FOUNDING BETA · OPEN ENROLLMENT$5.00 USD/month · no uptime SLA · limited email support
SMALL SITE/RW0.IO
ContractLegalDashboard

PRIVACY / BETA

Privacy Policy

We collect the minimum account and operational data needed to authenticate customers, bill subscriptions, publish static sites, prevent abuse, and recover the service.

Effective 2026-08-16 · Applies to the Small Site paid beta at rw0.io.

Information we collect

  • Beta enrollment and account: email address, enrollment or waitlist status, operator-invitation status when applicable, verification status, account state, policy acceptance, session and publishing-token metadata. When you arrive through a campaign link, we retain bounded first-touch source, medium, campaign, and creative labels with the enrollment request so the operator can measure whether that cohort verifies, generates a prompt, validates a ZIP, starts checkout, subscribes, and publishes.
  • Billing: Stripe customer, subscription, Price, status, invoice-event references, and entitlement state. Stripe processes payment-card details; we do not store them.
  • Published material: uploaded static artifacts, manifests, versions, deployment records, malware-scan results, stable site hostnames, and rollback history.
  • Product analytics: the rw0.io landing page sends a small set of first-party events for page views, prompt starts and copies, showcase opens, and signup clicks. The public ZIP checker records only whether a check started, passed, or failed in a broad diagnostic category; it does not retain the ZIP or its manifest. We store one-way hashes of random per-tab or per-form identifiers plus bounded source, medium, campaign, creative, placement, and showcase labels. For signed-in customers, bounded audit events record prompt generation and ZIP validation but never the prompt or uploaded file contents. We do not collect prompt text, email addresses, raw IP addresses, raw user agents, full referrer URLs, or advertising identifiers in anonymous analytics. These anonymous flows do not set analytics cookies. The landing page does not send events when Global Privacy Control or Do Not Track is enabled.
  • Operations and security: request identifiers, timestamps, status codes, bounded audit records, and one-way hashes of IP address and user-agent values. We do not use advertising pixels or third-party behavioral trackers in the beta.
  • Support: messages and attachments you choose to send.

How we use information

We use information to provide authentication, billing, publishing, validation, scanning, isolated serving, rollback, backups, support, security monitoring, fraud and abuse prevention, legal compliance, and service improvement. We do not sell personal information or use customer site content to train a general-purpose AI model.

Service providers

We disclose the minimum required data to infrastructure and service providers acting for us: DigitalOcean for hosting and encrypted backup transport/storage; Stripe for billing and payment communications; SMTP2GO for transactional email; Namecheap and certificate/DNS providers for domain operations; and security or legal providers when required. Customer sites are public by design and are delivered to their visitors.

Legal bases and disclosures

We process data to perform the customer contract, operate and secure the Service, comply with law, and pursue legitimate interests such as preventing abuse. We may preserve or disclose information when reasonably necessary to comply with law, enforce policies, protect rights or safety, investigate fraud or abuse, or complete a business transaction subject to appropriate safeguards.

Security and location

We use HTTPS, scoped credentials, one-time links, tenant checks, malware scanning, immutable content-addressed static releases, encrypted off-host backups, and operational monitoring. No system is perfectly secure. The beta is operated primarily in the United States, and information may be processed there.

Your choices

You may request access, correction, export, or deletion of account information by contacting support@rw0.io. We may need to verify the request and retain limited records for billing, fraud prevention, disputes, security, backups, or law. You can cancel billing in the hosted portal and revoke publishing tokens from Profile settings.

Children

The Service is for adults and organizations and is not directed to children under 13. Do not use the Service to collect children’s personal information.

Retention and changes

Raw anonymous landing analytics events are deleted after 90 days. Pending or declined beta requests are eligible for deletion after 90 days; converted-request attribution follows the associated account retention period. The separate Data Retention Policy states current account, operational, and backup periods. We may update this Privacy Policy and will communicate material changes affecting active paid customers when reasonably practicable.

Contact

Privacy requests: support@rw0.io. Security reports: security@rw0.io.

rw0.io · Static sites only · Immutable releases · No customer code runs on our servers

TermsPrivacyAcceptable useCancellation & refundsData retentionSupport