
Sandstorm.io
GDPR evidence
Take control of your web by running your own personal cloud server with
Sandstorm.io and GDPR
CertReports found no public GDPR evidence for Sandstorm.io as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 11 Apr 2017
- Scope
- Sandstorm intends only to gather your personal data in ways that are clear and obvious from the user interface. The service gathers email addresses from all users. Users are required to provide a valid email address, as this is the primary mechanism by which we will notify them of issues regarding their account. The service also gathers a few pieces of personal "profile information" for the purpose of identifying the user to other people on the service. These include: name, profile picture or avatar (optionally uploaded by user), unique user ID corresponding to the login service(s) the user used to authenticate (for example, the user's Github username, if they log in using Github), and any other personal information which the user chose to add to their profile. Sandstorm does not sell any personal data to any third party. We do not share personal data with any third party, except as necessary to implement the service. For instance, if you choose to log in through Github, then we share data with Github, but only as necessary to implement login.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Sandstorm.io: Inactive | Live pagesha256 ad3208bd9d |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Sandstorm.io GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 18 Sep 2026First indexed by CertReports1 evidence row across 1 framework entered the index.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.