Rundploy
  • Hosting
  • Features
  • Pricing
  • Resources
Log inGet Started
HostingFeaturesPricingResourcesLog inGet Started
← Back to home

Privacy Policy

Last updated October 7, 2026 · Operated by Aymen Lasfar · support@rundploy.com

In short

  • Aymen Lasfar, who operates Rundploy, is responsible for your personal data.
  • We collect what we need to run your account and websites, take payments, keep the platform secure and help you. We never sell your data or use it for advertising.
  • Our servers and database are in the European Union (Belgium and Ireland). Payment providers handle your card or wallet details; we never see them.
  • You can ask to see, correct, export or delete your data at any time: support@rundploy.com.

This summary is for convenience. The full text below is what applies.

Contents

  1. Who we are
  2. Data we collect
  3. How we use it, and our legal bases
  4. Trial and fraud protection
  5. Visitors to websites hosted on Rundploy
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. How we protect data
  10. Your rights
  11. Cookies and browser storage
  12. Children
  13. Changes to this policy
  14. Contact

1. Who we are

Rundploy (rundploy.com) is operated by Aymen Lasfar, who is the data controller for the personal data described here. Contact: support@rundploy.com.

This policy covers people who visit our website, create an account or contact us. It also explains our role for the visitors of websites our customers host on Rundploy (section 5).

2. Data we collect

TypeWhatWhere it comes from
AccountName, email address, password (stored only as a secure hash), plan and account settings.You, when you sign up or edit settings.
Google or GitHub sign-inYour account id with that provider, email address and name.Google or GitHub, when you choose to sign in with them.
GitHub connectionWhich GitHub account and repositories you connect, and the access needed to deploy them.GitHub, when you install our GitHub App.
Your websitesFiles you upload, code from repositories you connect, environment variables (encrypted), build logs, domains, and settings.You.
BillingPlan, billing period, payment status, and the payment provider's customer and subscription ids. No card numbers or wallet keys.You and our payment providers.
SupportMessages you send us and our replies.You.
Security signalsIP address, a random device id stored in your browser, a fingerprint of browser settings (screen size, time zone, language and similar), and connected Google/GitHub ids. Stored as one-way hashes.Your browser and sign-in.
Technical logsIP address, browser user agent, pages requested, time, errors.Your browser, automatically.

3. How we use it, and our legal bases

  • To provide the Service: create your account, sign you in, build and run your websites, connect domains, and show you logs and usage. (Performance of our contract with you.)
  • To take payments, send receipts and handle refunds, together with our payment providers, and to keep records for tax and accounting. (Contract, and legal obligations.)
  • To keep the platform secure: prevent fraud, repeated free trials, abuse and attacks, and enforce our Terms. (Our legitimate interest in a safe, fair service.)
  • To help you when you contact support, and to send service emails such as payment problems, security notices and important changes. (Contract, and legitimate interest.) We don't send marketing emails without your consent, and you can unsubscribe at any time.
  • To understand and improve the Service using aggregated usage figures. (Legitimate interest.)
  • To comply with the law and respond to valid legal requests. (Legal obligation.)

We don't sell personal data, share it for advertising, or make decisions with legal or similarly significant effects based only on automated processing. Our security checks can flag an account for review or block a free trial; you can always contact us to have a person look at it.

4. Trial and fraud protection

To stop the same person from claiming the trial offer many times, and to block fraud, we compare the security signals in section 2 between accounts. We store them only as one-way encrypted hashes, use them only for this purpose, and keep them after an account is deleted so a trial can't be claimed again. They can't be used to identify you on other websites.

5. Visitors to websites hosted on Rundploy

When someone visits a website a customer hosts on Rundploy, our infrastructure processes their request (IP address, user agent, requested address and time) to deliver the page, protect it from attacks, and show the website owner traffic statistics. Visitor counts are calculated from hashed values; we don't place cookies or tracking scripts on customer websites.

For this data the website owner is the controller and we act as their processor. If you visited a website hosted on Rundploy and have a privacy question, please contact the owner of that website first. We'll help them respond.

