Privacy Policy
Last updated: 23 September 2026
RunLite (“RunLite”, “we”, “us”) provides website hosting, a form backend, and a connector for AI coding tools (“the Service”). This policy explains what data we collect and why.
1. Who this policy is for
Two different groups of people interact with the data RunLite handles, and this policy covers both:
- Account holders — the developer, agency, or business that creates a RunLite account, deploys a site, and configures a form.
- Visitors — anyone who fills out a form embedded on a site an account holder has deployed. Their form submissions are collected on the account holder’s behalf, not ours. RunLite acts as a data processor for this data; the account holder is the data controller and is responsible for how their own visitors’ data is used, consistent with whatever they’ve told their own customers.
2. What we collect
About an account holder:
- Email address, once the account is claimed — an account created via
bootstrap_accounthas no email at all until then - API keys — we store only a salted hash and a short display prefix; the full key is shown once, at creation, and never again
- Site files uploaded for hosting, and form definitions
- Billing details processed via Razorpay (we never see or store card numbers — see Section 5)
About a visitor submitting a form:
- Whatever fields the account holder’s form asks for
- IP address, user agent, and referring page, used for spam filtering and rate-limiting
- A basic automated spam score
3. Why we collect it
- To provide the Service — hosting, form delivery, notifications
- To prevent abuse — spam filtering and rate limiting
- To bill for paid plans
- To communicate with account holders about their account
We do not sell personal data, and we do not use form-submission data for advertising.
4. Retention
- Unclaimed accounts are deleted, along with everything under them, 72 hours after creation if never claimed.
- Form submissions are retained for 90 days by default, then deleted automatically. An account holder can configure a different retention period for their own account.
- Rate-limiting records (used to detect abuse) are deleted after 24 hours.
5. Who else sees this data
We use the following service providers to run RunLite. Each only sees the data it needs to perform its function:
- Amazon Web Services (ap-south-1, Mumbai) — hosting, file storage, compute. Sees site files and submission data.
- Supabase — database and authentication. Sees account and submission data.
- Razorpay — payment processing. Sees billing details; we never see card numbers.
- Resend — transactional email delivery. Sees the content of notification emails.
- Cloudflare (Turnstile) — spam and bot filtering. Sees form-submission metadata.
6. Your rights
Depending on where you’re located, you may have rights to access, correct, or delete your personal data. Account holders can request deletion of their account and its data at any time by contacting us. Visitors who submitted a form should contact the account holder whose form they submitted — the data controller for that submission. We can assist an account holder with a request but do not have an independent relationship with visitors.
7. Security
API keys and claim tokens are stored as salted hashes, never in plain text. Database access that bypasses row-level security is limited to trusted server-side code; the dashboard itself never receives elevated privileges.
8. Changes to this policy
We may update this policy from time to time. We’ll update the date at the top when we do.
9. Contact
Questions about this policy: legal@runlite.in