Relay Privacy Notice
Effective: August 29, 2026
This Privacy Notice explains how Tidestone Technologies LLC (“Tidestone,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with Relay and related services (the “Service”). Relay is a product of Tidestone.
Relay is intended for business and professional use. A business customer (“Customer”) controls its Relay organization and decides which users, recipients, integrations, and operational information to place in Relay.
Tidestone's business address is:
Tidestone Technologies LLC
1968 S. Coast Hwy #5307
Laguna Beach, CA 92651
1. Scope and Our Roles
This Notice applies to Relay's public website, public status pages, web application, mobile applications, authentication, billing, operational coordination, monitoring and testing, alerts and notifications, integrations, APIs and imports, automation, artificial-intelligence-assisted features, support, and related operations.
Our role depends on the information and purpose:
- Customer-controlled operational and status-page data. We generally act as a processor or service provider when we process personal information solely on a Customer's instructions, such as operational, incident, schedule, responder, monitoring, integration, workflow, automation, analysis, generated-output, alert-recipient, Customer status-page, and Page Subscription destination, consent, preference, and delivery information. The Customer determines the purposes, content, recipients, and lawful basis. Our Data Processing Terms apply.
- Tidestone's Status Page. For the Status Page assigned to
/relay, Tidestone determines the publication and subscription purposes and acts as an independent controller. This may include enrollment in that Page after a Relay account email first becomes verified, subject to the controls below. - Tidestone business, safety, and account operations. We act as an independent controller and, where applicable, a business under privacy law when we create and secure individual Relay accounts, operate authentication and sessions, administer billing, maintain communications suppression and delivery-compliance records, receive product Feedback, prevent abuse, investigate complaints, comply with law, manage our support relationships, and run our business. When Relay applies Customer-configured memberships, roles, or organization access to an account, that processing remains subject to the processor terms above. Customer-controlled operational or status-page content included in product Feedback, a support request, safety review, or compliance record also remains subject to those terms, while we act independently for our own limited Feedback, relationship, safety, and compliance records.
If you use Relay for an employer or another organization, that organization may have its own privacy notice and may be the appropriate contact for questions about its operational data.
2. Information We Collect
We collect the following categories, depending on how Relay is configured and used.
2.1 Account, Identity, and Contact Information
- name, display name, first and last name, profile color, timezone, and time-format preference;
- email addresses and phone numbers, primary-contact status, verification status, and delivery-suppression status;
- authentication identity, login-provider identifiers, token and session metadata, and account state;
- login credentials submitted directly to AWS Cognito's managed authentication flow or a selected identity provider; Relay does not intentionally store plaintext account passwords;
- organization memberships, roles, permissions, invitations, invite status, and active-organization selection;
- identity-provider and directory attributes, external subject identifiers, groups, provisioning and deprovisioning state, and role or membership synchronization records; and
- notification preferences, alert policies, Incident-following settings, quiet hours, and communication-channel choices.
2.2 Organization and Operational Information
- organization name, configuration, billing arrangement and status, services, teams, tags, roles, and policies;
- schedules, rotations, on-call assignments, shifts, overrides, maintenance windows, readiness, and availability-related information;
- incidents, Signals, titles, notes, status, urgency, services, tags, responders, acknowledgements, resolutions, timelines, source history, and audit records;
- connected-system resources, health, status, topology, telemetry, logs, errors, monitoring and test results, code, version-control and deployment metadata, documentation, runbooks, and imported knowledge or operational content;
- tasks, workflows, automations, forms, reports, dashboards, metrics, trends, analyses, summaries, recommendations, drafts, prompts and instructions, retrieved context, actions, and other Customer-specific records and outputs; and
- user actions and change history needed to operate and account for activity in Relay.
Operational information may identify employees, contractors, responders, recipients, or other people mentioned in Customer-controlled operational data.
