← Back to home

Privacy Policy

Last updated: 18 July 2026

RenderContext helps teams run feature flags, experiments, and privacy-conscious product analytics. This policy explains what we collect, why we collect it, and the choices available to you.

RenderContext is operated by Cutting Soup Pty Ltd (ABN 88 665 504 272) (“RenderContext”, “we”, “us”, or “our”).

Who this policy covers

This policy applies to the RenderContext website, dashboard, SDK, and related services (together, the “Service”). “Customer” means the organisation that uses the Service. When a Customer uses RenderContext on its website or app, it decides what analytics to collect from its visitors; it is responsible for its own privacy notices and legal basis for that collection.

For Customer analytics data, RenderContext processes data on the Customer’s behalf. For account, support, and website data, RenderContext determines how that data is used as described below.

We do not sell or repurpose Customer data

We process Customer analytics data only to provide and operate the Service for that Customer.

We do not sell, rent, trade, or otherwise monetise Customer analytics data. We do not use it for advertising, to build profiles for other customers, or for any purpose unrelated to providing, securing, and supporting the Service for the Customer that collected it.

Information we collect

We collect only the information needed to provide the Service.

  • Account and workspace data: Google sign-in identity, email address, name, organisation and project settings, and team membership.
  • Product analytics data: page paths, event names, referrer and UTM fields, coarse country and region, browser/device category, session identifiers, and feature-flag or experiment assignments.
  • Support communications: information you include when you contact us.

We do not store IP addresses or full user-agent strings in analytics records. IP addresses may be handled transiently at the edge to apply rate limits and protect the Service.

Pseudonymous visitor identifiers

The browser SDK creates a random visitor identifier by default and keeps it in local storage. If a Customer supplies its own viewer identifier, the SDK derives a SHA-256 hash salted with that project’s public key before sending it to RenderContext. The same underlying identifier therefore produces different values across projects and environments.

These identifiers are pseudonymous, not anonymous: they can still be personal data when a Customer can link them to a person. The Service uses them to count visitors, maintain sessions, and make consistent experiment assignments; it does not use them to build advertising profiles or sell them.

Data minimisation controls

Captured page paths are normalised to the pathname only. Query strings and fragments are not retained as part of the page path, which helps prevent tokens and query-value personal information from being included in analytics. The SDK separately captures named UTM fields and may receive a referrer URL from the browser; a Customer's referrer policy affects what is included in that URL. Event properties accept only flat strings, numbers, and booleans and have size and count limits.

Customers must not send sensitive or unnecessary personal information in event properties, event names, URLs, or viewer identifiers. In particular, do not use the Service for health, financial, authentication, government-ID, or other sensitive information.

How we use information

We use information to:

  • authenticate users and operate Customer workspaces;
  • deliver analytics, feature flags, and experiment reporting;
  • secure the Service, prevent abuse, and investigate faults;
  • provide support and communicate important service changes; and
  • comply with applicable legal obligations.

Service providers and disclosures

We use infrastructure providers to operate the Service, including Google (including Firebase) and Cloudflare. They process data only to provide their services to us, subject to their applicable terms and safeguards.

We may disclose information where required by law, to protect the Service or its users, or as part of a corporate transaction. We do not sell personal information or share it for cross-context behavioural advertising.

Retention and deletion

Project configuration remains available while the project is active. When a Customer deletes a project, we disable its keys and stop new collection immediately. The project then enters an approximately 30-day grace period before an automated hard-purge removes its configuration and analytics data from our primary systems and initiates deletion of archived analytics records.

Some of the services we use keep recent, aggregated analytics data in a rolling window of about 90 days and do not support immediate deletion for an individual project. That remaining data ages out at the end of the applicable rolling window.

Plan-based retention for active projects is being finalised. Until its automated enforcement is available, do not rely on the Service to delete active-project analytics after a particular plan window; delete the project or contact us if you need deletion assistance.

Your choices and requests

Customers can manage or delete projects from the dashboard. To request access, correction, export, deletion, or help with another privacy request, contact us at support@rendercontext.com. We may need to verify your identity and authority before acting. Visitors should normally direct requests about a Customer’s website or app to that Customer first.

Cookies and local storage

The SDK uses browser local storage for a pseudonymous visitor ID, session ID, and related context. It is not a promise that a Customer’s implementation is cookie-free or consent-free in every jurisdiction. Customers must assess and meet the requirements that apply to their own sites and audiences.

Changes and contact

We may update this policy as the Service evolves. We will publish the updated version here and revise the “Last updated” date. Where reasonably practicable, we will give notice of material changes, unless immediate changes are needed for legal, security, or abuse-prevention reasons. For privacy questions, requests, or complaints, email support@rendercontext.com or write to Cutting Soup Pty Ltd, Unit 113, 18–20 Edinburgh Street, Oakleigh South VIC 3167, Australia. We will investigate privacy complaints and respond to you.