Last updated: 14 August 2026
Panda Capital Oy Ab (Finnish business ID 3297809-7) ("we", "us", "our") respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, and store personal data when you access or use the Saturn SQL service ("Service").
The controller responsible for data processing is Panda Capital Oy Ab, registered in Finland under business ID 3297809-7.
This Privacy Policy applies to personal data processed in connection with registration for and use of the Service, and any associated websites or communications.
We process personal data as necessary to perform our contract with you, comply with legal obligations, and pursue legitimate interests such as improving the Service, maintaining security, and preventing fraud. Processing is performed in accordance with the GDPR and Finnish law.
We may collect limited information necessary to operate and improve the Service:
| Category | Details |
|---|---|
| Account information | Details provided during signup and account management |
| Service usage information | Technical and operational data generated through normal use of the Service |
| Authentication information | Data required to verify identity and maintain secure sessions, including password hashes, two-factor authentication (TOTP) secrets, session and refresh tokens, and API keys you generate |
| Connection information | Database connection details you configure (host, port, database name, username, and credentials stored encrypted), SSH bastion details for tunnelled connections (host, username, and SSH private keys stored encrypted), and cloud credentials such as AWS access keys for Redshift Data API connections (stored encrypted), needed to establish and maintain access to external data sources |
| Google account information | If you sign in with Google or connect Google Sheets: your Google account email address, basic profile information, and OAuth tokens (see Section 7 for details) |
| Slack workspace information | If you connect Slack: your workspace identifier and name, a bot access token (stored encrypted), and the identifiers and names of the channels you select for scheduled exports (see Section 8 for details) |
| Billing and subscription information | Payment-related and plan-related data processed by trusted third-party providers |
| Support and communication records | Information shared with us when contacting support or providing feedback |
| Early access or waitlist information | Contact details submitted to express interest before product availability |
We use collected data to:
We may share personal data with:
We do not sell personal data.
If you use Google Sign-In or connect the Google Sheets integration, we access, use, store, and share Google user data as described in this section.
We use Google user data solely to provide the features you request: authenticating you into the Service and exporting query results to the spreadsheets you choose, including keeping scheduled exports up to date. We do not use Google user data for advertising, we do not sell it, and we do not use it to develop or train artificial intelligence or machine learning models.
We store the OAuth tokens needed to access Google APIs on your behalf, your Google account email address, and the identifiers and names of spreadsheets you select for exports. Tokens are held in our access-controlled database, encrypted at rest by our database provider, and transmitted only over encrypted connections. We do not store the contents of your spreadsheets.
We do not share Google user data with third parties, except that it is stored and processed by the infrastructure subprocessors listed in Section 15 as strictly necessary to host and operate the Service. We do not transfer Google user data to any other apps or services.
Disconnecting the Google Sheets integration in your account settings immediately deletes our copy of your Google OAuth tokens. Deleting your account also deletes them. You can additionally revoke SaturnSQL’s access at any time from your Google Account permissions page.
SaturnSQL’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If a workspace administrator connects Slack, we store the Slack workspace identifier and name, a bot access token (encrypted at rest), and the identifiers and names of the channels you select as export destinations. We use this data solely to deliver the query results you schedule or send to Slack. We do not read messages from your Slack workspace.
Disconnecting the Slack integration in your account settings deletes our copy of the bot token. You can additionally remove the SaturnSQL app from your workspace in Slack's app management settings at any time.
If data is transferred outside the EEA, appropriate safeguards such as EU Standard Contractual Clauses or adequacy decisions are applied.
We retain personal data only as long as necessary for providing the Service and meeting legal requirements. After account termination, data is deleted or anonymised unless retention is legally required or needed for legitimate business purposes such as resolving disputes or auditing.
Users have the right to:
Requests can be made through the contact form available in the Service.
Cookies and similar technologies are used to operate, measure, and improve the Service. We use first-party cookies for authentication and session management, and Google Analytics 4 to measure how our website is used (page views, referral sources, and aggregate usage statistics). You can manage or disable cookies through your browser settings.
We apply strong technical and organisational measures such as encryption, access control, and monitoring. Absolute security cannot be guaranteed. We are not liable for accidental loss or unauthorised access except where caused by gross negligence or willful misconduct. Any data breach will be notified as required by law.
Updates will be published on the website with an updated effective date. Major changes may also be communicated in-app.
We rely on carefully selected third-party providers for infrastructure, hosting, analytics, and payment processing. Each provider is bound by a data processing agreement and required to maintain adequate technical and organisational measures to protect data. Updated information about subprocessors is made available through the Service.
| Service Provider | Service | Data Processed | Location |
|---|---|---|---|
| Vercel Inc. | Application Hosting & Deployment | Account data, session data, query metadata, server logs | United States |
| Neon (Serverless Postgres) | Database Storage | All user data, query history, account information | United States (AWS) |
| Upstash | Redis Cache & Rate Limiting | IP addresses, request metadata, rate limit counters | United States |
| Stripe Inc. | Payment Processing | Billing information, subscription data, payment records | United States |
| Google LLC | Google Sign-In, Google Sheets exports, website analytics (Google Analytics 4) | Account email, profile information, OAuth tokens, exported query results, aggregate usage statistics | United States |
| Slack Technologies, LLC | Slack message delivery (if connected) | Query results you schedule or send to Slack, workspace and channel identifiers | United States |
Where we process personal data contained in your connected databases on your behalf, we act as a processor under our Data Processing Agreement, which forms part of our Terms & Conditions and is compliant with GDPR requirements. A countersigned copy is available on request.
Questions or requests regarding this Privacy Policy may be submitted through the contact form in the Service.
© 2026 Panda Capital Oy Ab. All rights reserved.