2.3 Integration and Provider Information
- content, files, payloads, events, external-resource and directory identifiers, source and destination context, permissions, configuration, and related metadata received from or sent to Customer-directed services;
- health, status, monitoring, test, log, error, cloud-resource, code, version-control, deployment, documentation, knowledge, communication, and collaboration information a Customer instructs Relay to receive or retrieve;
- provider-specific information, such as Datadog monitor state, priority, tags, scope, notes, links, and service context, and Slack workspace, app, user, channel, mapping, scope, permission, health, command, interaction, and automation data; and
- provider credentials or secrets submitted through a field designed for that purpose. Production storage provides infrastructure-level encryption at rest. Slack installation credentials and Status Page command-credential token material also receive application-level encryption; not every supported integration credential uses that additional layer. We restrict access and avoid exposing supported credentials in ordinary customer-facing responses, audit differences, or logs.
Depending on the Slack features a Customer or authorized user uses, invokes, configures, or enables, Relay may receive messages, replies, files, reactions, sender and participant identifiers, timestamps, links, conversation identifiers and context, and related metadata available to the installed app. Relay may process this information in response to a user action or through a Customer-configured workflow or automation to search, retrieve, classify, correlate, summarize, or analyze content from Customer-authorized sources; create or update Customer records; and provide Customer-specific recommendations, actions, or other outputs. Connecting Slack or granting technical permissions without using or enabling an applicable feature does not by itself cause Relay to collect conversation history.
A record or output created from Slack content is Customer-controlled operational data and may not automatically change when the source is later edited or deleted in Slack. Relay does not use Slack API data or information derived from it to train a large language or other machine-learning model, bulk-export Slack message or file data, or use one Customer's Slack API data to benefit another Customer or a third party. This does not prevent Relay from using automated systems or an authorized service provider to produce the Customer-specific result a Customer requests, provided the Slack API data is not used to train a model.
2.4 Public Status Page and Report Information
- status-page name, hosted slug, theme, links, selected organization name and normalized logo or favicon variants, public service, Incident, and Maintenance information, including schedules and lifecycle state, revision and publication history, and page or content safety state;
- public Status Page Subscription email destinations, consent origins, account associations, lifecycle state, and selected Incident, Maintenance, and Component preferences;
- scoped Status Page command-credential names, scopes, lifecycle and protection metadata, command results, and related audit evidence; ordinary lists, logs, and audit records do not contain the plaintext token; and
- status-page abuse, impersonation, phishing, intellectual-property, and other rights reports and our response history.
2.5 Alert, Notification, and Delivery Information
- email and phone destinations, mobile push tokens, app variant and version, device and operating-system metadata, and primary-device selection;
- message or call content selected for delivery, channel, destination, status, attempt, provider reference, error or suppression reason, and timestamps;
- delivery receipts, push interactions, acknowledgement actions, STOP/START and email-unsubscribe state, and readiness checks; and
- browser-notification permission and local notification settings.
2.6 Billing Information
- internal Relay signup and user identifiers, accepting-account email, legal-bundle metadata, billing arrangement, applied offer, one-way offer-code digest, redemption status, selected plan or price, billing interval, quantity or usage metric, and starting amount;
- for provider-billed organizations, the signup, legal, plan, price, offer, quantity, usage, and other order information Relay sends to the billing provider identified at checkout, such as Stripe;
- purchaser-entered billing-contact changes, billing address, payment information, and tax or exemption information supplied directly to that provider when its hosted flow requests the information;
- device, network, cookie, and fraud- or risk-assessment information the provider collects directly in its hosted flow under its privacy notice; and
- customer and purchaser-contact details, billing country, checkout, subscription, promotion, price, invoice, payment-status, adjustment, proration, credit, cancellation, and billing-history identifiers and metadata the provider returns to Relay for validation and records.
When provider billing is used, payment details are submitted directly to the billing provider identified at checkout. Relay does not intentionally store full payment-card or bank-account numbers or card security codes.
