Privacy Policy
Last updated: 2026-09-02
1. Who we are
Expiro is a product of Elixon LTD, a company registered in England and Wales. We provide contract renewal tracking software for businesses.
If you have any questions about this policy, contact us at support@expiro.io.
2. What data we collect
Every category below is something the application actually stores. It was written by reading the code rather than from a template.
- Your account - email address, company name, plan and billing status, time zone, and the settings you choose. Passwords are stored only as a hash, never as text.
- Your team - the email address of everyone you invite, their role, and the invitations themselves until they are accepted or expire.
- Contracts - everything you enter about each one: name, client name and email, value and currency, dates, notice period, notes, renewal terms, pipeline status and any custom fields you define, plus notes, comments and the timeline of what changed.
- Files you attach - contract attachments, stored in our own S3 bucket in London.
- Two-factor and sign-in data - your two-factor secret (encrypted with a separate key), hashed backup codes, and session tokens.
- Notification details you provide - a phone number if you turn on SMS alerts, a browser push subscription if you allow notifications, and the webhook URLs or chat identifiers for any channel you connect (Slack, Teams, Discord, Google Chat, Mattermost, Telegram, Pushover, ntfy or your own webhook).
- Activity records - the audit log of key account actions, in-app notifications, and the record of which alerts were sent and to whom.
- API tokens - stored as a hash. The token itself is shown to you once and never stored.
- How you found us - the campaign parameters and referring site of your first and most recent visit.
- Billing - handled by Stripe. We hold your Stripe customer reference and subscription status; card details never reach us.
- Usage analytics via Umami, our own self-hosted analytics on servers we run. While you are signed in, pages you visit are recorded against your internal account identifier - a random id we already hold - together with your plan and your role. No name, email address, company name or contract data is ever sent to analytics, and pages whose address carries a sign-in or unsubscribe link are not recorded at all.
- Error reports - when something breaks we record what failed, on our own monitoring server. Request bodies are never included, so contract data cannot leave this way.
- Backups - daily snapshots of the database, kept for 30 days in the same region and then deleted automatically.
3. How we use your data
- To provide and operate the Expiro service
- To send you contract expiry alerts and product emails
- To process payments via Stripe
- To improve the product by measuring how it is used, without personal data
4. Data storage
Your data is stored on servers located in the United Kingdom (London). Every part of it, including files you attach to a contract, stays in the UK:
- Application and database - Fly.io, London (lhr), volume encrypted at rest
- Contract attachments - AWS S3, London (eu-west-2)
- Database snapshots - Fly.io, London (lhr)
Some of the third parties listed below process data outside the UK on our behalf; each one is named in section 5 with what it receives.
5. Third parties
- Fly.io - hosting for the application and the database, in London. Subject to Fly.io's privacy policy.
- Amazon Web Services (S3) - storage for the files you attach to a contract, in London.
- Stripe - payment processing. Receives your email address and billing details; card details go to Stripe and never to us.
- Resend - email delivery. Receives the address and content of transactional emails, which include contract names and dates in your alerts.
- Twilio - SMS delivery, only if you turn SMS alerts on. Receives your phone number and the message.
- Any notification channel you connect yourself - Slack, Microsoft Teams, Discord, Google Chat, Mattermost, Telegram, Pushover, ntfy or your own webhook. Alerts you have asked for are sent there, which means the contract name, client and date go to that service. You choose which, and you can disconnect at any time.
- Umami - analytics, self-hosted by Elixon LTD. Your data is not shared with an analytics company: the software runs on our own servers. See section 2 for what is recorded.
- GlitchTip - error monitoring, also self-hosted by Elixon LTD on our own server. Receives what failed and where, never request bodies.
6. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict processing of your data
- Data portability
To exercise any of these rights, email us at support@expiro.io.
7. Data retention
Cancelling a subscription and deleting an account are two different things, and only one of them removes anything.
- Cancelling your subscription deletes nothing. Your account stays, your contracts stay, and you can still sign in, read everything and export it. Adding and editing contracts, and the automatic alerts, stop when the paid period ends.
- Deleting your account starts a 30-day grace period. During it nothing is destroyed and you can cancel the deletion yourself. When it runs out, a scheduled job permanently deletes the account and everything in it - contracts, attachments, notes, comments, audit records and tokens. That job is monitored, so a purge that fails to run is noticed rather than assumed.
- Backups. Database snapshots are kept for 30 days and then deleted automatically, so a purged account can persist in a snapshot until the last snapshot taken before the purge ages out.
Export before either. You can export your contracts as CSV and your whole account as JSON at any time from the application, without asking us.
8. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes by email.