Privacy Policy
Last updated: December 2024
1. Introduction
Identity Signal ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our breach monitoring service.
2. Information We Collect
Information You Provide
- Email Addresses: Email addresses you submit for breach monitoring
- Account Information: Name, email, and password (encrypted) when you create an account
- Payment Information: Billing details processed securely through Stripe (we do not store full credit card numbers)
Automatically Collected Information
- Usage Data: Information about how you interact with our service
- Device Information: IP address, browser type, operating system
- Cookies: We use cookies to maintain your session and improve user experience
3. How We Use Your Information
We use your information to:
- Monitor data breaches and send you alerts when your information is found
- Provide, maintain, and improve our services
- Process your payments and manage your subscription
- Communicate with you about service updates and security alerts
- Analyze usage patterns to enhance user experience
- Prevent fraud and ensure platform security
4. Data Security
We implement industry-standard security measures to protect your information:
- All data transmissions are encrypted using TLS/SSL
- Passwords are hashed using bcrypt
- We use secure authentication via Supabase
- Regular security audits and updates
- Limited access to personal data on a need-to-know basis
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your data only in the following circumstances:
- Service Providers: With trusted third-party services (Supabase for authentication, Stripe for payments) that help us operate our platform
- Legal Requirements: When required by law, court order, or government regulation
- Protection of Rights: To protect our rights, privacy, safety, or property, and that of our users
- Business Transfers: In connection with a merger, acquisition, or sale of assets
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. You may delete your account at any time, which will remove your personal data from our systems within 30 days, except where retention is required by law.
7. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal data
- Data Portability: Receive your data in a structured, commonly used format
- Withdraw Consent: Opt-out of marketing communications at any time
- Object: Object to processing of your personal data under certain circumstances
8. Cookies and Tracking
We use cookies and similar tracking technologies to enhance your experience. You can control cookies through your browser settings, though this may affect functionality.
9. Third-Party Services
Our service integrates with:
- Supabase: For authentication and database services
- Stripe: For secure payment processing
- Have I Been Pwned API: For breach data (we do not share identifiable information)
These services have their own privacy policies governing their use of your information.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in compliance with applicable laws.
11. Children's Privacy
Our service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. Continued use of our service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please use our Contact Form.
14. GDPR Compliance (EU Users)
If you are in the European Economic Area (EEA), you have additional rights under GDPR, including the right to lodge a complaint with a supervisory authority. We process your data based on:
- Consent for marketing communications
- Contractual necessity to provide our services
- Legitimate interests in improving our service and preventing fraud
- Legal obligations
15. California Privacy Rights (CCPA)
California residents have specific rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete personal information, and the right to opt-out of the sale of personal information. We do not sell personal information.