Skip to content
Relay
Company Privacy Account deletion

Relay Privacy Notice

Effective: July 27, 2026

This Privacy Notice explains how Tidestone Technologies LLC (“Tidestone,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with Relay and related services (the “Service”). Relay is a product of Tidestone.

Relay is intended for business and professional use. A business customer (“Customer”) controls its Relay organization and decides which users, recipients, integrations, and operational information to place in Relay.

Tidestone's business address is:

Tidestone Technologies LLC
1968 S. Coast Hwy #5307
Laguna Beach, CA 92651

1. Scope and Our Roles

This Notice applies to Relay's public website, web application, mobile applications, authentication, billing, alerts and notifications, integrations, support, and related operations.

Our role depends on the information and purpose:

  • Customer-controlled operational data. We generally act as a processor or service provider when we process personal information solely on a Customer's instructions, such as incident, schedule, responder, integration, and alert-recipient information. The Customer determines the purposes and lawful basis for that data. Our Data Processing Terms apply.
  • Tidestone business and account operations. We act as an independent controller and, where applicable, a business under privacy law when we create and secure individual Relay accounts, operate authentication and sessions, administer billing, prevent abuse, comply with law, manage our support relationships, and run our business. When Relay applies Customer-configured memberships, roles, or organization access to an account, that processing remains subject to the processor terms above. Customer-controlled operational content included in a support request also remains subject to those terms, while we act independently for our own support-relationship and business records.

If you use Relay for an employer or another organization, that organization may have its own privacy notice and may be the appropriate contact for questions about its operational data.

2. Information We Collect

We collect the following categories, depending on how Relay is configured and used.

2.1 Account, Identity, and Contact Information

  • name, display name, first and last name, profile color, timezone, and time-format preference;
  • email addresses and phone numbers, primary-contact status, verification status, and delivery-suppression status;
  • authentication identity, login-provider identifiers, token and session metadata, and account state;
  • login credentials submitted directly to AWS Cognito's managed authentication flow; Relay does not intentionally store plaintext account passwords;
  • organization memberships, roles, permissions, invitations, invite status, and active-organization selection; and
  • notification preferences, alert policies, subscriptions, quiet hours, and communication-channel choices.

2.2 Organization and Operational Information

  • organization name, configuration, billing status, services, teams, tags, roles, and policies;
  • schedules, rotations, on-call assignments, shifts, overrides, maintenance windows, readiness, and availability-related information;
  • incidents, Signals, titles, notes, status, urgency, services, tags, responders, acknowledgements, resolutions, timelines, source history, and audit records;
  • automation configuration and results; and
  • user actions and change history needed to operate and account for activity in Relay.

Operational information may identify employees, contractors, responders, recipients, or other people mentioned in Customer-controlled operational data.

2.3 Integration and Provider Information

  • generic webhook payloads and identifiers;
  • Datadog monitor identifiers, state, priority, tags, scope, notes, links, and service context supplied by a Customer;
  • Slack workspace identifiers, name, domain, and URL; app, user, and channel identifiers; user-directory names, display names, avatars, bot or deleted state; channel-directory names, visibility and status attributes; mapping, scope, permission, health, message, command, interaction, and automation data; and
  • provider credentials or secrets submitted through a field designed for that purpose. We store supported credentials using protective controls and do not intentionally expose them in customer-facing responses or logs.

2.4 Alert, Notification, and Delivery Information

  • email and phone destinations, mobile push tokens, app variant and version, device and operating-system metadata, and primary-device selection;
  • message or call content selected for delivery, channel, destination, status, attempt, provider reference, error or suppression reason, and timestamps;
  • delivery receipts, push interactions, acknowledgement actions, STOP/START and email-unsubscribe state, and readiness checks; and
  • browser-notification permission and local notification settings.

2.5 Billing Information

  • internal Relay signup and user identifiers, accepting-account email, legal-bundle metadata, price, and starting or occupied seat quantity sent to Stripe;
  • purchaser-entered billing-contact changes, billing address, payment information, and tax or exemption information supplied directly to Stripe when its hosted flow requests that information;
  • device, network, cookie, and fraud- or risk-assessment information Stripe collects directly in its hosted flow under its privacy notice;
  • Stripe customer and purchaser-contact details, billing country, Checkout Session, subscription, price, invoice, payment-status, proration, credit, cancellation, and billing-history identifiers and metadata returned to Relay for validation and records.

