1. Who this policy applies to
This policy applies when you visit cairn.press, create or use a Cairn account, work in the Cairn dashboard, use our APIs or contact us. In this policy, “Cairn”, “we”, “us” and “our” refer to the Cairn service.
Organisations that use Cairn may upload personal information to their projects. For that customer content, the organisation decides why and how the information is used and Cairn processes it on the organisation's behalf. Questions about content published by a Cairn customer should usually be directed to that customer first.
2. Information we collect
- Account information: your name, email address, password hash, authentication provider identifiers and account preferences.
- Project content: schemas, documents, assets, datasets, project settings, team membership and the history needed to operate features such as drafts, branches and backups.
- Billing information: subscription, plan and transaction details. Card details are collected and processed by our payment provider rather than stored by Cairn.
- Technical information: IP address, browser and device information, timestamps, request and error logs, API usage, and security events.
- Communications: information you send when asking for support, giving feedback or choosing to receive product updates.
3. How we use information
- Provide, maintain and improve the Cairn platform.
- Authenticate users, manage permissions and keep accounts secure.
- Host and deliver project content and assets, including previews and backups.
- Process subscriptions, enforce plan limits and keep billing records.
- Diagnose errors, prevent abuse and understand service performance.
- Respond to support requests and send service-related messages.
- Meet legal obligations and enforce our agreements.
4. Our legal bases
Where data protection law requires a legal basis, we process information as necessary to provide the service under our contract with you; for legitimate interests such as securing, maintaining and improving Cairn; with your consent, where requested; and to comply with legal obligations. You may withdraw consent at any time, without affecting earlier processing.
5. Cookies and similar technology
Cairn uses cookies and local storage that are necessary for sign-in, OAuth security, session continuity, remembering the last login method and other preferences. If we introduce non-essential analytics or advertising technology, we will request consent where required and update this policy.
6. When we share information
We share information only where needed to operate Cairn, including with:
- infrastructure, database, storage, email, monitoring and support providers;
- payment providers that process subscriptions and payments;
- Google or GitHub when you choose to connect those services;
- professional advisers and authorities where required by law or needed to protect rights and safety; and
- a successor involved in a merger, financing, acquisition or sale of the business, subject to appropriate confidentiality protections.
We do not sell personal information or share it for cross-context behavioural advertising.
7. International transfers
Cairn and its service providers may process information in countries other than the one where you live. Where required, we use recognised safeguards for international transfers, such as adequacy decisions or standard contractual clauses.
8. Retention
We retain information for as long as your account or project is active and as needed to provide the service. After deletion, limited copies may remain temporarily in backups, security records or records we must keep for legal, tax or fraud-prevention purposes. Retention periods depend on the type of information and why it is held.
9. Security
We use technical and organisational safeguards designed to protect information, including access controls, password hashing, encrypted network connections and security measures provided by our infrastructure partners. No online service can guarantee absolute security, so account owners should use strong credentials and protect their access tokens.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information; object to or restrict certain processing; withdraw consent; and complain to your local data protection authority. We may need to verify your identity before acting on a request.
Project owners control the content held in their Cairn projects. If your request concerns information that one of our customers manages, we may direct you to that customer or help them respond.
11. Children
Cairn is intended for professional use and is not directed to children under 16. If you believe a child has provided personal information to Cairn, please contact us so we can investigate and take appropriate action.
12. Changes to this policy
We may update this policy as Cairn or applicable law changes. We will publish the revised version here and update the date above. If a change materially affects how we use personal information, we will provide additional notice where appropriate.
13. Contact us
For questions or privacy requests, email privacy@cairn.press.