2.7 Support and Communications
- Help conversation titles, messages, status, urgency flag, resolution, and message history;
- Help attachment files, information and metadata contained in those files, original filename, media type, byte size, uploader and organization identifiers, ticket and message association, upload state, and upload, attachment, and expiry timestamps;
- requester or guest email, organization and user references, and limited page or route context submitted with a support request; and
- product ratings, corrections, suggestions, research responses, and other Feedback submitted for Tidestone's product-improvement purposes; and
- privacy, billing, legal, security, and other communications with Tidestone.
2.8 Device, Network, Security, and Diagnostic Information
- IP address, user agent, browser or app information, device and installation identifiers, requested route, HTTP method and status, request identifier, timing, and source metadata;
- necessary cookies, local storage, mobile secure storage, authentication state, demo-session state, and rate-limit identifiers;
- application, database, infrastructure, security, delivery, request, and provider diagnostics and logs; and
- error, performance, health, and diagnostic information.
3. Sources of Information
We receive information:
- directly from you when you create or use an account, configure Relay, contact support, or make a privacy request;
- from the Customer and its administrators, coworkers, invite issuers, and other authorized users;
- from Customer-directed integrations, APIs, imports, agents, connected systems, and external or public services a Customer selects, such as Slack, Datadog, and webhooks, including content and metadata an authorized user submits, selects, invokes, or authorizes a configured workflow or automation to receive or retrieve;
- automatically from browsers, apps, devices, networks, cookies, storage, and Relay's infrastructure;
- from delivery providers and telecommunications networks;
- from the billing provider identified at checkout, including Stripe, for checkout, billing, invoices, and subscription management when a provider-billed arrangement is used; and
- from identity and directory providers used to authenticate, provision, manage, or deprovision an account or organization access.
4. How We Use Information
For Customer-controlled operational data, we process personal information only for the processor purposes and documented instructions described in the Data Processing Terms. For information we control independently, and for processor data where the applicable instruction permits, we use personal information to:
- create, authenticate, secure, and administer accounts and organizations;
- provide operational coordination, incident response, on-call, monitoring, communications, collaboration, workflows, automations, integrations, billing, support, and related Customer-configured features;
- validate, store, display, and deliver Help attachments as part of the applicable support conversation;
- organize, index, search, classify, correlate, analyze, transform, and summarize Customer-controlled information and create Customer-specific records, reports, recommendations, drafts, actions, and other outputs through features a Customer or authorized user uses, invokes, configures, or enables;
- monitor or test Customer-connected systems and workflows and create alerts, incidents, records, or automated actions as instructed;
- publish Customer-selected information and normalized assets through public pages, feeds, embeds, communications, APIs, and other publication surfaces Customer enables;
- import, export, and route information and communications through APIs, agents, providers, and destinations selected by Customers and users;
- operate, maintain, and troubleshoot Relay;
- test and improve Relay using controller-scope, aggregated, or de-identified information;
- receive, evaluate, and use product Feedback as described in the Customer Terms while keeping embedded Customer Data subject to Customer's instructions;
- understand service health and reliability;
- prevent fraud, abuse, unauthorized access, and security incidents;
- honor delivery preferences and suppression, investigate complaints, and preserve necessary compliance and delivery evidence;
- enforce contracts and protect rights, safety, and the Service;
- send service, security, support, onboarding, and product-education communications, subject to applicable preferences and law;
- resolve offers and administer billing arrangements, payments, subscriptions, invoices, quantity or usage changes, credits, and cancellations;
- comply with law and respond to valid legal process; and
- create aggregated or de-identified information that does not reasonably identify a person or Customer.
Relay may use automated systems, including artificial intelligence, to carry out a Customer's instructions and produce Customer-specific results. We do not use Customer-controlled operational or status-page data, including Help content and attachments, or information derived from that data to train or improve a generalized artificial-intelligence or machine-learning model. We may otherwise use aggregated or de-identified information for the non-training purposes described above.
