Legal

Privacy Policy

Effective date: August 11, 2026 · Last updated: August 11, 2026

1. Who we are

StackSecured (“StackSecured,” “we,” “us,” or “our”) is a security scanning service that audits web applications for vulnerabilities. Our service is operated from India and available globally. Our primary contact email is djdeepakjha@gmail.com.

2. What data we collect

Data you provide

  • Email address — only if you create an account or purchase a report
  • App URLs — the URL you submit for scanning
  • Payment data — processed by our payment provider; we never see your card number

Data collected automatically

  • IP address — for abuse prevention and rate limiting
  • Scan results — the vulnerability findings for your submitted URL, stored in our database
  • Browser & device info — standard web analytics (page views, browser type)

Data we do NOT collect

  • Passwords or credentials for the apps you scan
  • Source code — we only scan publicly accessible endpoints
  • Data from inside your database or private files

3. How we use your data

  • To run the security scan you requested and display results
  • To store your scan history if you have an account
  • To process payments for unlocked reports
  • To send transactional emails (scan complete, report ready) — never marketing without consent
  • To detect and prevent abuse of the scanning service
  • To improve the accuracy and coverage of our scanners

4. Who we share your data with

We do not sell your data. We share only what is necessary to operate the service:

ProviderPurposeData shared
SupabaseDatabase & authenticationEmail, scan results, account data
VercelHosting & serverless functionsIP address, request logs
CashfreePayment processingEmail, payment amount
ResendTransactional emailEmail address, scan ID

5. Data retention

  • Scan results — retained for 90 days, then permanently deleted
  • Account data — retained while your account is active; deleted within 30 days of account closure
  • Payment records — retained for 7 years as required by financial regulations
  • Logs — retained for 30 days for abuse prevention

6. Cookies

We use session cookies to keep you logged in, and essential cookies for security (CSRF protection). We do not use tracking cookies or third-party advertising cookies. If we add analytics in future, we will update this policy and provide an opt-out.

7. Your rights

Depending on where you are located, you may have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Correction — request we fix inaccurate data
  • Deletion — request we delete your personal data (“right to be forgotten”)
  • Opt-out of sale — we do not sell data, so this right is automatically satisfied
  • Portability — request your data in a machine-readable format

To exercise any right, email us at djdeepakjha@gmail.com with “Privacy Request” in the subject line. We respond within 30 days.

8. Security of your data

We use industry-standard protections: HTTPS everywhere, encrypted database connections, row-level security on our database (Supabase RLS), and environment variable separation for secrets. No system is perfectly secure, and we cannot guarantee absolute security — but we take it seriously, which is why we built this product in the first place.

9. Children's privacy

StackSecured is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has submitted data to us, contact us and we will delete it immediately.

10. Changes to this policy

We may update this policy as the product evolves. If we make material changes, we will update the “Last updated” date at the top and, if you have an account, notify you by email. Continued use of the service after changes constitutes acceptance.

11. Contact

Questions about this policy? Email djdeepakjha@gmail.com with “Privacy Policy” in the subject line.