GOVERNANCE & TRUST
Privacy Policy
Current published version. For executed terms or procurement review, contact legal@costframe.co. See the legal and trust directory.
1. Introduction
Slingo Marbella SL, operating the Costframe product (“Costframe”, “we”, “us”, or “our”), respects your privacy. This policy describes how we collect, use, and handle data when you use our website, services, and cloud cost analysis platform.
Costframe provides read-only cloud cost analysis and related reporting for cloud environments such as AWS, Azure, and Google Cloud. Our system acts as an analysis engine, helping organizations safely monitor, understand, and reduce cloud infrastructure spending.
2. Data We Collect & Connect
We collect professional contact information, workspace information, subscription and billing records, usage analytics, and billing/utilization metadata from cloud environments you connect:
- Account Data: Standard identification fields including name, email address, organization name, roles, session identifiers, and account portal activity.
- Read-Only Cloud Metadata: Provider account, subscription, project, tenant, resource, pricing SKU, tag, billing, invoice, and utilization metadata needed to produce findings.
- Payment Data: Plan, invoice, subscription status, and customer billing metadata processed through Stripe. Costframe does not store full card numbers.
- Website and Product Analytics: Limited event, performance, and page-view data from tools such as PostHog, Vercel Analytics, Google Analytics, and Ahrefs Analytics where configured.
3. Structural Read-Only Boundary
Costframe connects to your cloud providers with strictly read-only authorization, such as Azure Reader and Cost Management Reader, AWS read-only IAM roles, or GCP read-only billing/resource access.
We do not seek, request, or use write, delete, or management permissions. Costframe never modifies, writes, deletes, or manages your underlying cloud resources, workloads, or deployments.
4. How We Handle & Share Data
We use collected metadata to authenticate users, operate workspaces, generate cloud cost optimization recommendations, process subscriptions, render technical cost reports, provide support, improve product reliability, and maintain platform health.
Costframe does not sell customer data. We do not sell or monetize personal or organization-specific details to third-party advertisers. We share data only with authorized subprocessors, service providers, professional advisers, or authorities where required to operate the service or comply with law.
5. AI-Assisted Processing
Costframe may use configured AI services to generate explanations or summaries from Costframe findings and evidence. AI output is advisory, may be incomplete, and must not be treated as an instruction to change cloud resources. Where AI is enabled, we limit the context sent to the information needed for the requested feature and use subprocessors under applicable data-processing terms.
Costframe does not grant an AI model write authority over customer cloud resources. Customers remain responsible for reviewing recommendations and for every remediation decision made through their own change process.
6. International Processing & Subprocessors
Costframe uses subprocessors to provide hosting, database, authentication, billing, email, analytics, observability, and infrastructure services. We choose EU regions where available and appropriate, but some vendors and their subprocessors may process data in the United States or other locations under their data-processing terms and transfer safeguards.
Our current subprocessor list is published at /subprocessors.
7. Credential Security & Encryption
Your cloud credentials and secrets are encrypted using industry-standard AES-256-GCM encryption and are not shown back in the dashboard after setup.
Data isolation is structurally enforced. Database queries partition data by verified Clerk organization identifiers to ensure strict tenant isolation, with row-level security (RLS) policies acting as a database-level safeguard.
8. Retention & Rights
We retain account, workspace, billing, audit, and security records for as long as needed to provide the service, comply with legal obligations, resolve disputes, and maintain audit integrity. Customers may request access, correction, export, or deletion of personal data where applicable law provides those rights.
9. Policy Updates
Costframe may update this policy from time to time. Any changes will be posted directly to this page with an updated effective date.
Contact Us
For privacy, security, DPA, or data-processing questions, contact us at legal@costframe.co.