PrivacyRadar

Legal

Privacy Policy

Effective: August 5, 2026 · Last reviewed: August 23, 2026

1. Who we are

This Privacy Policy describes how PrivacyRadar (“PrivacyRadar,” “we,” “us”) collects, uses, and shares personal information when you visit www.privacyradar.io, use app.privacyradar.io, or otherwise interact with our services.

Privacy contact: use the form at /contact?topic=privacy. Security contact: use the form at /contact?topic=security. We have not appointed a separate EU/UK representative or Data Protection Officer; privacy requests are handled through the Privacy topic on that form. For formal legal notices or service of process, submit via /contact?topic=privacy and we will provide a current mailing address.

PrivacyRadar provides a Privacy Observability Platform: continuous monitoring that surfaces privacy-risk, consent, and disclosure signals across websites, vendors, policies, and APIs that a customer authorizes us to scan. We do not provide legal advice.

2. Scope

This notice covers: (a) our public marketing website and free tools; (b) the authenticated SaaS product (dashboard, API, workers); and (c) related sales, support, and security-review communications.

It does not govern websites or services that PrivacyRadar merely scans on a customer’s instructions. For those properties, the customer is typically the controller; PrivacyRadar acts as a processor / service provider for scan-related personal data as described in the customer agreement and any Data Processing Agreement (DPA).

3. Personal information we collect

Depending on how you interact with us, we may process:

  • Account & identity data — name, work email, authentication identifiers, organization membership and roles (via Clerk).
  • Commercial & billing data — company name, plan, invoices, and payment-related metadata (via Stripe; card numbers are handled by Stripe).
  • Marketing & sales leads — work email, optional company name, optional website URL, optional message, lead source, and form metadata.
  • Customer content & scan data — URLs and assets you register; crawl/consent/policy observations; screenshots, HAR excerpts, cookie metadata, network logs, and other evidence artifacts; findings and reports derived from those observations.
  • Usage & device data — IP address, user agent, approximate location derived from IP, pages viewed, referring URLs, and similar diagnostics (including marketing analytics when enabled).
  • Communications — support tickets, security questionnaires, demo notes, and email correspondence.
  • Security & abuse-prevention data — rate-limit counters, honeypot signals, Turnstile challenge results (when enabled), and audit-log entries for authorization-sensitive actions.

4. Sources

We collect information directly from you (forms, account setup, support); automatically from your browser or device; from your organization administrators (invites, SSO/SCIM); from payment and identity providers; and from the public web pages and related resources you authorize us to scan.

Scan data may include personal information that appears on or is transmitted by the scanned property (for example, third-party identifiers in network traffic). We process that data to provide the service to the customer that authorized the scan.

5. How we use personal information

We use personal information to:

  • Provide, operate, secure, and improve the PrivacyRadar services.
  • Run authorized scans, generate findings and reports, and deliver change alerts.
  • Authenticate users, enforce roles and quotas, and maintain auditability.
  • Process subscriptions, invoices, and related billing.
  • Respond to demos, contact requests, security questionnaires, and support.
  • Detect fraud, abuse, and security incidents; protect our rights and users.
  • Comply with law and respond to lawful requests.
  • Understand aggregated product and marketing-site usage (including Google Analytics when configured and accepted) so we can improve reliability, content, and conversion.
  • Measure marketing-site advertising conversions with the LinkedIn Insight Tag when you accept optional advertising measurement.

6. Notice at collection (California)

At or before collection, we collect the categories in Section 3 for the business purposes in Section 5. We retain each category for the periods in Section 9. We disclose personal information to service providers / subprocessors listed at /trust/subprocessors for those business purposes.

We do not sell personal information for money. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA.

If you accept optional advertising measurement on the marketing site, we load LinkedIn’s Insight Tag so we can measure ad conversions. That tag may constitute “sharing” for cross-context behavioral advertising under the CPRA. It does not load if you reject optional measurement or if your browser sends Global Privacy Control (GPC).

