Effective Date: August 2, 2026
Privacy Policy
Vatt Labs LLC ("Nanorack", "we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, use our platform-as-a-service, or interact with our APIs and command-line tools (collectively, the "Service").
1. Our Two Roles: Controller and Processor
This policy distinguishes two kinds of information:
- Account and usage information you provide to sign up for and operate the Service. For this information, Nanorack acts as a data controller.
- Hosted Data — the data, code, and content you deploy and process using the Service. For Hosted Data, Nanorack acts as a data processor, handling it only on your instructions and on your behalf. You are the controller of your Hosted Data and are responsible for its lawful collection and use, including providing any required notices and obtaining any required consents from your own end users. Business customers may request a Data Processing Addendum (DPA) at [email protected].
2. Information We Collect
- Account Information: name, email address, password, organization name, and (if you authenticate via OAuth) basic profile information from your identity provider.
- Billing Information: billing address and payment details, processed by our third-party payment processor. We do not store full payment-card numbers on our systems.
- Operational Telemetry: resource usage and operational metrics for the workloads you run (such as CPU, memory, disk, and network usage) and deployment metadata, used for billing, capacity, and abuse prevention.
- Log and Device Data: information your browser or CLI sends when you interact with the Service, such as IP address, client/browser and CLI version, pages or endpoints accessed, timestamps, and diagnostic data.
- Support Communications: information you provide when you contact us for support or other inquiries.
3. Hosted Data
We do not access, inspect, or use your Hosted Data except as necessary to provide, secure, and maintain the Service, as instructed by you, or as required by law. We use tenant isolation between customer workloads. We access Hosted Data only where you request support that requires it, where necessary to address a security or operational incident, or where compelled by valid legal process.
4. How We Use Information and Legal Bases
We use the information we collect to: provide, operate, secure, and maintain the Service; authenticate accounts and provide support; meter usage and process billing; detect, prevent, and address fraud, abuse, and security or technical issues; communicate service and account notices; and comply with legal obligations. Where the GDPR or similar laws apply, we rely on these legal bases: performance of a contract (to provide the Service), legitimate interests (to secure, improve, and protect the Service and prevent abuse), consent (where required, e.g. certain communications), and legal obligation (e.g. tax and accounting records).
5. Cookies
Our website and dashboard use strictly necessary cookies to keep you signed in and to operate core functionality, and may use limited analytics to understand usage. We do not use third-party advertising cookies or sell information for advertising. You can control cookies through your browser settings; disabling essential cookies may impair the Service.
6. How We Share Information
We do not sell your Personal Information. We share information only as follows:
- Service Providers / Subprocessors: with vendors who process information on our behalf to run the Service — for example, payment processing, cloud and infrastructure hosting, DNS and content delivery, and email delivery — under contractual confidentiality and data-protection obligations.
- Legal and Safety: to comply with applicable law, valid legal process, or governmental requests, and to protect the rights, property, safety, or security of Nanorack, our customers, or the public.
- Business Transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
7. Data Retention
We retain account and billing records for as long as your account is active and thereafter as needed to comply with legal, tax, and accounting obligations and to resolve disputes. Operational logs and telemetry are retained for a limited period consistent with operating and securing the Service. Hosted Data is retained according to your use of the Service and is deleted following account termination after a commercially reasonable period. Ephemeral storage is not retained across redeploys.
8. Data Security
We implement technical and organizational measures designed to protect information, including encryption in transit, encryption at rest for stored secrets, tenant isolation, and access controls. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials, API tokens, and secrets, and for the security configuration of the workloads you deploy. We will notify affected users and regulators of a personal-data breach where required by applicable law.
9. International Data Transfers
Our infrastructure is located primarily in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate safeguards for such transfers, such as Standard Contractual Clauses.
10. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or port your Personal Information; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. California residents have rights under the CCPA/CPRA, including to know, delete, and correct Personal Information and to not be discriminated against for exercising these rights; we do not sell or "share" (as defined by the CPRA) Personal Information. EEA/UK residents may also lodge a complaint with their supervisory authority. To exercise your rights, contact us at [email protected]; you may also delete your account and associated Personal Information from your dashboard. We will verify requests as required by law. For Hosted Data, direct your request to the customer who controls that data; we will assist that customer as their processor.
11. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect Personal Information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy with a revised Effective Date and, where required, provide additional notice. Please review it periodically.
Contact Us
For questions about this Privacy Policy or our data practices, contact us at [email protected].