Privacy Policy
Version 2026-06-19
This Privacy Policy explains how skube processes your personal data. The data controller is VProcess Marcin Żyła, NIP PL6312711151, registered at ul. Derkacza 2/52, 44-122 Gliwice, Poland, email support@skube.dev. We are based in Poland and process personal data in line with the EU General Data Protection Regulation (GDPR). This Policy covers data for which we are the controller (your account, orders, and billing). For personal data of others that you place on your cluster, we act as your processor under our Data Processing Agreement, not under this Policy.
1. What we collect
- Account data: your email address and password. We store your email address in our own systems to run your account and orders. Passwords are stored only as a salted hash by our authentication provider; we never see them in plain text. If you sign in with a social provider, we receive your email address from that provider.
- Order and cluster data: an optional cluster name you choose, the region and size you select, and technical cluster details (such as node IP and kubeconfig) generated to deliver the Service.
- Consent records: when you accept these terms, we store which version you accepted, the time, your IP address, and your browser user-agent, as proof of consent, and your marketing opt-in choice.
- Billing references: identifiers and status from our payment provider (subscription, customer, and transaction IDs). We do not store your card number or full billing details: those stay with Paddle.
Except for your password and card details (held only by our authentication and payment providers), the data above is stored in skube's own database, including your email, cluster details, consent records (with IP and user-agent), and billing identifiers. We do not use analytics, advertising, or third-party tracking, and we do not set advertising cookies. Your login session is kept in your browser's local storage by our authentication provider so you stay signed in.
2. Why we process it, and our legal basis
- To provide the Service (create your account, provision and manage clusters, process your orders): performance of our contract with you.
- To bill you: performance of the contract, carried out through our payment provider.
- To secure the Service and keep consent records: our legitimate interest in operating safely and in being able to demonstrate consent, and compliance with our legal obligations.
- To send marketing emails: only with your consent, which you can withdraw at any time.
- To meet tax and accounting duties: compliance with legal obligations.
3. Who we share it with
We share personal data with providers that process it on our instructions to help us run the Service (our subprocessors):
- Authentication (currently Supabase).
- Transactional email, for example password reset and "cluster ready" notifications (currently Resend).
- Cluster hosting, the infrastructure that runs your Kubernetes clusters (currently Hetzner; further providers may be added).
- Application and website hosting (currently Contabo).
- DNS (currently Cloudflare).
Payments are handled by Paddle as Merchant of Record. For the payment transaction Paddle acts as an independent data controller, not our processor: it decides how it processes payment data under its own privacy policy.
Several of these providers are based in or transfer data to the United States (currently our authentication, email, payment, and DNS providers: Supabase, Resend, Paddle, and Cloudflare); our cluster and application hosting (currently Hetzner and Contabo) are in Germany. Where data is transferred outside the European Economic Area, we rely on appropriate safeguards: Cloudflare is certified under the EU-US Data Privacy Framework, and for providers not certified under it (currently Supabase and Resend) we rely on the European Commission's Standard Contractual Clauses. Paddle processes payment data as an independent controller under its own safeguards. A copy of the relevant safeguards is available on request. We do not sell your personal data.
4. How long we keep it
We keep your account and order data for as long as your account is active. If you ask us to close your account and erase your data (by emailing support@skube.dev), we delete your personal data except records we must keep to meet legal obligations or to establish, exercise, or defend legal claims. In particular, billing and tax records are kept for 5 years from the end of the relevant tax year, as required by Polish law. Consent and order-acceptance records (including the withdrawal acknowledgement, with IP and user-agent) are kept while your account is active and for up to 3 years after it closes, to establish or defend legal claims. Payment and invoice records are also retained by our payment provider under its own policy. Our hosting, authentication, and DNS providers keep technical logs (such as server access logs and IP addresses) on our behalf for limited periods under their own retention policies, to operate and secure the Service.
5. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data erased where the law allows;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing.
To exercise any of these, email support@skube.dev. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl), or your local authority in the EU.
6. Marketing
We send product and marketing emails only if you opt in. You can withdraw consent at any time from Settings or via the unsubscribe link in any such email. This does not affect essential service emails (for example billing, security, and account notices), which we send as part of providing the Service.
7. Security
We use technical and organizational measures to protect your data, including encrypted transport, hashed passwords, and restricted administrative access. No method of transmission or storage is completely secure, but we work to protect your information and to limit access to those who need it. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority, and you where required, in line with our obligations under Articles 33 and 34 of the GDPR.
8. Children
The Service is not directed to anyone under 18, and we do not knowingly collect their data.
9. Changes
We may update this Policy. When changes are material, we will ask you to review and accept the new version, and the version date above will change.
10. Contact
For any privacy question or request, contact VProcess Marcin Żyła at support@skube.dev.