Information we collect
We collect account and organization details, verified asset identifiers, authorization records, bounded scan results and remediation activity, notification and billing metadata, support communications, security audit records, and optional coarse service telemetry.
Contact requests
The public contact form sends the name, work email, optional company, selected topic, and bounded message through Resend to a private VulnerabilityScan inbox. Message content is not stored in the application database. The application retains a pseudonymous request fingerprint, payload digest, delivery state, and provider message identifier for up to 30 days to prevent abuse, support idempotent retries, and diagnose delivery—not the submitted contact fields.
How information is used
Information is used to provide and secure the service, execute authorized scans, prioritize findings, send configured notifications, bill customers, support users, prevent abuse, meet legal obligations, and improve reliability.
Optional public-site analytics
Google Analytics is blocked unless a visitor explicitly allows it. When allowed, it is limited to an approved public-page path and bounded page title; advertising features are disabled. Account, organization, asset, domain, IP, scan, finding, report, billing, form, query-string, and free-text data are excluded. The choice is stored in the visitor’s browser and can be changed through Analytics preferences in the public footer.
Product telemetry boundary
The separate coarse product telemetry adapter is off unless a provider is explicitly configured. Its schema permits only bounded event, surface, outcome, dependency, and error categories and excludes user, organization, asset, scan, and request identifiers; targets, URLs, emails, notes, evidence, secrets, bodies, and cookies.
Export, deletion, and retention
Workspace administrators can download a bounded customer-visible JSON export and submit a reversible deletion request with a 72-hour cancellation window. A request enters human review; it does not immediately erase Clerk identity, Stripe, immutable audit, legal-hold, or backup records. Production retention periods and verified-deletion timelines require founder and counsel approval.
Service providers
Proposed providers include Vercel, a configured PostgreSQL provider, Clerk, AWS, Resend, Stripe, and consent-gated Google Analytics. Exact legal entities, purposes, regions, transfers, retention, and change-notice terms must be verified before the subprocessor list is approved. Payment-card details are handled directly by Stripe and are not stored in the application database.
Your choices
Workspace administrators can use product data controls and change notification preferences. Public visitors can decline or revoke optional analytics without losing product functionality. Jurisdiction-specific access, correction, deletion, objection, appeal, verification, and authorized-agent procedures remain subject to counsel-approved policy.
Contact
Privacy questions may be directed to privacy@vulnerabilityscan.com.