Privacy notice
This notice explains what we do with your personal data when you create a Moorhold account to download Moorhold. It covers account.moorhold.dev and the Moorhold image registry only.
This account is separate from your organisation's Moorhold portal. The portal runs on your organisation's own servers, and your organisation controls the data in it. We never see it.
Who we are
Allotment Technology Ltd is the data controller. We are registered in England and Wales (company number 16925574) and with the Information Commissioner's Office (registration ZC092549).
Contact us about privacy at privacy@moorhold.dev.
What we collect
- Your email address, to identify you, verify you and send you service emails.
- Your name, if you choose to give one.
- Your organisation's name and your role in it.
- Which version of the account terms you accepted, and when.
- Your passkeys. We store only the public part of each passkey, and a label. If your device unlocks a passkey with your fingerprint or face, that stays on your device and we never receive it. We do not use passwords.
- Your access keys. We store an identifier, a label and a one-way hash. We show you the key once and cannot show it again.
- Invitations. A one-way hash of each invitation link, and its expiry.
- Security records. When a key is used, we record the time and the IP address it came from. We keep the IP address for 30 days. We also keep a log of security events, such as a key being created or a passkey being added. It does not contain your email address or IP address.
- Server logs. Like every website, our servers log each request's IP address, page and browser type. We delete the logs after 30 days.
We do not collect payment details. We use no analytics, no advertising, no tracking and no third-party scripts. We set only the cookies that are strictly necessary to keep you signed in and to complete a passkey sign-in. They are not used for anything else.
Why we use it, and our lawful basis
| What we do | Lawful basis |
|---|---|
| Run your account, verify your email, sign you in with passkeys, manage your organisation and its members, approve organisations, issue and revoke access keys, and send you service emails | Contract. We do this to provide the service under the account terms that you accept, and to take the steps you ask for before that. |
| Keep security records, limit abuse and investigate incidents | Legitimate interests: keeping the service and your keys secure. You can ask us for the balancing test we did. |
We review each new organisation before it can create its first access key. A person at Moorhold makes that decision, not a computer. If we refuse, we tell you, and you can reply to ask us to look again.
The few people at Moorhold who run the service can see accounts, organisations, their members and their keys (never a key itself), to support you and to act under the account terms: for example to suspend or restore an organisation's downloads, revoke a key, remove a member who has left, or delete an account when you ask. Each such action is recorded with its reason, and we email the people it affects.
We do not send you marketing.
Who we share it with
We share your data only with the companies that help us run the service, under contracts that protect it:
- Hetzner Online GmbH hosts our servers in Helsinki, Finland, and our backups in Falkenstein, Germany.
- Migadu-Mail GmbH, a Swiss email provider whose mail servers are in the EU, sends our emails to you: verification and recovery codes, and notices about your account and keys.
We do not sell your data or share it with anyone else, unless the law requires us to.
Where it is stored
In the European Union (Finland and Germany), and with Migadu in Switzerland and the EU. The UK recognises all of these as providing adequate protection for personal data.
How long we keep it
| Data | How long |
|---|---|
| A sign-up whose email is never verified | 7 days |
| Your account, passkeys, memberships and record of accepting the terms | Until you delete your account, then removed within 30 days |
| An access key's hash | Until the key is revoked or expires (keys expire after 12 months) |
| A revoked or expired key's record | 30 days |
| The IP address of a key's last use | 30 days |
| Invitations | Until they expire (7 days) |
| Security event log (no email address or IP address) | 12 months |
| Server logs | 30 days |
| Backups, including the encrypted nightly copy | 30 days |
Deleted data disappears from backups within 30 days of deletion.
Your rights
You can:
- see the data we hold about you, and download it, from your account page;
- correct your display name from your account page, or ask us to correct your email address;
- delete your account from your account page;
- object to our security records, or ask us to restrict how we use your data;
- ask us for anything else about your data by writing to privacy@moorhold.dev.
We reply within one month. We may ask you to sign in, or to reply from your account's email address, to confirm it is you.
Complaints
If you are unhappy with how we have handled your data, write to privacy@moorhold.dev. We will acknowledge your complaint within 30 days and tell you what we have done about it.
You can also complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113.
Changes
If we change this notice in a way that matters, we will tell you by email before the change takes effect.