Turbo
Decap Turbo — Privacy Policy
Last updated: 2026-08-13.
1. Who we are
Decap Turbo is operated by PM, poslovni mediji d.o.o., a company registered in Slovenia (registration number 2146215000, VAT ID SI27901181), with its registered office at Igriška ulica 5, 1000 Ljubljana, Slovenia (“we”, “us”, “our”). We are the controller for the personal data we collect about users of Decap Turbo, as described in this policy. For privacy questions or data requests, contact us — see section 12.
2. What we collect and why
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Email address, name | Creating and securing your account | Performance of a contract |
| Organization & role data | Org/site metadata, membership and role assignments | Running multi-user orgs and access control | Performance of a contract |
| Git hosting credentials | GitHub/GitLab access tokens (proxied, not shown to other users) | Operating the Git hosting API request proxy | Performance of a contract |
| Site configuration | Site variables you choose to store with us | Providing site variable storage | Performance of a contract |
| Support communications | Messages sent via our contact form | Responding to inquiries and support requests | Legitimate interest (providing support) |
| Security/technical logs | IP address, request logs, device/browser identifiers | Fraud prevention, abuse detection, and keeping the Service secure | Legitimate interest (security) and legal obligation, where applicable |
| Beta usage data (closed beta only) | Feature usage events (e.g. pages visited, actions taken, errors encountered), tied to your account | Understanding how beta testers use the Service, so we can improve it before general availability | Legitimate interest (product improvement during closed beta) |
We do not collect payment card details ourselves — see section 3.
3. Sub-processors and recipients
We share data with the following categories of recipients:
- Service providers / sub-processors — Supabase for authentication and data storage. Supabase processes data on our behalf under its own security and privacy terms.
- Merchant of record — Paddle, for the sale of Decap Turbo subscriptions, payment collection, subscription management, tax compliance, and invoicing. Paddle acts as an independent controller of your payment and billing data under its own privacy policy — see also our Terms of Service.
- Professional advisers — lawyers, accountants, or auditors, where necessary.
- Authorities — where required by law, or to protect our rights, safety, or property, or that of our users.
We don’t sell your personal data, and we don’t use third-party advertising or tracking services. During the closed beta, we collect basic product-usage data ourselves, stored only in our own Supabase database — never sent to a third-party analytics provider — to understand how the Service is used; see the table in section 2 and how to opt out in section 5.
4. International transfers
We and our sub-processors may process personal data outside the EU/EEA and UK — for example, on infrastructure operated by Supabase or Paddle in other jurisdictions. Where this happens, we rely on appropriate safeguards recognized under EU/UK data protection law, such as Standard Contractual Clauses or an applicable adequacy decision, to ensure your data receives an equivalent level of protection.
5. Cookies
We use a session cookie to keep you signed in, and an active_org_id cookie to remember which organization you’re currently working in. Both are strictly necessary for the Service to function and are set without requiring consent. We don’t use analytics, advertising, or third-party tracking cookies.
Beta usage data. While Decap Turbo is in closed beta, we record basic product-usage events (e.g. which features you use, page navigation, and errors you encounter) under your account, to help us improve the Service before general release. This data is stored only in our own database (see section 3) and is never shared with third parties or used for advertising. You can turn this off at any time under “Beta usage data” in your profile settings within the Service. This collection will stop, or be re-disclosed under updated terms, before or at general availability.
6. Data retention and deletion
We retain account and org data for as long as your account is active. If you close your account, we delete your account data within a reasonable period, except where we’re required to retain billing or transaction records for legal or tax purposes, or need to retain limited data to resolve disputes or enforce our agreements.
7. Security
We use appropriate technical and organizational measures to protect your data, including encryption in transit, access controls limiting who can view account and site data, and credential storage designed so that secrets you store with us aren’t exposed to other users.
If we become aware of a personal data breach that’s likely to pose a risk to your rights or freedoms, we’ll notify the relevant supervisory authority within the timeframe required by law, and notify affected users directly where the breach is likely to result in a high risk to them.
8. Children’s privacy
The Service isn’t directed to children, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we’ll delete it.
9. Third-party links
Our site and the Service may link to third-party websites (for example, GitHub or Paddle). We aren’t responsible for the privacy practices or content of those third-party sites — review their own privacy policies before providing them with personal data.
10. Your rights
If you’re in the UK or EEA, or otherwise entitled to these rights under the law of your country of residence, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”), subject to our retention obligations in section 6;
- Restrict or object to certain processing;
- Port your data to another service in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent;
- Complain to your local data protection authority (in Slovenia, the Information Commissioner) if you believe we’ve mishandled your data.
To exercise any of these rights, contact us. We’ll respond within one month, extendable where permitted by law for complex requests.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we’ll notify you by email or through the Service before it takes effect. The “last updated” date at the top of this page reflects the latest version.
12. Contact
Questions about this policy or a data request? Contact us, or write to us at the registered office address in section 1.