Payment details are submitted directly to Stripe. Relay does not intentionally store full payment-card or bank-account numbers or card security codes.

2.6 Support and Communications

  • Help conversation titles, messages, status, urgency flag, resolution, and message history;
  • requester or guest email, organization and user references, and limited page or route context submitted with a support request; and
  • privacy, billing, legal, security, and other communications with Tidestone.

2.7 Device, Network, Security, and Diagnostic Information

  • IP address, user agent, browser or app information, device and installation identifiers, requested route, HTTP method and status, request identifier, timing, and source metadata;
  • necessary cookies, local storage, mobile secure storage, authentication state, demo-session state, and rate-limit identifiers;
  • application, database, infrastructure, security, delivery, request, and provider diagnostics and logs; and
  • error, performance, health, and diagnostic information.

3. Sources of Information

We receive information:

  • directly from you when you create or use an account, configure Relay, contact support, or make a privacy request;
  • from the Customer and its administrators, coworkers, invite issuers, and other authorized users;
  • from Customer-directed integrations and providers, such as Slack, Datadog, and webhooks;
  • automatically from browsers, apps, devices, networks, cookies, storage, and Relay's infrastructure;
  • from delivery providers and telecommunications networks;
  • from Stripe for checkout, billing, invoices, and subscription management; and
  • from identity providers used to authenticate an account.

4. How We Use Information

For Customer-controlled operational data, we process personal information only for the processor purposes and documented instructions described in the Data Processing Terms. For information we control independently, and for processor data where the applicable instruction permits, we use personal information to:

  • create, authenticate, secure, and administer accounts and organizations;
  • provide incident response, on-call schedules, Signals, alerts, notifications, integrations, automations, billing, and support;
  • route information and communications to destinations selected by Customers and users;
  • operate, maintain, and troubleshoot Relay;
  • test and improve Relay using controller-scope, aggregated, or de-identified information;
  • understand service health and reliability;
  • prevent fraud, abuse, unauthorized access, and security incidents;
  • enforce contracts and protect rights, safety, and the Service;
  • process payments, subscriptions, invoices, seat changes, credits, and cancellations;
  • comply with law and respond to valid legal process; and
  • create aggregated or de-identified information that does not reasonably identify a person or Customer.

Where non-U.S. law requires a legal basis for our controller processing, we rely as appropriate on performance of a contract, legitimate interests in operating and securing Relay and our business, compliance with legal obligations, and consent where required. The Customer determines the legal basis for Customer-controlled operational data.

5. How We Disclose Information

We disclose personal information only as described below.

5.1 Service Providers and Subprocessors

We use providers for hosting, identity, email, billing, telecommunications, mobile push, monitoring, security, and other operations. The current providers and processing purposes are in the Subprocessor List.

5.2 Customer and Authorized Users

We make organization information available according to Customer configuration, organization membership, Relay permissions, and platform-support access. Normal organization members may read organization data that Relay makes generally available to members; sensitive actions and surfaces use additional permissions. Customer administrators control membership and most organization roles.

5.3 Customer-Directed Recipients and Integrations

We send information to users, responders, subscribers, email addresses, phone numbers, devices, Slack workspaces, webhook providers, and other destinations selected or configured by Customer or its users. Those recipients and services may use the information under their own terms and privacy notices.

5.4 Legal, Safety, and Security

For Customer Personal Data, we disclose only as authorized by the Agreement, Data Processing Terms, Customer instructions, or law. For controller-scope information, we may disclose when we reasonably believe disclosure is necessary to comply with law or valid legal process; protect rights, safety, or property; investigate fraud, abuse, or a security incident; enforce agreements; or establish, exercise, or defend legal claims.

5.5 Business Transactions

We may disclose controller-scope information under appropriate confidentiality protections in connection with financing, diligence, a merger, acquisition, reorganization, sale of assets, or similar transaction. We disclose Customer Personal Data in such a transaction only as authorized by the Agreement, Data Processing Terms, Customer instructions, or law. A successor may receive Customer Personal Data only after assuming the applicable Agreement and data-protection obligations.

5.6 Professional Advisers

We may disclose limited controller-scope information to lawyers, accountants, insurers, auditors, and other professional advisers who need it and are subject to appropriate confidentiality duties. An adviser may receive Customer Personal Data only when authorized as a Subprocessor or when Customer instructions or law permit the disclosure.

