Sluiceway terms of service
These are the current terms of the hosted Sluiceway app. The free Sluiceway action is not covered by them: it is under the Apache-2.0 licence only.
Last updated
These terms apply to the hosted Sluiceway app (the "Service"): the GitHub App named Sluiceway, the console at console.sluiceway.dev and its command-line API. They are an agreement between you, the organization that installs the app (the "Customer"), and Robbe Verhelst (sole proprietorship), Buisstraat 45, 2890 Sint-Amands, Belgium, company and VAT number BE 1024.261.897 ("Sluiceway", "we").
The Service is for businesses, not for consumers. By installing the app or subscribing to a plan, you confirm that you use it for your trade, business or profession.
The open source Sluiceway action is not covered by these terms. It is licensed under Apache-2.0 and has no account, no fee and no contract with us.
1. What the Service does
The Service reads the Sluiceway dashboards, deployment records and workflow runs of the repositories you install it on, and gives you:
- the console: an org-wide view of every stack of every repository, each repository's dashboard, and your organization's settings;
- ticking a stack to deploy, and rescanning, from the console and from the command line, as well as on the dashboard issue;
- an onboarding pull request that sets Sluiceway up in a repository, and pull requests that change a repository's Sluiceway settings, which a person on your side merges;
- an audit log of every deploy, rescan and command-line pull request, and Insights computed from your deploys, merges and scans;
- emails about your plan and your data to the billing email of your plan;
- on a paid plan, a required second approver: a deploy waits until a second person approves it;
- personal API tokens for the command line.
2. What Sluiceway never does
These are part of the agreement, not only a description:
- Sluiceway never holds a credential of your cloud or infrastructure. Previews and deploys run in your own GitHub Actions runners with your own secrets.
- Sluiceway never deploys on its own initiative. A deploy starts only from a tick by a person your repository's tick rule allows, whether the tick is made on the dashboard issue, in the console or from the command line. The app judges each tick with the Sluiceway action's own code. For an allowed tick it opens the deployment record and starts your workflow, which runs in your runners with your credentials, previews again and deploys only what was ticked.
- Sluiceway keeps stack-level facts only: the repository, the stack id (which names where the stack lives in the repository and what it is called), its state, the counts of changes, who ticked, merged, rescanned or approved, which commit, when, and whether a deploy skipped your rules. It never keeps resource names, resource types, property paths, diffs, property values or the text of your dashboard issue. Those stay on GitHub.
3. Your responsibilities
- Deploys are yours. Whatever runs in your workflows, and whatever it changes in your infrastructure, is under your control and your responsibility. The Service observes, reports and starts the workflow for a tick your rules allow; it does not decide what a deploy changes. On a paid plan, a second approver you choose approves or rejects each held deploy.
- A flag from the Service is a detective control: it tells you a deploy skipped your rules after it happened. It does not block that deploy unless you set up blocking, such as the required second approver.
- You keep your GitHub account, your repositories and your personal API tokens secure, and you decide who in your organization may install or configure the app.
- You do not use the Service to break the law, to attack GitHub or others, or to try to reach data of other customers.
4. Plans and fees
| Plan | Repos | History | Price |
|---|---|---|---|
| Hosted free | up to 5 | 30 days | 0 |
| Team | up to 25 | 13 months | 199 USD a month, or 1,990 USD a year |
| Team Plus | up to 100 | 3 years | 499 USD a month, or 4,990 USD a year |
| Larger | over 100 | as agreed in writing | as agreed in writing |
Prices exclude VAT and other taxes, which are added where the law requires. A self-serve plan is paid by card through Stripe when you subscribe, and renews each month or year until you cancel it. If the Service is offered on GitHub Marketplace and you buy it there, GitHub bills you under its own terms. A plan agreed in writing is invoiced, and invoices are due within 30 days.
History is how long the audit log keeps deploys, ticks, rescans and merges. We may change the free plan or prices with 30 days' notice; a price change applies to a paid plan from its next renewal.
5. Cancelling
- You can cancel at any time: in the billing portal, which the console's billing settings open, by uninstalling the app from your GitHub organization, or by writing to [email protected].
- A monthly plan ends at the end of the month paid for. A yearly plan ends at the end of the year paid for. We do not refund the unused part, unless the law requires it.
- When a paid plan ends, your organization stays on the hosted free plan. History older than the free plan's 30 days is deleted within 31 days after the plan ends.
- When the app is uninstalled, we delete your data within 31 days after. An admin of your organization can also delete everything at once from the console's settings. See section 7.
- We may end the Service for you with 30 days' notice, or at once if you break these terms seriously. If we end it without such a reason, we refund the unused part of a prepaid period.
6. Availability
The Service runs on hardware Sluiceway owns and operates itself. We make no promise of uptime and offer no service level agreement. GitHub stays the source of truth: when the Service is down, the console falls behind, flags are delayed and ticks made in the console wait, and when it comes back it catches up from GitHub. Your dashboards, ticks and deploys on GitHub keep working without the Service, because the open source action does not depend on it.
7. Your data
Your data is yours. What we hold, how long, and who else sees it is in the privacy policy and, for personal data we process on your behalf, in the data processing agreement, which is part of these terms.
8. Liability
The Service is provided as it is. To the extent the law allows:
- we are not liable for indirect or consequential loss, lost profit, or anything that follows from a deploy, since deploys run in your runners under your control;
- our total liability in any 12 months is at most what you paid us in those 12 months.
Nothing in these terms limits liability that the law does not allow to be limited.
9. Changes to these terms
We tell you about changes at least 30 days before they apply, by email to the billing email of a paid plan or the address on your invoice, and by posting the new terms on this page with their date. If you do not agree, you may cancel before they apply and we refund the unused part of a prepaid period.
10. Law and courts
These terms are governed by the law of Belgium. Disputes go to the courts of Antwerp, division Mechelen (the district of the seller's seat), Belgium, unless the law gives you the right to another court.
Contact
Robbe Verhelst (sole proprietorship), Buisstraat 45, 2890 Sint-Amands, Belgium, company and VAT number BE 1024.261.897, [email protected]