Pipeshift — Privacy Policy
Version 1.0 · Effective date: August 14, 2026 · Last updated: August 14, 2026
This Privacy Policy explains how Infercloud, Inc., a Delaware corporation doing business as Pipeshift (“Pipeshift“, “we“, “us“ or “our“), collects, uses, discloses and protects personal data.
1. Our privacy commitments
Before the detail, the five commitments that matter most for a generative AI inference platform:
We do not train on your data. We do not use customer prompts, inputs, outputs, code, model weights or datasets — in identifiable, pseudonymised, de-identified, anonymised, aggregated or any other form — to train, fine-tune, retrain, evaluate, benchmark or otherwise develop or improve any machine learning or artificial intelligence model, whether for our own benefit or for any third party. This is a contractual commitment in our Terms of Service and our Data Processing Addendum, and it is not subject to an opt-out.
We do not sell or share your personal data for cross-context behavioural advertising.
Customer content belongs to the customer. We process it only to run the service the customer asked us to run.
We publish who we use. Our sub-processors are listed in Section 8 and in Schedule 1 to our Data Processing Addendum.
We do not re-identify de-identified data. Where we hold data in de-identified form, we process it solely in de-identified form and we do not attempt to re-identify it.
2. Scope and our role
This policy covers personal data we handle as a controller — that is, where we decide why and how it is processed. That includes:
visitors to our website;
prospects who contact us or book a call;
individuals who administer a customer account (name, work email, credentials);
support enquiries submitted by customers’ users;
operational and usage telemetry generated by the platform.
Customer content is handled differently. When a customer runs inference on Pipeshift, any personal data contained in their prompts, inputs, embeddings or outputs is processed by us as a processor on that customer’s instructions. The customer is the controller and their own privacy notice governs their end users’ rights. Our obligations for that data are set by our Terms of Service (https://pipeshift.com/terms-and-conditions) and our Data Processing Addendum (https://pipeshift.com/dpa), which applies to every customer. Sections 6, 9 and 12 below describe how we handle customer content, for transparency.
If you are an end user of a product built on Pipeshift and want to exercise rights over your data, please contact the company operating that product. We will refer such requests to the relevant customer.
3. Personal data we collect
You give us:
Data
Context
Name, job title, business email, phone number, company
Contact forms, demo bookings, sales correspondence, support requests
Account credentials and authentication identifiers
Account creation and sign-in
API key identifiers (never the secret value)
Account and access management
Billing contact and payment details
Paid accounts, processed by our payment processor
Correspondence content
Email, support tickets, shared channels
We collect automatically:
Data
Context
IP address, browser and device type, operating system, referring URL
Website visits
Pages viewed, actions taken, session activity
Product analytics
Request timestamps, endpoints accessed, HTTP status codes, token counts, latency and performance telemetry
Operating and metering the platform
Authentication and administrative access logs
Security monitoring
We receive from others: identity information from single sign-on providers where you sign in that way; billing status from our payment processor; and business contact information from a customer that has authorised you to use its account.
Account credentials and billing details are needed to open and operate an account; without them we cannot provide the Services. We do not intentionally collect special categories of personal data (such as health, biometric or political data) in our capacity as a controller. Customers must not submit special category data, or any of the other prohibited categories listed in Section 5.1(b) of our Terms of Service, through the Services except where expressly agreed in writing.
4. How and why we use personal data
Purpose
Legal basis (GDPR / UK GDPR)
Provide, operate, maintain and secure the Services and our website
Performance of a contract; legitimate interests
Understand how our website and dashboard are used, through analytics and, where enabled, session replay
Legitimate interests; consent, where required by law for non-essential cookies
Authenticate users and manage access
Performance of a contract
Meter usage, invoice and collect payment
Performance of a contract; legal obligation
Provide support and respond to enquiries
Performance of a contract; legitimate interests
Monitor for abuse, fraud and security incidents
Legitimate interests; legal obligation
Analyse and improve the performance, reliability, capacity and functionality of the Services, and develop new products and services
Legitimate interests
Send service and security notices
Performance of a contract; legal obligation
Send marketing communications about Pipeshift
Consent, or legitimate interests where permitted
Comply with law and enforce our terms
Legal obligation; legitimate interests
Where we rely on legitimate interests, we have assessed that our interest in operating a secure, reliable and commercially viable platform is not overridden by your rights. You may object — see Section 11. Where our Data Processing Addendum restricts our use of a customer’s administration data — which includes support enquiries from its users — that restriction applies, and we do not use that data for marketing.
We use operational and usage telemetry — request volumes, token counts, latency, error rates and similar metrics — to operate, secure, meter and improve the platform, including capacity planning and product development. This telemetry does not include prompts, inputs, outputs or customer code, and the no-training commitment in Section 1 applies in full to those.
5. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
6. Customer content, prompts and outputs
Prompts, inputs, embeddings and outputs submitted to the Services, and any code, model weights or datasets a customer deploys on them, are processed on the instructing customer’s behalf, for the purpose of returning an inference result and operating the deployment. They are:
not used to train, fine-tune, retrain, evaluate, benchmark or otherwise develop or improve any model, as set out in Section 1;
not disclosed to other customers;
not logged or written to persistent storage by default — request and response content logging is off on both serverless and dedicated deployments, and is enabled only where a customer explicitly asks for it;
retained, where a customer enables logging, for the period agreed with that customer, and otherwise only as described in Section 9 and in our Data Processing Addendum.
De-identified data. Where we de-identify data, we publicly commit to process it solely in de-identified form, to make no attempt to re-identify it, and to contractually require the same of any recipient. We do not use de-identified, anonymised or aggregated data derived from customer content to train or improve any model — the commitment in Section 1 applies to derived data in every form.
Processing may take place in any location where we or our sub-processors maintain facilities, as listed in Section 8. Customers with data residency requirements should raise them with us before onboarding so that any commitment can be recorded in their agreement.
7. Cookies and similar technologies
We use cookies and similar technologies on our website to keep it working, remember preferences, and understand how it is used. Categories:
Strictly necessary — sign-in, session integrity, security. These cannot be disabled.
Functional — remembering preferences.
Analytics — understanding how the Pipeshift dashboard is used, including product analytics and, where enabled, session replay of interactions with the dashboard. These are used to understand how customers navigate and use product features. They are not used for advertising, and we do not run advertising or retargeting trackers.
We do not use cookies for cross-context behavioural advertising.
You can control cookies through your browser settings; blocking some may affect site functionality. Where required by law, we present a consent mechanism and set non-essential cookies only after consent. We respond to Global Privacy Control signals where required.
8. Who we share personal data with
We share personal data only as described here. We do not sell it.
Service providers and sub-processors. We engage the following, and we require each to be bound by written data protection terms no less protective than our own commitments before it processes customer content. Some are listed for transparency rather than because they process customer inference data — the purpose column states what each one handles:
Provider
Purpose
Processing location
Amazon Web Services
Cloud hosting, compute and storage
India, EU, US
Cloudflare
CDN, DNS, network security and DDoS protection
Global edge
ClickHouse Cloud
Operational and usage telemetry datastore
EU, India, US
Tailscale
Zero-trust administrative network access (connection and identity metadata only)
Canada (control plane)
Stripe
Payment processing and billing
US
Google Workspace
Business email, document storage, support communications
US
Slack
Support and internal communications
US
Microsoft Teams
Support communications
US
Linear
Issue and project tracking
US
Resend
Transactional email (invitations, magic-link sign-in)
US
PostHog
Product analytics
US
GPU infrastructure providers. Inference workloads run on infrastructure operated by: Denvr Dataworks (US), Neysa Networks (India), E2E Networks (India), Massed Compute (US), NexGen Cloud / Hyperstack (US, Canada), Nebius (EU, US), Verda Cloud (EEA — Finland, Iceland), Crusoe Energy Systems (US, EEA — Iceland) and Ubicloud (US, EU). We additionally procure GPU capacity on certain of these providers through the Shadeform marketplace (US), which acts as a provisioning layer rather than a location where inference runs.
Others. We may also disclose personal data to professional advisers; to authorities where required by law or to establish or defend legal claims; and to a counterparty in connection with a merger, acquisition or sale of assets, subject to this policy continuing to apply.
The table and the infrastructure providers listed above together form our published sub-processor list; the same list appears as Schedule 1 to our Data Processing Addendum. We give customers at least fourteen (14) days’ notice before adding or replacing a sub-processor, with a ten (10) day objection window; where an objection cannot be resolved, a customer may terminate the affected services as set out in the Data Processing Addendum. We do not maintain a separate sub-processor page, so the table above is our published list. Notice of changes is given by email to the account’s administrative contact; if we later publish a dedicated sub-processor page or trust centre, we will tell customers before relying on it as the notice channel.
9. Retention
We keep personal data only as long as necessary for the purposes in Section 4:
Data
Retention
Account and administrative data
For the life of the account, then as required for legal, tax and audit purposes
Customer content processed as processor
Per the customer’s configuration and our Data Processing Addendum; deleted on request, or at the end of the 30-day retention period following termination. Deletion covers backup copies. We keep only copies we are required to retain by law
Website and dashboard analytics data
For as long as needed to understand usage trends, then deleted or reduced to aggregate statistics
Support and sales correspondence
For the duration of our relationship with you or your organisation, then as required for legal and audit purposes
Request and response content (prompts, model outputs)
Not logged or retained by default. Where a customer enables logging, the terms of their agreement apply
Performance and timing logs
1 year
Node-level operational metrics
30 days
Security and access logs
For as long as needed for security monitoring and incident investigation, then deleted
Billing records
As required by tax and accounting law
Marketing contact data
Until you opt out or the data goes stale
Some customers agree stricter or deployment-specific retention terms with us; where those apply, they govern for that customer’s data.
10. International transfers
We operate across the United States, the European Union and EEA, the United Kingdom, India, Canada and other regions where our infrastructure providers operate. Personal data may therefore be transferred outside the country in which it was collected.
