Legal
Privacy Policy
Last updated 5 July 2026
This policy explains what personal data Hosterman processes, why, and the rights you have. It follows the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for processing your personal data is Swiss Web Development Kiefer (Marvin Kiefer), Steinstrasse 60, 5406 Rütihof, Switzerland. For any privacy request, contact marvin.kiefer@swisswebdev.ch.
2. What we collect
We only process data we need to run the service:
- Account data — your email address, display name and a securely hashed password (we never store passwords in plain text).
- Authentication & security data — session identifiers, and your IP address and browser user-agent, used to keep you signed in, protect the account and rate-limit abuse.
- Project data — the configuration of the projects you create (names, settings, chosen plan) and any content you upload or deploy. Environment variables you save are encrypted at rest.
- Operational data — container logs, resource metrics and activity history, so you can operate and troubleshoot your projects.
- GitHub data — if you connect GitHub, an access token and the repository details needed to deploy your code. You can disconnect at any time.
- Cookies — only strictly necessary cookies. See our Cookie Policy.
We do not run advertising or third-party analytics trackers, and we do not sell your data. No payment data is collected during the beta.
3. Why we process it (legal bases)
- To provide the service — performance of our contract with you (Art. 6(1)(b) GDPR).
- Security, abuse prevention and service integrity — our legitimate interests (Art. 6(1)(f) GDPR).
- Legal obligations — e.g. accounting and responding to lawful requests (Art. 6(1)(c) GDPR).
- Consent — where we ask for it; you may withdraw it at any time (Art. 6(1)(a) GDPR).
4. Service providers (processors)
We share data only with providers that help us run Hosterman, under appropriate data-processing terms:
- Hostinger — server infrastructure that hosts the platform and your projects.
- Cloudflare — DNS and TLS certificate management for domains.
- GitHub — only if you choose to connect it to deploy from a repository.
5. International transfers
Where a provider processes data outside Switzerland or the EEA, we rely on recognised safeguards such as the EU Standard Contractual Clauses and equivalent Swiss mechanisms to protect your data.
6. How long we keep it
We keep account and project data for as long as your account is active. When you delete a project, its data is removed. Free, time-limited projects are stopped when their timer ends and their data is kept for one day so you can recover it, after which it is deleted permanently. When you delete your account, we delete or anonymise your personal data, except where we must retain it to meet legal obligations.
7. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict and port your data, and to object to certain processing. Where processing is based on consent, you may withdraw it at any time. To exercise any right, email marvin.kiefer@swisswebdev.ch.
You may also lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or in the EU your local data protection authority.
8. Security
We use appropriate technical and organisational measures — including encryption in transit (HTTPS), hashed passwords, encryption of stored secrets, per-project isolation and access controls — to protect your data. No method of transmission or storage is perfectly secure, but we work to keep your data safe.
9. Changes
We may update this policy as the service evolves. The date at the top reflects the latest version; material changes will be communicated through the service.
10. Contact
Questions about privacy? Email marvin.kiefer@swisswebdev.ch or write to us at Steinstrasse 60, 5406 Rütihof, Switzerland.