Privacy Policy
Last updated: 11 September 2026
This Privacy Policy explains how Elyne Consulting AB, a Swedish limited company (aktiebolag) with organisation number 559479-3373 (“Metrostack,” “we,” “us”), processes personal data when you use the Metrostack website, applications, waitlist, and related services (the “Service”). Elyne Consulting AB is the data controller for that processing under the EU General Data Protection Regulation (GDPR).
All contact with us about privacy, including requests to exercise your rights, shall be made by email to metrostack@elyneconsulting.com.
1. What Metrostack Is, in Privacy Terms
Metrostack is a crowdsourced database of companies, offices, and teams, including their technology stacks and AI-usage practices. The database itself is about organisations, not people. The personal data we process is mostly what we need to run your account, credit your contributions, and understand whether the product works during its beta.
2. The Personal Data We Process, Why, and on What Legal Basis
2.1 Account and authentication. When you create an account we process your email address and a password. The password is stored only as a salted hash by our authentication provider; we never see or store it in plain text. We also process session cookies and the technical sign-in metadata our authentication provider keeps (such as the time of your last sign-in). Legal basis: performance of our contract with you (Art. 6(1)(b)).
2.2 Terms acceptance. When you accept the Terms of Service we record your user id, the version accepted, and the time. Legal basis: our legitimate interest in being able to show that you agreed to the Terms (Art. 6(1)(f)).
2.3 Waitlist and invitations. If you join the waitlist we process your email address, a referral code, which existing waitlist member referred you (if any), an unguessable token that forms your personal status-page link, and when and by whom you were invited. Legal basis: steps taken at your request before entering a contract (Art. 6(1)(b)).
2.4 Contributions and rewards. Companies, offices, teams, technologies, relationships, and AI-usage details you contribute are linked internally to your user id so that we can credit you. We keep a ledger of your contribution events and compute your points, level, achievements, and any premium-access windows you earn. Your name or email is not shown publicly next to a contribution. Legal basis: performance of our contract with you (Art. 6(1)(b)).
2.5 Product usage telemetry (first-party only). To learn whether Metrostack is useful we record a small set of in-product events against your user id: when a session starts, which company dossiers you open, searches that returned no results (including the text you searched for, so we know what is missing), contributions you make, when a premium gate is shown and which button you click, when the one-time product survey is shown and how you answer it, when you dismiss the welcome screen, and which offices you bookmark. This data is analysed only by us, in aggregate, in an internal admin view. We do not use third-party analytics or advertising tools and we do not build advertising profiles. Legal basis: our legitimate interest in understanding and improving a beta product (Art. 6(1)(f)). You may object to this processing (see Section 6).
2.6 Feedback and reports. If you send feedback, answer the product survey, or file a bug report or feature idea from inside the app, we process what you wrote, the page you sent it from, and your email address so that we can follow up. Legal basis: our legitimate interest in responding to feedback you chose to send (Art. 6(1)(f)).
2.7 Technical and security logs. Our servers write structured logs for each request: method, path, status code, duration, a correlation id, and, for signed-in requests, your user id and email address. We also use your IP address transiently, in memory only, to rate-limit the waitlist form and the browser-telemetry endpoint; the IP address is not written to our database. Legal basis: our legitimate interest in the security, reliability, and troubleshooting of the Service (Art. 6(1)(f)).
2.8 Emails we send. We send transactional emails only: waitlist invitations, email verification, and password resets. We do not send marketing email. If we introduce a newsletter in the future we will ask for your separate consent first. Legal basis: performance of our contract with you (Art. 6(1)(b)).
3. Who We Share Personal Data With
We do not sell personal data. We share it with the following service providers, who process it on our behalf under data-processing agreements, or who receive it directly from your browser:
- Supabase(Supabase Pte. Ltd, Singapore) — authentication and database hosting. Our production database is hosted in Germany. Supabase’s support team operates from the United States.
- Mailtrap(Railsware Products Studio LLC, United States) — delivery of the transactional emails in Section 2.8. Mailtrap processes and stores data in the United States.
- Slack(Slack Technologies Limited, Ireland, part of Salesforce) — we post internal notifications to a private Slack workspace when you join the waitlist, a contribution is made, feedback or a survey answer is submitted, or an AI-usage overview changes. Those notifications include your email address and a summary of the event, and are stored in the United States.
- GitHub, Inc.(United States) — bug reports and feature ideas you submit are filed as issues in a private repository stored in the United States. The issue contains your report and an internal user id, not your email address or name; GitHub cannot connect it to you.
- Mapbox, Inc.(United States) — the map is rendered from Mapbox tiles that your browser requests directly; Mapbox therefore sees your IP address and the map areas you view. Mapbox keeps IP addresses for 30 days.
- OpenStreetMap Foundation (Nominatim)— when you search for an address or place a pin, your browser sends the text you typed, or the coordinates, and your IP address directly to the Nominatim geocoding service.
