Hosting Privacy
How Bitbolt handles your data when we host your server. Last updated: 2 September 2026.The short version
If we host your server, we hold your business data. That is the deal — it is what managed hosting is — and it is the opposite of what our mobile app does. We store it, we back it up, and a small number of named people can reach it in order to operate and support the service. We do not sell it, mine it, or use it to train anything.What we hold
Everything you put into it: your records, documents, attachments, messages and the accounts of the people who sign in. It lives in a database created for you and used by nobody else. It is not pooled with other customers’ data, although the server and the database service it runs on are shared with other customers’ systems.We also hold the things needed to run the account itself — your company name, the subdomain you chose, your billing contact, and how many seats you hold.Where it is
On Microsoft Azure infrastructure in the South Central US region, which is where both the running database and its backups sit today. If your organization needs data held in a particular jurisdiction, ask before you sign up — we would rather tell you no than surprise you later.Who can reach it
jayBird staff operating the service. Access is for running and supporting your tenant — investigating a fault you have reported, restoring a backup, performing an upgrade — not for reading your business.Support access to a tenant happens through a dedicated, separately authenticated route that creates its own clearly-marked account rather than borrowing yours, so it is visible in your own system who came in and when.Backups
Your database and its files are backed up nightly and stored in Azure Blob Storage in the same region. Each backup is kept for a year, moving to cheaper storage after the first month.Backups are test-restored rather than assumed to work. Every week the latest backup of every database is restored into a scratch copy, and real attachment bytes are read back from the backup's own files and checked against their recorded checksums, because a database restored without its files has perfect row counts and every attachment broken. A backup nobody has restored is a guess, not a backup.Who else is involved
These are the services your data passes through or rests on. We do not add one without a reason.| Service | What it does | Where |
|---|---|---|
| Microsoft Azure | The servers and storage your database and files live on, and the nightly backups. | South Central US |
| Microsoft Entra External ID | Sign-in. It verifies who you are; it does not receive your business records. | Microsoft global identity infrastructure |
| Cloudflare | DNS for your subdomain, TLS, the tunnel your traffic reaches us through, and the support form on this site. | Global edge network |
| Stripe | Payments and sales tax. Stripe collects and holds your card details and billing address; we never receive the card. | Stripe global infrastructure |
| Azure Communication Services | The email and text messages we send you (welcome, billing, support replies), and delivery of the support form. | United States |
| Apple and Google push services, via a relay we run on Cloudflare | Only if you turn on mobile notifications: device tokens and notification payloads, which your own server encrypts before they leave it. | Apple, Google and Cloudflare global infrastructure |
Keeping it, and deleting it
We keep your data for as long as you are a customer. If a payment fails and is still unpaid after 14 days, your server is suspended rather than deleted — it stops answering, the data stays exactly as it was, and settling the balance brings it back. Suspension starts no deletion clock.When you cancel, or we terminate, your database and its files are kept for at least 30 days so you can pick it back up or ask us for an export. Deletion after that is a deliberate operation somebody performs and confirms, not an automatic sweep; if you want it gone sooner, say so and we will do it. Nightly backups expire on their own schedule, a year after they were taken.You can ask for an export of your data at any time while it exists, and you can ask us to correct or delete what we hold about you as the account holder.Your own users
The people you add are your users, and their records are your data. You decide who has access and you are their first point of contact — to them, this is your system, and your own privacy policy governs what you do with what they put in it.Payments
Card details are entered on Stripe’s own pages and held by Stripe. They do not pass through our servers and we could not produce your card number if you asked us to. We keep what Stripe tells us about the subscription: who is billed, for how many seats, and whether it is paid.If something goes wrong
If we find that your data has been exposed or taken, we will tell you without undue delay, and within 72 hours of becoming aware of it. We will tell you what we know at the time rather than waiting until we know everything: what happened, which of your data was involved, what we have done, and what we advise you to do. If we are still establishing the facts, we will say so and follow up.We would rather tell you about something that turns out to be nothing than be quiet about something that turns out to matter.Data protection terms
You are the controller of the data you put in your system; we are the processor, and this policy together with the terms of service is the written record of that processing. We do not yet have a separate Data Processing Addendum, and we would rather say so than promise one on request.Be aware of where things are: your database, its backups and the people who administer them are in the United States, in Azure's South Central US region. There is no EU or UK region today. If you are subject to GDPR or UK GDPR, that means a transfer out of the EU or UK, and we do not yet have the European Commission's standard contractual clauses in place to cover it. If you need your data to stay in the EU or UK, we cannot do that yet, and we would rather say so here than in a procurement questionnaire.Cookies and third parties on this site
This site sets no cookies of its own and runs no analytics. The signup page loads Stripe.js, which sets Stripe's own cookies for fraud prevention, and the site uses Google Fonts, which means your browser fetches font files from Google. Your system at your own address sets Odoo's session cookie, which is what keeps you signed in.Changes
Material changes to this policy will be published at this address with a new date at the top. If a change affects where your data lives or who can reach it, we will tell you rather than rely on you noticing.Contact
jayBird, LLC — support@bitbolt.io. Data questions, export requests and deletion requests all go here.For the Bitbolt mobile app, which hosts nothing, see the app privacy policy.© 2026 jayBird, LLC
Odoo is a registered trademark of Odoo S.A. Bitbolt is developed by jayBird and is not affiliated with, endorsed by, or sponsored by Odoo S.A. What we host is Odoo Community, the open-source edition.