Privacy Policy

Last updated July 28, 2026

This privacy notice for ManyRows Pty Ltd (‘ManyRows’, ‘we’, ‘us’, or ‘our’) describes how and why we collect, store, use, and share (‘process’) your information when you use our services (‘Services’) — when you visit our website at https://manyrows.com, when you register for and use the ManyRows application, or when you engage with us in any other related way.

Questions or concerns? Reading this notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services.

Two kinds of data, treated differently

This distinction runs through the whole notice, so it comes first.

Account data is information about you as a user of ManyRows: the email address you register with, your authentication credentials, your workspace and billing records, and the logs our servers keep. We decide how this is handled, and this notice governs it. In the language of privacy law, we are the controller of account data.

Customer content is what you and your team put into a project: records, types and fields, bills of materials, images, files, comments and history. That is your data, not ours. We process it on your instructions in order to run the Services. We do not sell it, we do not mine it for our own purposes, and we do not use it to train machine-learning models. In the language of privacy law, we are a processor of customer content and the organisation that put it there is the controller. If customer content includes personal information about your own staff, customers or suppliers, you are responsible for having a lawful basis to put it there, and we will act on your instructions in respect of it.

Summary of key points

What personal information do we process? Account and contact details, authentication credentials, billing records, technical and usage logs, and any personal information you choose to place in your own project content.

Do we process sensitive personal information? We do not ask for and do not knowingly process sensitive personal information as part of account data. What you place in your own project content is under your control.

Do we receive information from third parties? Yes, in one narrow respect: our payment processor tells us the status of your subscription and payments. We do not buy personal information from data brokers or advertising networks.

How do we process your information? To provide, secure, bill for, support and improve the Services, to communicate with you about them, and to meet legal obligations.

With whom do we share it? With a short, named list of service providers who host, bill, email and measure on our behalf. That list is in section 5.

Do we sell your information? No. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

How long do we keep it? Specific periods are in section 7, including what happens to your data when you cancel.

What are your rights? Depending on where you live, you may have rights of access, correction, deletion, portability and objection. Section 10 explains how to use them.

Table of contents

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on to process your personal information?
  4. Do we use your data to train AI models?
  5. When and with whom do we share your personal information?
  6. Where is your information processed?
  7. How long do we keep your information?
  8. How do we keep your information safe?
  9. Do we collect information from minors?
  10. What are your privacy rights?
  11. Do we use cookies and other tracking technologies?
  12. Controls for do-not-track features
  13. Do United States residents have specific privacy rights?
  14. Do other regions have specific privacy rights?
  15. Do we make updates to this notice?
  16. How can you contact us, review, update, or delete your data?

1. What information do we collect?

Information you give us. When you register and use the Services we collect your email address, your name or username if you provide one, and your workspace and project names. When you contact us for support, we collect what you put in that message.

Authentication data. We store a cryptographic hash of your password, never the password itself. If you use a passkey we store the public credential; if you use an authenticator app we store the secret needed to verify your codes. These exist only to sign you in.

Payment information. Card payments are taken by Stripe on their own hosted checkout page. Card numbers never reach our servers. What we store is the customer and subscription identifiers Stripe gives us, your plan, and its billing status.

Customer content. Whatever you and your team put into a project — records, fields, structures, images, files, comments and their history. This may include personal information about third parties if you choose to model it that way; see the section above on the two kinds of data.

Information collected automatically. When you use the Services we log technical information: IP address, browser and device characteristics, pages and endpoints requested, timestamps, and errors. We use this to keep the Services running, to enforce rate limits, to investigate abuse and faults, and for aggregate analytics. Approximate location may be inferred from an IP address; we do not collect precise geolocation.

Audit records. The Services deliberately keep an audit history of who created and changed what inside a project. That is a product feature your team relies on, and it necessarily records the acting user’s identity against each action.

2. How do we process your information?

We process personal information to: create and administer your account and authenticate you; provide the Services and store the content you put into them; take payment and manage subscriptions, renewals and cancellations; send you service messages such as change-request notifications, approval requests, trial and billing notices, and security alerts; provide support and respond to what you ask us; keep the Services secure, prevent and investigate abuse, and diagnose faults; understand in aggregate how the Services are used so we can improve them; and comply with legal obligations and enforce our terms.

We do not use your information for advertising, and we do not make decisions about you by automated means that have a legal or similarly significant effect.

3. What legal bases do we rely on?

We only process personal information where we have a valid legal basis under applicable law. For users in the EEA, the UK and Switzerland, those bases are:

  • Performance of a contract — to give you the Services you have signed up for, to authenticate you, and to bill you. This is the main basis for most account data.
  • Legitimate interests — to keep the Services secure and available, to prevent abuse, to diagnose faults, to understand usage in aggregate, and to tell you about material changes to the Services. We consider your interests and rights when we rely on this.
  • Legal obligation — to keep tax and accounting records, and to respond to lawful requests.
  • Consent — for anything we ask your permission for separately, such as optional analytics cookies where consent is required. You may withdraw consent at any time.

Where we process customer content, we do so as a processor on the instructions of the customer who controls it, under a contract with them.

If you are located in Canada, we rely on your express or implied consent, with the exceptions applicable law permits.

4. Do we use your data to train AI models?

No. We do not use your account data or your customer content to train machine-learning models, ours or anyone else’s, and we do not send either to a third-party model provider.

The Services include a feature that helps you generate a schema with an AI tool of your own choosing. It works by giving you a specification to copy into whatever assistant you use, and then importing what you paste back. Nothing is transmitted to a model provider by us, and that exchange happens under your own account with that provider and their terms, not ours.

