Privacy Policy
Summary: We collect minimal data needed to provide the Service. Your sandbox contents are private and encrypted. We never sell your data. You can export or delete your data at any time.
1. Introduction
This Privacy Policy explains how Sandbox Platform ("we", "us", "our") collects, uses, and protects your information when you use our cloud compute service. We are a New Zealand-based company and our primary privacy obligations are governed by the New Zealand Privacy Act 2020.
We are committed to protecting your privacy and handling your data transparently. This policy applies to all users of our Service, including developers, organisations, and AI agents operating on their behalf.
2. Information We Collect
2.1 Account Information
When you register, we collect:
- Email address
- Name (optional)
- Organization name (for team accounts)
- Billing information (processed by Stripe)
2.2 Usage Data
We automatically collect:
- API request logs (endpoints, timestamps, response codes)
- Resource usage metrics (CPU, memory, storage)
- Container lifecycle events (create, start, stop, delete)
- IP addresses for security and rate limiting
2.3 Sandbox Contents
Your sandbox contents include code, files, and data you upload or generate. We do not access, analyze, or use this content except:
- To provide the Service (e.g., executing your code)
- When you explicitly request support
- To investigate security incidents or abuse reports
- When required by law
2.4 Information We Do NOT Collect
- Contents of browser sessions (we don't record your browsing)
- Keystrokes or screen recordings
- Personal data from third-party sites you visit in containers
3. How We Use Your Information
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide the Service | Account info, usage data | Contract performance |
| Billing | Usage metrics, payment info | Contract performance |
| Security monitoring | IP addresses, API logs | Legitimate interest |
| Service improvements | Aggregate usage statistics | Legitimate interest |
| Support | Account info, logs | Contract performance |
| Legal compliance | As required | Legal obligation |
4. Data Retention
4.1 Active Accounts
- Account data: Retained while account is active
- Sandbox contents: Retained while sandbox exists
- API logs: 90 days
- Usage metrics: 12 months (aggregated thereafter)
4.2 After Account Deletion
- Personal data: Deleted within 30 days
- Sandbox contents: Deleted immediately
- Billing records: Retained 7 years (legal requirement)
- Security logs: Retained 1 year
5. Data Sharing
5.1 We Share Data With:
- Infrastructure providers: AWS (compute, storage) - under DPA
- Payment processor: Stripe (billing only) - PCI compliant
- Analytics: Aggregate, anonymized metrics only
5.2 We Never:
- Sell your personal data
- Share sandbox contents with third parties
- Use your data for advertising
- Train AI models on your code or data
5.3 Legal Requests
We may disclose data when required by valid legal process. We will notify you unless legally prohibited, and we challenge overbroad requests.
6. Data Security
We implement comprehensive security measures:
- Encryption: TLS 1.3 in transit, AES-256 at rest
- Isolation: Each sandbox runs in isolated containers
- Access control: Role-based access, MFA required for staff
- Monitoring: Security monitoring and alerting on all infrastructure
See our Security page for more details.
7. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your data
- Correction: Update inaccurate information
- Deletion: Delete your account and data
- Portability: Export your data in standard formats
- Restriction: Limit certain processing activities
- Objection: Object to processing based on legitimate interest
To exercise these rights, contact privacy@ab0t.com or use the dashboard settings.
8. International Transfers
We are based in New Zealand. New Zealand has been granted EU adequacy status under GDPR, meaning data transfers from the EU/EEA to us do not require additional mechanisms such as Standard Contractual Clauses. Our compute infrastructure runs on AWS (us-west-2). Data Processing Agreements are in place with all subprocessors.
9. Cookies and Tracking
We use minimal cookies:
| Cookie | Purpose | Duration |
|---|---|---|
session_id |
Authentication | Session |
preferences |
UI preferences | 1 year |
We do not use third-party tracking or advertising cookies.
10. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect data from children. If you believe a child has provided us with data, contact us immediately.
11. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email and update the "Last updated" date.
12. Contact Us
For privacy-related questions or requests:
- Email: privacy@ab0t.com
- Address: New Zealand (address available on request)
13. Regional Provisions
13.1 California (CCPA)
California residents have additional rights including the right to know what data we collect and the right to opt-out of data sales. We do not sell personal information.
13.2 European Union (GDPR)
EU residents can submit GDPR-related requests to privacy@ab0t.com. As a New Zealand-based company with EU adequacy status, data transfers from the EU to us are lawful without additional safeguards. EU residents may also lodge complaints with their local supervisory authority.
13.3 New Zealand (Privacy Act 2020)
Our primary privacy obligations are governed by the New Zealand Privacy Act 2020. Complaints may be referred to the Office of the Privacy Commissioner at privacy.org.nz.