Privacy Policy
Effective date: July 30, 2026
Last updated: August 1, 2026
Summary
This summary is for convenience. The full policy below explains our practices in more detail.
- We collect information needed to provide Shed, such as account, billing, deployment, device, usage, and support information.
- We process code, configuration, logs, secrets, and application data when you ask Shed to build and run your software.
- When we manage your account and operate Shed, we generally act as the controller of your personal data.
- When we process personal data inside your application on your instructions, we generally act as your processor or service provider.
- We use service providers to operate infrastructure, process payments, provide support, secure the Service, and understand how it is used.
- We do not sell personal data or use Customer Material to train machine-learning models.
- Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data.
- You can contact us at support@shed.codes about privacy.
1. Who we are
Shed is operated by REDRESS SPACE LTD, a company registered in England and Wales with its registered office at Level 30, The Leadenhall Building, 122 Leadenhall Street, City of London, London EC3V 4AB, United Kingdom ("Shed," "we," "us," or "our").
For personal data described in this policy that we use for our own purposes, REDRESS SPACE LTD is the controller.
Contact: support@shed.codes
2. Scope
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you:
- visit our website;
- create or use a Shed account;
- use our command-line tools, APIs, software, build, deployment, hosting, or related services;
- communicate with us or request support; or
- otherwise interact with Shed.
Together, these are the "Service."
This policy should be read with our Terms of Service. It does not govern third-party services, websites, or applications that we do not control, including applications operated by Shed customers.
3. Our roles
When Shed is a controller
We act as a controller when we decide why and how to process personal data for our own purposes. Examples include account administration, billing, security, support, product analytics, legal compliance, and communications about the Service.
When Shed is a processor
Customers may deploy applications that process personal data about their own users, employees, customers, or other individuals ("Customer Application Data"). For that data, the customer normally determines the purpose and means of processing, and Shed processes the data on the customer's instructions.
If you want to exercise rights concerning Customer Application Data, contact the customer that operates the relevant application. We will assist that customer as required by our applicable data processing agreement and data-protection law.
When we act as a processor, we process personal data only on the customer's documented instructions, as needed to provide and secure the Service, and as required by applicable law.
4. Personal data we collect
The data we collect depends on the features you use and how you interact with the Service.
| Category | Examples | Why we process it |
|---|---|---|
| Account and contact data | Name, email address, username, organization, account identifiers, profile information | Create and administer accounts, authenticate users, communicate with you, and provide support |
| Authentication data | Password hashes, login tokens, API keys, authentication events, and information received from an identity provider | Secure accounts, provide sign-in, prevent abuse, and investigate incidents |
| Billing and commercial data | Billing contact, billing address, tax information, subscription, usage, invoices, payment status, payment-card type and last four digits | Process purchases, calculate charges, administer credits, prevent fraud, and maintain financial records |
| Project and deployment data | Project names, repository metadata, configuration, Shedfiles, build instructions, deployment status, domains, region, runtime settings, and resource usage | Build, deploy, operate, troubleshoot, meter, and secure applications |
| Customer Material | Source code, files, databases, prompts, environment configuration, secrets, application content, and other data you submit to the Service | Perform the actions you request and provide the Service |
| Logs and telemetry | Build logs, application logs, audit events, command and API activity, errors, performance measurements, request metadata, timestamps, and diagnostic data | Operate, debug, secure, support, and improve the Service |
| Device and network data | IP address, browser, operating system, device type, language, approximate location derived from IP, referrer, and cookie identifiers | Deliver the website, maintain sessions, protect the Service, understand usage, and comply with law |
| Communications | Support requests, emails, survey responses, feedback, call notes, and attachments you provide | Respond to you, troubleshoot, improve the Service, and maintain records |
| Marketing and preference data | Communication preferences, campaign interactions, and product interests | Send permitted communications and measure their effectiveness |
Payment-card numbers may be collected directly by a payment provider rather than stored by Shed.
We may create aggregated or de-identified information that does not reasonably identify an individual. We may use that information for lawful business purposes, including capacity planning, security analysis, and product improvement. We will not attempt to re-identify it except to test whether our de-identification measures are effective or where permitted by law.
5. How we collect personal data
We collect personal data:
- From you, when you register, configure a project, deploy an application, purchase a plan, contact us, or otherwise provide information.
- Automatically, when your browser, command-line tool, application, agent, or device interacts with the Service.
- From authorized users, such as an administrator who invites you to an organization or configures your account.
- From connected services, such as a source-code host, identity provider, cloud provider, or integration that you authorize.
