Privacy Policy
Last updated: August 2, 2026
Overview
DBShifts ("we", "us") operates the DBShifts data platform (the "Service") — database migration, the Data Console, and the Agent Gateway. This policy explains what we collect, how we use it, and your rights. By using DBShifts you agree to this policy.
Controller vs. Processor — Whose Policy Applies to What
This policy covers your Account Data — the information described below that you give us directly (name, email, billing) and that we generate about your use of the Service (audit logs, sign-in security). For that data, DBShifts is the controller and this policy is the relevant one.
For Customer Data — the contents of databases you connect (which may include personal data about your own customers, employees, or end users) — you are the controller and DBShifts is the processor, acting only on your instructions to provide the Service. If someone wants to exercise a data-subject right (access, deletion, etc.) over personal data inside a database you've connected, that request should go to you, not to us — you're the one with the relationship to that person and the legal basis for holding their data. We'll assist you in responding if you ask us to.
Information We Collect
Account: name, email, bcrypt-hashed password. If you enable two-factor authentication, an encrypted TOTP secret and hashed recovery codes.
Database connection details: hosts, ports, names, and credentials you provide — encrypted at rest, decrypted only in memory during a job or query.
Usage: job IDs, status, row counts, schema metadata, error logs, reconciliation results.
Agent & console activity: audit logs of gateway queries (table, columns, row counts, masked columns, requesting IP) and Data Console access — kept so you can answer "who saw what". Agent tokens are stored only as SHA-256 hashes.
Dataset version control: if you commit a snapshot of a table (or an Agent Gateway auto-commits one after an approved write), the row content is stored — content-addressed, unchanged rows stored once — plus commit metadata (message, timestamp, row-level diff summary). See "Agent Gateway & Data Console" below for how this differs from the rest of the Service.
Sign-in security: device fingerprints (IP + browser) of known sign-ins, used to alert you to new-device access.
Billing: plan + subscription status. Card data is handled by Stripe, never stored on our servers.
Technical: IP, browser, pages visited (server logs).
Legal Basis for Processing
Where GDPR or UK GDPR applies, we process Account Data on these bases:
- Contract — to create your account and provide the Service you signed up for
- Legitimate interests — security, fraud and abuse prevention, service reliability, and improving the Service — balanced against your rights, and you can object (see Your Rights below)
- Consent — analytics cookies, which stay off until you accept them
- Legal obligation — retaining billing records as required by tax and financial regulation
How We Use It
- Operate the Service and run the migrations, queries, and monitors you start
- Send transactional and security email (verification, reset, new-device sign-in, 2FA changes)
- Process billing and enforce plan quotas
- Detect errors, abuse, and security incidents (rate limits, anomaly alerts)
- Comply with legal obligations
Password breach screening: when you set a password we check it against known breaches using k-anonymity — only the first 5 characters of a SHA-1 hash ever leave our servers; your password never does.
We never train ML models on your data or sell it to advertisers. (DBShifts contains no AI/LLM components; the Agent Gateway governs your agents' access — we run none of our own.)
Database Credentials & Migrated Data
DBShifts is a data processor acting on your instructions. Credentials are encrypted at rest. Row data moves between your source and target via our worker nodes and is not persistently stored after a job completes. Migration logs retain counts and timestamps, not full row payloads. Rows a target rejects may be quarantined for your review until you retry or discard them. You are responsible for your right to migrate the data involved.
Agent Gateway & Data Console
Both products read your connected databases on demand — query results are returned to you (or your agent) and are not persistently stored by us, with three exceptions: audit logs (metadata about each access: table, columns, row counts, masked columns, IP — not full row payloads, except write-action undo snapshots you explicitly approve), masked test-data copies you generate into a target you control, and dataset version control (below).
PII masking, column rules, row limits, usage budgets, and token IP restrictions are applied server-side according to your policy configuration. Detection of sensitive columns is automated and best-effort — review the scan results; you remain the controller of what your policies expose. Owner "replay" of an agent query re-runs it under the same masking rules and is itself audited.
Dataset version control is the one place row content is persistently stored rather than read on demand: committing a table (manually, or automatically on the Agent Gateway's "agent-writes" branch after an approved write) stores its content until you delete the branch/commit or the connected resource. Your PII masking policy is applied whenever that history is viewed — checking out a past commit or diffing two commits returns masked values exactly like browsing does — but the underlying stored content is not masked at rest. If a table shouldn't have its history retained this way, don't commit it.
If you enable Slack approvals, write-action proposals (action name, parameters, requesting agent) are sent to the Slack webhook you configure — governed by Slack's own terms.
International Data Transfers
We host the Service on infrastructure in the United States (see Third-Party Processors below). If you or your data originate outside the U.S., your data — Account Data, and any Customer Data you choose to connect — will be transferred to and processed in the U.S. Where required (for example, transfers of personal data out of the EEA, UK, or Switzerland), we rely on Standard Contractual Clauses or another recognized transfer mechanism with our processors. You control which databases you connect and where they're hosted — connecting a database doesn't change where its data was already located, except for the copies described in this policy (audit logs, masked test-data, dataset version control).
