Data controller
The controller for personal data processed directly by SwitchPilot is:
Triven Kadiata134 avenue des Bleuets, 93370 Montfermeil, France
dev.triven.kadiata@gmail.com
Paddle acts under its own role and notices when it processes checkout, transaction, tax and payment data as Merchant of Record.
Data collected
| Category | Examples |
|---|---|
| Account and authentication | Name or account identifier when provided, email, internal user ID, password-derived authentication data, linked identity-provider information and email-verification state. |
| Session and technical data | Session identifiers, IP address and user-agent where collected by the authentication system, browser and device information contained in requests, timestamps and technical logs. |
| Product data | Projects, project names, feature-flag names and keys, descriptions, environments, flag values, configuration, usage metadata and activity needed to provide the service. |
| API credentials | One-way SHA-256 hashes of project API keys and masked key previews. A newly generated plaintext key is displayed for initial use but is not stored in the project database. |
| Billing | Plan, Paddle customer ID, subscription ID, price ID, subscription status, renewal/cancellation state and billing-period dates. Full card numbers are not stored directly by SwitchPilot. |
| Support and security | Messages sent to support, troubleshooting context, abuse reports, webhook event identifiers and security-relevant records. Transactional email delivery may include the recipient email address, technical message content and necessary delivery metadata. |
Purposes and legal bases
| Purpose | Main legal basis |
|---|---|
| Create accounts, authenticate users and provide projects, flags, environments, APIs and SDK access | Performance of the contract or steps requested before entering it |
| Manage plans and synchronise subscriptions with Paddle | Performance of the contract; legal obligation for records that must be retained |
| Prevent abuse, protect accounts, verify webhooks and investigate security incidents | Legitimate interests in securing SwitchPilot and its users; legal obligation where applicable |
| Diagnose errors, maintain reliability and improve the service | Legitimate interests in operating and improving the product, balanced against user rights |
| Respond to support and rights requests | Performance of the contract, legitimate interests and legal obligations, depending on the request |
| Non-essential analytics, marketing communications or optional trackers if introduced | Consent where required. No such tracker is currently detected in the application |
API keys
Project API keys are server credentials. SwitchPilot generates a key, stores a one-way SHA-256 hash for verification and retains a masked preview for identification. The product does not claim that the original key can be decrypted from the stored hash.
Keep keys out of browser code and public repositories. Rotate a key when exposure is suspected and contact SwitchPilot if compromise may affect the service.
Processors and recipients
Access is limited to providers and recipients needed for the purposes above. The repository confirms the following structure:
| Provider | Purpose | Implementation status |
|---|---|---|
| Vercel Inc. | Application and website hosting | Confirmed in the project architecture |
| Paddle | Merchant of Record, checkout, payments, taxes, subscriptions, refunds and payment documents | Confirmed in the billing implementation |
| PostgreSQL (self-managed in the current configuration) | Application database | The repository configures PostgreSQL directly and does not identify a separate hosted database processor |
| GitHub and GitLab | Optional identity providers when the corresponding sign-in method is configured and selected | Conditional integrations in the authentication configuration |
| Resend | Delivery of transactional emails such as password reset messages; data includes the email address, technical email content and necessary delivery metadata | Configured integration; production delivery requires a verified domain |
PostgreSQL operation
SwitchPilot uses PostgreSQL (self-managed in the current configuration) through Prisma. The repository does not configure or identify a separate hosted database processor.
Better Auth is the authentication software used by the application; it is not identified in the repository as a separate hosted data processor. Resend is configured for transactional messages such as password resets; it is not described here as a marketing provider. No error-monitoring or analytics provider is currently present in the project dependencies or configuration.
International transfers
Some service providers, including Vercel, Paddle or an identity provider selected by a user, may process data outside the European Economic Area. Where transfer restrictions apply, an appropriate transfer mechanism and supplementary safeguards must be used as required by applicable law. This policy does not claim that a particular contractual mechanism has been executed where the repository does not provide that evidence.
Retention
Personal data is kept only as long as reasonably needed for its purpose, security, dispute handling and legal duties. The current categories are:
| Category | Retention approach |
|---|---|
| Active account and product data | For as long as the account remains active. |
| Billing and transaction records | 10 years for accounting records and supporting documents where SwitchPilot is required to retain them. Paddle applies its own legal retention duties as Merchant of Record. |
| Security and technical logs | 180 days from collection, unless an incident requires documented longer retention. |
| Deleted account data | Deleted from the live application database immediately (0 days) after Paddle cancellation succeeds. |
| Backups | Where backups exist, residual copies expire within 30 days and are not restored except for disaster recovery. |
| Support communications | 24 months after the last exchange. |
| Paddle webhook metadata | 24 months after receipt for event deduplication, billing security and auditability. |
Your rights
Subject to the conditions in applicable data-protection law, you may request:
- access to personal data and a copy of it;
- rectification of inaccurate or incomplete data;
- erasure of data;
- restriction of processing;
- objection to processing based on legitimate interests;
- portability of data where applicable; and
- withdrawal of consent at any time for future processing based on consent.
Send a request to dev.triven.kadiata@gmail.com. Identity may need to be verified proportionately. You may also lodge a complaint with the CNIL or another competent supervisory authority.
Security
SwitchPilot applies reasonable technical and organisational measures suited to the service, including access controls, server-side secrets, separation of Development and Production environments according to plan, signed Paddle webhook verification, restricted database access, security logging, HTTPS in transit through the hosted application, and backup measures where configured in the hosting and database infrastructure.
No online system is completely secure. Users must protect their credentials, keep API keys server-side, restrict internal access and maintain application fallbacks appropriate to their own risk.
Account deletion
An authenticated user can open Dashboard Settings, choose Delete account, and enter the confirmation phrase displayed by the interface. The application then asks Better Auth to delete the user record. Database cascade rules remove associated sessions, linked login accounts, projects, feature flags, environment values, API-key hashes and masked previews.
Paddle is cancelled first
If a Paddle subscription is linked, SwitchPilot requests immediate cancellation before deleting local data. If Paddle cannot confirm cancellation, deletion stops and the account remains intact. Paddle may independently retain transaction and tax records under its legal obligations and privacy notice.
Residual copies may expire progressively from backups, and limited records may be retained where required by law or necessary for security and dispute handling, following the retention approach above.
Policy changes
This policy may be updated when the product, providers or law changes. Material changes will be communicated by an appropriate method where required, and the effective date will be updated.
Contact
Privacy questions and rights requests may be sent to dev.triven.kadiata@gmail.com or by post to 134 avenue des Bleuets, 93370 Montfermeil, France.