BoostRail Privacy Policy (Draft)
*Draft revised 2026-08-16 (originally prepared 2026-07-15) for legal review. Controller: Boostly Limited, New Zealand.*
1. What we collect
- Account data: email address, display name, password hash, language preference, and optional phone number.
- Billing data: order and payment records, billing address, invoice header details, and tax IDs where provided. Card details are processed by Stripe and never touch our servers. For bank-transfer top-ups we collect the declaration details — payer or account name, transfer amount, and bank reference — to match the transfer against the bank statement.
- Usage data: per-request metadata — timestamps, model names, token counts, unit prices, and API key identifiers — retained for billing and reconciliation.
- Request content: prompts and responses are transmitted to the selected model provider to serve the request. We do not use request content to train models. Transient logs used for reliability are retained for a limited period.
- Customer-provided provider keys (BYOK): provider API keys you choose to store are encrypted at rest (AES-256-GCM); interfaces and logs only ever show the last four characters. They are used solely to route your own organization's requests to the corresponding provider, and can be deleted at any time in the console, effective immediately. Key changes and usage are recorded in an audit log.
- Attribution data: if you arrive at our website from an ad or an external link, a first-party cookie (
br_attr, 90 days) stores the campaign parameters (such as UTM tags or an ad click ID) and the referring page. If you later sign up, this is linked to your account so we know which channel brought you. It is not used to build a behavioral profile.
2. How we use data
To provide and bill the service, to secure it (abuse and fraud prevention), to meet tax and accounting obligations, and to communicate service notices such as balance alerts and payment confirmations. We may also send occasional product usage and onboarding guidance emails to help you get started with the service; each such email includes an unsubscribe link, and opting out does not affect service notices. We do not sell personal data.
Where the GDPR applies, our legal bases are: performance of the contract (providing and billing the service), legal obligation (tax and accounting records), legitimate interests (securing the service, preventing abuse, and measuring which marketing channels work), and consent where the law requires it (advertising cookies).
3. Cookies and advertising
The console uses cookies necessary for sign-in and session security. The marketing website sets the br_attr attribution cookie described above and loads a Google advertising tag (Google Ads), which helps us show BoostRail ads to previous visitors of our website on Google services (remarketing). The Google tag may set cookies or use identifiers governed by Google's privacy policy; you can opt out of personalized ads at adssettings.google.com. For visitors in the EU/EEA, the United Kingdom, and Switzerland, the advertising tag is not loaded and the attribution cookie is not set. We do not run any other third-party analytics or tracking scripts.
4. Processors and transfers
We use service providers to operate the platform, including Stripe (payments and tax calculation), banking partners (receiving bank-transfer top-ups), an email delivery provider (transactional email), and hosting providers. Where personal data is transferred across borders, we rely on safeguards recognized under applicable law; our payment, email, and hosting processors offer data processing terms incorporating standard contractual clauses where required. Model requests are transmitted, at your direction, to the provider that serves the selected model, which may be located outside your country. Under BYOK, requests to a provider are served through your own account with that provider, under your own agreement with them.
5. Retention
Account data is retained while the account is active. Billing and tax records are retained as required by law. Usage metadata is retained for billing accuracy and dispute resolution. Deleted BYOK keys are removed from active use immediately; audit records of key changes are retained.
6. Security
Data is encrypted in transit (TLS), and sensitive stored data — such as customer-provided provider keys — is encrypted at rest. Access to production data is restricted and audited. If a data breach is likely to cause serious harm, we will notify affected users and the relevant authorities as required by applicable law, including the New Zealand Privacy Act 2020 and, where it applies, the GDPR.
7. Your rights
You can access and update account data in the console, export usage data, and request account deletion via support (subject to legally required retention of billing records). Depending on your location, additional statutory rights may apply, including rights under the New Zealand Privacy Act 2020 and, where applicable, the GDPR. You can also lodge a complaint with your local data protection authority — in New Zealand, the Office of the Privacy Commissioner.
8. Children
The service is not directed at children, and an account requires you to be at least 18 years old. We do not knowingly collect children's personal data.
9. Contact
Privacy enquiries: support@boostrail.com — Boostly Limited, New Zealand.