SecRift
BlogContact
Sign in
Legal

Privacy Policy

Last updated 20 June 2026

Introduction

SecRift ("we," "our," or "us") operates SecRift available at secrift.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

Information We Collect

Account Information

When you create an account, we collect:

  • Full name and email address
  • Profile picture and communication preferences

Usage Data

We automatically collect:

  • Application Logs: Feature usage, actions performed, errors encountered
  • Device Information: Browser type, operating system, screen resolution, device type
  • Network Information: IP address, approximate location (city/country level)
  • Session Data: Login times, session duration, pages/features accessed
  • Performance Data: Load times, crashes, and diagnostic information

Information from Third Parties

We may receive information from:

  • Authentication Providers: If you sign in via Google, or other OAuth providers
  • Payment Processors: Transaction status and billing details (we do not store full credit card numbers)
  • Analytics Services: Aggregated usage patterns

How We Use Your Information

PurposeLegal Basis (GDPR)
Provide and maintain the ServiceContractual necessity
Process payments and subscriptionsContractual necessity
Send transactional emails (receipts, password resets)Contractual necessity
Improve features and user experienceLegitimate interest
Detect and prevent fraud or abuseLegitimate interest
Send product updates and announcementsLegitimate interest (opt-out available)
Send marketing communicationsConsent
Comply with legal obligationsLegal obligation

Data Storage and Security

Infrastructure

Your data is stored on servers provided by AWS located in Europe.

Security Measures

We implement industry-standard security measures:

  • All data encrypted in transit (TLS 1.2+)
  • Data encrypted at rest (AES-256)
  • Regular security audits and penetration testing
  • Role-based access controls
  • Multi-factor authentication available
  • Automated backups with encryption
  • SOC 2 Type II compliance (if applicable)

Data Breach Response

In the event of a data breach that affects your personal information, we will:

  1. Notify affected users within 72 hours (as required by GDPR)
  2. Notify relevant supervisory authorities
  3. Provide details on the nature of the breach and remediation steps

Third-Party Services

We use the following third-party services that may process your data:

ServicePurposeData Shared
Google Analytics, Tag ManagerUsage analyticsAnonymized usage data
AWSTransactional emailsEmail address, name
SentryBug detectionError logs, device info
CloudflareContent deliveryIP address

Each third-party service has its own privacy policy governing the use of your information.

Data Sharing

We do not sell your personal information. We may share data:

  • With your team/organization: If you use a team or enterprise plan, administrators may access usage data and manage accounts
  • With service providers: As listed above, strictly for providing the Service
  • For legal compliance: When required by law, subpoena, or court order
  • During business transfers: In connection with a merger, acquisition, or asset sale (you will be notified)

Data Retention

Data TypeRetention Period
Account dataDuration of account + 30 days after deletion
User-generated contentDuration of account + 30 days after deletion
Usage logs12 months
Payment records7 years (legal requirement)
Support tickets3 years

After account deletion, we remove or anonymize your data within 30 days, except where retention is required by law.

Your Rights

All Users

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate information
  • Deletion: Delete your account and associated data
  • Export: Download your data in a machine-readable format
  • Objection: Object to certain processing activities

GDPR Rights (EEA/UK Residents)

  • Right to restrict processing
  • Right to data portability
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

Data Protection Officer: [email protected].

CCPA Rights (California Residents)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt out of the sale of personal information (we do not sell data)
  • Right to non-discrimination

To exercise any of these rights, contact us at [email protected] or use Contact Form.

Cookies

We use cookies for:

  • Authentication: Keeping you logged in
  • Preferences: Remembering your settings
  • Analytics: Understanding how the Service is used
  • Security: Detecting and preventing threats

You can manage cookie preferences in your browser settings.

International Data Transfers

If you access the Service from outside UE, your data may be transferred to and processed in Europe. We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) for EU data transfers
  • Data Processing Agreements with all sub-processors

Children's Privacy

The Service is not intended for users under 16 years of age. We do not knowingly collect information from children.

Changes to This Policy

We will notify you of material changes via email or an in-app notification at least 30 days before the changes take effect. Continued use of the Service after changes constitutes acceptance.

Contact

For privacy-related inquiries:

  • Email: [email protected]
  • Address: Z. Wasiutynskiego 17, 00-707 Warsaw, Poland
  • Data Protection Officer: [email protected]

SecRift

Fast, professional security scans for any domain - email auth, mail transport, and DNS, graded and reported.

ProductScan a domain
CompanyBlogContact
LegalTermsPrivacy
© 2026 SecRift. All rights reserved.