Privacy Policy
Effective 9 September 2026
This version replaces the version effective 22 August 2026.
1. Scope
1.1 This policy explains how Flapico Technologies Private Limited ("plym", "we", "us") collects, uses, shares, and protects personal data. It covers the plym.io website, the documentation and free tools published there, and plym Cloud, our hosted service at cloud.plym.io, including the sites we host on plym.space subdomains and on customer domains (together, the "Services").
1.2 It does not cover a copy of the plym software that you run on infrastructure of your own. Section 12 explains what that means.
1.3 It does not cover the content that our customers publish on the sites we host for them, or the data those sites collect about their own visitors. For that data the customer is the controller and we act as their processor. Section 11 explains the split.
1.4 For the personal data described here, plym is the controller. Our contact details are in section 15.
2. Personal data we collect
2.1 Information you give us:
- Account details. Your email address. A plym Cloud account has no password: we email you a single-use link when you sign in.
- Site details. The name and subdomain of each site you create, any custom domain you connect, and the settings you choose.
- Content. The posts, drafts, media, templates, and other material you put into plym Cloud.
- Billing details. Your billing name, address, and tax identifiers where required. Card and other payment details are given directly to our payment provider and are never received or stored by us. We hold the customer and subscription identifiers our payment provider returns, together with the plan, status, and renewal date.
- Correspondence. What you send us when you contact support, ask about enterprise pricing, or report a problem, and our replies.
2.2 Information we collect automatically:
- Server logs. Each request to our servers is logged with the IP address it came from, the browser user agent, the address requested, the referring page, and the time.
- Service events. We record account and service events such as sign-ups, sign-ins, deployments, and billing status changes, with the time and the IP address they came from.
- Device and browser characteristics. When you sign up or sign in to plym Cloud, the console reads your time zone, browser language, platform, screen size and colour depth, touch capability, processor core count, and reported device memory, and sends them with a hash of those values. We use this only to detect fraud and abuse, such as repeated abusive trial sign-ups from one device.
- Local storage. The console stores your session token and display preferences in your browser. See section 5.
2.3 Information from third parties. Our payment provider tells us the status of your subscription and the outcome of payments. We do not buy personal data, and we do not build profiles from third-party sources.
3. How we use personal data
We use personal data to:
- create and administer your account, authenticate you, and provide the Services;
- host, publish, and serve the sites you create, and to back them up;
- take payment, manage subscriptions, issue invoices, and meet tax and accounting obligations;
- send service messages such as sign-in links, billing notices, and notices of changes to these documents or to the Services;
- provide support and answer what you write to us;
- keep the Services secure, investigate incidents, detect and prevent fraud and abuse, and enforce our Terms of Service;
- understand how the Services are used, so we can maintain and improve them; and
- comply with the law and to establish, exercise, or defend legal claims.
We do not sell personal data. We do not use it for cross-context behavioural advertising. We do not use customer content to train machine learning models.
4. Legal bases
Where the UK GDPR or the EU GDPR applies, we rely on the following bases:
- Performance of a contract, for creating and running your account, hosting your site, providing support, and taking payment.
- Legitimate interests, for security, fraud and abuse prevention, service logging, product analytics, responding to enquiries, and the ordinary administration of our business. We have considered your interests and rights in each case and limit what we collect to what those purposes need.
- Legal obligation, for tax and accounting records and for responding to lawful requests.
- Consent, where we ask for it, for example for optional marketing email. You can withdraw consent at any time, and doing so does not affect processing carried out before you withdrew it.
5. Cookies and similar technologies
5.1 The plym.io website sets one cookie, for our own product analytics, together with a matching entry in your browser's local storage. It holds a randomly generated device identifier and session identifier, so that we can count visits and see which pages are used. It does not hold your name or your email address, and no other website can read it. It expires a year after it is set, and you can delete it in your browser at any time. There is no advertising technology on the website and no cross-site tracking.
5.2 The plym Cloud console stores a session token and your display preferences in your browser's local storage. These are strictly necessary to keep you signed in and to render the console as you have set it, and they are not used to track you across other websites.
5.3 Pages on plym.io make one request to a third party in your browser: web fonts are requested from Google Fonts. Google receives your IP address and user agent as a necessary part of serving that request. It does not receive your name, your email address, or anything you type.
5.4 Sites published by our customers may use cookies or other technologies chosen by the customer. Those are the customer's responsibility, not ours.
5.5 Our product analytics are provided by PostHog. The analytics requests your browser makes are sent to plym.io and passed on by us, so your browser makes no direct connection to PostHog, and the IP address the request came from is not passed on with it. Section 6.1 describes what PostHog receives.
