Version 2026-08-15 · Last updated: August 15, 2026
This Privacy Policy explains what information Stingray Technology Solutions, LLC ("Stingray," "we," "our," or "us") collects in connection with Nexus, how we use it, who we share it with, and how long we keep it. It applies to the Nexus platform, the Nexus desktop and web clients, the Nexus Excel add-in, and the Stingray marketing website (together, the "Service"). It is part of, and should be read with, our SaaS Terms of Service.
Nexus is enterprise software sold to organizations. Most of the information we handle relates to a business customer and its personnel rather than to consumers.
This policy covers the Nexus software-as-a-service subscription, which Stingray operates for you. If Nexus is instead deployed into your own Microsoft Azure subscription as a Managed Application, the Nexus Self-Hosted Privacy Policy applies to you instead, and the difference is significant: in that model we never hold your business data at all.
Our role depends on the type of information:
If you are an employee of one of our customers and have a question about the business data your employer processes in Nexus, please contact your own organization first. We will refer such requests to the customer that controls the data.
This is the single most important thing to understand about our handling of Customer Data, so it is stated plainly: under this policy, we hold it.
Stingray runs the customer's Nexus instance in a Stingray-operated Microsoft Azure subscription, in the United States. In this model Customer Data is stored on infrastructure we operate. Each customer gets a dedicated application instance, a dedicated database, and a dedicated Azure Key Vault for credentials. The database server is shared at the server level with other customers' separate databases; the data itself is not commingled.
Deployments into Microsoft Azure Government, including GCC High, run in the customer's own government-cloud tenant and are governed by a separate written agreement. Stingray does not hold Customer Data from those deployments.
Users sign in through Microsoft Entra ID. Microsoft performs the authentication and returns a token to Nexus. From that token and from the Microsoft directory we may receive:
We never receive or store user passwords.
For subscriptions purchased through the Microsoft Azure Marketplace, Microsoft is the merchant of record. Microsoft sends us the information needed to provision and maintain the subscription, which includes the subscription identifier, the plan, the purchaser's name and email address, the Azure tenant identifier, and lifecycle notifications such as renewal, suspension, and cancellation.
We do not receive, process, or store payment card numbers, bank details, or any other payment instrument. Those are handled entirely by Microsoft.
A Nexus instance can report limited operational information to a Stingray-operated control plane so we can monitor product health, diagnose faults, and understand which capabilities are used. Telemetry is deliberately narrow, and what it contains is fixed by an allowlist in the software:
| Category | What is sent |
|---|---|
| Instance identity | Tenant and deployment identifiers, Nexus version, adapter names and versions |
| Usage counters | Counts only — for example the number of active reports, pipelines, and configured connections. Names and values of connections are never sent. |
| Errors and diagnostics | Error type, error message, the connector or pipeline step involved, and HTTP status. Error messages are automatically stripped of file paths, IP addresses, and credential-shaped strings before transmission. |
| Security alerts | Aggregate signals such as an unusual number of failed sign-ins or pipeline failures within a time window |
Telemetry does not include customer business records, query results, report contents, file contents, or connection credentials. An administrator can turn telemetry off at any time from the product's administration settings, and it can also be disabled in the instance's configuration at deployment time.
When you contact support, we retain your name and email address, the content of your request, and any logs, screenshots, or diagnostic information you choose to send us. Please do not send us production business records or credentials in a support request; if you do, they will be handled as Customer Data and deleted when the request is closed.
If you ask to be contacted about Nexus through the Microsoft Azure Marketplace — for example by requesting a private offer or asking us to get in touch — Microsoft passes us the contact details you provided, which typically include your name, business email address, company name, country, and any message you wrote. We store those details in our own Microsoft Azure storage in the United States and use them solely to respond to your enquiry and to keep a record of it. We do not use them for unrelated marketing, and we do not sell or share them. Ask us to delete a lead record at any time using the contact address in Section 13.
Our marketing website is a static site delivered through a content delivery network. Standard server-side request logs, including IP address, user agent, and requested URL, are generated by that infrastructure. We do not use advertising cookies or third-party tracking or analytics scripts on the marketing website.
We necessarily store what the customer puts into their instance, because we operate that instance. Beyond that, and beyond material a customer voluntarily sends us in a support request, we do not collect:
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use Customer Data to train machine-learning or artificial-intelligence models. Nexus itself ships no artificial-intelligence features.
We use the information described above to:
Where the law requires a legal basis for processing, ours is the performance of our contract with the customer, our legitimate interests in operating and securing the Service, and compliance with legal obligations.
