SX-LEGAL-002 · Privacy

Privacy Policy

How Stitchaxis handles tenant payloads, account telemetry, and data subject rights. Last revised August 2026.

What we collect

Two categories only. Tenant payloads — logs, traces, and streams you deliberately route into the gateway. Account telemetry — operator identity, billing contact, and product usage metrics required to operate the console.

How we process

Processing is limited to delivering the contracted micro-tools, security monitoring, billing, and support. We do not sell personal data. We do not use customer content to train shared foundation models.

Tenant isolation

Orgs are fenced at the API key, database row, and vault namespace layers. Cross-tenant access requires explicit break-glass procedures documented in our internal runbooks.

Encryption & retention

Data in transit uses TLS 1.3. Data at rest is encrypted with provider-managed keys. Retention defaults follow your Core plan (Gateway Solo or Gateway Team) and can be shortened via support for enterprise contracts. Coming Soon catalog packs do not create billing or retention entitlements until they are live.

Your rights

Subject to applicable law, you may request access, correction, export, or erasure of personal data associated with your operator account. Contact privacy@stitchaxis.com.

Subprocessors

Infrastructure and billing subprocessors (cloud host, Stripe, transactional email) are listed on request for enterprise diligence.