Skip to content

Legal

Privacy Policy

Last updated: September 6, 2026

This policy describes what we collect when you use this website, and what we do with it. It's written to match what this site actually does — not a generic template — because we'd rather you trust what's written here than have to take it on faith.

Who controls your data. Olympia is a service of Circus Corporation, a corporation incorporated in the State of Delaware, United States. "Olympia", "we", "us" and "our" in this policy mean Circus Corporation, and Circus Corporation is the data controller for the information described below. We are a US company; the services we use to run this site are US-based or US-hosted, so your data is stored and processed in the United States. If you are outside the US, submitting a form or placing an order means your information is transferred there.

What we collect

Analytics. We use Plausible Analytics, a privacy-focused analytics service that does not use cookies and does not track you across sites or build an individual profile of you. It records aggregate page-view and event data (for example: a calculator was used, a form was submitted, a tier's Configure button was clicked) so we can see which pages and features people actually use. It cannot identify you personally. Because we set no tracking cookies, there is no cookie banner on this site — there is nothing to consent to.

Form submissions. When you submit the lead-capture form (opened from the migration, SaaS-cost-reduction, or custom-software CTAs, or from this site's Contact page) or the location-request form, we collect what you type into that form — typically your name, email address, and any details you add about your project or request. These submissions go to our third-party form-backend provider, and we read them there.

Orders and payments. When you buy a server, checkout happens on Stripe's own domain. Stripe collects your card details and your billing address; we never see or store your card number. Stripe then tells our server that the payment succeeded, and we record the order — see the next section for exactly what that record contains.

What we do not collect. We don't run advertising trackers, third-party marketing pixels, or fingerprinting scripts. We don't sell, rent or share your data with anyone for their own marketing, and we don't build advertising profiles.

What we hold, and where

The pages you're reading are static files with no application server behind them. But we do operate one small backend, and it does store data, so here is the honest picture rather than the flattering one:

  • Order records — stored by us. When a payment succeeds, a small service we run on Cloudflare writes one row to a database we control. That row holds the email address you used at checkout, the Stripe customer and subscription identifiers, the amount paid and its currency, and what you ordered (tier, location, application, add-ons). It is how we know a server needs building, and it is our record of the sale. It does not contain your card number, and it does not contain anything from inside your server.
  • Form submissions — stored by our form-backend provider, on their infrastructure, where we read them.
  • Payment and billing records — stored by Stripe, who are the payment processor and hold the card data on their own PCI-compliant systems.
  • Aggregate traffic statistics — stored by Plausible, with no identifier that points back to you.

Nothing on this list gives us access to the contents of a server you rent from us. You have root; we don't read your data.

How we use it

  • To respond to your inquiry, quote, or migration/support request.
  • To take your order, provision your server, bill your subscription and handle refunds or cancellations.
  • To keep the financial and tax records a US company is required to keep.
  • To understand, in aggregate, how visitors use this site so we can improve it.

That's the whole list. We don't use your details for anything you didn't come here for, and we don't email you marketing you didn't ask for.

How long we keep it

We keep form submissions for as long as the conversation is useful, and delete them on request. We keep order and payment records for as long as we are legally required to keep financial records, which is longer than you may want and is not something we can waive — if you ask us to delete everything, that's the part that stays, and we'll tell you so. Aggregate analytics data contains nothing that identifies you and is not deleted per-person, because there is no per-person record to find.

Your choices

You can ask us what information we hold about you, ask us to correct it, or ask us to delete it. Use our contact page. We'll acknowledge within 48 hours, in line with our published support response time, and we won't charge you for it or make you create an account to ask. Deletion means removing your submission from our form-backend provider and deleting your order row from our own database, minus the payment records we are required to retain.

California privacy law (CCPA/CPRA)

California's privacy law applies to a business by size and by what it does with data — broadly, revenue above a statutory threshold, personal information about large numbers of California consumers, or revenue earned from selling or sharing personal information. We are a small company that meets none of those thresholds today, so the CCPA does not currently apply to us. We'd rather tell you that than display a compliance badge we haven't earned.

Two things are true regardless: we do not sell or share your personal information, and we will honor a request to see, correct or delete your data from anyone who asks, in California or not. If our size changes so that the law does apply, this section changes with it.

If you are in the UK or Europe (GDPR)

We are a US company selling to customers anywhere, which means the GDPR and UK GDPR may apply to us in respect of visitors and customers in those regions. We have not completed a formal GDPR compliance program — we have not appointed a data protection officer, run a data protection impact assessment, or had our transfer arrangements reviewed by counsel. Claiming otherwise would be a lie, and this section is here instead of that claim.

What we do in practice: we collect the minimum we need to answer you and to run your subscription, we use it only for the purposes listed above, we don't sell or share it, we hold it in the United States, and we act on access and deletion requests when we get them.

If the GDPR applies to your data, it gives you rights of access, correction, erasure, portability, restriction and objection. Ask us through our contact page and we will act on the request. If our answer doesn't satisfy you, you can complain to your national data protection authority.

Changes to this policy

We may update this policy as the site changes. We'll update the "Last updated" date above when we do.

Contact

Questions about this policy, or want to exercise any of the rights above? Email legal@olympia.so, or use our contact page — either reaches a person, and we reply within 48 hours. Write to us as Circus Corporation and mention Olympia so we can find your records.