Cloudy CMS
Privacy Policy
Effective date: 22 September 2026
Operator: Cloud By Day Group Pte. Ltd., 7030 Ang Mo Kio Avenue 5, #05-042, Northstar @ AMK, Singapore 569880.
This notice covers the whole Cloudy service: the web dashboard that businesses log into, the APIs behind it, and the player application that runs on their screens. A shorter, app-specific summary is at the player privacy notice.
1. Who this applies to
Cloudy is a business tool. Two groups of people are involved, and we treat them differently:
- Operators: the staff of a business who hold a Cloudy account and manage screens. We hold personal data about them as the controller.
- Members of the public near a screen: people walking past a display. We do not identify them. Section 5 explains exactly what the optional audience-measurement feature does and does not record.
2. Data we collect about operators
- Account details: name, email address, role, and the organisation the account belongs to.
- Authentication records: sign-in, sign-out and failed sign-in events, including the IP address they came from.
- Activity records: what was published, which screen was linked or unlinked, role and billing changes, with the acting account, the IP address, and a timestamp.
- Content you upload: images, video and documents. If you choose to put personal data into your own signage content, you remain the controller of it.
- Billing details: billing name and email. Card details are entered directly with our payment processor and never reach our systems.
- Support correspondence and anything you type into the in-product assistant.
3. Data we collect from screens
- Device identifiers: a device ID we generate at linking, an authentication token, and an organisation ID. These identify the screen, not a person.
- Push token, used solely to deliver control commands such as sync, volume, or reboot.
- Technical telemetry: platform, screen dimensions, storage used, installed content version, sync results, and playback status.
- Linking address and location: when a screen is linked we record the IP address of the network it was linked on, and look up an approximate city from it so an operator can tell their own screens apart. We store both the IP address and the resulting city, region and country, a rough area, not a precise position. The lookup is performed by a third party (section 7).
4. How we use it
To deliver the service (linking screens, delivering the right playlists, applying remote settings), to keep it secure and available (monitoring, alerting, fraud and abuse prevention), to bill for it, to support you, and to improve the product. We do not sell personal data, and we do not use it for advertising.
5. Audience measurement: what it does not do
Cloudy offers an optional audience-measurement feature that estimates whether anyone was in front of a screen and for how long. It is off by default and has to be switched on by the operator, per organisation and per screen.
In every case:
- Camera frames are analysed on the device and discarded immediately. No image or video is transmitted or stored.
- No facial template or biometric identifier is created. We do not attempt to identify anyone, and we cannot recognise the same person on a later visit.
- Emotion and ethnicity are never measured. Age and gender are not measured unless the organisation operating the screen has turned on audience demographics and confirmed that a notice is displayed at the screen. Where it has, the screen estimates a gender and an age band (20-39, 40-59 or 60 and over) on the device, people under 20 are never broken down, and only per-play counts leave the device. No per-person record of age or gender is created, stored or sent.
- What leaves the device is a set of numbers per piece of content played: how many viewers were counted, the peak number at once, how long attention and presence lasted in milliseconds, and quality indicators describing how reliable the measurement was.
- The camera runs while content is playing, and for a short grace period after playback stops.
No image and no per-face geometry leaves the screen, at any time and by any route. There is no on-screen indicator: the business operating the screen is responsible for signage telling people that audience measurement is in use on its premises.
6. Legal basis and your rights
We handle personal data under the Singapore Personal Data Protection Act (PDPA). You may ask us for a copy of the personal data we hold about you, ask us to correct it, or withdraw consent. Write to our Data Protection Officer at dpo@cloudycms.app. We respond to access and correction requests as soon as reasonably possible and in any case within the timeframes the PDPA sets.
