Privacy Policy
Version 2026-09-11 · Effective 15 September 2026 at 08:00 CEST (Europe/Paris)
This policy explains how Exostack SARL (SIREN 922 481 981, Paris, France), publisher of Carillon, processes the personal data of the people who visit the Carillon website and who use a Carillon account. For this data, Exostack is the controller.
The data your apps send about their own users (push tokens, external identifiers, tags and delivery records) is processed by Exostack as a processor on behalf of the Customer that operates the app. That processing is governed by the Data Processing Agreement. If you use an app that relies on Carillon, contact the company that publishes the app.
What we process, why, and on which basis
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email address, password (stored as a one-way hash), account creation and update times | Creating and operating your account | Performance of the contract |
| Organization name, address slug, membership and role; invitations (invited email address, role, inviter, expiry) | Letting organizations manage their team | Performance of the contract |
| Session records: IP address and browser user agent at sign-in, expiry; sign-in codes for the command-line tool; access tokens for agents connected to the hosted MCP endpoint | Keeping you signed in and securing access | Performance of the contract and legitimate interest in security |
| The Terms of Service version you accepted and the time of acceptance | Proving which contract applies | Legitimate interest and legal obligation to prove the contract |
| Organization name and identifier in internal Slack alerts | Notifying our team when an organization is created | Legitimate interest in operating the service |
| Sign-up campaign label (see below) | Measuring which campaigns bring new accounts | Legitimate interest |
| Emails we send: invitations, password resets, billing notices, delivery incident notices and provider credential notices | Operating the service | Performance of the contract |
| Messages you send to support | Answering you | Performance of the contract and legitimate interest |
| Technical logs and metrics produced by the service | Operating, securing and troubleshooting the service | Legitimate interest |
Rate limiting uses the IP address of each request in memory, to protect the service; it is not written to the database.
Sign-up campaign label
Links to Carillon may carry a campaign label in the source, s or utm_source query
parameter. When you create an account from such a link, the label is stored with your
account. Only short labels made of letters, digits, dots, underscores and hyphens are kept;
anything else is stored as invalid, and no label as direct. The label names a campaign,
not a person.
The website sets no attribution cookie, uses no browser storage, assigns no visitor identifier, and sends no request to an external analytics service. Leaving the site and coming back without a labelled link loses the label.
Cookies and browser storage
When you sign in, the dashboard sets an authentication cookie (__Host-carillon.session_token
and the related cookies of the authentication library). They are strictly necessary for the
service, HttpOnly, Secure and limited to the dashboard host. The dashboard does not store
session tokens in browser storage.
The public pages set no cookie, load no third-party script and serve their fonts from the Carillon host.
Payments
Paid plans are purchased through Stripe Managed Payments, where Stripe acts as the merchant of record and sells through Link. Stripe collects the payer's name, email address, billing address and payment details directly at checkout and processes them as an independent controller under its own privacy policy. Exostack creates a Stripe customer record that carries the Carillon organization identifier, and sends Stripe the organization's usage totals. Exostack sends Stripe no device data, app names or notification content. Exostack receives the subscription and invoice status back from Stripe.
Internal alerts
When an organization is created, Exostack sends its name and identifier to an internal Slack channel. These alerts contain no account email address, device data, provider credentials or notification content.
Recipients
| Recipient | Role | Location |
|---|---|---|
| Slack | Internal organization-creation alerts (organization name and identifier) | International, including the United States; see Slack’s privacy policy |
| Scaleway SAS | Hosting, database, transactional email, logs and metrics | European Union |
| Stripe (Link) | Merchant of record for paid plans | International, including Ireland and the United States; see Stripe’s Privacy Center |
Personnel of Exostack access personal data only when needed to operate the service or answer a request. Exostack does not sell personal data and does not use it for advertising.
Transfers outside the European Union
Exostack hosts the service in the European Union. Stripe may process payment data outside the European Union under the safeguards described in its own privacy policy. Slack may process the organization name and identifier outside the European Union, including in the United States, under the safeguards described in its privacy policy and Data Processing Addendum.
Retention
| Data | Retention |
|---|---|
| Account, organization and membership data | While the account exists, then deleted from active systems within 30 days of account closure, except where retention is required by law |
| Sessions | Expire seven days after the last use. Expired session records are deleted by daily maintenance. |
| Invitations | Expire 48 hours after they are sent. Records remain until deleted through the dashboard or the organization is closed. |
| Terms acceptance and sign-up label | With the account |
| Technical logs and traces | 7 days |
| Metrics | 31 days |
| Database backups | 14 days |
Your rights
You can ask for access to, correction of, or deletion of your personal data, ask for its restriction or portability, and object to processing based on legitimate interest. You can correct your name in the dashboard. For any other request, write to support@carillon.dev.
If you are not satisfied with the answer, you can lodge a complaint with the CNIL, the French supervisory authority (cnil.fr).
Changes
Each version of this policy is dated. Exostack will inform account holders by email of a change that affects how their data is used.