Turbo

Decap Turbo — Privacy Policy

Last updated: 2026-08-13.

1. Who we are

Decap Turbo is operated by PM, poslovni mediji d.o.o., a company registered in Slovenia (registration number 2146215000, VAT ID SI27901181), with its registered office at Igriška ulica 5, 1000 Ljubljana, Slovenia (“we”, “us”, “our”). We are the controller for the personal data we collect about users of Decap Turbo, as described in this policy. For privacy questions or data requests, contact us — see section 12.

2. What we collect and why

CategoryExamplesPurposeLegal basis
Account dataEmail address, nameCreating and securing your accountPerformance of a contract
Organization & role dataOrg/site metadata, membership and role assignmentsRunning multi-user orgs and access controlPerformance of a contract
Git hosting credentialsGitHub/GitLab access tokens (proxied, not shown to other users)Operating the Git hosting API request proxyPerformance of a contract
Site configurationSite variables you choose to store with usProviding site variable storagePerformance of a contract
Support communicationsMessages sent via our contact formResponding to inquiries and support requestsLegitimate interest (providing support)
Security/technical logsIP address, request logs, device/browser identifiersFraud prevention, abuse detection, and keeping the Service secureLegitimate interest (security) and legal obligation, where applicable
Beta usage data (closed beta only)Feature usage events (e.g. pages visited, actions taken, errors encountered), tied to your accountUnderstanding how beta testers use the Service, so we can improve it before general availabilityLegitimate interest (product improvement during closed beta)

We do not collect payment card details ourselves — see section 3.

3. Sub-processors and recipients

We share data with the following categories of recipients:

  • Service providers / sub-processorsSupabase for authentication and data storage. Supabase processes data on our behalf under its own security and privacy terms.
  • Merchant of recordPaddle, for the sale of Decap Turbo subscriptions, payment collection, subscription management, tax compliance, and invoicing. Paddle acts as an independent controller of your payment and billing data under its own privacy policy — see also our Terms of Service.
  • Professional advisers — lawyers, accountants, or auditors, where necessary.
  • Authorities — where required by law, or to protect our rights, safety, or property, or that of our users.

We don’t sell your personal data, and we don’t use third-party advertising or tracking services. During the closed beta, we collect basic product-usage data ourselves, stored only in our own Supabase database — never sent to a third-party analytics provider — to understand how the Service is used; see the table in section 2 and how to opt out in section 5.

4. International transfers

We and our sub-processors may process personal data outside the EU/EEA and UK — for example, on infrastructure operated by Supabase or Paddle in other jurisdictions. Where this happens, we rely on appropriate safeguards recognized under EU/UK data protection law, such as Standard Contractual Clauses or an applicable adequacy decision, to ensure your data receives an equivalent level of protection.

5. Cookies

We use a session cookie to keep you signed in, and an active_org_id cookie to remember which organization you’re currently working in. Both are strictly necessary for the Service to function and are set without requiring consent. We don’t use analytics, advertising, or third-party tracking cookies.

Beta usage data. While Decap Turbo is in closed beta, we record basic product-usage events (e.g. which features you use, page navigation, and errors you encounter) under your account, to help us improve the Service before general release. This data is stored only in our own database (see section 3) and is never shared with third parties or used for advertising. You can turn this off at any time under “Beta usage data” in your profile settings within the Service. This collection will stop, or be re-disclosed under updated terms, before or at general availability.

6. Data retention and deletion

We retain account and org data for as long as your account is active. If you close your account, we delete your account data within a reasonable period, except where we’re required to retain billing or transaction records for legal or tax purposes, or need to retain limited data to resolve disputes or enforce our agreements.

7. Security

We use appropriate technical and organizational measures to protect your data, including encryption in transit, access controls limiting who can view account and site data, and credential storage designed so that secrets you store with us aren’t exposed to other users.

If we become aware of a personal data breach that’s likely to pose a risk to your rights or freedoms, we’ll notify the relevant supervisory authority within the timeframe required by law, and notify affected users directly where the breach is likely to result in a high risk to them.

8. Children’s privacy

The Service isn’t directed to children, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we’ll delete it.

Our site and the Service may link to third-party websites (for example, GitHub or Paddle). We aren’t responsible for the privacy practices or content of those third-party sites — review their own privacy policies before providing them with personal data.

10. Your rights

If you’re in the UK or EEA, or otherwise entitled to these rights under the law of your country of residence, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data (“right to be forgotten”), subject to our retention obligations in section 6;
  • Restrict or object to certain processing;
  • Port your data to another service in a structured, machine-readable format;
  • Withdraw consent at any time, where processing is based on consent;
  • Complain to your local data protection authority (in Slovenia, the Information Commissioner) if you believe we’ve mishandled your data.

To exercise any of these rights, contact us. We’ll respond within one month, extendable where permitted by law for complex requests.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we’ll notify you by email or through the Service before it takes effect. The “last updated” date at the top of this page reflects the latest version.

12. Contact

Questions about this policy or a data request? Contact us, or write to us at the registered office address in section 1.