and service names, build settings, environment variable keys, and the connection details for the servers you link;
  • operational logs and metrics needed to deploy, monitor and troubleshoot your services; and
  • support requests you send us.

3. Secrets and environment variables

Environment variables and secrets you store are encrypted at rest and are only decrypted when needed to build or run your services. We treat them as confidential, restrict internal access, and never use their contents for any purpose other than running your deployments. Do not store secrets you are not authorised to process.

4. Where your data lives

Your application data (databases, files, and anything your apps write) resides on the servers you connect and control. Taxiway does not copy or retain that application data beyond what is transiently required to deploy and operate your services. Because you own the underlying infrastructure, you remain in control of where that data physically sits and who your hosting provider is.

5. Sub-processors

We use a small set of trusted providers to deliver the service. Each is bound by contract to appropriate data protection and security obligations:

Provider Purpose Region
Stripe Payment processing, subscription billing, tax and invoicing USA / EU / UK
Cloudflare Website hosting, DNS, CDN and security Global (UK/EU edge)
Resend Transactional and account email USA / EU

We will give reasonable notice before adding or replacing a sub-processor that handles personal data, so you have the opportunity to object.

6. Security

We protect data with appropriate technical and organisational measures, including:

  • encryption of data in transit (TLS) and of secrets at rest;
  • hashed credentials and scoped access tokens;
  • role-based access controls and the principle of least privilege;
  • logging and monitoring of platform activity; and
  • regular review of our dependencies and security practices.

No service can guarantee absolute security. If a personal data breach occurs and we are required to, we will notify the ICO within 72 hours and affected users without undue delay.

7. Data retention and deletion

We retain platform data for as long as your account is active. When you delete a service, its configuration and associated platform metadata are removed; when you close your account, we delete or anonymise your platform data within a reasonable period, except where we must keep certain records (such as billing and tax records, kept for at least six years). Application data on your own servers is yours to retain or delete as you see fit.

8. Your responsibilities

As the controller of your application data, you are responsible for:

  • having a lawful basis to process the data your apps handle;
  • providing your own privacy notices to, and honouring the rights of, your end users;
  • securing and backing up the servers you connect; and
  • keeping your account credentials and access tokens safe and only granting access to people who need it.

9. Data processing terms

Where we process personal data on your behalf, we do so only on your documented instructions, keep it confidential, assist you with data subject requests and breach notifications, and delete or return it at the end of our agreement. If you require a separate Data Processing Agreement (DPA) for your records, contact us at [email protected].

10. Changes

We may update this Data Policy as the service evolves. We will update the "last updated" date above and notify you of material changes where appropriate.

Questions about this policy? Email [email protected] .

Taxiway

The easy way to self-host your apps. Push from GitHub, run on a server you own. Free.

Product

  • Features
  • Recipes
  • Pricing
  • FAQ
  • Departures

Company

  • Dashboard
  • Contact

© 2026 Taxiway · TWY 2026

Privacy Terms Data