- Our own infrastructure— the application and our log and trace storage run on servers located in the European Union (Germany or the Netherlands).
We may also disclose personal data when required by law, a court order, or a regulatory demand, or to establish, exercise, or defend legal claims.
The company, office, and team data you contribute is not your personal data. As described in the Terms of Service it may be published, licensed, and distributed; it is not linked to your identity when it is.
4. International Transfers
Our application, our logs, and our primary database are hosted in the European Union. Some of the providers in Section 3 process personal data outside the EU: Slack (Salesforce), Mapbox, and Mailtrap in the United States, and Supabase, whose contracting entity is in Singapore and whose support staff work in the United States. GitHub receives only a pseudonymous user id together with your report.
For transfers to the United States we rely on the EU-US Data Privacy Framework. Salesforce (covering Slack), Mapbox, and Railsware (Mailtrap) are certified under it. For Supabase, and as a fallback for the others, we rely on the European Commission’s Standard Contractual Clauses, which each provider has incorporated into its data-processing agreement with us. The OpenStreetMap Foundation is established in the United Kingdom, which the European Commission has recognised as providing adequate protection.
5. How Long We Keep Personal Data
- Account data: for as long as your account exists. When your account is deleted, your email address and authentication data are removed from our systems. We keep a record of the deletion itself (the reason you gave, and how much you had used the Service) under your former user id, which no longer maps to any person.
- Contributions and reward history: kept after account deletion, because the database depends on them, but disconnected from your identity: the user id that remains no longer maps to any email address or person.
- Waitlist entries: until you are invited and create an account, until you ask us to remove you, or 12 months after joining if you are never invited.
- Usage telemetry and feedback: up to 24 months, after which entries are deleted or reduced to aggregate statistics.
- Technical logs: 30 days.
- Copies in Slack and GitHub:subject to those services’ retention; we delete the Slack copies on request where the service allows it. The GitHub copies contain no personal data.
6. Your Rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data (you can change your email and password in the app; contact us for anything else);
- erase your data, including deleting your account. You can delete your account yourself at any time from the menu in the app (Delete account). We ask for your reason and confirm with your password; the deletion is immediate and cannot be undone. Your email address, sign-in, contributor profile, reward grants, bookmarks and Terms acceptances are removed, and your contributions are disconnected from your identity as described in Section 5. For anything the app cannot delete for you, email us and we will do it within one month;
- restrict processing in the circumstances set out in the GDPR;
- receive the data you provided to us in a portable, machine-readable format;
- object to processing based on our legitimate interests, in particular the usage telemetry in Section 2.5. If you object we will stop recording those events for your account unless we can show compelling legitimate grounds;
- withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before the withdrawal.
To exercise any right, email metrostack@elyneconsulting.com. We may ask you to verify your identity, normally by writing from the email address on your account. We respond within one month, extendable by two further months for complex requests, in which case we will tell you.
You also have the right to lodge a complaint with a supervisory authority. In Sweden that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se. You may also complain to the authority in the EU country where you live or work.
7. Cookies and Local Storage
We use only cookies and browser storage that are strictly necessary to run the Service:
- Authentication cookies set by our authentication provider (names beginning with
sb-) keep you signed in. auth_recovery, a cookie that lives for at most 10 minutes, carries you through the password-reset and invitation flows.- A session flagin your browser’s session storage ensures that one visit is counted once for the telemetry in Section 2.5. It is cleared when you close the tab.
We do not use advertising, tracking, or third-party analytics cookies, so we do not show a cookie banner. You can delete cookies through your browser settings; the Service will sign you out when you do.
8. Security
We protect personal data with encryption in transit (TLS), hashed password storage, access limited to the people who need it to operate the Service, and separate database roles for the application and for administration. No system is perfectly secure; if we become aware of a personal-data breach that is likely to put your rights at risk we will notify you and the supervisory authority as the GDPR requires.
9. Personal Data About People in Contributions
Metrostack is about organisations. Contributors must not enter personal data about individuals, such as names, contact details, or opinions about specific people, into company, office, or team records. If you believe a contribution contains personal data about you, or is otherwise inaccurate, email metrostack@elyneconsulting.com; we will assess and, where required, remove or correct it, as described in the Terms of Service.
10. Automated Decisions
Your contributor level and any premium-access windows are calculated automatically from the points you earn. These calculations affect only which features of the Service you can use; they have no legal or similarly significant effect on you, and we do not use automated decision-making or profiling of that kind.
11. Children
The Service is for adults. You must be at least 18 years old to create an account, and we do not knowingly process personal data about anyone younger. If you believe we hold such data, contact us and we will delete it.
12. Changes to This Policy
We may update this Policy when the Service or the law changes. If a change is material we will notify you through the Service before it takes effect. The date at the top shows when the Policy was last revised.
13. Contact
The Service is operated by Elyne Consulting AB (org. no. 559479-3373), Sweden. All contact with us regarding this Policy, your personal data, or your rights shall be made by email to metrostack@elyneconsulting.com.