Back to Ghost Deploy
Legal policy

Privacy Policy

How Ghost Deploy handles account information, sign-in data, hosted content and service records, and how to exercise your privacy choices.

Version 3 · Effective 1 October 2026 (UTC) · QUBIT CODES

About Ghost Deploy

Ghost Deploy is developed, operated and managed by QUBIT CODES. Ghost Deploy is the platform and service brand of QUBIT CODES, based in Ernakulam, Kerala, India. For support and enquiries, contact support@ghostdeploy.com.

Who this policy covers

Ghost Deploy provides application deployment, hosting, workspaces, databases, storage, domains and email services. This policy applies to our website, control panel, APIs, account management, billing and support. The operator and contact details appear below. For personal information inside a customer's application, database, files or mailboxes, the customer normally decides how that information is used and we process it to provide the requested service. Contact that customer about their application or end-user privacy practices; contact us about your Ghost Deploy account or our own handling of information.

Information we collect and use

  • Account and workspace information: your name, phone number, email address where provided, profile details, team membership, permissions and subscription choices.
  • Service information: repository and deployment metadata, domains, configuration, usage, database and storage records, backups, mailbox information and content that you or your workspace ask us to host, transmit or import.
  • Billing and support records: orders, invoices, payment status, transaction references, tax information where provided, and communications with us. Payment providers process payment credentials in their own payment flows.
  • Security and technical records: IP addresses, device/browser information, sessions, sign-in attempts, audit events, service logs and diagnostic information used to protect accounts, investigate abuse and operate the platform.

Google and GitHub sign-in

Connecting Google or GitHub is optional. We use Firebase Authentication to verify your selected provider account. The authentication flow can receive your provider identifier, email address, verification status and basic profile information such as your name or profile picture. Ghost Deploy stores the provider identifier and available verified email with the connection to your existing account; Firebase may retain the associated authentication profile. We use this information to authenticate you, display your connected sign-in method and protect account access. We do not receive your Google or GitHub password.

Google sign-in does not give Ghost Deploy access to your Gmail messages, Google Drive files, contacts or calendar. GitHub sign-in is separate from connecting a repository for deployment; repository access requires its own authorization. We do not use Google sign-in data for advertising, sell it, or use it to train generalized artificial-intelligence or machine-learning models. Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Phone verification and authentication providers

We use Firebase for SMS verification and account identity records, and MSG91/WhatsApp for the WhatsApp verification option. Your phone number may be registered with Firebase even when you use WhatsApp, so that your account can use supported authentication methods consistently. Firebase and its abuse-prevention services process phone numbers and technical signals to authenticate users and prevent spam and abuse. The chosen messaging provider receives the information needed to deliver your code. Requesting a code does not subscribe you to marketing messages.

Why we process information

We process information to provide the services you request, verify account ownership, manage workspace access, run deployments and infrastructure, process payments, deliver service notices, troubleshoot problems and respond to support requests. We also use relevant records to prevent fraud, protect services, resolve disputes and meet applicable legal obligations. Where consent is required, we request it for the relevant use. Where applicable, processing may instead be necessary to perform our agreement, comply with law, or pursue legitimate service and security interests subject to your rights.

Sharing and international processing

We share information needed to operate a requested feature with service providers, including Google/Firebase for authentication, GitHub for authorized identity or repository connections, MSG91/WhatsApp for messaging, MailBaby for outgoing mail, Cashfree or PayU for payments, and infrastructure, storage and domain providers. Providers may process information in countries other than yours under their applicable terms and data-protection arrangements. Workspace owners and authorized administrators can access workspace information according to their permissions. Authorized support personnel may access relevant information when needed to assist you, maintain services, investigate abuse or comply with law. We do not sell personal information. We may disclose records when legally required or necessary to protect rights and safety, and will provide legally required notice or choices for material business transfers.

Security, retention and deletion

We use access controls, encrypted connections and other technical and organizational measures to protect information. No online system can guarantee complete security. We retain information for as long as needed for the service, account security, billing, legal obligations and dispute resolution. Retention depends on the resource, subscription and configured backup or recovery settings. Deletion from active systems may not immediately remove information from protected backups or legally retained records; those copies remain subject to applicable access restrictions and retention requirements.

Your choices and privacy requests

You can review connected providers in Security > Sign-in methods and disconnect them after verifying your phone. You can also revoke Ghost Deploy's access in your Google or GitHub account settings. Disconnecting a provider stops its use for future Ghost Deploy sign-in but does not itself delete your Ghost Deploy account or all historical security records. To request access, correction, export or deletion of your account information, including associated Firebase authentication records, contact the privacy address below. We verify account ownership before acting and explain any information that must be retained. Depending on your location, you may also have rights to object, restrict processing, withdraw consent or complain to a relevant regulator. Workspace data belonging to other members or required for an ongoing organization account may need separate handling.

Browser storage and third-party services

We use cookies and browser storage for sign-in, session continuity, security and interface preferences. Authentication providers may use their own storage and anti-abuse tools during sign-in. Blocking essential storage can prevent login or other features from working. External websites and customer applications have their own privacy policies. Any optional tracking introduced by Ghost Deploy is subject to the notices and choices required by applicable law.

Children and policy updates

Ghost Deploy is intended for people able to enter a service agreement and for authorized organization representatives, rather than services directed at children. Contact us if you believe a child has supplied account information improperly. We publish updates at this URL with an effective date and version. Material changes will be communicated through appropriate service channels, and additional consent will be requested when required before information is used for a new purpose.

Related guides and references