Privacy Policy
Last updated 20 June 2026
Introduction
SecRift ("we," "our," or "us") operates SecRift available at secrift.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Information We Collect
Account Information
When you create an account, we collect:
- Full name and email address
- Profile picture and communication preferences
Usage Data
We automatically collect:
- Application Logs: Feature usage, actions performed, errors encountered
- Device Information: Browser type, operating system, screen resolution, device type
- Network Information: IP address, approximate location (city/country level)
- Session Data: Login times, session duration, pages/features accessed
- Performance Data: Load times, crashes, and diagnostic information
Information from Third Parties
We may receive information from:
- Authentication Providers: If you sign in via Google, or other OAuth providers
- Payment Processors: Transaction status and billing details (we do not store full credit card numbers)
- Analytics Services: Aggregated usage patterns
How We Use Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and maintain the Service | Contractual necessity |
| Process payments and subscriptions | Contractual necessity |
| Send transactional emails (receipts, password resets) | Contractual necessity |
| Improve features and user experience | Legitimate interest |
| Detect and prevent fraud or abuse | Legitimate interest |
| Send product updates and announcements | Legitimate interest (opt-out available) |
| Send marketing communications | Consent |
| Comply with legal obligations | Legal obligation |
Data Storage and Security
Infrastructure
Your data is stored on servers provided by AWS located in Europe.
Security Measures
We implement industry-standard security measures:
- All data encrypted in transit (TLS 1.2+)
- Data encrypted at rest (AES-256)
- Regular security audits and penetration testing
- Role-based access controls
- Multi-factor authentication available
- Automated backups with encryption
- SOC 2 Type II compliance (if applicable)
Data Breach Response
In the event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours (as required by GDPR)
- Notify relevant supervisory authorities
- Provide details on the nature of the breach and remediation steps
Third-Party Services
We use the following third-party services that may process your data:
| Service | Purpose | Data Shared |
|---|---|---|
| Google Analytics, Tag Manager | Usage analytics | Anonymized usage data |
| AWS | Transactional emails | Email address, name |
| Sentry | Bug detection | Error logs, device info |
| Cloudflare | Content delivery | IP address |
Each third-party service has its own privacy policy governing the use of your information.
Data Sharing
We do not sell your personal information. We may share data:
- With your team/organization: If you use a team or enterprise plan, administrators may access usage data and manage accounts
- With service providers: As listed above, strictly for providing the Service
- For legal compliance: When required by law, subpoena, or court order
- During business transfers: In connection with a merger, acquisition, or asset sale (you will be notified)
Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion |
| User-generated content | Duration of account + 30 days after deletion |
| Usage logs | 12 months |
| Payment records | 7 years (legal requirement) |
| Support tickets | 3 years |
After account deletion, we remove or anonymize your data within 30 days, except where retention is required by law.
Your Rights
All Users
- Access: Request a copy of your personal data
- Correction: Update inaccurate information
- Deletion: Delete your account and associated data
- Export: Download your data in a machine-readable format
- Objection: Object to certain processing activities
GDPR Rights (EEA/UK Residents)
- Right to restrict processing
- Right to data portability
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
Data Protection Officer: [email protected].
CCPA Rights (California Residents)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt out of the sale of personal information (we do not sell data)
- Right to non-discrimination
To exercise any of these rights, contact us at [email protected] or use Contact Form.
Cookies
We use cookies for:
- Authentication: Keeping you logged in
- Preferences: Remembering your settings
- Analytics: Understanding how the Service is used
- Security: Detecting and preventing threats
You can manage cookie preferences in your browser settings.
International Data Transfers
If you access the Service from outside UE, your data may be transferred to and processed in Europe. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Data Processing Agreements with all sub-processors
Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect information from children.
Changes to This Policy
We will notify you of material changes via email or an in-app notification at least 30 days before the changes take effect. Continued use of the Service after changes constitutes acceptance.
Contact
For privacy-related inquiries:
- Email: [email protected]
- Address: Z. Wasiutynskiego 17, 00-707 Warsaw, Poland
- Data Protection Officer: [email protected]