6. How we share personal data
6.1 We share personal data with service providers who process it on our instructions and under contract:
- Hetzner Online GmbH, a company established in Germany, which provides the servers that run the Services. Those servers are located in Finland.
- Cloudflare, Inc., United States, which provides authoritative DNS, content delivery, and the object storage in which published site files are held.
- Dodo Payments, which acts as our payment provider and merchant of record, and which processes payment and billing data.
- Resend, Inc., United States, which delivers our transactional email, such as sign-in links.
- PostHog, which we use for product analytics on the plym.io website and on plym Cloud. Analytics requests from your browser are proxied through our own servers, and PostHog receives the events without the IP addresses they came from.
6.2 We also disclose personal data:
- where the law requires it, or to respond to a valid legal request, and we will tell you unless we are prohibited from doing so;
- where necessary to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of any person;
- to professional advisers such as lawyers and accountants, under a duty of confidence; and
- to a buyer or successor, if we are involved in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
6.3 We do not share personal data with anyone else, and we do not sell it.
7. International transfers
Our servers are in the European Union. Some of our service providers are established outside the United Kingdom and the European Economic Area, principally in the United States. Where personal data is transferred out of the UK or the EEA, we rely on the European Commission's and the UK's standard contractual clauses, together with the safeguards and, where applicable, the adequacy decisions that apply to the provider in question.
8. Retention
- Account data is kept while your account is open, and for 30 days after it is closed.
- Content in plym Cloud is deleted from production systems within 60 days of termination, as described in our Terms of Service.
- Backups age out on a rolling basis and are deleted within 90 days.
- Server logs are kept for up to 90 days.
- Service event and fraud prevention records, including device characteristics, are kept for up to 12 months.
- Billing and tax records are kept for as long as tax law requires, which is generally between six and ten years depending on the country.
- Correspondence is kept for 24 months, or for as long as you remain a customer.
Where we are required to keep something to comply with the law or to defend a legal claim, we keep it for as long as that requires and no longer.
9. Security
We serve everything over HTTPS. Signing in to plym Cloud uses a single-use link sent to your email address, so we hold no password for your account; passwords for the team accounts you create inside your own site are stored only as hashes. Access to production systems and to customer content is restricted to the people who need it to do their work. We keep the software we run up to date and we log administrative access.
No service can promise perfect security. If a breach affects your personal data and the law requires it, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify you without undue delay where the breach is likely to result in a high risk to you.
To report a vulnerability, write to [email protected]. We will not pursue researchers who act in good faith and give us a reasonable opportunity to fix a problem before disclosing it.
10. Your rights
10.1 If the UK GDPR or the EU GDPR applies to you, you have the right to ask us for a copy of your personal data, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent you have given. Where we rely on legitimate interests, you may object at any time.
10.2 If you are a resident of California, you have the right to know what personal information we collect and how we use and disclose it, to request deletion or correction, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the CCPA and CPRA, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising any right.
10.3 Residents of other jurisdictions with comparable laws have equivalent rights, and we handle those requests in the same way.
10.4 To exercise a right, write to [email protected]. We reply within one month, and there is no charge. We may need to verify your identity before we act.
10.5 You have the right to complain to your data protection authority. In the United Kingdom that is the Information Commissioner's Office at ico.org.uk; in the European Economic Area it is the authority in the country where you live or work.
11. Sites we host for our customers
11.1 Where a customer publishes a site on plym Cloud, the customer decides what is published on it and what data it collects about its visitors. For that data the customer is the controller and we act as their processor, handling it only on their instructions.
11.2 If you are a visitor to a site hosted on plym Cloud and want to exercise a right over data that site holds about you, contact the operator of that site. If you contact us instead, we will pass the request on where we can identify the site.
11.3 Our own server logs for requests to hosted sites, described in section 2.2, are processed by us for security and service operation.
11.4 Customers who need a data processing agreement should write to [email protected].
12. Software you run yourself
We do not distribute the plym software for you to install and run on infrastructure of your own. If you hold and run a copy that we published earlier, we receive nothing from it. There is no telemetry endpoint, no licence check, and no update ping that identifies you or your installation. What your own deployment collects, and who it discloses it to, is a matter between you and your visitors. If your deployment requests anything from plym.io, that request reaches our servers and is logged as described in section 2.2.
13. Children
The Services are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to [email protected] and we will delete it.
14. Changes to this policy
We may update this policy. The current version is always published at plym.io/privacy-policy with the effective date at the top. Where a change materially affects how we use personal data, we will give notice by email to account holders or in the console before it takes effect.
15. Contact
Flapico Technologies Private Limited
Write to that address for privacy questions, for data protection rights requests, for a data processing agreement, and to report a vulnerability.