Skip to content
CSDocs View CSDocs

Privacy notice

Collect what the service needs. Explain the rest.

This notice covers the CSDocs marketing site, trial checkout, customer onboarding, subscription service, and support. It also identifies the infrastructure details that must be confirmed before stronger privacy claims are made.

Scope

Who this notice covers

CSDocs is a Cloud Steward service for business customers. This notice applies when you visit a CSDocs page, start or manage a subscription, authorize onboarding, use a customer workspace, request support, or communicate with Cloud Steward about CSDocs.

Your organization may separately control information that it places in CSDocs. Questions about your employer’s use of that information should normally be directed to your organization first.

Information collected

Information depends on how you interact with CSDocs

Trial and subscription information
Stripe collects the contact, billing, and payment information entered at checkout and through its billing services. CSDocs can receive and access the account and subscription information needed to provide support, confirm status, and administer billing. Full payment-card details are handled by Stripe rather than the CSDocs funnel database.
Customer and user information
This can include company name, authorized user names, business email addresses, account roles, onboarding decisions, and the settings needed to provide a private CSDocs workspace.
Customer documentation
CSDocs may process NetSuite customization information and customer-supplied context needed to build and maintain documentation. The exact source objects, connection method, permissions, data fields, and AI-processing path must be documented during the production infrastructure audit and disclosed before onboarding.
Communications and support
CSDocs receives the information you include in emails, support requests, meeting notes, feedback, cancellation requests, and security reports. Do not send credentials, payment-card details, or unrelated personal information by email.
Website interaction events
The privacy-minimal funnel described below records a small set of page and conversion events, using a temporary pseudonymous token rather than an identified visitor profile.
Infrastructure request logs
Web hosts, content-delivery services, security layers, and email systems may process request metadata such as IP address, timestamp, and user agent to deliver and protect the service. The provider list and each provider’s exact log retention remain part of the infrastructure audit; these records are separate from the CSDocs funnel database.

Purpose

How CSDocs uses information

  • Provide, configure, maintain, and support the CSDocs service.
  • Authenticate authorized users and administer customer access.
  • Process trial, subscription, payment, cancellation, and account-status activity.
  • Respond to questions, support requests, security reports, and legal obligations.
  • Protect the service, investigate abuse, and diagnose operational failures.
  • Measure whether the `/start/` page and its demo and trial links work, using the limited funnel data described below.
  • Enforce the CSDocs Terms and document customer decisions.

CSDocs does not use its funnel event database to build advertising profiles or to store payment-card details.

Website measurement

A cookie-free, pseudonymous funnel

The CSDocs `/start/` measurement system is designed to understand a short conversion path without creating a persistent browser identity.

What is recorded

Event name, page version, CTA location, broad device category, broad referrer category, and operator-allowlisted source, medium, and campaign values when configured.

How events connect

A random visit token exists in memory for the page visit. The application stores only a keyed hash of it and passes the opaque token to Stripe as a checkout reference when a trial link is opened.

What is excluded

The funnel database does not store email address, raw IP address, full user agent, full referrer URL, card data, Stripe customer ID, or a raw Stripe webhook payload. A short-lived keyed hash derived from the request IP is used only to rate-limit abuse; server, proxy, and Stripe logs are separate.

What the browser retains

The funnel does not use cookies, local storage, or session storage. Leaving or reloading the page can create a new, unrelated token.

Why “pseudonymous,” not “anonymous”?

The temporary token is disclosed to Stripe as a checkout reference when a trial link is opened. It does not identify the visitor by itself, but that limited connection means “anonymous” would be too broad a claim.

Stripe and other pages you choose to visit operate under their own notices and may use their own browser technologies. The CSDocs cookie-free description applies only to the funnel measurement described here.

Providers and disclosure

When information is handled by someone else

CSDocs discloses information when needed to operate the service, follow customer instructions, process a transaction, protect people or systems, comply with law, or complete a business transfer subject to appropriate safeguards.

Infrastructure and communications providers

Register under review

The complete production hosting, storage, AI, content-delivery, monitoring, and email provider register must be verified against the live architecture before it is represented as exhaustive.

Publication gate

The provider register is not complete until the infrastructure audit identifies the current provider, purpose, data category, processing location, and retention behavior for each production system.

Retention and deletion

Different records have different lifetimes

CSDocs record-retention schedule
Record Retention Reason
Raw pseudonymous funnel events Up to 180 days Diagnose page, demo-link, and trial-link performance.
Aggregated funnel metrics Up to 25 months Compare monthly and annual performance. These reports contain counts rather than visit-level records.
Customer documentation and access Defined during onboarding or in a signed order Document access, export availability, active-copy treatment, and deletion timing before customer data is connected.
Backups, infrastructure logs, and provider copies Audit required A specific removal period will be published only after live backup, log, cache, export, and provider behavior is verified.
Billing and business records As required for accounting, disputes, fraud prevention, and legal obligations Operate the business and comply with applicable requirements.

When service ends, CSDocs follows the offboarding and deletion commitments documented during onboarding or in a signed order. A request to delete other information may not remove the limited billing, legal, or security records CSDocs must retain for a current obligation, active dispute, security investigation, or legitimate accounting requirement. Any exception is limited to the necessary records.

Your choices

Access, correction, deletion, and cancellation

You can ask CSDocs what personal information it holds about you, request correction, or request deletion. CSDocs will verify the requester and respond according to the rights and exceptions that apply. If your organization controls the relevant customer workspace, CSDocs may direct the request to that organization.

You can cancel a subscription by emailing ben@thecloudsteward.com. Cancellation and service deletion are described in the CSDocs Terms.

Contact and changes

Ask a privacy question

Contact Benjamin Rogol about this notice or a privacy request. If this notice changes materially, its revision date will change and the updated version will be published here.

ben@thecloudsteward.com