Privacy

Privacy policy

This policy explains what Glacier Backups, LLC collects when you use glacierbackups.com and the Data Convoy service, how we use it, and the choices you have. Last updated September 2, 2026.

What this policy covers

This policy applies to our website at glacierbackups.com and to Data Convoy, the hosted control plane we operate (together, the "Service"). It does not cover your own AWS account or software you run in your own infrastructure, which are governed by your agreements with those providers.

Information we collect

We collect only what is needed to run your account and the workflows you configure.

Account details

Your email address, your name, and the teams and roles you hold.

Sign-in and security data

One-time sign-in codes, session records, and the IP address and browser details attached to authenticated requests and audit events.

Team configuration

Bucket names and prefixes, schedules, exclusion rules, and worker registrations.

Job and audit metadata

What moved, when, its outcome, and who authorized it.

Usage measurements

Bucket sizes reported by your workers, used to enforce free-tier limits and meter paid usage.

Billing details

Your AWS Marketplace customer and entitlement identifiers, or the contact and invoicing details for a direct-pay plan.

Messages

Anything you send us through the contact form or by email.

What we never hold

The objects you archive, back up, or restore never pass through the Service. They move between buckets in your own AWS account, copied by workers you run with credentials you control, and Glacier Backups holds no credentials for your AWS account. S3 keys and paths are treated as sensitive: each record is encrypted at rest with its own data key, sealed to your team's key, and is not stored in cleartext in our database.

How we use information

We use this information to operate the Service: to sign you in, scope teams and jobs to the people authorized to see them, run the archive, backup, and restore workflows you configure, and keep an audit trail for your team. We also use it to detect abuse and secure the Service, provide support, bill paid plans, and meet our legal obligations. We do not sell personal information and we do not use it for advertising.

Cookies and analytics

The Data Convoy app sets a signed session cookie to keep you signed in and, during AWS Marketplace registration, a short-lived cookie to complete account linking. The website sets no cookies and uses no third-party analytics or advertising trackers; it stores only your light or dark theme preference in your browser.

Who we share it with

We share information only with the providers we need to run the Service, and only for that purpose. We may also disclose information when the law requires it, to protect the rights and safety of our users or the public, or as part of a merger or sale of the business, in which case this policy continues to apply.

Amazon Web Services

Hosts the application and, if you subscribe through AWS Marketplace, processes your subscription and metered usage.

Resend

Delivers our transactional email, such as sign-in codes and account notifications.

Retention and deletion

We keep account, team, and job data while your account is active. Older team audit records are exported to a log bucket in your own AWS account before they are removed from our database, so the history stays in infrastructure you control; if no log bucket is configured, they are retained. Deleted teams and jobs are purged after a short retention window. To close your account, email us; we delete the data tied to it within 30 days, except records we must keep for billing, security, or legal reasons.

Security

We protect the Service with the measures described on the Data Convoy security page, including encryption of sensitive metadata at rest, per-team key boundaries, hashed sign-in codes and worker tokens, and audit logging of privileged actions. No system is perfectly secure. If a breach affects your personal data, we will notify you as required by law.

Your rights and choices

You can ask us to access, correct, export, or delete the personal data we hold about you by emailing [email protected]. We respond within 30 days. Depending on where you live, you may have additional rights under local law, such as the GDPR or CCPA; we honor those rights where they apply and will not treat you differently for exercising them. Transactional email such as sign-in codes cannot be turned off while your account is open.

International transfers

Glacier Backups is based in the United States and processes data there. If you use the Service from elsewhere, your information will be transferred to and stored in the United States.

Children's privacy

The Service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18; if we learn we have, we will delete it.

Changes to this policy

We may update this policy from time to time. For material changes we will notify account owners by email or an in-product notice before they take effect. The date at the top shows the latest revision.

Contact

This policy is issued by Glacier Backups, LLC, 30 N Gould St, Suite #67516, Sheridan, WY 82801. Send questions or requests about your personal data to [email protected].

Your buckets. Your workers. Your control.

Make the next archive reversible.