6. Who we share data with

We share personal data only with service providers that help us run Rundploy, under contracts that require them to protect it and use it only for us:

ProviderPurposeLocation
Google CloudRunning websites and the dashboard, builds, file storage, logs.European Union (Belgium)
SupabaseOur database (accounts, websites, billing status).European Union (Ireland)
CloudflareCustom domains, SSL certificates, routing and protection from attacks.Global network
Google Firebase AuthenticationSign-in with Google or GitHub.Global
GitHubDeploying repositories you connect.United States
CreemCard and other payments; merchant of record, tax and invoices.See Creem's privacy policy
WhopPayments made through Whop checkout.See Whop's privacy policy
NOWPaymentsCryptocurrency payments.See NOWPayments' privacy policy

Payment providers process your payment details under their own privacy policies, as independent controllers for that part. We may also disclose data if the law requires it, to protect people's safety or our rights, or as part of selling or transferring the Service, in which case this policy continues to apply.

7. International transfers

Our main systems are in the European Union. Some providers above may process data in other countries, including the United States. Where that happens, we rely on safeguards recognised by EU law, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

8. How long we keep data

  • Account data and your websites: while your account is open. When you ask us to delete your account, we delete your websites, files, domains, environment variables and account data within 30 days. Copies in short-lived backups and logs expire soon after.
  • Technical logs and website request logs: about 30 days.
  • Billing and invoice records: as long as tax and accounting law requires (often up to 10 years). These are mostly kept by our payment providers.
  • Support messages: while your account is open, then deleted with it.
  • Security signal hashes: kept after account deletion, as explained in section 4, for as long as needed to prevent abuse.

9. How we protect data

All traffic to Rundploy uses HTTPS. Passwords are stored as bcrypt hashes, environment variables are encrypted, your personal GitHub access tokens are used only during sign-in and never stored, and sign-in sessions are signed. Access to production systems is limited to what's needed to run and support the Service. No system is perfectly secure; if a breach affects your personal data, we'll notify you and the authorities as the law requires.

10. Your rights

Depending on where you live (for example under the EU and UK GDPR, or US state privacy laws), you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct data that is wrong or incomplete;
  • delete your data and your account;
  • give you your data in a portable format;
  • restrict or object to processing based on our legitimate interests;
  • withdraw consent where we rely on it.

Email support@rundploy.com from your account's email address. We may need to confirm it's you. We reply within 30 days. You can also complain to your local data protection authority, though we'd appreciate the chance to fix things first.

11. Cookies and browser storage

We use only cookies needed for the Service to work and stay secure. We don't use advertising or third-party analytics cookies.

NamePurposeDuration
rundploy_sessionKeeps you signed in.7 days
rundploy_tzRemembers your time zone so dates show correctly.1 year
rd_did (cookie and local storage)Random device id used for trial and fraud protection (section 4).2 years
Firebase sign-in cookiesOnly while you sign in with Google or GitHub.Session

Payment pages are run by the payment providers and may set their own cookies.

12. Children

Rundploy isn't meant for children and you must be 18 or older to create an account. We don't knowingly collect data from children; if you think we have, contact us and we'll delete it.

13. Changes to this policy

We'll update this policy when our practices change. The date at the top shows the latest version, and we'll email you about important changes before they apply.

Contact

Rundploy is operated by Aymen Lasfar, an individual. Questions about this page, your account or a payment: support@rundploy.com. We reply within 3 business days, usually much sooner.

Terms of ServiceRefund Policy
Rundploy

Simple hosting. Powerful infrastructure.

Product

  • Hosting
  • Pricing
  • Features
  • Dashboard

Company

  • About
  • Contact
  • Support

Resources

  • Documentation
  • FAQ
  • Status

Legal

  • Privacy
  • Terms
  • Refund Policy
© 2026 Rundploy, operated by Aymen Lasfar. Support: support@rundploy.comMade for people who just want their website online.