Privacy Policy

Last updated: July 13, 2026

Summary

PropETL processes client Excel and CSV files in server memory and wipes them immediately after the ETL file is generated. Nothing is written to disk, stored in a database, or sent to any third party. The service is EU-hosted, GDPR-compliant, and a Data Processing Agreement is available on request.

1. What We Process

Account information. Email address, license key, purchase source (Gumroad, Stripe, or free trial), and license validity window. Stored in our Supabase (PostgreSQL) knowledge-base database on EU infrastructure.

Client files. The Excel/CSV files you upload for mapping. These are held in per-session heap memory (never written to disk or database) and explicitly wiped after the ETL file is generated. Session state also dies with the MCP session.

Telemetry. Metadata-only usage events: tool name, timestamp, license-key hash, request outcome (success/error), token counts for AI-assisted features, and non-sensitive parameters (module name, row count). We never log file contents, column values, or personally identifiable data from your files.

2. What We Do Not Process

  • We do not store client file contents at rest — ever.
  • We do not send client data to third-party AI providers unless you are running PROPETL through your own Claude connector, in which case Claude receives the parts of the file you explicitly show it.
  • We do not sell, rent, or share your data with advertisers or data brokers.

3. Hosting & Infrastructure

The MCP server runs on Railway in an EU region. The Supabase database sits in an EU region. The marketing site and customer portal are hosted on Vercel with EU edge routing. No client data crosses the Atlantic in the ordinary course of processing.

4. Cookies & Analytics

The website uses two analytics tools:

  • Vercel Analytics — cookieless page-view and Web Vitals collection. No cross-site tracking.
  • Google Analytics (gtag.js) — anonymized page views for marketing attribution. IP anonymization enabled.

No advertising cookies. No third-party tracking pixels. The customer portal uses a first-party session cookie for authentication only.

5. Retention

  • Client files: memory only, wiped at the end of the session — typically seconds to minutes.
  • Account records: retained for the lifetime of your license, plus 12 months for tax and audit purposes.
  • Telemetry: aggregated retained indefinitely; per-event rows retained 12 months.
  • Support email: retained 24 months, then deleted.

6. Your Rights (GDPR)

If you are in the EU/EEA/UK you have the right to access, correct, export, or delete your personal data, to restrict or object to processing, and to lodge a complaint with a supervisory authority. Email support@propetl.com and we will action requests within 30 days.

7. Data Processing Agreement

A Data Processing Agreement (DPA) is available on request for enterprise procurement. Email support@propetl.com — typically returned within 1 business day.

8. Security

  • All traffic over TLS 1.2+.
  • OAuth 2.1 + PKCE (S256) for MCP session authentication; license validation on every session start.
  • Least-privilege database access via Supabase service roles; no direct customer access to the knowledge-base DB.
  • Session tokens and license keys are hashed before persistence where hashing is applicable.

9. Changes to This Policy

We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be surfaced on the website.

10. Contact

Privacy questions or requests: support@propetl.com.