Version 2026-08-15 · Last updated: August 15, 2026
This Privacy Policy explains what information Stingray Technology Solutions, LLC ("Stingray," "we," "our," or "us") collects in connection with Nexus, how we use it, who we share it with, and how long we keep it. It applies to the Nexus platform, the Nexus desktop and web clients, the Nexus Excel add-in, and the Stingray marketing website (together, the "Service"). It is part of, and should be read with, our Self-Hosted Terms of Service.
Nexus is enterprise software sold to organizations. Most of the information we handle relates to a business customer and its personnel rather than to consumers.
This policy covers Nexus deployed into your own Microsoft Azure subscription as a Managed Application, where we never hold your business data at all. If Stingray instead operates your Nexus instance for you as a software-as-a-service subscription, the Nexus SaaS Privacy Policy applies to you instead, and the difference is significant: in that model we do hold your data.
Our role depends on the type of information:
If you are an employee of one of our customers and have a question about the business data your employer processes in Nexus, please contact your own organization first. We will refer such requests to the customer that controls the data.
This is the single most important thing to understand about our handling of Customer Data, so it is stated plainly: under this policy, we do not hold it.
Nexus is installed into the customer's own Microsoft Azure subscription as a Managed Application. The application, database, key vault, and storage belong to the customer, and run in the Azure region the customer chooses. Customer Data is read, transformed, and stored entirely within the customer's own Azure tenant and does not transit or rest on Stingray-operated infrastructure. We hold no copy of it, we cannot query it, and there is nothing of it for us to hand over, lose, or delete.
Credentials for connected systems are held in a key vault inside the customer's own subscription. We never receive them.
What we do receive is limited to the account, subscription, and operational information described in Section 3 — chiefly who bought the subscription, and narrow allowlisted telemetry about how the software is running.
Deployments into Microsoft Azure Government, including GCC High, run in the customer's own government-cloud tenant and are governed by a separate written agreement. Stingray does not hold Customer Data from those deployments.
Users sign in through Microsoft Entra ID. Microsoft performs the authentication and returns a token to the customer's own Nexus instance. That identity information stays within the customer's instance in the customer's Azure subscription and is not transmitted to Stingray. The information the instance handles from that token and from the Microsoft directory is:
Neither the customer's instance nor Stingray ever receives or stores user passwords; authentication is performed entirely by Microsoft. The only identity-related details that reach Stingray are those the purchaser gives Microsoft when buying the subscription, described in Section 3.2, and any name and email address in a support request or enquiry.
For subscriptions purchased through the Microsoft Azure Marketplace, Microsoft is the merchant of record. Microsoft sends us the information needed to provision and maintain the subscription, which includes the subscription identifier, the plan, the purchaser's name and email address, the Azure tenant identifier, and lifecycle notifications such as renewal, suspension, and cancellation.
We do not receive, process, or store payment card numbers, bank details, or any other payment instrument. Those are handled entirely by Microsoft.
A Nexus instance running in a customer's own Azure subscription can report limited operational information to a Stingray-operated control plane so we can monitor product health, diagnose faults, and understand which capabilities are used. Telemetry is deliberately narrow, and what it contains is fixed by an allowlist in the software:
| Category | What is sent |
|---|---|
| Instance identity | Tenant and deployment identifiers, Nexus version, adapter names and versions |
| Usage counters | Counts only — for example the number of active reports, pipelines, and configured connections. Names and values of connections are never sent. |
| Errors and diagnostics | Error type, error message, the connector or pipeline step involved, and HTTP status. Error messages are automatically stripped of file paths, IP addresses, and credential-shaped strings before transmission. |
| Security alerts | Aggregate signals such as an unusual number of failed sign-ins or pipeline failures within a time window |
Telemetry does not include customer business records, query results, report contents, file contents, or connection credentials. An administrator can turn telemetry off at any time from the product's administration settings, and it can also be disabled in the instance's configuration at deployment time.
Separately from telemetry, a deployment contacts the Stingray control plane to renew the license lease that permits it to run and to check for available software and adapter updates. The request body of each of those calls contains the deployment's own identifier and nothing else, alongside the credentials that authenticate the deployment to us. They carry no Customer Data, no user information, and no configuration. Licensing calls are how the software verifies it is entitled to operate, so they continue even when telemetry is switched off.
When you contact support, we retain your name and email address, the content of your request, and any logs, screenshots, or diagnostic information you choose to send us. Please do not send us production business records or credentials in a support request; if you do, they will be handled as Customer Data and deleted when the request is closed.
If you ask to be contacted about Nexus through the Microsoft Azure Marketplace — for example by requesting a private offer or asking us to get in touch — Microsoft passes us the contact details you provided, which typically include your name, business email address, company name, country, and any message you wrote. We store those details in our own Microsoft Azure storage in the United States and use them solely to respond to your enquiry and to keep a record of it. We do not use them for unrelated marketing, and we do not sell or share them. Ask us to delete a lead record at any time using the contact address in Section 13.
Our marketing website is a static site delivered through a content delivery network. Standard server-side request logs, including IP address, user agent, and requested URL, are generated by that infrastructure. We do not use advertising cookies or third-party tracking or analytics scripts on the marketing website.
We do not hold customer business records at all under this policy. The instance that holds them belongs to the customer, and nothing in the following list is ever sent to us — not in telemetry, not in logs, not on cancellation. The only exception is material a customer voluntarily attaches to a support request, which we ask them not to send. We do not collect:
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use Customer Data to train machine-learning or artificial-intelligence models. Nexus itself ships no artificial-intelligence features.
We use the information described above to:
Where the law requires a legal basis for processing, ours is the performance of our contract with the customer, our legitimate interests in operating and securing the Service, and compliance with legal obligations.
