Skip to main content

Privacy

How information is used and protected.

This page explains the information SixStack Relay needs to run a business account and its service operations workspace.

Pre-release legal draft. The legal business name, retention schedule, and final effective date still require owner and legal approval before customer sales open.

Information the service handles

  • Account information, such as names, business email addresses, password hashes, roles, sessions, and password-reset records
  • Business and team settings, including lead sources, pipeline labels, response targets, assignments, and notification recipients
  • Lead and contact information entered by a customer or received from an authorized website form, plus notes, tasks, quotes, outcomes, and activity history
  • Billing identifiers, subscription and invoice status, and checkout records from Stripe; SixStack Relay does not store full card numbers
  • Security and operations records, including audit events, delivery results, rate-limit records, and technical error details

Why it is used

Information is used to provide the workspace, authenticate users, keep each business account separate, route and track lead work, operate billing, deliver requested notifications, answer support requests, investigate misuse, and maintain service security.

SixStack Relay is built as a business operations product. It is not designed to sell personal information or create third-party advertising profiles.

Service providers and disclosure

Information may be processed by the hosting, database, payment, and email providers configured to operate the service. Stripe handles checkout and card payment details on its own hosted pages. Access may also be provided when required by law, to protect the service or its users, or during an approved business transaction.

Each provider must be reviewed before production use. SixStack Relay does not ask a provider to use customer lead data for its own advertising.

Retention, access, and deletion

Authorized client owners can export their organization’s supported data. Correction, access, and deletion requests require identity and authority verification before any change is made.

The final retention periods for leads, webhook records, sessions, reset tokens, rate-limit records, audit history, billing evidence, and backups are not yet approved. Those periods and the matching deletion procedure are release-blocking work; data is not represented as automatically deleted on a schedule until that work is complete.

Contact and policy status

Privacy contact: contact@sixstackrelay.com

Legal business name: SixStack LLC
Effective date: not yet effective