We honor GPC and similar browser opt-out preference signals as a request to opt out of sale or sharing. When GPC is present, advertising measurement does not load even if you previously accepted optional cookies.

8. How we share information

We share personal information with subprocessors that host or power the service (see /trust/subprocessors), with professional advisors under confidentiality, with authorities when required by law, and with a successor in connection with a corporate transaction (subject to appropriate confidentiality).

We do not sell personal information for money. Advertising measurement (LinkedIn Insight Tag) loads only after you accept optional measurement, and never when GPC is present.

Customer scan outputs are available to that customer’s authorized users and, if the customer configures them, to the customer’s integrations (for example webhooks or API consumers).

9. Retention

We retain personal information only as long as needed for the purposes above, including to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Typical periods:

  • Marketing and sales leads — up to 24 months from last meaningful contact, or sooner if you ask us to delete.
  • Account and organization data — for the life of the membership or organization relationship, then up to 90 days after deletion or account closure (longer if needed for security, dispute, or legal holds).
  • Scan evidence, findings, and reports — while the customer subscription is active and for up to 90 days after cancellation or deletion request, unless a customer contract or legal hold requires longer retention.
  • Security and authorization audit logs — up to 24 months.
  • Billing and tax records — up to 7 years or as required by applicable tax and accounting rules.

10. Security

We implement administrative, technical, and organizational measures appropriate to the risk, including tenant-scoped queries, hashed evidence storage, signed report exports when signing keys are configured, scoped API credentials, encryption in transit, secrets in a managed vault, and access controls with audit logging. See /security for a public summary.

No method of transmission or storage is perfectly secure. If you believe you have found a vulnerability, submit a report via /contact?topic=security.

11. International transfers

We and our subprocessors may process personal information in Canada (including Azure Canada Central for primary infrastructure), the United States, and other countries where our providers operate.

Where GDPR or UK GDPR transfer rules apply, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and UK addenda where required), provider adequacy mechanisms, or other lawful transfer tools described in our customer DPA. Enterprise customers may request a DPA via /contact?topic=privacy.

12. Your rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent where processing is consent-based. California residents may have additional rights under the CCPA/CPRA, including to know, delete, correct, and opt out of sale/sharing, and not to be discriminated against for exercising rights.

To exercise rights, submit a request via /contact?topic=privacy from the address associated with your request (or have your organization’s admin contact us for account-level requests). We may need to verify your identity. Authorized agents may submit requests where law allows, subject to verification. We aim to respond within 45 days (or sooner where local law requires), and may extend once where permitted.

If we deny a request, you may appeal by replying to our decision email or submitting via /contact?topic=privacy with the subject line “Privacy Appeal” in the message. If you are unsatisfied after appeal, you may contact your local data protection authority or, for California residents, the California Privacy Protection Agency.

13. Cookies and similar technologies

The marketing site and application use strictly necessary cookies and similar technologies for security and session continuity (including authentication cookies set by our identity provider).

If you accept optional measurement, the marketing site may load Google Analytics (usage analytics) and the LinkedIn Insight Tag (advertising conversion measurement). Both stay off until you accept. You can change this later via Cookie settings in the footer. Global Privacy Control blocks the LinkedIn tag.

You can also control cookies through your browser settings. Blocking some necessary cookies may affect sign-in or form abuse protection.

14. Children

PrivacyRadar is a business service and is not directed to children under 16 (or the age required by local law). We do not knowingly collect personal information from children. If you believe a child has provided us information, use /contact?topic=privacy and we will take appropriate steps.

15. Changes

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date. Material changes may be communicated by email or in-product notice where appropriate.

16. Contact

Privacy questions and rights requests: /contact?topic=privacy

Security reviews and vulnerability reports: /contact?topic=security

General contact: /contact

Related: Privacy Policy · Acceptable Use · Trust Center · Subprocessors · Security.