Stay Green
Back to home

Privacy Policy

Last updated: July 23, 2026

This Privacy Policy explains what data Stay Green ("we", "us") collects, why we collect it, and the choices you have. It applies to the Stay Green website and dashboard (the "Service"). We handle personal data in line with the GDPR and Brazil's LGPD.

Data we collect

Account data: your name, email address, and a securely hashed password (or passkey/two-factor credentials) that you provide when you sign up.

Slack connection credentials: to keep your status active we store the Slack session token (xoxc) and cookie (xoxd) for each workspace you connect. These are session credentials for your own Slack account.

Slack profile data: for each connected workspace we cache your display name, real name, username, email and avatar, plus the workspace name and icon, so the dashboard can show which account is connected.

Schedule data: the status text, emoji, time windows, timezone and settings you configure.

Billing data: your subscription status and history. Card details are handled entirely by Stripe — we never see or store your full card number.

Support data: the subject and message of any request you send us through the support form.

Technical data: minimal server logs and error reports needed to operate and secure the Service.

How your Slack credentials are protected

Your Slack tokens and cookies are encrypted at rest with AES-256-GCM. They are never returned to the browser, never written to logs in plaintext, and are used only to read and set your status and presence on the workspaces you connected.

Error-monitoring events are scrubbed to remove any token, cookie or authorization value before they are recorded.

How we use data

  • To provide the core Service: keeping your Slack status and presence active on the schedule you set.
  • To authenticate you and secure your account.
  • To process payments and manage your subscription (through Stripe).
  • To send transactional email — verification, password reset, billing, and reminders when a workspace connection expires.
  • To respond to support requests.
  • To detect, prevent and address abuse, security incidents and technical problems.

Legal bases

We process account, Slack-connection and schedule data to perform our contract with you. We process billing data to comply with legal obligations and to perform the contract. We rely on legitimate interests for security, fraud prevention and product operation. Where required, we rely on your consent, which you can withdraw at any time by disconnecting a workspace or deleting your account.

Sub-processors and sharing

We do not sell your personal data. We share data only with providers that help us run the Service:

  • Slack — the platform whose status you are automating (you provide the credentials).
  • Stripe — payment processing and subscription billing.
  • Our hosting and database provider — to run the Service.
  • An email delivery provider (SMTP) — to send transactional email.
  • Sentry — error monitoring, with credentials scrubbed from events.

Each processes data on our behalf under appropriate agreements.

Cookies

We use strictly necessary cookies only — the session cookie that keeps you signed in, and cookies set by Stripe during checkout. We do not use advertising or cross-site tracking cookies, so no cookie-consent banner is required.

Data retention

We keep account, schedule and connection data while your account is active. When you delete your account, that data — including your encrypted Slack credentials — is removed. Disconnecting a workspace deletes its stored credentials. Some billing records are retained where required by law. Server and error logs are kept only as long as needed to operate and secure the Service.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. You can update your details and delete your account directly from the dashboard, or contact us to exercise any of these rights.

International transfers

Our providers may process data in countries other than yours. Where that happens we rely on appropriate safeguards, such as standard contractual clauses.

Children's privacy

The Service is not directed to anyone under 16, and we do not knowingly collect their data.

Changes

We may update this policy. We will change the effective date above and, for material changes, notify you by email or in the dashboard.

Contact

Questions about this policy or your data: [email protected].