1. Parties
- The customer, the controller: the organisation that uses PrivateCrates for its GitHub organisation, as named in the order or account.
- The processor: PrivateCrates: during the private preview, the operator named in the private preview terms; from general availability, the company that runs PrivateCrates, whose name, number and registered address will be given here.
This agreement forms part of the terms of service between them.
2. Processing details
| Subject matter | Running a private Cargo registry for the customer’s GitHub organisation. |
|---|---|
| Duration | For as long as the customer uses the service, and then until deletion under section 7. |
| Nature and purpose | Authenticating developers and CI through GitHub; checking their access; publishing crate files to the customer’s own storage repository; serving the index and downloads; billing. |
| Data subjects | Members of the customer’s GitHub organisation and outside collaborators who use the registry; the customer’s billing contact. |
| Personal data | GitHub logins, names and avatars (shown at sign-in, not stored); organisation membership and roles; the GitHub login of each publisher, written into the customer’s repository; the billing email address, held by Stripe; the GitHub ID and login of the admin who accepted the terms, in the processor’s record of the acceptance; GitHub tokens, in transit only; client IP addresses, in the hosting provider’s HTTP request logs. |
| Special categories | None. |
3. Processor obligations
- Process personal data only on the customer’s documented instructions, including this agreement.
- Ensure that people authorised to process the data are bound by confidentiality.
- Apply the security measures in section 5.
- Help the customer respond to data subjects’ requests and meet its obligations on security, breach notification and impact assessments, taking into account that the only personal data the service stores durably is the record of an admin accepting the terms.
- Make available the information needed to show compliance, and allow audits: on 30 days’ written notice, at most once a year, at the customer’s cost, answered first with the documents on the trust centre and the subprocessors’ own audit reports.
4. Subprocessors
The customer authorises the subprocessors below. The processor will tell the customer before adding or replacing one, at least 30 days before the change, by updating the subprocessor list on the trust centre and emailing the customer’s billing email address. The customer may object within that period on reasonable data protection grounds; if the processor cannot accommodate the objection, the customer may end the service and receive a prorated refund of anything prepaid. Where a subprocessor must be replaced urgently, for example after a failure or a breach, the processor may make the change at once and gives notice as soon as it can.
| Subprocessor | Purpose | Location |
|---|---|---|
| Railway | Hosts the PrivateCrates service: it runs the server, terminates TLS for our domains, keeps its logs, and runs the Postgres database (with backups) that holds terms acceptances and invitation requests. | United States, US East (Virginia) region |
| GitHub | Identity, permissions and storage. Your crates and index live in your own organisation’s repository; GitHub Actions signs provenance. | Under your organisation’s GitHub agreement |
| Stripe | Subscriptions, invoices, card payments and the trial-ending reminder email, from general availability. Billing is off during the private preview, so Stripe receives nothing yet. | United States and elsewhere, under Stripe’s terms |
| Cloudflare | DNS for privatecrates.dev (not proxied: traffic goes straight to Railway), and the status page at status.privatecrates.dev. | Global network |
GitHub stores the customer’s crates in the customer’s own organisation, under the customer’s own agreement with GitHub, so for that storage GitHub is the customer’s own processor. GitHub is listed as a subprocessor for what the service itself sends it: sign-in and permission checks.
5. Security measures
The measures in force are described on the trust centre. In summary:
- No durable storage of registry data or code; in-memory caches keyed by token hashes. The only durable record is terms acceptances.
- Tokens never logged, stored or sent anywhere but GitHub’s API.
- Least-privilege GitHub Apps; no repository administration permission.
- HTTPS only with HSTS; an encrypted,
HttpOnlysession cookie. - Immutable releases, GitHub-signed provenance and an open-source verifier the customer runs.
- Secrets held as encrypted environment variables at the hosting provider, with rotation procedures.
6. Personal data breach
The processor will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer’s data, and in any case within 72 hours. Notice goes to the customer’s billing email address where there is one, and to any other contact the customer names by email to the contact address below. It will describe the breach, the data and people likely affected, the likely consequences, and the measures taken or proposed. Service incidents are also posted on the status page.
7. Deletion and return
- Registry data (crates, index and settings) is in the customer’s own GitHub repository throughout. The customer keeps it, or deletes it, directly; uninstalling the PrivateCrates GitHub Apps ends the processor’s access.
- Caches are in memory only and are lost on restart; access caches expire within 5 minutes.
- Logs are deleted by the hosting provider after 30 days.
- Terms acceptances are kept for as long as the customer uses the service, then for 6 years, as evidence of the agreement.
- Billing records at Stripe are kept for as long as tax law requires (6 years in the UK). There are none during the private preview.
8. International transfers
The service runs in the United States, in Railway’s US East (Virginia) region. Before this agreement comes into force, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum will be incorporated for transfers from the EU and the UK.
9. General
Liability is as in the terms of service. Where this agreement and the terms conflict about personal data, this agreement wins. Governing law and jurisdiction are those of the terms of service, which will name them at general availability.
Questions about this agreement: contact@privatecrates.dev. Security questions: security@privatecrates.dev.