We do not sell information, and we share it only as described here. Our sub-processors are:
| Provider | What it does for us | What it may handle |
|---|---|---|
| Microsoft Corporation — Azure | Cloud infrastructure for our control plane only: the licensing, update, catalog, telemetry-intake, and container-registry services we run. The customer's own deployment runs in the customer's own Azure subscription, which is not infrastructure we operate. | Account, subscription, and operational information. No Customer Data — we do not handle any. |
| Microsoft Corporation — Entra ID | User authentication and directory lookup for the customer's own instance | Identity information, which stays within the customer's Azure tenant |
| Microsoft Corporation — Azure Marketplace | Sale, billing, and subscription lifecycle for Marketplace subscriptions, and delivery of any lead or private-offer enquiry you submit | Subscription, purchaser, and lead information |
| Microsoft Corporation — Azure Monitor and Application Insights | Operational logging and application diagnostics for our control-plane services | Our own operational logs, and telemetry received from customer instances |
| Amazon Web Services — S3 and CloudFront | Hosting the marketing website and distributing the desktop client installers | Website request logs only. No Customer Data. |
We require each sub-processor to be bound by obligations no less protective than those we owe our customers, and we remain responsible for their performance. We may update this list as our infrastructure changes; material additions affecting Customer Data will be reflected here.
We may also disclose information where we are legally required to do so, where necessary to establish or defend legal claims, or to a successor in connection with a merger, acquisition, or sale of assets. If we are legally compelled to disclose a customer's data, we will give that customer notice before doing so unless the law forbids it — though in this deployment model a demand for a customer's business records cannot be satisfied by us at all, because we do not hold them, and would have to be directed to the customer.
Separately, Nexus connects to third-party systems that the customer chooses, such as NetSuite, SQL Server, PostgreSQL, MySQL, QuickBooks Online, Monday.com, or a REST API. Those systems are not our sub-processors. Data sent to or read from them is governed by the customer's own relationship with those providers.
We maintain administrative, technical, and organizational safeguards designed to protect the information under our control — account and subscription records, telemetry, lead and support material, and the software and update channel we distribute. These include encryption of data in transit using TLS and encryption at rest, role-based access control, audit logging, and restricted internal access on a need-to-know basis.
The security of the deployment itself is in the customer's hands, not ours, because it runs in the customer's own Azure subscription: the customer's network controls, encryption keys, and Azure policies apply to it directly. The software stores credentials for connected systems in a key vault in that subscription and never returns their values in plaintext through the API, and it enforces the role-based access control the customer's administrators configure. We have no access to any of it.
We do not hold, and do not claim, SOC 2, ISO 27001, HIPAA, FedRAMP, or CMMC certification, and we do not claim a third-party penetration test. Microsoft's certifications for the underlying Azure platform are Microsoft's and are not ours. We do operate a documented internal security program and can provide evidence of it under a non-disclosure agreement.
No system can be guaranteed absolutely secure. If we become aware of a security incident affecting information under our control, we will notify the affected customer without undue delay and cooperate in their investigation and notification obligations. Incidents inside a customer's own Azure subscription are the customer's to detect and respond to, since we have no visibility into that environment; we will assist on request.
| Information | How long we keep it |
|---|---|
| Customer Data | We never hold it. Retention is entirely the customer's own decision within their Azure subscription, and cancelling a subscription does not cause us to delete anything, because there is nothing of it in our possession to delete. |
| Operational telemetry and logs | Up to thirty (30) days, unless a longer period is required for security investigation, audit, or legal reasons. |
| Account and subscription records | For the life of the relationship and for as long as needed afterwards for tax, accounting, and legal purposes. |
| Marketplace leads and enquiries | For as long as reasonably necessary to respond and to keep a record of the enquiry, and then deleted on request. |
| Support communications | For as long as reasonably necessary to resolve the request and to maintain a support history, and then deleted on request. |
If a customer deletes the managed application from their Azure subscription, Azure deletes the resources it created there, including the database, key vault, and stored files. That happens inside the customer's own subscription and is irreversible, so we recommend exporting anything you wish to keep first.
Customers and their users may:
Send requests to support@stingraytechnologysolutions.com. We will verify that the request comes from the customer or an authorized administrator before acting on it, and we will respond within a reasonable period. Where a request concerns Customer Data that we hold as a processor, we will refer it to the customer who controls that data, or act on that customer's documented instructions.
Customer Data stays in the Azure region the customer chooses, because the deployment runs in the customer's own Azure subscription and we hold no copy of it. Data residency for that data is therefore the customer's decision, not ours, and no transfer of it to us occurs.
What does cross to us is the account, subscription, lead, support, and operational telemetry information described in Section 3. Stingray is based in the United States and our control-plane services run in Microsoft Azure regions within the United States, so that information is transferred to and processed in the United States, where data-protection laws may differ from those in your country. A customer whose requirements do not permit even that should contact us to discuss options, including turning telemetry off, which an administrator can do at any time.
Nexus is business software intended solely for organizational use. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.
We may update this Privacy Policy. We will publish the updated version at this address with a new version identifier and "Last updated" date. For changes that materially affect how we handle personal information, we will give at least thirty (30) days' advance notice through the Service or by email to customer administrators before the change takes effect. Continued use of the Service after an updated version takes effect constitutes acceptance of it, and we may ask users to re-accept it in the product.
Stingray Technology Solutions, LLC
12 Bristol Ln
Palm Coast, FL 32137
United States
| Purpose | Address |
|---|---|
| Privacy and data requests, legal and contractual notices, and technical support | support@stingraytechnologysolutions.com |
| Security reports | security@stingraytechnologysolutions.com |