Privacy Policy
Last updated: 4 October 2026
This policy explains how we handle personal data when you visit the OneDeploy website, use your account, and run apps with OneDeploy.
1. Who is responsible for your data?
Related Code Kft. is the data controller for the OneDeploy website and your OneDeploy account. This means we decide why and how that personal data is used. For privacy questions or requests, contact us:
Related Code Kft.Honvéd utca 8. I/2.
1054 Budapest, Hungary
EU TAX: HU12450990
info@relatedcode.com
The data that you and your users put into your apps is different. You decide what it is and how it is used, so you are its controller. We process it only on your behalf, to run, back up, restore and move your services, as described in our Terms of Service.
2. Data we process
Account data. When you sign up or sign in, our authentication provider, Clerk, processes your account identifier, email address, sign-in credentials, and session information. Depending on your sign-in method, this may include your name, profile image, and information from a sign-in provider you choose.
Service data. For each service, we store the app, name, region, plan, web address, custom domains, admin email address, app settings, backup schedule, backups, and the history of actions and their results. We use this to run the service and show it in your dashboard. App passwords and other secrets are stored to run the app and are masked in the dashboard.
Usage data. We record how long each service runs, its price, and its backup storage, to charge your balance and show your usage. We also record each credit you add to your balance.
App data. Everything stored inside your apps, such as files, messages, contacts and user accounts, stays on the service’s server and in its backups. We do not look at it except when needed to fix a problem you report, or when the law requires it.
Account records and preferences. We keep a record for your account with your preferences, such as the theme, recent activity, and records that stop a repeated request from running twice.
Technical data. Our servers and service providers process connection details, such as your IP address and browser information, to deliver and secure the service. Our logs record each request’s route, method, result and duration, page and tab visits, common button clicks, and errors, with the related service and operation identifiers. Logs exclude request contents, passwords, cookies, full query strings and what you type into forms. Error messages are shortened and have secrets removed.
Messages. If you contact us, we process your email address, the message, and any information you choose to include.
You provide data directly, through your browser, or through a sign-in provider you choose. We need account and service data to provide OneDeploy; without it, you cannot deploy or manage services.
3. Why we use data
- To provide OneDeploy: signing you in, creating and running your services, backups, domains, and showing your usage. The legal basis is performance of our contract with you (GDPR Article 6(1)(b)).
- To protect and improve the service: investigating errors, preventing abuse, protecting accounts, and understanding which features are used. The legal basis is our legitimate interest in a secure, reliable service (Article 6(1)(f)).
- To answer messages: responding to questions and support requests. The basis is our contract with you where the request concerns the service, or our legitimate interest in answering other enquiries.
- To meet legal duties: handling valid legal requests and keeping records required by law. The legal basis is compliance with a legal obligation (Article 6(1)(c)).
OneDeploy does not use advertising trackers. We do not sell your data, use it for advertising, or make decisions with legal or similarly significant effects about you based solely on automated processing.
4. Cookies and browser storage
OneDeploy only uses cookies and browser storage that it needs:
- Authentication: Clerk uses cookies and related browser storage for sign-in, sessions and security. Their duration depends on the cookie and session settings.
- Demo workspace: when the demo version is enabled, the
onedeploy-democookie identifies your anonymous test workspace for up to 30 days. - Settings in your browser: your theme choice and the error notices you dismissed are kept in local storage until you clear it.
- Unfinished work: catalog filters and an unfinished deployment form are kept in session storage, which your browser clears when you close the tab. App passwords and secrets are never saved there.
You can block or clear cookies and storage in your browser. Doing so may sign you out or prevent sign-in. It does not delete your account or services.
5. Who receives data?
We use these service providers to run OneDeploy:
- Vercel: hosting the website and handling the requests needed to serve it.
- Clerk: account management, authentication and session security.
- Stripe: processing payments when you add credit. Stripe receives your payment details directly; we do not see or store your card or wallet details. We keep the amount, the date and the payment reference of each credit.
- Z8Data: storing account records and preferences.
- Z8Log: processing request, activity and error logs.
- Hetzner, DigitalOcean and Vultr: the cloud providers whose servers run your apps. Your service runs with the provider of the region you choose.
To issue TLS certificates, a certificate authority receives the web addresses and custom domains of your services. These names are published in public certificate logs, as they are for every website with a certificate.
Your apps are reachable on the internet at their web addresses. Who can see or use an app depends on the app and the settings you choose.
People who handle support and technical operations may access data as needed for their work. We may also disclose information when required by law or when necessary to establish, exercise or defend legal claims.
6. International processing
Our providers may process data outside Hungary and the European Economic Area, including in the United States. Your apps and their data are stored in the region you choose for each service, which may be outside the European Economic Area.
Where GDPR requires a transfer safeguard, this must be an applicable adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses. Contact info@relatedcode.com for information about the safeguards relevant to your data or to request a copy.
7. How long we keep data
We keep your account data while your account exists. A service and its app data are kept until you delete the service. After deletion, its backups stay restorable for 14 days, then they are erased. The service’s history, usage and payment records stay in your account, because they are needed for billing and records.
For support messages and technical logs, retention depends on the time needed to resolve the request or issue, investigate abuse, and meet legal duties or handle legal claims. Where records must be kept for these reasons, we limit retention to the relevant purpose and applicable legal period.
You can ask us to delete your account and its data by email. Delete your services first, or tell us that you want them deleted too.
8. Your rights
Under the GDPR, and subject to its conditions, you can:
- Ask for access to your personal data and a copy of it.
- Ask us to correct inaccurate data or delete data.
- Ask us to restrict processing.
- Object to processing based on legitimate interests because of your particular situation.
- Receive data you provided in a portable format when processing is automated and based on a contract or consent.
- Withdraw consent at any time if we rely on it for a particular activity. This does not affect processing that took place before withdrawal.
Send requests to info@relatedcode.com. We may need to check your identity. Do not send passwords or session cookies. We normally respond within one month. If the law allows an extension, we will explain the reason within that month.
If you are a user of an app that a OneDeploy customer runs, please contact that customer first. They control the data in their app, and we will help them answer your request.
You can complain to a data protection authority, including in the country where you live or work. In Hungary, this is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH). You do not need to contact us before making a complaint.
9. Updates and contact
We may update this policy as the service or our data practices change. We will update the date above and provide additional notice of material changes where required. For any privacy question, email info@relatedcode.com.