Where non-U.S. law requires a legal basis for our controller processing, we rely as appropriate on performance of a contract, legitimate interests in operating and securing Relay and our business, compliance with legal obligations, and consent where required. The Customer determines the legal basis for Customer-controlled operational data.
5. How We Disclose Information
We disclose personal information only as described below.
5.1 Service Providers and Subprocessors
We use providers for hosting, identity, email, billing, telecommunications, mobile push, monitoring, security, and other operations. Relay may use an authorized provider for artificial-intelligence-assisted functionality when a Customer selects a feature that requires it. A provider that processes Customer Personal Data for Relay is identified in the current Subprocessor List before that processing begins.
5.2 Customer and Authorized Users
We make organization information available according to Customer configuration, organization membership, Relay permissions, and Relay administrator access. Normal organization members may read organization data that Relay makes generally available to members; sensitive actions and surfaces use additional permissions. Customer administrators control membership and most organization roles.
Private Help attachments are available through Relay only to participants authorized for the applicable support conversation and authorized Tidestone support personnel. Relay stores hosted attachment objects with its hosting provider and does not make the attachment bucket or object URL public.
5.3 Customer-Directed Recipients and Integrations
We send information to users, responders, communication channels, providers, connected systems, and other recipients or destinations selected or configured by Customer or its users. Those recipients and services may use the information under their own terms and privacy notices.
5.4 Public Status Pages
When a Customer publishes a status page, anyone may view the Customer-selected status copy, organization name, service, Incident, and Maintenance information, including schedules and lifecycle state, links, and normalized logo or favicon variants included in that publication. Public material may be indexed, cached, copied, or redistributed by third parties. Uploading an asset alone does not publish it. Relay publishes an organization asset only after an authorized user enables it for status-page reuse and publishes a page or revision that includes it.
People may subscribe an email destination to selected public Status Page updates and manage that consent anonymously or through an associated verified Relay account email. Authorized Page managers receive only the documented masked subscriber and categorical delivery projections.
We do not publish Customer-private operational content, original asset uploads, account data, report contact information, or complaint evidence on a status page.
Status Page Subscription Consent and Communications
Anonymous signup uses double opt-in. A signed-in Relay user may immediately subscribe an address already verified on that account. Account association adds authenticated management but does not change the destination's authority, consent provenance, or anonymous management path.
Changing a Relay account email does not silently move a Status Page Subscription. A user may move or merge a Subscription into another verified account email or unlink it from account management. On personal-account deletion, a Subscription that began anonymously returns to anonymous management; an account-created Subscription is unsubscribed unless the user explicitly retains it for anonymous management.
Relay may automatically enroll a primary account email in the Status Page assigned to /relay when that email first becomes verified after enrollment is enabled. Relay does not backfill earlier verified users, provides a disclosure with immediate Page-level management and unsubscribe, and does not automatically reactivate an address that withdrew or opted out.
Status email is operational Page communication and does not contain promotion, cross-sell, or generic Relay Notification content. It uses a stable Page/list identity, Page-level one-click unsubscribe, and visible management and Page-unsubscribe actions when applicable. Page unsubscribe changes only that Page Subscription. A separate global block writes shared communications suppression, which overrides eligible Status email without changing Page-level consent.
If a Page's Status channel is quarantined, new signup, confirmation or resend, broadcast planning, and unhanded Status delivery stop, and unsent Status broadcasts are discarded. Public Page authoring and reading and existing preference, manage, and unsubscribe paths remain available. Recovery applies only to future eligible work and does not clear Page opt-outs, global suppression, bounce or complaint state, or safety history.
5.5 Legal, Safety, and Security
For Customer Personal Data, we disclose only as authorized by the Agreement, Data Processing Terms, Customer instructions, or law. For controller-scope information, we may disclose when we reasonably believe disclosure is necessary to comply with law or valid legal process; protect rights, safety, or property; investigate fraud, abuse, or a security incident; enforce agreements; or establish, exercise, or defend legal claims.
