Information you provide
The SystemLineage website may receive contact details, company records, inventory and job information, workflow requirements, files, pricing rules, support messages, and account-connection approvals that you choose to provide. Do not send passwords, card details, or unnecessary sensitive records through a public form.
Website and sample information
Public sample screens use invented data and stay separate from customer workspaces. Browser-only free tools process entered values locally unless a page clearly says otherwise. Basic security logs may record an IP address, browser information, time, route and error details needed to protect the service.
How information is used
- Respond to enquiries and prepare an approved scope.
- Provide accounts, company workspaces, product features, exports and support.
- Send requested operational notices, reports and renewal reminders.
- Protect accounts, audit important changes, prevent abuse and investigate errors.
- Meet contractual, payment, tax, fraud-prevention and legal obligations.
Selected service providers
Namecheap hosts the application and may carry application email. Clerk provides authentication when configured. PostgreSQL stores company records. Configured private storage holds approved files and encrypted backups. Upstash supports bounded rate limits. Paddle acts as seller of record for Paddle transactions and handles checkout, payment details, taxes, receipts, refunds and chargebacks. A provider is used only after it is configured for the relevant environment.
Payment information
The SystemLineage application does not collect or store card numbers. Paddle Checkout and Paddle's customer portal handle payment details. The service receives the transaction, subscription, customer and entitlement information needed to provide access and support the order.
Retention
Active workspace data is kept while the service is supplied. After the paid period, a cancelled workspace receives 30 days of read-only export access. Terminated-company data is retained for 90 days before reviewed deletion may begin, unless a longer legal, tax, fraud, dispute, security or written-contract requirement applies. Payment, audit and security records may follow different required retention periods.
Your choices
An authorised user can request access, correction or export. A company owner can request reviewed deletion with recent multi-factor authentication after accounts are enabled. A deletion request is auditable and cancelable during review; no payment webhook automatically deletes customer data.
International processing and mandatory rights
Selected providers may process information in other countries under their own safeguards and legal obligations. Privacy rights vary by location. Nothing in this policy removes a mandatory right available under applicable law.
Contact
Use the contact page for a privacy request. Include enough detail to identify the relevant account or service, but never send passwords, card details or private documents through the public form.