7. Who we share data with
We use the service providers below. Each one receives only what it needs for its stated purpose, and none of them is permitted to use it for their own purposes. Some of them process data outside Singapore; where they do, we rely on their contractual commitments to provide a standard of protection comparable to the PDPA.
| Provider | Purpose | What they receive |
|---|---|---|
| Vercel Inc. | Application hosting, content delivery, scheduled jobs, and sandboxed presentation conversion | Account identifiers, IP addresses in request logs, and files processed during a presentation import |
| Supabase Inc. | Managed database, authentication, and realtime messaging | Account name, email address, and all customer content and operational records |
| Cloudflare, Inc. | Object storage and delivery of media files | Customer-uploaded media. No camera images: audience measurement runs entirely on the screen and transmits only aggregate counts |
| Google LLC — Firebase Cloud Messaging | Delivering control commands to signage devices | The device push token. No account personal data |
| Stripe, Inc. | Subscription billing and payment processing | Billing name and email. Card details are collected by Stripe directly and never reach our systems |
| Functional Software, Inc. — Sentry | Application error monitoring | Error reports, which can include the acting account identifier and request metadata |
| PostHog Inc. | Product usage analytics for the dashboard | A pseudonymous account identifier, the account's role, and the organisation identifier — no name or email address — plus page views, performance metrics, IP address and browser details collected by their script |
| ipapi.co | Resolving an approximate city from the network a screen was linked from, so operators can recognise their own devices | The IP address seen at the moment a screen is linked |
| Anthropic PBC | Powering the in-product assistant, when an operator uses it | The conversation content the user types into the assistant |
| Telegram FZ-LLC | Delivering operational alerts, where an operator opts into that channel | Alert text, which can name an organisation or a screen |
| Healthchecks.io | Confirming our scheduled jobs are still running | None. Liveness pings carry no personal data |
| Google LLC — Drive | Importing a presentation the operator chooses to import | Only the file the operator selects, at the moment they select it |
| Google LLC — Places and Maps | Address autocomplete and the location map on an organisation's profile | The address text an operator types, and the resulting place identifier and coordinates |
| Google LLC — YouTube | Playing YouTube content an operator adds to a playlist, and showing its thumbnail | The IP address and player telemetry of the screen playing it, and of the dashboard browser previewing it |
| Expo (650 Industries, Inc.) | Delivering over-the-air updates to the player application | Device IP address, platform, and application runtime version, sent whenever a screen checks for an update |
| Microlink | Generating a preview thumbnail for a web page an operator puts on a screen | The page address being previewed, plus the operator browser's IP address and user agent, because the preview image loads directly in their browser |
| Email relay provider | Sending transactional email — invitations, password resets, trial reminders and alerts | Recipient email address and the content of the message |
We may also disclose data where the law requires it, or to establish or defend a legal claim.
8. How long we keep it
- Account data: for as long as the account exists.
- Activity and sync records: on the plan retention window, currently 7 days on a trial and 90 days on a paid plan. If a paid plan lapses, the window returns to 7 days.
- Security records (sign-in, sign-out, failed sign-in, role changes), retained for 365 days regardless of plan, so a security question can still be answered later.
- Audience-measurement records: these contain no personal data, and they have no time limit. Removing a screen from your dashboard archives it and keeps its history. They are erased only when the screen is permanently deleted, or when the organisation is deleted.
- Screen records: a screen you unlink is archived rather than erased, so its history stays readable. Its stored details, including the address of the network it was linked on, are retained until the screen is permanently deleted or the organisation is deleted.
- Billing records: kept as long as tax and accounting law requires.
9. Deleting your data
Unlinking a screen archives it: it stops receiving content, but its record and history are kept so past reporting still makes sense. Permanently deleting an archived screen erases it and its history.
Deleting an organisation removes its content, stored media, schedules, screens and audience records, deletes the accounts that belong to it, and cancels its subscription. Accounts that manage several organisations are detached rather than deleted, because they outlive any one organisation. See data deletion for how to request it and what is retained afterwards.
10. Security
Data is encrypted in transit. Each organisation’s data is isolated at the database level as well as in the application. Passwords are handled by our identity provider and are never stored by us. Device credentials are held as a cryptographic hash once a screen has collected them, and in protected system storage on the device. Access to production data is limited to staff who need it.
If a data breach occurs that is likely to result in significant harm or is of significant scale, we will notify the Personal Data Protection Commission and affected individuals as required under the PDPA.
11. Children
Cloudy is a business tool. It is not directed at children and we do not knowingly collect their personal data.
12. Changes
We may update this notice. The effective date above reflects the latest revision, and material changes will be notified to account holders.
13. Contact
Cloud By Day Group Pte. Ltd.
7030 Ang Mo Kio Avenue 5, #05-042, Northstar @ AMK, Singapore 569880
Data Protection Officer: dpo@cloudycms.app
Telephone: +65 8967 7188
General enquiries: support@cloudycms.app