For personal data we hold as a controller (the data this policy covers), where we transfer it out of the EEA, the UK or Switzerland to a country without an adequacy decision, we put in place the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) with the relevant recipient, together with the UK International Data Transfer Addendum and a Swiss addendum where applicable, and we apply supplementary measures including encryption in transit and at rest.
For customer content we process on a customer’s behalf, the transfer mechanism is set out in our Data Processing Addendum, which incorporates Module Two (controller to processor) of the Standard Contractual Clauses, the UK International Data Transfer Addendum (template version B.1.0) and a Swiss addendum. India’s Digital Personal Data Protection Act 2023 permits transfer of personal data outside India except to countries restricted by government notification; our Data Processing Addendum is the contract under which we act as a customer’s data processor, as that Act requires. Sector-specific localisation requirements — such as those imposed by the Reserve Bank of India — remain the customer’s responsibility to assess.
You may request a copy of the relevant transfer mechanism at [email protected].
11. Your rights
Subject to local law, you may have the right to: access your personal data; correct inaccurate data; delete data; restrict or object to processing, including profiling and direct marketing; receive your data in a portable format; and withdraw consent at any time without affecting prior processing.
EEA / UK / Switzerland. You may exercise the rights above and lodge a complaint with your local supervisory authority. Where personal data is transferred under our Standard Contractual Clauses, the competent supervisory authority is determined in accordance with Clause 13 of those Clauses — in general, the authority of the EU member state in which the data exporter is established; where the exporter is not established in the EU but has appointed an Article 27 representative, the authority of the member state in which that representative is established; and otherwise the authority of a member state in which the relevant data subjects are located. We ask that you contact us first so we can try to resolve the issue.
India. Under the Digital Personal Data Protection Act 2023 you may access, correct, update and erase your personal data, nominate another individual to exercise your rights in the event of death or incapacity, and access our grievance redressal process at [email protected].
California. Under the CCPA/CPRA you may request to know, delete and correct personal information, and may limit the use of sensitive personal information. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not sold or shared personal information in the preceding twelve months. We do not knowingly collect or sell the personal information of consumers under 16. You may use an authorised agent, and we will not discriminate against you for exercising these rights. The categories we collect, our purposes and the recipients are set out in Sections 3, 4 and 8. In the preceding twelve months those categories have been: identifiers; commercial information; internet or other electronic network activity information; and professional or employment-related information. We do not collect sensitive personal information, as defined in the CCPA, in our capacity as a controller. We operate exclusively online and interact with you directly, so email is our designated method for submitting requests.
Other US states. Residents of states with comprehensive privacy laws have comparable rights. Where the applicable state law provides one — including Virginia, Colorado and Connecticut — you also have a right to appeal a refused request. To appeal, reply to our decision or write to [email protected].
How to exercise. Email [email protected]. We will verify your identity before acting and will respond within the period required by applicable law. If you are an end user of a customer’s product, see Section 2.
12. Security
We maintain technical and organisational measures designed to protect personal data, including:
Encryption — TLS 1.2 or higher in transit. Customer content is stored at rest only in Amazon Web Services, encrypted with AES-256 using keys managed by AWS. The GPU compute providers listed in Section 8 process customer content transiently in order to run inference and do not store it at rest. Other personal data — account, billing, support and operational telemetry — is held by the service providers listed in Section 8 under their platform storage encryption.
Access control — least-privilege, individually named accounts, with multi-factor authentication enforced on cloud, administrative and billing consoles. Production systems are not exposed to the public internet and are reachable only over a zero-trust WireGuard network requiring single sign-on with MFA.
Logging and monitoring — access to systems processing personal data is logged, monitored and escalated.
Resilience — automated daily backups with point-in-time recovery within a 10-day window.
Change management — production changes deployed through CI/CD for repeatable configuration.
Personnel — confidentiality obligations for staff and contractors.
Governance — assigned responsibility for security and privacy, and continuous security and compliance monitoring tooling.
Sub-processors — we require each to be bound by written data protection terms no less protective than our own commitments before it processes customer content.
We notify affected customers of a confirmed security incident affecting their data without undue delay and in any event within 48 hours of confirmation, provide the information they need for their own notifications, and assist with them. Customers may request documentation evidencing the measures above, and have the audit rights set out in our Data Processing Addendum.
No system is perfectly secure, and we cannot guarantee absolute security.
13. Children
The Services are business tools that are not directed to children. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, contact [email protected] and we will delete it. Customers must not submit personal data of children under 13 (or the applicable age of digital consent, where higher) through the Services; that category is prohibited under our Terms of Service and our Data Processing Addendum. Access to the Services under our Terms of Service is separately restricted to individuals aged 18 or over.
14. Changes to this policy
We may update this policy. If a change is material, we will give notice by email or by a prominent notice on our website at least thirty (30) days before it takes effect, and update the “last updated” date above. Continued use of our website or the Services after the effective date constitutes acceptance.
15. Contact us
Infercloud, Inc. (d/b/a Pipeshift)
Privacy enquiries and rights requests: [email protected]
Security: [email protected]