5. When and with whom do we share your personal information?

We do not sell personal information. We share it only with service providers who process it on our behalf, under contract, for the purposes below. As at the date of this notice, they are:

  • Heroku (Salesforce, Inc.) — application hosting and the managed PostgreSQL database that holds account data and customer content.
  • Amazon Web Services — object storage for the images and files uploaded to a project.
  • Stripe, Inc. — payment processing, subscription management and the billing portal. Stripe handles card data as an independent controller under its own privacy policy.
  • CloudMailin, or an SMTP provider we configure — delivery of transactional email such as approval requests and billing notices.
  • Google (Google Analytics) — aggregate measurement of traffic to our public website. This runs on the marketing website, not inside your project.

We may also disclose information where we are legally required to, to establish or defend legal claims, or in connection with a merger, financing, acquisition or sale of assets — in which case we will continue to protect it and will notify you before it becomes subject to a different privacy notice.

We will keep this list current. If you have a contract with us that requires notice of new sub-processors, that contract governs.

6. Where is your information processed?

ManyRows Pty Ltd is an Australian company. Our hosting, storage, payment and email providers operate data centres and support functions in the United States, the European Union and elsewhere, so your information is transferred and processed outside your own country, including outside the EEA, the UK and Australia.

Where we transfer personal information out of the EEA or the UK, we rely on the transfer mechanisms available under applicable law — including the European Commission’s Standard Contractual Clauses and the UK Addendum — together with the safeguards in our agreements with each provider. You can ask us for details of the mechanism used for a particular transfer.

7. How long do we keep your information?

We keep personal information only as long as we need it for the purposes in this notice, unless a longer period is required by law. In practice:

  • Records you delete go to a recycle bin and are recoverable for 30 days, after which they are permanently purged along with any uploaded files that only they referenced.
  • A workspace that never subscribes is in trial for 7 days. If it is still unsubscribed 7 days after that, it and its content are deleted. We email you before that happens.
  • A workspace that has subscribed and then cancels keeps its data for 30 days after the end of the paid period, so a cancellation is recoverable, and is then deleted.
  • Audit history inside a project is retained for the life of the workspace, because its purpose is to be a durable record. It is deleted with the workspace.
  • Billing records are retained for as long as tax and accounting law requires, which is longer than the account itself.
  • Server logs are retained for a short operational period and then rotated out.

Deleted data may persist in encrypted backups for a limited period before those backups expire in the ordinary course.

You can export your whole project — schema, records, structures and history — at any time before deleting anything, and we would encourage you to.

8. How do we keep your information safe?

We use technical and organisational measures appropriate to the risk, including encryption in transit, encryption of stored credentials and secrets, hashed passwords, role-based access control within a workspace, tenant isolation between customers, rate limiting, and audit logging. Access to production systems is limited to those who need it.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.

9. Do we collect information from minors?

We do not knowingly collect information from, or market to, anyone under 18, and we do not sell such information. By using the Services you confirm you are at least 18. If we learn we hold information from someone under 18, we will delete it. Contact us if you believe that is the case.

10. What are your privacy rights?

Depending on where you live, you may have the right to request access to the personal information we hold about you, to have it corrected or deleted, to receive a portable copy, to restrict or object to certain processing, to withdraw consent where we rely on it, and not to be discriminated against for exercising any of these rights.

To make a request, email [email protected] or use our contact page. We will respond within the period applicable law allows, and we may need to verify your identity first.

If your request concerns customer content held in someone else’s workspace — for example if you are an employee or supplier of a ManyRows customer — we are a processor of that content and cannot act on it directly. Please contact that organisation. If you contact us instead, we will refer you to them and assist them in responding.

You can also change or delete much of your data yourself inside the application. If you are in the EEA or UK and are unhappy with our response, you may complain to your local supervisory authority. In Australia, you may complain to the Office of the Australian Information Commissioner.

11. Do we use cookies and other tracking technologies?

On the application we use cookies that are strictly necessary to sign you in, keep your session, and remember your interface preferences. The Services do not work without them.

On our public marketing website we also use Google Analytics to understand in aggregate which pages are useful. We do not run advertising cookies, we do not operate advertising pixels, and we do not share information for cross-context behavioural advertising. You can block analytics cookies in your browser without affecting the application.

12. Controls for do-not-track features

Most browsers offer a Do-Not-Track (‘DNT’) setting. Because no uniform standard for honouring DNT has been finalised, we do not currently respond to DNT signals. We will revisit this if a standard is adopted.

13. Do United States residents have specific privacy rights?

If you are a resident of a US state with a comprehensive privacy law — including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah or Virginia — you may have the right to know what personal information we hold and how we have processed it, to correct inaccuracies, to obtain a copy, and to have it deleted. We do not sell personal information and do not process it for targeted advertising or profiling with legal effects, so there is nothing to opt out of on those grounds. Use the contact details in section 16 to make a request; you may use an authorised agent where the law allows.

14. Do other regions have specific privacy rights?

Australia and New Zealand. We handle personal information in accordance with Australia’s Privacy Act 1988 and the Australian Privacy Principles, and New Zealand’s Privacy Act 2020. You may request access to or correction of your personal information at any time, and may complain to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner.

EEA, UK and Switzerland. See sections 3, 6 and 10 for the legal bases we rely on, how we handle international transfers, and how to exercise your rights.

15. Do we make updates to this notice?

Yes. We will update this notice as our practices or the law change, and we will change the ‘Last updated’ date at the top. If a change materially affects how we handle your personal information, we will tell you directly — by email or in the application — rather than relying on you to notice.

16. How can you contact us, review, update, or delete your data?

For any privacy question or request, email [email protected], or write to ManyRows Pty Ltd via our contact page. You may also ask us to review, correct or delete the personal information we hold about you, as described in section 10.