Policy desk

Privacy Policy

How RelayBoard processes business-workspace information, which providers are involved, and where application controls end.

Effective
July 19, 2026
Version privacy-2026-07-19

01

Introduction

This Privacy Policy explains the information RelayBoard processes to provide the service, the providers involved, and the controls available for workspace information.

02

Information processed

RelayBoard processes the following information to operate the service:

  • Account and profile information: Email address, name, optional job title, company name, workspace role, and email-verification state.
  • Workspace data: Tasks, comments, announcements, reactions, meetings, team structure, notification preferences, and settings entered by workspace members.
  • Contract evidence: The accepting representative, business workspace, policy versions, exact acceptance statement, timestamp, request IP address, and browser user-agent associated with business signup.
  • Diagnostic data: Error reports, sampled performance traces, operational logs, route metadata, and pseudonymous profile and workspace identifiers. Application monitoring context does not add names or email addresses.
  • Billing state: Plan, subscription status, billing-period information, and provider identifiers. Card details are handled by Paddle and are not stored by RelayBoard.

03

How information is used

Information is used to authenticate members, provide workspace features, send service and digest email, manage subscriptions and access, support calendar connections, respond to requests, diagnose faults, protect resource-intensive routes, and perform administrator-requested exports or deletion.

04

Service providers

RelayBoard uses WorkOS for identity, Paddle for billing, Resend for email, Sentry for monitoring, Railway for application and database hosting, and the calendar provider selected by a workspace member. Calendar providers receive meeting data when a member enables a connection; RelayBoard stores the credentials or tokens needed to operate it.

Those providers process information under their own terms and retention practices. RelayBoard’s security page explains where RelayBoard controls end and a named service provider takes over.

05

Sessions and cookies

WorkOS AuthKit provides the primary authentication flow. RelayBoard stores session values in HttpOnly, SameSite=Lax cookies and marks them Secure in production or when the configured app origin uses HTTPS. A separate cookie stores the selected light or dark theme.

Workspace access also requires an active, verified profile linked to the authenticated session.

06

Storage location

RelayBoard currently hosts the application and PostgreSQL workspace data on Railway. RelayBoard does not provide an in-product control for selecting a storage region.

07

Monitoring

RelayBoard uses Sentry for error monitoring, sampled performance traces, and operational logs. Default PII sending is disabled and application context is sanitized. Session replay is currently off; if enabled later, text and inputs are masked and media is blocked.

08

Retention, cancellation, and deletion

Active workspace content, removed-member records, contract evidence, and local workspace audit or delivery records remain associated with the workspace until they are deleted by a supported product action or the workspace is deleted. Canceling a subscription does not delete that data.

A workspace administrator can separately request workspace deletion. RelayBoard queues a retryable job that cancels non-terminal Paddle subscriptions and removes linked WorkOS identities that are not used by another workspace before deleting the local company record and company-scoped records. If cleanup fails, the local workspace remains for retry. RelayBoard currently retains deletion-job evidence as a separate security and operational record without an automatic deletion schedule.

Unverified signup records are automatically removed after 24 hours; expired consumed magic-token records are removed after expiry; terminal workspace invitations are removed after 90 days. No other universal retention period is currently published. Billing records, email records, monitoring data, provider logs, external calendar events, and backups may remain under provider terms or applicable legal obligations.

09

Business privacy roles and processing terms

This policy does not assign RelayBoard or a customer a controller, processor, business, service-provider, or equivalent statutory role. Those roles depend on applicable law and any approved processing agreement. RelayBoard does not currently publish or promise a DPA.

10

Access, export, and requests

Workspace administrators can download a versioned JSON export of workspace business data. The export excludes session material, access codes, policy-acceptance evidence, calendar credentials and tokens, and billing provider identifiers.

You may contact supportrelayboard.app about access, correction, deletion, or other privacy rights available under applicable law. Identity and authority must be verified before acting on a request. RelayBoard does not publish a response-time commitment beyond periods required by applicable law.

11

Changes and contact

Each published policy revision has a version and effective date. Questions can be sent to supportrelayboard.app.

← Policy index