- From service providers, such as payment, fraud-prevention, analytics, security, or support providers.
- From public sources, where permitted by law, such as a public company website or public software repository.
If you connect a third-party account, we receive only the information made available by that provider and authorized through the connection. You can usually manage this access in the third party's settings.
6. How and why we use personal data
We use personal data to:
- create, authenticate, administer, and secure accounts;
- receive code and configuration and carry out requested builds and deployments;
- provide domains, networking, storage, logs, databases, scheduled jobs, and related functionality;
- calculate usage, process payments, issue invoices, and administer credits;
- monitor reliability, diagnose failures, prevent fraud, and address abuse;
- respond to requests and provide technical or customer support;
- maintain, analyze, and improve the Service;
- communicate operational, security, billing, and legal information;
- send marketing communications where permitted, with an unsubscribe option;
- establish, exercise, or defend legal claims and enforce our agreements;
- comply with legal obligations and valid requests from authorities; and
- support a merger, financing, acquisition, reorganization, or sale of all or part of our business.
Lawful bases under UK and EU data-protection law
Where UK GDPR or EU GDPR applies, we rely on one or more of the following lawful bases:
| Purpose | Typical lawful basis |
|---|---|
| Creating an account and providing requested features | Performance of a contract |
| Billing and administering purchases | Performance of a contract; legal obligation |
| Security, fraud prevention, service reliability, and product improvement | Our legitimate interests and those of our users |
| Required tax, accounting, sanctions, and legal records | Legal obligation |
| Essential account, security, and legal notices | Performance of a contract; legal obligation; legitimate interests |
| Optional marketing or non-essential cookies | Consent where required; otherwise legitimate interests |
| Responding to a threat to someone's safety | Vital interests where applicable |
Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where our interests are overridden by their rights and freedoms.
You may withdraw consent at any time where consent is the basis for processing. Withdrawal does not make earlier processing unlawful.
7. Customer Material and application data
We process Customer Material only as needed to provide, secure, maintain, and support the Service; comply with law; enforce our agreements; or follow your instructions.
We will not use Customer Material to train machine-learning models or sell it to third parties unless you separately and expressly opt in.
Your use of Shed does not make us responsible for the privacy practices of your application. If you operate an application using Shed, you are responsible for:
- providing your own privacy notice to its users;
- establishing a lawful basis for processing their personal data;
- responding to their privacy requests;
- configuring appropriate access, logging, security, and retention controls; and
- entering into any data-processing agreements required by law.
Do not submit regulated or highly sensitive data unless the Service expressly supports it and an appropriate written agreement is in place.
8. How we disclose personal data
We may disclose personal data to:
- Infrastructure and hosting providers that supply compute, storage, networking, databases, observability, content delivery, and related services.
- Account and identity providers when you choose an external sign-in or integration.
- Payment and billing providers that process payments, taxes, invoices, subscriptions, and fraud checks.
- Security, analytics, and support providers that help us protect, understand, and support the Service.
- Professional advisers, including lawyers, accountants, auditors, and insurers, where reasonably necessary.
- Your organization and authorized users, according to workspace roles, account configuration, and your instructions.
- Third parties you authorize, such as an integration or application you connect to Shed.
- Authorities or other parties for legal reasons, where disclosure is required by law or reasonably necessary to protect rights, safety, the Service, or others.
- A corporate transaction participant, subject to appropriate safeguards, in connection with a financing, merger, acquisition, reorganization, insolvency, or sale of assets.
Information about our current service providers is available by contacting support@shed.codes.
We do not sell personal data or share it for cross-context behavioural advertising.
9. Cookies and similar technologies
We may use cookies, local storage, pixels, and similar technologies to:
- keep the website and account area functioning;
- authenticate users and maintain sessions;
- remember preferences;
- protect against fraud and abuse;
- understand performance and usage; and
- measure communications or campaigns.
Essential technologies are used where necessary to provide the Service. Non-essential analytics, advertising, or preference technologies will be used only as permitted by law and, where required, after you provide consent.
You can control cookies through your browser settings and through any preference controls we make available in the Service. Blocking essential cookies may prevent some features from working.
10. International data transfers
Shed and its providers may process personal data outside the country where you live. Those countries may have different data-protection laws.
Where UK, EEA, or Swiss personal data is transferred to a country that has not been recognized as providing adequate protection, we will use a lawful transfer mechanism where required. This may include:
- the UK International Data Transfer Agreement or UK Addendum;
- the European Commission's Standard Contractual Clauses;
- an applicable adequacy decision; or
- another transfer mechanism permitted by law.
