Legal

Privacy Policy

Last updated: May 19, 2026

1. Overview

This Privacy Policy describes how RedPennon ("we", "us", "our") collects, uses, and protects information in connection with redpennon.dev and the RedPennon feature flag platform (the "Service"). It applies both to visitors to our marketing site and to authenticated users of the Service.

For personal information about our own account holders, billing contacts, and website visitors, RedPennon is the data controller. For personal information contained in Customer Data that you submit to the Service (for example, end-user context payloads sent to the evaluation API), RedPennon acts as a data processor on your behalf and processes that information in accordance with our Terms of Service and your documented instructions.

2. Information we collect

We collect three categories of information:

  • Account information — name, email address, organisation name, and authentication identifiers when you sign up; billing contact details processed by our payment processor.
  • Customer Data — feature flag definitions, targeting rules, audiences, and the user-context payloads you submit to the evaluation API. You control the content and lawfulness of Customer Data.
  • Usage and diagnostic data — IP address, browser, OS, request timing, evaluation metrics, and error reports collected automatically when you use the Service.

3. How we use information

  • To provide, maintain, and improve the Service.
  • To evaluate feature flags against user contexts you submit.
  • To detect, investigate, and prevent abuse, fraud, or security incidents.
  • To send service-related notifications and billing receipts, and to send product updates where you have opted in.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following legal bases: performance of our contract with you (to provide the Service); our legitimate interests (to secure, improve, and promote the Service, in a way that does not override your rights); compliance with legal obligations; and your consent where required (for example, marketing emails), which you may withdraw at any time.

4. Sharing and sub-processors

We do not sell personal information and we do not share it for cross-context behavioural advertising. We share information only with sub-processors required to operate the Service (such as cloud hosting, payment processing, and transactional email), or when compelled by law, legal process, or to protect the rights, safety, or property of RedPennon, our customers, or the public. Sub-processors are bound by contract to appropriate confidentiality and security obligations. A current list of sub-processors is available on request from privacy@redpennon.dev.

5. Cookies and tracking

We use strictly necessary cookies to authenticate sessions, protect against cross-site request forgery, and remember your preferences. We do not use third-party advertising cookies or cross-site tracking on our marketing site or in the application, and we do not deploy fingerprinting or session replay tools. We honour the Global Privacy Control signal where applicable.

6. Data retention

Account information and Customer Data is retained for the lifetime of your account and for a short period after termination to support recovery, billing reconciliation, and legal obligations (typically up to 30 days unless a longer period is required by law). Audit logs are retained for one year. Diagnostic logs are typically retained for 30 days. Aggregate, de-identified usage statistics that cannot reasonably be linked to an individual may be retained indefinitely.

7. Security

Customer Data is encrypted in transit (TLS 1.2+) and at rest in our managed PostgreSQL database. Access to production systems is restricted to a small number of operators using SSO and least-privilege roles, and is logged. We follow standard practices for credential management, dependency patching, and backup. No system is perfectly secure; you are responsible for using strong, unique credentials and for safeguarding API keys. Report vulnerabilities to security@redpennon.dev.

8. Data breach notification

If we become aware of a personal data breach affecting your information, we will notify affected account holders without undue delay and, where required by law (including under the Australian Notifiable Data Breaches scheme and Article 33 of the GDPR), within applicable statutory timeframes. Our notification will describe the nature of the breach, the categories of data affected, the likely consequences, and the steps we are taking in response.

9. Your rights

Depending on your jurisdiction (including under the GDPR, the UK GDPR, the Australian Privacy Principles, and the CCPA/CPRA), you may have the right to access, rectify, port, restrict, object to, or delete your personal information, and to lodge a complaint with a supervisory authority. To exercise these rights, contact privacy@redpennon.dev. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request, and we will not discriminate against you for exercising a right.

You can opt out of product update and marketing emails at any time by using the unsubscribe link in those emails or by contacting us. We will continue to send service-related notifications (such as billing receipts and security alerts) that are necessary to operate the Service.

If your personal information is contained in Customer Data submitted by one of our customers, please direct your request to that customer (the controller); we will support them in responding to you.

10. Children

The Service is intended for use by businesses and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, please contact privacy@redpennon.dev and we will take steps to delete it.

11. Automated decision-making

RedPennon does not make decisions based solely on automated processing of personal information that produce legal or similarly significant effects on you. Feature flag evaluations performed by the Service operate on the user-context payloads you submit and on rules you configure; they are not used by RedPennon to make decisions about you.

12. International transfers

The Service is hosted in AWS Sydney (ap-southeast-2). If you access the Service from outside Australia, your information will be transferred to and processed in Australia, which may provide different data protection standards from your home jurisdiction. Where transfers are subject to the GDPR or UK GDPR, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) with our sub-processors. A copy of the relevant transfer mechanism is available on request from privacy@redpennon.dev.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 30 days before they take effect. Non-material changes (such as clarifications) take effect when posted, and the "Last updated" date above will reflect the change.

14. Contact

Privacy questions and requests can be sent to privacy@redpennon.dev.

RedPennonredpennon.dev
© 2026 RedPennon. All rights reserved.