Privacy and data protection

Privacy notice

This notice explains how Adam Hjort Consulting AB processes personal data when you visit stackferry, create an account, connect a repository, purchase a service or contact us.

Effective 15 July 2026 · version 2026-07-15

1. Controller and contact

Adam Hjort Consulting AB, Swedish organisation number 559396-6749 and VAT number SE559396674901, is the controller for stackferry account, commercial, support and website data. Our address is c/o Hellman Treschow, Vanadisvägen 21, 113 46 Stockholm, Sweden.

Questions and data-subject requests can be sent to adam@sprow.co. Please do not send passwords, private keys, payment-card data or production database exports by email.

2. Scope and roles

This notice applies to stackferry.dev, the private stackferry application and related support and commercial communications. It does not govern a destination provider, GitHub, Stripe or another third-party service when that provider determines its own processing purposes.

For ordinary account and order administration, Adam Hjort Consulting AB is controller. If a separately signed order requires stackferry to process personal data contained in a customer system solely on the customer's instructions, the parties will document the applicable controller and processor roles before that processing begins. A standard port does not include production rows, authentication identities or stored customer files.

3. Data we process

Account data can include name, business email, authentication identifiers, company name, profile information, acceptance records and managed support correspondence. Project data can include repository URL, source platform, chosen providers, project description, audience, workflow state and derived compatibility findings. Destination requests can include a provider name, public product URL, requested category, business or technical rationale and review status.

GitHub connection data can include the account login, installation identifier, repository selection and metadata for repositories you select. Destination-provider connection data can include a stable provider account identifier, account email and name, account creation time, selected workspace metadata, granted scopes, connection status and last verification time. Provider access and refresh tokens are encrypted server-side and are not stored in browser code or ordinary project records. Payment and order data can include Stripe customer and Checkout identifiers, business name, billing country, VAT or tax identifier, amounts, currency, payment status and invoice identifiers. We do not receive or store full payment-card numbers.

Technical and operational event data can include IP address, browser and device information, timestamps, signup method, GitHub connection state, project creation, destination requests, porting and payment milestones, support status, notification-delivery state, security events and essential session identifiers. stackferry is not intended for special-category personal data, payment credentials, provider secrets or production customer datasets.

4. Sources of data

We receive data from you, your authorised workspace users, GitHub when you sign in or install the read-only stackferry GitHub App, a destination provider such as Railway when you authorise an account connection, Stripe when you complete or attempt a payment, and our hosting and security providers when they generate operational logs.

You must have authority to provide project and repository information and must not submit personal data that stackferry does not need for the agreed purpose.

5. Purposes and legal bases

We process account, project, repository and order data to create and administer your workspace, assess portability, provide requested services, manage payments and communicate about an order. The legal basis is performance of a contract or steps requested before entering a contract.

We process limited first-party operational events, fraud-prevention, support and product-security data for our legitimate interests in operating, protecting, measuring and improving stackferry. Operator notifications can be sent when an account is created or a material workflow event occurs. We balance those interests against the rights and expectations of affected individuals.

We process invoices, transaction evidence and related business records to comply with Swedish accounting, tax and legal obligations. We use consent where consent is legally required, including for non-essential marketing or tracking. You can withdraw consent without affecting earlier lawful processing.

6. Repository access

Public repositories can be inspected from their URL. Private repositories require installation of the stackferry GitHub App with read-only Metadata and Contents permissions for the repositories you select. stackferry mints short-lived installation tokens server-side and does not store repository credentials in project records or browser code.

The current inventory reads repository metadata, a recursive path and object inventory, language totals and a bounded set of package manifests to derive framework and infrastructure signals. It does not execute repository code. stackferry stores the repository URL and derived project findings; it does not store a copy of the repository source tree. You can remove the GitHub App installation in GitHub and delete the connection from your stackferry account.

7. Payments

Payments are processed on Stripe-hosted Checkout. Stripe collects payment details, billing address and, where supported, business tax identifiers. stackferry receives order and payment status but not full card data. Stripe may act as our processor for some activities and as an independent controller for activities it determines, including regulatory and fraud-prevention obligations.

Checkout requires acceptance of the current stackferry Terms of Service. Stripe receipts and invoices are generated using the business and tax information entered at Checkout.

8. Service providers and international transfers

We use Netlify for web hosting and content delivery, Supabase for authentication, database and server functions, GitHub for account login and repository access, Railway or another selected destination provider for authorised account verification and provisioning, Stripe for payments, invoicing and tax-related checkout features, Amazon Web Services Simple Email Service (SES) for transactional authentication and operator notification email, and Google Ads for consent-based advertising measurement. These providers process data under their own security, privacy and contractual frameworks.

A provider may process data outside Sweden or the EEA. Where the GDPR requires a transfer mechanism, we rely on an adequacy decision, approved contractual safeguards such as the European Commission's Standard Contractual Clauses, or another lawful mechanism made available by the provider.

9. Retention

Active account, project, destination-request and authorised provider-connection records are retained while the workspace is used. Following a verified deletion request, provider disconnection or account closure, ordinary account, project, destination-request, GitHub connection, destination-provider connection and workflow data is deleted from active systems within 30 days, subject to security, dispute and legal-retention exceptions. Residual encrypted backups may persist for up to 90 days before rotation.

Repository content fetched for inventory is processed transiently and is not retained as a source-tree copy. Support correspondence is normally retained for up to 24 months. Security and access logs are normally retained for up to 12 months unless an incident requires longer preservation.

Invoices, payment evidence and accounting material are retained for at least seven years as required by Swedish bookkeeping and tax rules. Data needed to establish, exercise or defend legal claims can be retained for the applicable limitation period.

10. Cookies and local storage

stackferry uses local storage necessary for authentication, security and core application state. When a campaign parameter or Google click identifier is present, stackferry also retains a first-party attribution record for up to 90 days and connects it to an account only after sign-in. This lets the operator measure the route from campaign to repository scan and paid port without building a cross-site behavioural profile.

The Google tag loads with advertising storage, advertising user-data, advertising personalisation and analytics storage denied by default. Before consent it does not write advertising or analytics cookies. If you choose Allow measurement, stackferry grants advertising storage, advertising user-data and analytics storage while advertising personalisation remains disabled. If you decline, storage remains denied and stackferry does not upload attributed purchase conversions to Google. You can change the choice at any time through the Privacy choices control. GitHub and Stripe may set their own cookies when you visit their domains for authentication or payment.

11. Security and data integrity

We use access controls, Supabase row-level security, server-side secret storage, encryption for retained destination-provider OAuth tokens, read-only repository permissions, TLS, signed Stripe webhooks, least-privilege service integrations and separation between public browser keys and administrative credentials. Payment-card data remains with Stripe.

No online service can guarantee absolute security. Customers must keep credentials out of project fields, restrict repository access, review destination accounts and promptly report suspected misuse to adam@sprow.co. More detail is available on the Security & data integrity page.

12. Your rights

Subject to the GDPR and applicable exceptions, you can request access, rectification, erasure, restriction, portability and information about our processing. You can object to processing based on legitimate interests and always object to direct marketing. Where processing relies on consent, you can withdraw it.

Use the account settings for available export and deletion controls or email adam@sprow.co. We may need to verify your identity and authority before acting. We normally respond within one month. You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.

13. Automated decisions, children and changes

Compatibility scores and provider comparisons support human decisions; stackferry does not make solely automated decisions that produce legal or similarly significant effects. stackferry is a business service and is not directed to children.

We may update this notice when the service, providers or law changes. Material changes will be communicated in the application or by email when appropriate. The effective date and version identify the notice that applies.