We do not sell information, and we share it only as described here. Our sub-processors are:
| Provider | What it does for us | What it may handle |
|---|---|---|
| Microsoft Corporation — Azure | Cloud infrastructure for your Nexus instance and for our control plane: compute, database, key vault, storage, and container registry | Customer Data, account and operational information |
| Microsoft Corporation — Entra ID | User authentication and directory lookup | Identity information |
| Microsoft Corporation — Azure Marketplace | Sale, billing, and subscription lifecycle for Marketplace subscriptions, and delivery of any lead or private-offer enquiry you submit | Subscription, purchaser, and lead information |
| Microsoft Corporation — Azure Monitor and Application Insights | Operational logging and application diagnostics | Operational logs and telemetry |
| Amazon Web Services — S3 and CloudFront | Hosting the marketing website and distributing the desktop client installers | Website request logs only. No Customer Data. |
We require each sub-processor to be bound by obligations no less protective than those we owe our customers, and we remain responsible for their performance. We may update this list as our infrastructure changes; material additions affecting Customer Data will be reflected here.
We may also disclose information where we are legally required to do so, where necessary to establish or defend legal claims, or to a successor in connection with a merger, acquisition, or sale of assets. If we are legally compelled to disclose a customer's data, we will give that customer notice before doing so unless the law forbids it.
Separately, Nexus connects to third-party systems that the customer chooses, such as NetSuite, SQL Server, PostgreSQL, MySQL, QuickBooks Online, Monday.com, or a REST API. Those systems are not our sub-processors. Data sent to or read from them is governed by the customer's own relationship with those providers.
We maintain administrative, technical, and organizational safeguards designed to protect the information under our control. These include encryption of data in transit using TLS and encryption at rest, per-customer isolation of application instances, databases, and credential vaults, credential storage in Azure Key Vault with values never returned in plaintext through the API, role-based access control, audit logging, and restricted internal access on a need-to-know basis.
We do not hold, and do not claim, SOC 2, ISO 27001, HIPAA, FedRAMP, or CMMC certification, and we do not claim a third-party penetration test. Microsoft's certifications for the underlying Azure platform are Microsoft's and are not ours. We do operate a documented internal security program and can provide evidence of it under a non-disclosure agreement.
No system can be guaranteed absolutely secure. If we become aware of a security incident affecting Customer Data under our control, we will notify the affected customer without undue delay and cooperate in their investigation and notification obligations.
| Information | How long we keep it |
|---|---|
| Customer Data | For the life of the subscription. On cancellation, or on expiry of the term without renewal, access is suspended immediately and the data is retained in recoverable form for thirty (30) days, after which the instance, its database, its stored files, and its key vault contents are permanently deleted. |
| Operational telemetry and logs | Up to thirty (30) days, unless a longer period is required for security investigation, audit, or legal reasons. |
| Account and subscription records | For the life of the relationship and for as long as needed afterwards for tax, accounting, and legal purposes. |
| Marketplace leads and enquiries | For as long as reasonably necessary to respond and to keep a record of the enquiry, and then deleted on request. |
| Support communications | For as long as reasonably necessary to resolve the request and to maintain a support history, and then deleted on request. |
Deletion after the thirty-day window is irreversible. We recommend exporting anything you wish to keep before cancelling, and in any event during that window.
Customers and their users may:
Send requests to support@stingraytechnologysolutions.com. We will verify that the request comes from the customer or an authorized administrator before acting on it, and we will respond within a reasonable period. Where a request concerns Customer Data that we hold as a processor, we will refer it to the customer who controls that data, or act on that customer's documented instructions.
Stingray is based in the United States, and Hosted Deployments run in Microsoft Azure regions within the United States. If you access the Service from outside the United States, information about you will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Customers with data-residency requirements that a United States region does not satisfy should deploy Nexus into their own Azure subscription under the Self-Hosted Privacy Policy, which runs in the Azure region the customer chooses, or contact us to discuss options.
Nexus is business software intended solely for organizational use. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.
We may update this Privacy Policy. We will publish the updated version at this address with a new version identifier and "Last updated" date. For changes that materially affect how we handle personal information, we will give at least thirty (30) days' advance notice through the Service or by email to customer administrators before the change takes effect. Continued use of the Service after an updated version takes effect constitutes acceptance of it, and we may ask users to re-accept it in the product.
Stingray Technology Solutions, LLC
12 Bristol Ln
Palm Coast, FL 32137
United States
| Purpose | Address |
|---|---|
| Privacy and data requests, legal and contractual notices, and technical support | support@stingraytechnologysolutions.com |
| Security reports | security@stingraytechnologysolutions.com |