We will also apply supplementary safeguards where required. Information about the applicable mechanism may be requested at support@shed.codes.
11. Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Service, comply with legal obligations, resolve disputes, collect fees, enforce agreements, and maintain security.
We determine retention periods by considering how long an account remains open, how long information is needed to provide and secure the Service, applicable legal and accounting requirements, the time needed to resolve disputes, and the settings or plan that apply to the relevant feature. Customer Material is handled according to the deletion periods described in the Terms of Service. Logs and support records are retained only for as long as reasonably necessary for their operational, security, support, or legal purpose.
We may retain data longer where required by law, subject to a legal hold, needed to address abuse or security, or necessary to establish or defend legal claims. Data may remain in backups until those backups expire under our ordinary cycle.
We may retain aggregated or de-identified information where it can no longer reasonably identify you.
12. Security
We use technical and organizational measures designed to protect personal data, taking account of the data's nature, the processing, and the risks involved. Measures may include access controls, encryption, logging, network protections, secure development practices, vulnerability management, backups, and incident response.
No internet service is completely secure. You are responsible for protecting your credentials, limiting access to your account, securing your applications, and promptly notifying us at support@shed.codes if you suspect unauthorized access.
Additional information about security measures applicable to Customer Application Data may be made available on request.
13. Your choices
You may:
- update certain account information through the Service;
- unsubscribe from marketing emails using the link in the message;
- manage cookies through the available preference controls;
- revoke a connected service through Shed or the third party;
- export Customer Material using available product features; and
- close your account according to the Terms of Service.
You cannot opt out of essential operational, billing, security, or legal communications while maintaining an account.
14. UK, EEA, and Swiss privacy rights
Subject to applicable law and exceptions, you may have the right to:
- request access to your personal data;
- correct inaccurate or incomplete personal data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests or for direct marketing;
- receive certain personal data in a portable format;
- withdraw consent where processing relies on consent; and
- complain to a data-protection authority.
To exercise a right, email support@shed.codes. Describe your request and the account or interaction it concerns. We may ask for information reasonably needed to verify your identity and authority. We will respond within the period required by law.
If Shed processes your data on behalf of a customer, please contact that customer first. We will assist them as required.
You may complain to the UK Information Commissioner's Office through ico.org.uk, or to the supervisory authority where you live or work. We encourage you to contact us first so we can try to resolve the issue.
15. U.S. state privacy rights
Residents of certain U.S. states may have rights, subject to applicable thresholds and exceptions, to:
- confirm whether we process their personal data and obtain access;
- correct inaccuracies;
- request deletion;
- receive a portable copy;
- obtain information about certain third parties receiving their data;
- opt out of sale, targeted advertising, or certain profiling;
- limit certain uses of sensitive personal data; and
- appeal a denied request.
We do not sell personal data, share it for cross-context behavioural advertising, or use it for targeted advertising.
Submit a request or appeal to support@shed.codes. Use the subject line "Privacy Request" or "Privacy Rights Appeal". We may verify your identity and, where permitted, ask an authorized agent to provide proof of authority.
We will not unlawfully discriminate against you for exercising a privacy right.
California disclosures
The categories of personal information we may have collected during the previous 12 months are described in Section 4. The business purposes and categories of recipients are described in Sections 6 and 8.
We do not use or disclose sensitive personal information to infer characteristics about individuals.
California residents may also request information concerning certain disclosures for third parties' direct-marketing purposes by contacting support@shed.codes.
16. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to Shed, contact support@shed.codes. We will investigate and delete the data where required.
Customers must not use the Service to process children's personal data subject to COPPA or similar laws unless Shed expressly supports that use and the parties have an appropriate written agreement.
17. Automated decisions
We may use automated systems to detect fraud, abuse, security threats, service failures, or violations of our Terms. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for individuals.
Where required, you may request human review or challenge an automated decision by contacting support@shed.codes.
18. Changes to this policy
We may update this Privacy Policy to reflect changes to the Service, our practices, or the law. We will post the updated version and revise the "Last updated" date.
If a change materially affects your rights or how we use personal data, we will provide additional notice through the Service, by email, or by another appropriate method before the change takes effect where required.
19. Contact
Questions, requests, or complaints about this Privacy Policy may be sent to:
REDRESS SPACE LTD
Level 30, The Leadenhall Building, 122 Leadenhall Street, City of London, London EC3V 4AB, United Kingdom
Email: support@shed.codes