Privacy Policy

Last Updated: July 14, 2026

This Privacy Policy explains how Shorlabs, Inc. ("Shorlabs", "we", "us", or "our") collects, uses, stores, shares, and protects your personal information when you use our website at shorlabs.com and our deployment platform (together, the "Service"). Shorlabs builds, deploys, and runs your applications, databases, and domains inside your own Amazon Web Services (AWS) account.

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect your name, email address, and profile picture. Authentication is handled by our identity provider, Clerk. You can sign up with an email address or through a third-party identity provider such as Google.

1.2 Google User Data

If you choose to sign in with Google, we receive limited information from your Google account through Google's OAuth 2.0 service: your name, email address, and profile picture. We use this information solely to create and authenticate your Shorlabs account, display your identity within the product, and communicate with you about the Service.

  • Access: We request only basic profile information (name, email address, profile picture). We do not request access to your Gmail, Google Drive, Google Calendar, contacts, or any other Google service or content.
  • Use: Google user data is used exclusively to provide and improve authentication and account functionality within the Service. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models.
  • Storage: Your name, email address, and profile picture are stored securely by our authentication provider, Clerk, and in our own systems where needed to operate the Service. Data is encrypted in transit (TLS) and at rest.
  • Sharing: We do not sell Google user data, and we do not share it with third parties except with the service providers listed in Section 4 that are necessary to operate the Service, or where required by law.
  • Retention and deletion: Google user data is retained for as long as your account is active. When you delete your account, the associated Google user data is deleted as described in Section 6. You can also revoke Shorlabs' access at any time via your Google Account security settings.

Shorlabs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

1.3 GitHub Data

To deploy your applications, you may connect your GitHub account through the Shorlabs GitHub App. We collect repository metadata (repository names, branches, commit information) and receive webhook events (such as pushes) to trigger deployments. We access repository contents only to build and deploy your applications, and we do not retain copies of your source code beyond what is required for the build process.

1.4 AWS Connection Data

Shorlabs deploys infrastructure into your own AWS account through a cross-account IAM role that you create and authorize. We store the role identifier (ARN), your AWS account ID, and metadata about the resources we provision on your behalf (such as service names, domains, and deployment configuration). We never ask for and never store your AWS root credentials, passwords, or long-lived access keys.

1.5 Payment and Billing Information

Billing is usage-based and processed by our billing providers, Autumn and Stripe. When you add a payment method, your card details are collected and stored directly by Stripe — we never see or store full card numbers. We retain billing records such as usage metrics, invoices, and transaction history as required to operate the Service and comply with tax and accounting obligations.

1.6 Usage, Log, and Technical Data

We collect information about how you use the Service, including deployment activity, build and runtime logs, resource usage metrics (requests, bandwidth, compute), device and browser information, IP addresses, and approximate location derived from IP. Build and runtime logs for your applications are stored so you can view them in your dashboard.

1.7 Cookies

We use cookies and similar technologies that are strictly necessary for the Service to function — primarily session and authentication cookies set by Clerk. We do not use third-party advertising cookies.

2. How We Use Your Information

We use the information we collect to:

  • Create, authenticate, and secure your account;
  • Provision, build, deploy, and operate your applications and infrastructure in your AWS account;
  • Stream build and runtime logs to your dashboard;
  • Measure usage and calculate billing;
  • Send service-related communications such as deployment notifications, security alerts, billing notices, and updates to our terms or policies;
  • Respond to your support requests;
  • Monitor, protect, and improve the reliability and security of the Service, and prevent fraud and abuse;
  • Comply with legal obligations.

We do not sell your personal information, and we do not use your personal information or the contents of your repositories for advertising.

3. Legal Bases for Processing (GDPR)

Where the EU or UK General Data Protection Regulation applies, we process your personal data on the following legal bases: performance of a contract (providing the Service you signed up for), legitimate interests (securing and improving the Service, preventing abuse), legal obligation (tax, accounting, and compliance records), and consent where required (which you may withdraw at any time).

4. How We Share Information

We share personal information only with the service providers (sub-processors) needed to operate the Service:

  • Amazon Web Services (AWS) — hosting for our control plane, data storage, and log storage;
  • Clerk — user authentication and identity management;
  • Google — sign-in with Google (OAuth), if you choose to use it;
  • GitHub — repository connection and deployment webhooks, if you connect a repository;
  • Autumn and Stripe — billing, metering, and payment processing.

We may also disclose information if required by law, regulation, legal process, or enforceable governmental request; to protect the rights, property, or safety of Shorlabs, our users, or the public; or in connection with a merger, acquisition, or sale of assets (in which case we will notify you before your personal information becomes subject to a different privacy policy).

5. Data Security

We follow industry-standard security practices. All data is encrypted in transit using TLS and encrypted at rest. Access to production systems is restricted through least-privilege IAM roles, and secrets are managed through dedicated secrets-management services (such as AWS KMS and AWS SSM). Access to your AWS account is performed exclusively through the scoped IAM role you authorize, and you can revoke that access at any time from your AWS console. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

6. Data Retention and Deletion

We retain your personal information for as long as your account is active or as needed to provide the Service. Build and runtime logs are retained on a rolling basis and expire automatically. Billing records are kept as long as required by tax and accounting law.

When you delete your account or a project, we tear down the associated infrastructure configuration and schedule deletion of associated personal data from our systems. Resources deployed in your own AWS account remain under your control at all times. You may request deletion of your account and personal data at any time by contacting us at [email protected].

7. Your Privacy Rights

Depending on where you live, you may have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — correct inaccurate or incomplete data;
  • Erasure — request deletion of your personal data ("right to be forgotten");
  • Portability — receive your data in a structured, commonly used, machine-readable format;
  • Restriction and objection — limit or object to certain processing;
  • Non-discrimination — exercise these rights without receiving discriminatory treatment (California residents, under the CCPA/CPRA);
  • Withdraw consent — where processing is based on consent.

To exercise any of these rights, email [email protected]. We will respond within the timeframe required by applicable law (generally 30 days). You may also lodge a complaint with your local data protection authority.

8. International Data Transfers

Our control plane is hosted in the United States on AWS. If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States and other countries where our sub-processors operate. Where required, we rely on appropriate safeguards such as standard contractual clauses for these transfers. Infrastructure you deploy through Shorlabs runs in the AWS regions you choose within your own AWS account.

9. Children's Privacy

The Service is not directed to anyone under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at [email protected] and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page, and for material changes — including any change to how we use Google user data — we will provide notice through the Service or by email before the change takes effect.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at [email protected].