6. No Sale, Advertising, or Cross-Site Tracking

We do not sell personal information for money or share it for cross-context behavioral advertising. We do not use personal information for targeted advertising or use nonessential advertising, analytics, or session-replay trackers in Relay. Because Relay does not currently sell or share personal information for cross-context behavioral advertising, browser Do Not Track and Global Privacy Control signals do not change Relay's current behavior.

Third-party services may collect information when you leave Relay for their site, use their app, or enable an integration. Their collection is governed by their own notices. Relay does not permit a third-party advertising network to track people across Relay's authenticated product surfaces.

7. Cookies and Similar Storage

Relay uses only storage that is reasonably necessary for authentication, security, session continuity, preferences, app operation, demo access, rate limiting, and optional in-browser notification coordination.

Examples include secure authentication and demo-session cookies, browser storage for interface and notification coordination, and mobile secure storage for authentication state. A public demo uses separate session, re-access, and rate-limit cookies. We do not use a cookie-consent platform because Relay does not currently use nonessential advertising or analytics cookies.

You can block or clear browser storage, but doing so may sign you out, remove preferences, prevent demo re-access, or impair Relay functions.

8. Retention

We retain information only as long as reasonably needed for the purposes described in this Notice, Customer instructions, security, legal compliance, disputes, and operation of Relay. Retention depends on the type of information, the Customer's use of Relay, contractual commitments, configured lifecycle controls, and legal requirements.

Customer-controlled operational data is retained while the applicable Service is active and is returned or deleted under the Data Processing Terms after processing ends. Limited account-security tombstones and billing, security, support-relationship, communications-suppression, and legal records may be retained as needed for those purposes. Short-lived diagnostics, rate-limit records, demo state, provider records, and backups follow their configured or provider-controlled lifecycle.

Archiving an organization is retention, not deletion, and does not cancel its Stripe subscription. Removing a person from one organization ends that membership but does not automatically delete the person's Relay account or rewrite historical operational records.

Personal-account deletion removes or redacts the active account data described in Section 9.2. Relay keeps the deleted account's stable internal user UUID and opaque Cognito provider-subject mapping as security and integrity tombstones. The retained provider-subject mapping prevents a stale identity-provider callback from recreating or authenticating the deleted account.

Customer-owned incident, schedule, support, audit, billing, and provider-delivery history is not rewritten as if the deleted person's activity never occurred. Those records, communications-suppression contacts, diagnostics, backups, and other integrity-preserving or legally necessary records may retain a stable user UUID, contact destination, or provider identifier, or follow their normal bounded lifecycle, where reasonably needed for Customer operations, security, legal compliance, disputes, fraud prevention, suppression, or legal claims. Where direct identifiers are removed but retained history can still be resolved through the deleted-user tombstone, that history is pseudonymized, not anonymous. Records that still contain a contact destination or provider identifier remain personal information.

Deletion does not promise immediate or perfect erasure from provider systems, logs, backups, or rare operations already in flight. Residual copies may remain temporarily in protected backups or logs, and an in-flight operation may create or update a record after deletion; those records remain subject to the applicable retention and deletion lifecycle described above. Third parties apply their own retention terms when acting independently.

9. Your Choices and Privacy Requests

9.1 Product Controls

Depending on your account and permissions, Relay lets you update profile information, email addresses, phone numbers, notification preferences, quiet hours, subscriptions, alert policies, device registrations, and integration mappings. Signed-in non-demo users may also permanently delete their personal Relay account through the account-deletion page on the web or the signed-in account-deletion screen in the Relay mobile app. Some verified or historical records cannot be changed through those controls.

Email unsubscribe and phone STOP apply globally to the relevant Relay contact destination. Saved preferences may remain visible while delivery is suppressed. You may use the applicable re-subscribe control after Relay verifies that the contact destination belongs to you.

9.2 Personal-Account Deletion

The public account-deletion page explains the workflow and is the signed-in web initiation route. The Relay mobile app provides the same self-service personal-account deletion through its native signed-in screen. Personal-account deletion is separate from organization archive, Customer-data export, or Customer-data deletion and does not delete an organization's operational data.