5.6 Business Transactions
We may disclose controller-scope information under appropriate confidentiality protections in connection with financing, diligence, a merger, acquisition, reorganization, sale of assets, or similar transaction. We disclose Customer Personal Data in such a transaction only as authorized by the Agreement, Data Processing Terms, Customer instructions, or law. A successor may receive Customer Personal Data only after assuming the applicable Agreement and data-protection obligations.
5.7 Professional Advisers
We may disclose limited controller-scope information to lawyers, accountants, insurers, auditors, and other professional advisers who need it and are subject to appropriate confidentiality duties. An adviser may receive Customer Personal Data only when authorized as a Subprocessor or when Customer instructions or law permit the disclosure.
6. No Sale, Targeted Advertising, or Cross-Site Tracking
Relay does not sell or share mobile information with third parties for promotional or marketing purposes.
We do not sell personal information for money, share it for cross-context behavioral advertising, or use it for targeted advertising. We may use first-party or service-provider analytics and similar technologies to measure use, performance, and reliability, improve Relay, and protect the Service, but not for cross-context tracking or advertising. We honor opt-out preference signals where applicable; because we do not sell or share personal information for cross-context behavioral advertising, those signals do not otherwise change these practices.
Third-party services may collect information when you leave Relay for their site, use their app, or enable an integration. Their collection is governed by their own notices. Relay does not permit a third-party advertising network to track people across Relay's authenticated product surfaces.
7. Cookies and Similar Storage
Relay uses cookies and similar storage for authentication, security, session continuity, preferences, app operation, demo access, rate limiting, notification coordination, and, when enabled, service analytics and improvement.
Examples include secure authentication and demo-session cookies, browser storage for interface and notification coordination, and mobile secure storage for authentication state. A public demo uses separate session, re-access, and rate-limit cookies. Where law requires consent for nonessential storage, Relay requests it before use.
You can block or clear browser storage, but doing so may sign you out, remove preferences, prevent demo re-access, or impair Relay functions.
8. Retention
We retain information only as long as reasonably needed for the purposes described in this Notice, Customer instructions, security, legal compliance, disputes, and operation of Relay. Retention depends on the type of information, the Customer's use of Relay, contractual commitments, configured lifecycle controls, and legal requirements.
Customer-controlled operational data is retained while the applicable Service is active and is returned or deleted under the Data Processing Terms after processing ends. During or after the term, export and deletion may be completed through functionality Relay makes available or through a verified request. Unless Customer configures or requests a supported lifecycle, most core operational, audit, billing, and public-status history does not use a fixed automatic deletion schedule. Limited account-security tombstones and billing, Feedback, security, support-relationship, communications-suppression, and legal records may be retained as needed for those purposes. Selected diagnostics, rate-limit records, delivery ledgers, demo state, provider records, logs, and backups follow configured or provider-controlled lifecycles.
Help attachments associated with a message follow the applicable Help conversation and Customer-controlled operational data lifecycle. Upload reservations expire under the applicable product controls and cannot then be uploaded or attached. A file uploaded but never attached may remain in protected storage until applicable cleanup or Customer-data disposition. Personal-account deletion does not erase an attachment or related history owned by a Customer. Attachment reservation metadata included in request telemetry follows that telemetry's configured lifecycle.
When an integration-connected feature creates a Relay record or other output, that result follows the Customer-controlled operational data lifecycle and does not necessarily track later edits or deletion in the source service. Raw or temporary integration content used for a Customer-instructed function follows the applicable feature controls, Customer instructions, provider requirements, and the Data Processing Terms.
Public Status Page content, publication revisions, normalized assets, Subscription consent provenance, preferences, lifecycle and opt-out history, limited delivery and complaint evidence, and safety evidence are retained according to Customer instructions, page lifecycle, security needs, communications compliance, and legal obligations. Unpublishing content does not immediately remove protected backup copies or copies independently cached, indexed, or retained by third parties.
