This policy explains what personal data Mersoft Corporation (“Mersoft”, “we”) holds when you use Pealboard, why we hold it, who else processes it, how long we keep it, and what you can ask us to do with it.
It is written to be read. Where a term has a legal meaning — controller, processor, legitimate interests — it is used with that meaning and explained.
Two roles, and which one we are
Pealboard has two kinds of person in it, and our role differs between them.
Workspace members. People who sign into app.pealboard.com. For their
personal data we are the controller: we decide why and how it is
processed, and this policy governs it.
Portal customers. People who sign into a portal at a subdomain of
pealboard.com. For their personal data we are the processor, and the
workspace that runs the portal is the controller. We process it on that
workspace’s instructions under the data processing
addendum. A portal customer with a question about how their data
is used should ask the organization whose portal they signed into; we will
help that organization answer.
What we hold, and why
Workspace members
| Data | Why | Legal basis |
|---|---|---|
| Name, email address, password hash | To create an account and sign you in | Performance of the contract |
| Linked GitHub account: numeric id, login, an OAuth token | So issues and comments you create are authored as you in GitHub, if you chose that | Consent, given by linking; withdraw by unlinking |
| Workspace memberships and roles | To decide what you may do | Performance of the contract |
| Sessions: a token, the approximate location, the browser, the last time used | To keep you signed in and let you end a session | Performance of the contract |
| Notification preferences and in-app notifications | To send only what you asked for | Performance of the contract |
| Saved views, and the activity record of writes you made | To provide the product and to keep an audit trail | Performance of the contract; legitimate interests in security |
| Billing contact and subscription state | To bill the workspace | Performance of the contract; legal obligation for tax records |
Portal customers, processed for a workspace
| Data | Why |
|---|---|
| Email address | To sign in with a code or a link, and to send status and comment notifications |
| Display name and company | To attribute a request, in the portal and on the GitHub issue |
| Requests, comments, votes and attachments | To provide the portal |
| Sign-in codes and sessions | To sign in and stay signed in |
Everyone
We keep server logs of requests, with a request id, a timestamp, the path, the response status and an IP address, for security and for diagnosing failures. Logs are retained for 30 days.
We do not use advertising cookies, analytics that profile individuals, session recording, heat mapping, or third-party trackers on this site or in the product. The only storage this website uses is one entry recording whether you chose the light or the dark theme, which stays in your browser and is never sent to us.
What we write into GitHub, and what we never write
When a portal customer submits a request, we create a GitHub issue in the repository the workspace chose. The issue body carries the request, and one attribution line naming the requester and their company.
We never write an email address into GitHub. The attribution line carries a display name and a company only. This is deliberate: an issue in GitHub may be public, and content in GitHub cannot be recalled. Because Pealboard authored that line, it can rewrite it later to honor a deletion request; it could not recall an email address it had published.
Who else processes it
These are our sub-processors. Each processes only what the service needs.
| Processor | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Runs the application, the API, the portals and this website; stores portal attachments; provides the bot check on unauthenticated forms | Global edge network |
| Neon, Inc. | The Postgres database holding accounts, workspaces, portals, requests, the synced copy of your GitHub data, and billing state | AWS us-east-2, United States |
| Stripe, Inc. | Subscriptions, checkout and invoices. Stripe holds the payment card; we never see or store a card number | United States and the European Union |
| Resend (Plus Five Five, Inc.) | Sends transactional email: verification, invitations, sign-in codes, notifications, digests | United States |
| GitHub, Inc. | Holds the issues, comments, labels, milestones and projects. GitHub is where your work lives, not a place we send it for our own purposes | United States |
We do not sell personal data, and we do not share it for advertising. We disclose it only to these processors, and where the law requires it.
International transfers
Our processing happens in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred there. The transfer relies on the European Commission’s standard contractual clauses, which are incorporated into the data processing addendum, together with the additional safeguards described there.
There is no data-residency option today. If your organization requires processing to stay in a particular region, Pealboard does not meet that requirement.
How long we keep it
| Account and workspace data | While the workspace exists |
| After a workspace is deleted | Deleted within 30 days |
| After an individual account is deleted | Deleted within 30 days |
| Portal customer data | On the controlling workspace’s instructions, and deleted within 30 days of that workspace being deleted |
| Server logs | 30 days |
| Billing and tax records | 7 years, as tax law requires |
| Backups | Overwritten on a rolling 30-day cycle. A deletion reaches backups within that period |
Your rights
If we are the controller of your data — that is, if you are a workspace member — you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete it, subject to records we must keep for tax or security;
- restrict or object to processing based on legitimate interests;
- export it in a portable, machine-readable form;
- withdraw consent where consent is the basis, such as by unlinking GitHub.
Email privacy@pealboard.com. We answer within 30 days. We may ask you to
confirm your identity, and we will not charge you.
If you are a portal customer, the controller is the organization whose portal you use. You can also exercise two rights directly in the portal: Download my data returns your requests and comments as JSON, and Delete my account removes your portal account and rewrites the attribution lines Pealboard wrote into GitHub to “a former customer”. The issue itself stays, because it belongs to the organization, not to us.
If you are in the EEA or the UK you may complain to your supervisory authority. We would rather you told us first.
Security
The controls we operate are listed at /security: tenant isolation enforced in the database, authorization declared per route, host-only session cookies, secrets held only as server secrets, API keys stored as digests, and verified webhook signatures.
We hold no security certification. There is no SOC 2 report, no ISO 27001 certificate and no third-party penetration test, and nothing in this policy should be read as claiming one.
If a breach affects your personal data, we will tell the affected workspace owners without undue delay, and supervisory authorities where the law requires it.
Children
Pealboard is not for anyone under 16, and we do not knowingly collect their
data. If you believe a child’s data is in Pealboard, email
privacy@pealboard.com and we will remove it.
Changes
We will change this policy as the product changes. A material change is announced on the changelog and by email to every workspace owner before it takes effect. The effective date at the top of this page always reflects the current version.
Contact
Mersoft Corporation, the controller for workspace member data.
Privacy questions and requests: privacy@pealboard.com. Anything else:
hello@pealboard.com.