Relay checks eligibility across every active organization membership before showing the action and rechecks it when deletion is confirmed. Deletion is blocked while you are the sole active administrator of any organization, including an archived organization, or while you have an unresolved paid-organization signup. Relay provides administration, billing, and support recovery paths where they apply. You may need to transfer administrator access, address billing for an affected paid organization, or finish or cancel a pending signup before trying again.

After a successful confirmed deletion, Relay:

  • deletes every actively linked Cognito user and disables Relay sign-in;
  • ends all active organization memberships and retires current responder assignments, schedule and team participation, subscriptions, and related member-specific projections;
  • removes active email and phone records, verification state, collaboration mappings, and mobile push registrations;
  • clears or replaces personal profile fields with the deleted-user tombstone; and
  • removes or redacts current personal notifications, runtime state, queued deliveries, and recipient-owned delivery content.

If Cognito deletion is temporarily unavailable, Relay leaves the local account intact so the signed-in user can try again. After successful deletion, Relay disables account access and the initiating client begins sign-out and local credential cleanup. The retained records and limitations described in Section 8 still apply, including the internal user and provider-subject tombstones and pseudonymized Customer-owned history.

9.3 Access, Correction, Export, and Other Privacy Requests

Depending on applicable law, you may ask to access, correct, export, delete, restrict, or object to processing of personal information, or withdraw consent for future processing that relies on consent, by:

  • starting a signed-in Help conversation when available; or
  • using the protected contact method in the Company and Contact Notice with the subject Privacy Request.

We may ask for information needed to verify identity, authority, account, organization, and request scope. We will respond using the process and timing required by applicable law.

If the request concerns Customer-controlled operational data, we may direct you to the Customer and will assist the Customer as required by our Data Processing Terms and applicable law. We will not disclose another person's or Customer's data in response to your request. You may also use these request methods when self-service personal-account deletion is unavailable or does not address the scope of your request.

Tidestone will determine the records in scope, the role in which it holds them, and any lawful retention requirement. Historical Customer-controlled operational records are not automatically deleted merely because one user leaves an organization, completes personal-account deletion, or makes a privacy request.

You may use an authorized agent where applicable law permits. We may require proof of the agent's authority and may still verify your identity directly. We will not discriminate against you for exercising an applicable privacy right.

9.4 Appeals and Complaints

If applicable law gives you a right to appeal our decision, reply to the decision with the subject Privacy Appeal and explain why you believe it should be reconsidered. You may also complain to the privacy or data-protection authority in your jurisdiction.

10. Security

We use technical and organizational safeguards designed for the nature of Relay and the information it processes, including encrypted transport, encryption at rest for core data stores and backups, tenant and permission controls, protected secrets and provider credentials, logging and monitoring, backups, and deployment and recovery controls.

No system is completely secure. We do not promise that Relay will prevent every unauthorized access, loss, or security incident. Customers should use appropriate account, role, invitation, integration, device, and backup controls and should not submit unsupported regulated or high-risk data.

11. International Processing

Tidestone is based in the United States. Relay's primary infrastructure is in the United States, and our providers may process information in the United States and other locations identified in the Subprocessor List.

Before a Customer submits Customer Personal Data in a transfer that requires a legal transfer mechanism, the Customer must contact Tidestone through the Company and Contact Notice and receive written confirmation that the required mechanism is in place. The Data Processing Terms describe that process. If applicable law requires a safeguard for our controller-side account, authentication, billing, security, or support processing, we will put the required safeguard in place and provide information about it on request.

12. Children

Relay is a business service and is not directed to children. You must be at least 18 years old to create or accept a Relay business account, and Customers must not create accounts for minors. Customer-controlled operational data may include information about a minor submitted by an authorized adult or integration; the Customer is responsible for having legal authority and using only supported business data. If we learn that a child created an account or submitted personal information directly, or that a Customer submitted children's information unlawfully, we will review and address it.

13. Changes to This Notice

We may update this Notice as Relay, our providers, or legal requirements change. We will post the updated Notice with its effective date. If a change materially affects how we collect, use, disclose, or retain information, we will provide additional notice through Relay or the account email when reasonably appropriate or legally required.

14. Contact

Tidestone Technologies LLC operates Relay. Contact details and request instructions are in the Company and Contact Notice.

Relay Customer Terms Relay Privacy Notice Relay Data Processing Terms Relay Subprocessor List Company and Contact Notice Account deletion

Relay is a product of Tidestone Technologies LLC.