Archiving an organization is retention, not deletion, and does not cancel its provider-billed subscription, end an externally billed commitment, or otherwise change its billing arrangement. Removing a person from one organization ends that membership but does not automatically delete the person's Relay account or rewrite historical operational records.
Personal-account deletion removes or redacts the active account data described in Section 9.2. Relay keeps the deleted account's stable internal user UUID and exact login-provider identifiers issued by Cognito and configured enterprise identity providers as security and integrity tombstones. Retaining these identifiers prevents a stale identity-provider callback or upstream identity from recreating, claiming, or authenticating the deleted account.
Customer-owned incident, schedule, support, audit, billing, and provider-delivery history is not rewritten as if the deleted person's activity never occurred. Those records, communications-suppression contacts, diagnostics, backups, and other integrity-preserving or legally necessary records may retain a stable user UUID, contact destination, or provider identifier, or follow their normal bounded lifecycle, where reasonably needed for Customer operations, security, legal compliance, disputes, fraud prevention, suppression, or legal claims. Where direct identifiers are removed but retained history can still be resolved through the deleted-user tombstone, that history is pseudonymized, not anonymous. Records that still contain a contact destination or provider identifier remain personal information.
Deletion does not promise immediate or perfect erasure from provider systems, logs, backups, or rare operations already in flight. Residual copies may remain temporarily in protected backups or logs, and an in-flight operation may create or update a record after deletion; those records remain subject to the applicable retention and deletion lifecycle described above. Third parties apply their own retention terms when acting independently.
9. Your Choices and Privacy Requests
9.1 Product Controls
Depending on your account and permissions, Relay lets you update profile information, email addresses, phone numbers, notification preferences, quiet hours, Incident-following settings, public Status Page Subscriptions, alert policies, device registrations, and integration mappings. Signed-in non-demo users may also permanently delete their personal Relay account through the account-deletion page on the web or the signed-in account-deletion screen in the Relay mobile app. Some verified or historical records cannot be changed through those controls.
9.2 Personal-Account Deletion
The public account-deletion page explains the workflow and is the signed-in web initiation route. The Relay mobile app provides the same self-service personal-account deletion through its native signed-in screen. Personal-account deletion is separate from organization archive, Customer-data export, or Customer-data deletion and does not delete an organization's operational data.
Relay checks eligibility across every active organization membership before showing the action and rechecks it when deletion is confirmed. Deletion is blocked while you are the sole active administrator of any organization, including an archived organization, or while you have an unresolved organization signup. Relay provides administration, billing, and support recovery paths where they apply. You may need to transfer administrator access, address billing for an affected organization, or finish a pending signup or contact support before trying again.
After a successful confirmed deletion, Relay:
- deletes every actively linked Cognito user and disables Relay sign-in;
- ends all active organization memberships and retires current responder assignments, schedule and team participation, membership-owned Incident follows, and related member-specific projections;
- removes active email and phone records, verification state, collaboration mappings, and mobile push registrations;
- revokes unused account-activation grants while retaining the login-provider identifiers needed to prevent reassignment or stale sign-in;
- clears or replaces personal profile fields with the deleted-user tombstone; and
- removes or redacts current personal notifications, runtime state, queued deliveries, and recipient-owned delivery content.
If Cognito deletion is temporarily unavailable, Relay leaves the local account intact so the signed-in user can try again. After successful deletion, Relay disables account access and the initiating client begins sign-out and local credential cleanup. The retained records and limitations described in Section 8 still apply, including the internal user and login-provider tombstones and pseudonymized Customer-owned history.
Status Page Subscriptions follow the destination-owned controls in Section 5.4. Originally anonymous Subscriptions return to anonymous management. Account-created Subscriptions are Page-unsubscribed unless the user explicitly elects to retain them anonymously. Shared communications-suppression and limited compliance evidence remain subject to their ordinary retention.
