Privacy Policy
A Holdings Company LLC ("ZoneRails," "we") is the data controller for personal information processed under this policy.
Contents
1. Quick Summary
ZoneRails runs on your own hardware — as a desktop application, or as the self-hosted ZoneRails Server your team reaches through a browser. The heavy data — your DNS records, API tokens, AD credentials, user accounts, audit logs — stays on your machine or your server. We collect only what is needed to issue and enforce a license and to keep the service running. Specifically:
- We do not read, store, or transmit your DNS records or zone data to our servers.
- We do not have access to your Cloudflare API token or AD credentials. They live in your operating system's secure storage on your machine.
- We collect the email address you give us when registering a license, a device fingerprint plus your device hostname (during activation only) to bind and identify the license on a machine, and license activation/deactivation events.
- Our licensing server logs request metadata (including IP address) for security and abuse prevention; we do not use this metadata to profile or track individual users.
- We do not sell or share your personal information.
2. Scope
This policy describes how A Holdings Company LLC handles personal information collected through the ZoneRails desktop application, the self-hosted ZoneRails Server, the websites at getzonerails.com and register.getzonerails.com, and our license-issuance APIs. It does not cover data your own organisation processes on a self-hosted ZoneRails Server (such as the user accounts your administrators create or your audit logs) — for that data, your organisation is the controller.
3. What We Collect
| Category | Examples |
|---|---|
| License-registration data | Email address you submit and the product key prefix |
| Device fingerprint | A stable identifier derived from your operating system's machine UUID (/etc/machine-id on Linux, IOPlatformUUID on macOS, MachineGuid in the Windows registry), hashed by the node-machine-id library on your device. The same fingerprint persists across reinstalls of ZoneRails on the same machine and is used to bind a license to a device. |
| Device hostname | Your operating system's hostname (e.g., joes-macbook-pro.local) is transmitted once during license activation and stored alongside the fingerprint so that activated devices can be recognized by name when you activate or deactivate machines from within the ZoneRails application. It is not transmitted on routine license validation or heartbeat calls. |
| Activation events | Timestamp and device fingerprint when a license is activated, deactivated, or fails to validate; first-seen and last-seen timestamps |
| Platform string | The platform identifier reported by the Software (e.g., darwin-arm64, win32-x64) and the ZoneRails version |
| Support correspondence | Anything you voluntarily send to [email protected] |
| Server-side logs | HTTP request metadata for the licensing server, including IP address, user-agent, timestamp, and status code, retained for security and abuse prevention (see Section 8) |
| Website analytics | Aggregate visitor counts and referrers via Umami, a self-hosted, cookieless first-party analytics tool. No per-visitor profiling, no cross-site tracking. |
Neither the desktop application nor a self-hosted ZoneRails Server phones home with your DNS records, zone names, ticket numbers, change notes, or user account details. License activation transmits your license key, device fingerprint, hostname, and platform string; routine license validation and heartbeat calls transmit only your license key and fingerprint. A ZoneRails Server's heartbeat additionally reports the count of enabled user accounts (a single number, used to enforce named-seat limits) — never usernames, emails, or any other account details.
4. Why We Collect It and Our Legal Basis
For users in the European Economic Area, the United Kingdom, and other jurisdictions requiring a stated lawful basis for processing, the following bases apply:
| Purpose | Legal Basis (GDPR / UK GDPR) |
|---|---|
| Issue and enforce licenses — deliver your license key by email, bind it to your device, and detect activation abuse | Performance of a contract (Art. 6(1)(b)) |
| Provide and improve the Service — aggregate logs and crash diagnostics to identify bugs and platform issues | Legitimate interests (Art. 6(1)(f)) — operating and securing the Service |
| Communicate transactionally — license delivery, password-reset (Server tier), and security notices | Performance of a contract (Art. 6(1)(b)) |
| Marketing email — only if you have explicitly opted in | Consent (Art. 6(1)(a)), withdrawable at any time |
| Comply with law and protect rights — investigate fraud, enforce our Terms, respond to lawful requests | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
6. Third-Party Sub-processors
| Sub-processor | Purpose |
|---|---|
| Google (Gmail API) / Mailgun | Transactional email delivery (license keys, support replies) |
| Cloudflare | DNS, CDN, and DDoS protection for our marketing and license-server hosts |
| Hosting provider | Compute and storage for the licensing server |
Each sub-processor is bound by contract to use personal information only for the purposes we specify and to maintain reasonable security. A current list of named sub-processors is available on request at [email protected].
If paid tiers are introduced in the future, additional sub-processors (such as a payment processor) will be added to this list before any associated processing begins, and the change will be communicated in accordance with Section 13.
7. Cookies & Tracking
The desktop application does not use web cookies. The ZoneRails Server web interface stores a short-lived authentication token in your browser's session storage and a local preference for the active connection — both scoped to your server, never sent to us, and not used for tracking. The marketing website uses essential first-party cookies (e.g., to remember consent state) and uses Umami, a self-hosted cookieless analytics tool. The licensing server's registration form uses a single short-lived session cookie for CSRF protection. We do not use third-party advertising or cross-site tracking cookies.
8. Retention
- License records are retained for the lifetime of the license plus 24 months for support and audit purposes.
- Server-side logs (including IP addresses) are retained for 90 days unless an active investigation requires longer retention.
- Support email is retained for 24 months unless you ask us to delete it sooner.
- Tax and accounting records, if applicable in the future (e.g., upon introduction of paid tiers), will be retained per applicable tax and accounting regulations (typically 7 years).
9. Security
We protect personal information with industry-standard technical and organisational measures, including encryption of data in transit (TLS) and at rest where applicable, access controls, and regular review of our security practices. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify affected users without undue delay, and in any case within 72 hours of becoming aware of a breach where required by applicable law, consistent with GDPR Article 33.
Your Cloudflare API tokens and AD credentials are stored in your operating system's secure store (Keychain on macOS, Credential Vault on Windows, libsecret on Linux) or, on a self-hosted ZoneRails Server, encrypted at rest (AES-256-GCM) in your server's own database — in every case never on our servers.
10. Your Rights
Depending on where you live, you may have rights under GDPR, UK GDPR, CCPA/CPRA, or other privacy laws — including the right to access, correct, delete, port, or restrict processing of your personal information, the right to object to certain processing, and the right not to be discriminated against for exercising your rights.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You may also lodge a complaint with your local data-protection authority. If you are in the EEA or UK and wish to withdraw consent for any processing based on consent, you may do so at any time without affecting the lawfulness of processing carried out before withdrawal.
Self-service. From within the desktop application's Settings → License pane — or, on ZoneRails Server, the Settings drawer available to your administrators — you can deactivate and delete the stored license at any time. To delete your registration record on our servers, email us as above.
11. International Transfers
We are based in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. or in any country where our sub-processors operate. Where applicable, we rely on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent safeguards for international transfers.
12. Children
The Service is not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
13. Changes
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated via email or in-app notice.
14. Contact
Privacy questions or requests may be sent to:
A Holdings Company LLC
Email: [email protected]