Data Protection & Privacy

Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains how Hydratik inc ("PGBox," "we") collects, uses, and protects information in connection with PGBox Cloud.

3.1 What We Collect

  • Account information: Name, email address, and authentication credentials you provide at signup.
  • Billing information: Processed by our payment processor (Stripe); we do not store full payment card numbers ourselves.
  • Usage and metering data: Compute time, storage consumed, data egress, and connection counts, used for billing and platform operation.
  • Technical and security logs: Connection metadata (e.g. source IP, timestamps, authentication attempts) retained for security purposes such as intrusion detection.
  • Your database content: The data you store in your provisioned databases. We do not access, read, or use the content of your databases except as described in Section 1.4 of the Terms of Service (your request, necessary service operation such as backups, or legal requirement).

3.2 How We Use Information

  • To provide, operate, and secure the Service;
  • To process billing and communicate about your account;
  • To detect and prevent abuse, fraud, or security incidents;
  • To communicate service updates, incidents, or changes to these policies.
We do not sell your personal information or your database content to third parties.

3.3 Third-Party Processors

We share limited data with the following categories of service providers, solely to operate the Service:

  • Payment processing (Stripe): Billing information and transaction processing.
  • Email delivery (AWS SES or equivalent): Account lifecycle and transactional operational emails.
  • Backup and object storage (Cloudflare R2 / AWS S3 or equivalent): Encrypted database snapshot backups.
  • Infrastructure and hosting providers: Underlying compute and storage for provisioned databases.

Each processor is bound by its own data protection obligations to us; we do not control their independent use of data outside providing these services to us.

3.4 Data Location

The physical location of your cluster may vary based on the time of creation and provisioning region; this information will be made available to you on demand.

3.5 Data Retention

  • Account data is retained while your account is active and for a period of 90 days after closure, to allow for account recovery and legal/billing recordkeeping, after which it is deleted except where retention is legally required.
  • Database backups are retained per the schedule described in your plan (see pricing/documentation) and deleted on a rolling basis per that retention policy.
  • Upon account termination, database content is deleted per Section 1.11 of the Terms of Service.

3.6 Security

We apply technical measures including TLS encryption in transit, encrypted backup storage, high-entropy credential generation, and intrusion-prevention monitoring, as described in our architecture documentation. No system can be guaranteed 100% secure, and we encourage customers to follow good security practices on their own end (credential rotation, IP allowlisting where available, least-privilege access).

3.7 Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information. To exercise these rights, contact privacy@pgboxhub.com. We will respond within the timeframe required by applicable law.

3.8 Children's Privacy

The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children.

3.9 Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-console notice.

3.10 Contact Information

Questions about this Privacy Policy: privacy@pgboxhub.com