Sidecar Data

Legal

Privacy policy

This policy explains what Sidecar Data collects, how we use it, and the controls you have over your information.

Last updated August 2026

Information we collect

We collect the minimum needed to run the platform and support your team.

  • Account data: name, work email, company, and role.
  • Platform metadata: warehouse query history, job and model metadata, cost and usage metrics, lineage, and test results.
  • Product usage: pages viewed, features used, and diagnostic logs.
  • Website data: basic analytics such as referrer, device type, and approximate location.

What we do not collect

Sidecar operates on metadata. We do not copy the contents of your tables into our systems, and we do not need row level access to your customer records to do our work. Where a workflow requires reading data values, we ask for it explicitly and scope it to that workflow.

How we use information

We use information to deliver and improve the service.

  • Run cost, performance, reliability, and catalog workflows in your environment.
  • Give your forward deployed engineer the context needed to scope and complete work.
  • Provide support, security monitoring, and incident response.
  • Communicate about product changes, billing, and service status.

AI and model training

Agents use your metadata to reason about your platform at the time of a request. We do not train foundation models on your data, and we do not share your data with model providers for training purposes. Model providers process requests under zero retention or short retention terms.

Sharing

We share information with the subprocessors listed on our subprocessors page, with your own connected tools when you authorize a connection, and when required by law. We do not sell personal information.

Retention

Account data is retained while your account is active. Metadata and logs are retained for the period needed to run the service and are deleted within 30 days of account termination, unless a longer period is required by law.

Security

Sidecar is SOC 2 compliant. Data is encrypted in transit and at rest, access is scoped by role and reviewed regularly, and credentials are stored in a managed secrets service. Read the security section of our docs for details.

Your rights

You can request access, correction, export, or deletion of personal information we hold about you. Email legal@sidecardata.com and we will respond within 30 days.

Changes

If we make a material change to this policy we will notify account administrators by email before it takes effect.

Questions about this page? Email legal@sidecardata.com.