9.3 Access, Correction, Export, and Other Privacy Requests
Depending on applicable law, you may ask to access, correct, export, delete, restrict, or object to processing of personal information, or withdraw consent for future processing that relies on consent, by:
- starting a signed-in Help conversation when available; or
- using the protected contact method in the Company and Contact Notice with the subject
Privacy Request.
We may ask for information needed to verify identity, authority, account, organization, and request scope. We will respond using the process and timing required by applicable law.
If the request concerns Customer-controlled operational data, we may direct you to the Customer and will assist the Customer as required by our Data Processing Terms and applicable law. We will not disclose another person's or Customer's data in response to your request. You may also use these request methods when self-service personal-account deletion is unavailable or does not address the scope of your request.
Tidestone will determine the records in scope, the role in which it holds them, and any lawful retention requirement. Historical Customer-controlled operational records are not automatically deleted merely because one user leaves an organization, completes personal-account deletion, or makes a privacy request.
You may use an authorized agent where applicable law permits. We may require proof of the agent's authority and may still verify your identity directly. We will not discriminate against you for exercising an applicable privacy right.
9.4 Appeals and Complaints
If applicable law gives you a right to appeal our decision, reply to the decision with the subject Privacy Appeal and explain why you believe it should be reconsidered. You may also complain to the privacy or data-protection authority in your jurisdiction.
10. Security
We use technical and organizational safeguards designed for the nature of Relay and the information it processes. Public production traffic and supported provider connections use encrypted transport. Production databases, backups, caches, block storage, private Help-attachment object storage, and managed secret resources are configured for infrastructure-level encryption at rest. Slack installation credentials and Status Page command-credential token material stored by Relay also use application-level encryption; other supported integration credentials may rely on infrastructure encryption, access controls, restricted responses, and audit redaction rather than a separate application-encryption layer. Help attachments use authenticated access limited to authorized participants in the applicable support workflow and authorized Tidestone support personnel, together with private object storage. Relay validates the declared size and a supported media signature, but that validation is not a malware scan or a guarantee that a file is safe or free of hidden or embedded information. Additional measures include tenant and permission controls, logging and monitoring, backups, and deployment and recovery controls.
No system is completely secure. We do not promise that Relay will prevent every unauthorized access, loss, or security incident. Customers should use appropriate account, role, invitation, integration, device, and backup controls and should not submit unsupported regulated or high-risk data.
11. International Processing
Tidestone is based in the United States, and Relay's primary infrastructure is in the United States. Our providers may process information in the United States and other countries or regions where they or their subprocessors operate, depending on the service, configuration, and live-account terms. The Subprocessor List links to provider materials about possible processing locations.
Before a Customer submits Customer Personal Data in a transfer that requires a legal transfer mechanism, the Customer must contact Tidestone through the Company and Contact Notice and receive written confirmation that the required mechanism is in place. The Data Processing Terms describe that process. If applicable law requires a safeguard for our controller-side account, authentication, billing, security, or support processing, we will put the required safeguard in place and provide information about it on request.
12. Children
Relay is a business service and is not directed to children. You must be at least 18 years old to create or accept a Relay business account, and Customers must not create accounts for minors. Customer-controlled operational data may include information about a minor submitted by an authorized adult or integration; the Customer is responsible for having legal authority and using only supported business data. If we learn that a child created an account or submitted personal information directly, or that a Customer submitted children's information unlawfully, we will review and address it.
13. Changes to This Notice
We may update this Notice as Relay, our providers, or legal requirements change. We will post the updated Notice with its effective date. If a change materially affects how we collect, use, disclose, or retain information, we will provide additional notice through Relay or the account email when reasonably appropriate or legally required.
14. Contact
Tidestone Technologies LLC operates Relay. Contact details and request instructions are in the Company and Contact Notice.