PairRail
Product Score Onboard Protocols Verify Pricing About
Log in
Terms Privacy Security DPA Subprocessors FAQ Support

Legal

Privacy Policy

Last updated: September 25, 2026 · Operators of pairrail.com (“PairRail,” “we,” “us”)

This Privacy Policy explains how PairRail collects, uses, and shares information when you use PairRail Atlas on pairrail.com and related APIs.

1. Who this covers

  • Seller users who sign in to the console (Google or GitHub via Firebase Authentication).
  • Visitors to the marketing site and public protocol endpoints.
  • Agents and integrators that call protocol or OpenAPI surfaces.

PairRail operators (internal platform staff) are authenticated users with elevated roles. Operator console actions are not forwarded to the seller product telemetry pipeline described below.

2. Information we collect

Account and authentication

When you sign in with Google or GitHub through Firebase Authentication, we receive identifiers such as email address, display name, profile photo URL (if provided by the identity provider), user UID, and sign-in provider. Session tokens may be held in browser session storage for the console. Firebase and the identity provider may set their own cookies or local storage as described in our Cookie Notice.

Seller workspace and commercial content

To operate Atlas we process Customer Content you submit or generate in-product, including organization/workspace identifiers, seller profiles, catalog versions, pricing and packaging, evidence metadata, publication state, onboarding inputs, extraction previews, readiness reports, and configuration for protocol publication (UCP, MCP, A2A, ACP, UAP, and related feeds).

Billing

If you subscribe to a paid plan, checkout and payment details are handled by our payment partner (e.g., Dodo Payments). We receive subscription status, plan identifiers, and related billing metadata needed to entitle features — not full card numbers.

Product telemetry and feedback (Cloudflare edge)

For seller users (not operators), we may record operational events to Cloudflare-backed storage (D1 database and, where attachments are provided, R2 object storage), including:

  • Auth events — login-related signals such as email, UID, provider, organization/workspace IDs, plan, coarse location metadata (e.g., country from the edge), and limited metadata.
  • Action events — console actions such as catalog edits, pricing previews, extracts, and similar product operations, with associated user and workspace identifiers.
  • Protocol usage — protocol name, endpoint, seller ID, optional agent name, operation, latency, status code, and country for agent/API traffic analytics.
  • Feedback — category, message, optional email/seller ID, and optional attachments (screenshots or traces) stored in object storage.

Technical and security logs

Like most web services, our hosts, CDN, and application layers may process IP addresses, user agents, request paths, timestamps, and error diagnostics for security, reliability, and abuse prevention.

3. How we use information

  • Provide, secure, and improve the Service (including protocol serving, extraction, and governance features).
  • Authenticate users, enforce roles and plan limits, and process billing entitlements.
  • Monitor reliability, diagnose issues, and prevent abuse.
  • Respond to support and feedback requests.
  • Comply with legal obligations and enforce our Terms and Acceptable Use Policy.

We do not sell personal information.

4. Sharing

We share information with:

  • Infrastructure and auth processors — listed on Subprocessors, including Google Cloud (Firebase Authentication and Hosting, Cloud Run, Cloud Storage, Gemini / Vertex AI), Cloudflare (edge telemetry/feedback storage and DNS/CDN), Resend (transactional mail), and our payment provider for subscription checkout.
  • Payment processors — for subscription checkout and webhooks.
  • Identity providers you choose — Google or GitHub, under their policies when you authenticate.
  • Professional advisors or authorities when required by law or to protect rights and safety.

Published protocol endpoints intentionally expose the commercial data you choose to publish so that buying agents and integrators can discover offers. That exposure is controlled by your publication settings, not by this Privacy Policy alone.

5. Retention and deletion

Sandbox keeps about 14 days of activity. Pro retains audit trail and catalog versions for 90 days. Enterprise can extend retention under contract. We also keep account and billing metadata as needed to operate the Service, meet legal obligations, resolve disputes, and maintain security.

Workspace owners may request deletion at support@pairrail.com. We take down published rails for that seller and delete or anonymize Customer Content we no longer need. Some records may remain in backups or logs for a limited period. See the Data Processing Terms.

6. Security

We apply administrative and technical safeguards appropriate to a B2B SaaS control plane. No method of transmission or storage is perfectly secure. See our Security & Responsible Disclosure page for how to report vulnerabilities.

7. International processing

PairRail may process data in the United States and other countries where our providers operate. If you access the Service from elsewhere, you understand that information may be transferred to those locations.

8. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Contact support@pairrail.com. We may need to verify your identity before fulfilling a request. You can sign out of the console and revoke Google/GitHub access via those providers.

9. Children

The Service is intended for business users and is not directed to children under 16. We do not knowingly collect personal information from children.

10. Changes

We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted in-product or by email when practicable.

11. Contact

Privacy questions: support@pairrail.com. Security incidents: security@pairrail.com.

Enterprise customers can request an executable DPA from the Data Processing Terms page.

PairRail

Governed pricing for the agents buying from you.

© 2026 PairRail. All commercial responses are indicative and governed by seller policy.
Legal Terms of Use Privacy Policy Code of Conduct Acceptable Use Security Subprocessors DPA Cookie Notice
Support Support FAQ About Home