Trust & Governance

Privacy Policy

Last Updated: August 28, 2026

1. Information We Collect

We collect information necessary to operate and secure Devoxn renewal management workspaces:

  • Account Data: Name, email address, and authentication credentials (including OAuth provider identifiers).
  • Workspace Records: Metadata regarding tracked obligations, renewal dates, notice windows, departmental allocations, and uploaded PDF document attachments.
  • Billing Records: Transaction identifiers and subscription states processed securely via our Merchant of Record, Lemon Squeezy. We do not store raw credit card numbers.

2. How We Use Information

Collected information is used strictly to:

  • Provide, maintain, and authenticate access to your organization's workspace.
  • Evaluate renewal deadlines and dispatch automated email reminders via configured email providers (e.g., Resend).
  • Enforce subscription entitlements, resource quotas, and rate limits.
  • Prevent fraud, abusive requests, and security incidents.

3. Data Isolation & Security

Devoxn utilizes PostgreSQL Row Level Security (RLS) policies to enforce strict multi-tenant data boundaries. Your renewal items, documents, and audit logs are accessible only to authenticated members of your workspace according to their designated roles.

4. Data Sharing & Third-Party Processors

We do not sell customer data. We share data only with verified sub-processors necessary to deliver the service:

  • Supabase: Cloud database, authentication, and encrypted object storage infrastructure.
  • Lemon Squeezy: Merchant of Record for global checkout, billing synchronization, and invoice handling.
  • Resend: Transactional email delivery for reminder notifications.

5. Data Retention & Deletion

Workspace records and audit history remain stored for as long as your workspace is active. Workspace owners may request permanent deletion of workspace records and attached files at any time.