Privacy Policy
Pace HQ LLC (“Pace”) operates pacehq.io, app.pacehq.io, and tenant workspaces at {tenant}.pacehq.io. This policy explains what we collect and how we use it in plain language.
What we collect
- Account information: name, email, organization, role, and authentication identifiers (via Stytch B2B)
- Waitlist: email address and optional plan/source metadata when you join from pacehq.io (used to invite you and measure demand). Joining the waitlist does not require creating an account.
- Usage logs: IP address, browser type, pages and features used, security and audit events
- Agent execution metadata: task type, outcomes, timestamps, and audit records (not raw model prompts unless required for support)
- Billing data: subscription status, invoices, and payment metadata via Stripe (we do not store full card numbers)
- Workspace content: files, messages, and documents your organization uploads — processed on your behalf
Controller vs processor
For signup, billing, platform security, and marketing, Pace is the data controller. For business data inside a customer workspace, your organization is generally the controller and Pace is the processor.
Subprocessors
We use trusted vendors to run the platform (all US-based unless noted):
- Supabase — Postgres database (us-east-2)
- Railway — Relay and Strut control plane
- Cloudflare — CDN, DNS, WAF, Pages hosting
- Stytch — authentication
- Upstash — Redis Streams and Pub/Sub
- Stripe — payments and billing
See also Subprocessors for the detailed list.
Data retention
- Prometheus metrics: 30 days
- Loki logs: 30 days
- Postgres (tenant data): retained until the tenant requests deletion or the subscription ends, plus any export window in your agreement
- Billing records: retained as required by tax and accounting law
What we do not do
We do not sell personal information. We do not use advertising trackers on the product. We do not use workspace content to train public AI models.
Your rights (GDPR)
If you are in the EEA or UK, you may request access, rectification, erasure, restriction, or portability of personal data we control. Workspace users should contact their organization administrator first. Email privacy@pacehq.io — we respond within 30 days where applicable.
California residents (CCPA)
California residents may request disclosure of categories of personal information collected and request deletion of personal information we hold as a controller. We do not sell personal information.
Security
See our Security & Trust page. Report vulnerabilities to security@pacehq.io.
Contact
privacy@pacehq.io
Pace HQ LLC