Privacy Policy
Last updated 21 July 2026
This policy explains how [Legal entity] (“we”) handles personal data for this website and the OAuth Verification Pack. We are the data controller. It covers our own site — it is not the privacy policy we help you build for your app.
What we collect
- Free scanner: the URL and scopes you submit, and the resulting report, are logged so we can improve the tool and follow up if you ask. Don’t paste secrets.
- Purchases: your email, billing details, and order data. Card details are handled by our payment processor (Stripe) — we never see or store full card numbers.
- Intake: the information you provide to build your pack (domain, scopes, stack, and the rejection email you upload).
- Email & account: your email address for transactional email and, if you sign in, basic account data.
Why, and the legal basis (GDPR)
- To deliver what you bought and provide support — performance of a contract.
- To operate and improve the scanner and site — our legitimate interests.
- To meet tax and accounting obligations — legal obligation.
Processors we use
- Vercel (hosting), Supabase (database/auth), Stripe (payments), Resend (email).
- Each processes data under its own data-processing terms. International transfers rely on the appropriate safeguards (e.g. SCCs / EU–US DPF) where applicable.
Retention
We keep order and intake data for as long as needed to deliver the Service and meet legal obligations, then delete or anonymise it. Scanner logs are kept to improve the tool and are periodically pruned. You can ask us to delete your data (see below).
Your rights
Subject to law, you can request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent. Email hello@oauthpack.dev; we respond within 30 days. You may also complain to your local data-protection authority.
Cookies
We use only what’s necessary to run the site and process payments. We do not run advertising trackers. If we add analytics, we’ll use a privacy-friendly, cookieless tool and update this policy.
Contact
Data controller: [Legal entity, address] · hello@oauthpack.dev.
Draft — complete the bracketed details and have it reviewed before publishing.