Security & Breach Notification
- TLS 1.2+ in transit; credentials encrypted at rest with rotatable keys
- bcrypt password hashing + breach screening on new passwords
- Optional TOTP two-factor authentication with hashed recovery codes
- httpOnly JWT cookies + CSRF double-submit tokens
- Agent tokens: hashed at rest, scopable, revocable, optionally IP-bound
- Rate limiting, usage budgets, and anomaly detection
Report vulnerabilities to contact@dbshifts.com.
If a security incident affects your Account Data or Customer Data, we will notify you without undue delay after we become aware of it, and in any case within the timeframe required by applicable law (for example, 72 hours under GDPR where the incident poses a risk to individuals), with what we know at the time and how we're responding.
Data Retention
- Account deletion: scheduled with a short grace period (sign in again to cancel), then all owned data — projects, credentials, data sources, gateways, agent tokens, test-data sets — is permanently purged
- Database credentials: deleted with the resource or the account, whichever comes first
- Migration logs: no independent expiry — retained for as long as the project exists, deleted when the project or account is deleted
- Gateway audit logs: 90 days
- Webhook delivery records: 30 days
- Reconciliation monitor history: 90 days
- Dataset version control (commits, branches, stored row content): retained until you delete the branch/commit, delete the connected data source or gateway, or delete your account — no automatic expiry
- Billing: we don't store invoices or payment history ourselves — Stripe is the system of record and retains them per its own policies (typically several years, for tax and financial regulation). We keep only your current plan and subscription status.
Your Rights (GDPR / CCPA / Other U.S. State Laws)
The rights below apply to your Account Data (see Controller vs. Processor above for Customer Data, which is your responsibility as controller). Depending on where you live, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete it; receive a portable copy; object to or restrict certain processing; and not be discriminated against for exercising any of these rights (we won't charge you more or provide a worse Service). To exercise any of these, email contact@dbshifts.com; we respond within 30 days (or the timeframe your local law requires, if shorter). We may need to verify your identity first.
California (CCPA/CPRA) specifics: the categories of personal information we collect, our purposes for collecting it, and the categories of third parties we share it with are described in Information We Collect, How We Use It, and Third-Party Processors above. We do not sell or share personal information for cross-context behavioral advertising, and never have. California residents have the rights above plus the right to non-discrimination for exercising them, as described here.
Other U.S. state privacy laws (Virginia, Colorado, Connecticut, Utah, and others as they take effect) provide similar rights — access, correction, deletion, portability, and opt-out of targeted advertising or sale, which we don't do. Contact us at the email above to exercise them regardless of which state's law applies to you.
Do Not Track: our systems don't currently respond to browser "Do Not Track" signals; the Cookies section above describes how to opt out of analytics directly.
Data Processing Addendum: if you're a business customer needing a GDPR Article 28-compliant DPA for the Customer Data you process through the Service, request one at contact@dbshifts.com.
India — Digital Personal Data Protection Act (DPDPA)
DBShifts is based in India. For Account Data, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDPA"); for Customer Data processed on your instructions, we act as a Data Processor for you as the Fiduciary, consistent with the Controller vs. Processor section above.
As a Data Principal under the DPDPA, you have the right to:
- obtain a summary of your personal data we process and the processing activities
- request correction, completion, updating, or erasure of your personal data
- have your grievance addressed — see Grievance Officer below
- nominate another individual to exercise these rights on your behalf in the event of death or incapacity
- withdraw consent at any time, as easily as it was given (for processing based on consent, such as analytics cookies)
Grievance Officer: for any grievance regarding processing of your personal data, contact our Grievance Officer at contact@dbshifts.com. We will respond within the timeframe required by the DPDPA. If unresolved, you may escalate to the Data Protection Board of India.
Cross-border transfer: our infrastructure providers are based in the United States (see Third-Party Processors). The DPDPA permits transferring personal data outside India except to countries specifically restricted by the Central Government — the U.S. is not currently restricted. We'll revisit this if that changes.
Children's Privacy
The Service is a business/developer tool and is not directed at children. You must be at least 16 to create an account (see Terms of Service). We do not knowingly collect personal data from anyone under 16. If we learn we've collected it, we'll delete it — contact contact@dbshifts.com if you believe a child has provided us data.
Third-Party Processors
- Amazon Web Services — application hosting (API, frontend, and background workers all run on EC2)
- MongoDB Atlas — primary database (AWS)
- Stripe — payments (US/EU)
- Slack — only if you enable Slack approvals, and only the proposal metadata you route there
- Have I Been Pwned — anonymized password-breach screening (5-character hash prefix only)
All processors are bound by contract to protect your data and use it only to provide their service to us. We'll update this list and, for enterprise customers under a DPA, provide notice before engaging a new sub-processor that will handle Customer Data — email contact@dbshifts.com to object on reasonable data-protection grounds.
Changes
Material changes are announced via email or in-app notice at least 14 days before taking effect.