Scope and who is responsible
Rallid is operated by Standard Magic in Portland, Maine. This policy applies when you visit rallid.com, use the Rallid portal, communicate with us, join a waitlist, or receive BlackRail or KingRail managed services.
A customer may separately control personal information placed in a hosted site or application. In that situation, the customer determines why that information is processed and Rallid acts as a service provider on its instructions.
Information we collect
- Account and company information: name, email address, company, role, team membership, and communication preferences.
- Passkey information: public credential identifiers, device labels, and security events. Rallid does not receive your biometric data and does not use account passwords.
- Billing information: plan, order, invoice, tax, transaction status, and limited payment metadata supplied by our payment providers. We do not store complete payment card numbers.
- Service information: domains, site configuration, deployment and backup records, integrations, project files, support requests, and instructions you provide.
- Technical information: IP address, browser and device details, timestamps, security logs, feature use, referring pages, and diagnostic events.
- Communications: contact forms, support conversations, estimates, account invitations, waitlist answers, and newsletter preferences.
Where information comes from
We receive information directly from you, from teammates or clients who invite you, from systems and sites you ask us to manage, from service providers involved in a transaction, and automatically when you use our website or portal.
How we use information
We use personal information to provide and secure accounts and services; process orders and billing; operate, monitor, back up, and improve managed systems; respond to support and project requests; communicate service and security notices; maintain records; detect abuse; comply with law; and send marketing you requested.
Depending on the context, processing is based on performing a contract, taking steps you request before a contract, our legitimate interests in operating and protecting the service, your consent, or a legal obligation.
How information is shared
We share information only as reasonably needed with infrastructure, security, payment, accounting, email, analytics, and support providers; with integrations you direct us to connect; with professional advisers; during a business reorganization; or when required to protect rights, safety, systems, or legal obligations.
Service providers may use information only for the contracted purpose and under appropriate confidentiality and security obligations. Rallid does not sell personal information and does not use it for cross context behavioral advertising.
Payments through Paddle
Online subscription purchases may be processed by Paddle as our reseller and merchant of record. Paddle independently processes payment, transaction tax, fraud prevention, and buyer support information under its privacy notice. Rallid receives the transaction and customer details needed to provide the purchased service.
Cookies and similar technology
Rallid uses essential cookies and local storage for sessions, passkey flows, security, preferences, and core portal functions. We may use limited first party analytics to understand performance and feature use. We do not use advertising cookies or sell activity for targeted advertising.
Retention
We retain information for as long as needed to provide the service, maintain business and tax records, resolve disputes, enforce agreements, protect systems, and meet legal obligations. Waitlist and marketing records remain until you unsubscribe or ask us to delete them, subject to suppression records needed to honor that choice.
Operational backups age out on their normal schedule. Some information may be preserved longer for a legal hold, fraud prevention, or an unresolved claim.
Security and passkeys
We use administrative, technical, and physical safeguards appropriate to the information and service, including role based access, encryption where appropriate, logging, backups, and passkey based authentication. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
International processing
Rallid and its providers may process information in the United States and other countries. Where required, we use contractual or other lawful safeguards for transfers across borders.
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent. You may unsubscribe from marketing at any time without affecting service messages.
Submit a request through the contact page or email hello@rallid.com. We may verify identity and may retain information where law or a legitimate operational need permits. You may also appeal a denied request or contact your local privacy authority where applicable.
Children
Rallid services are intended for organizations and adults. They are not directed to children under 13, and we do not knowingly collect personal information from a child under 13.
Changes and contact
We may update this policy as our practices or law changes. We will post the new effective date and provide additional notice where required.
Privacy questions and requests may be sent through the contact page or to hello@rallid.com.