Privacy Policy
Last updated: March 9, 2026
REDWIPE LLC ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the REDWIPE platform ("Service").
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, organization name, and role. If you sign up using Google SSO, we receive your Google profile name, email, and profile image.
Scan Results
When you use our scanning services, we collect and store scan results, including discovered assets, vulnerabilities, findings, evidence data, and remediation recommendations. This data is associated with your organization and protected by multi-tenant row-level security.
Payment Information
Payment processing is handled by Stripe. We do not store credit card numbers or full payment details on our servers. Stripe provides us with a customer ID, subscription status, and billing history.
Usage Data
We collect anonymized usage analytics using cookieless analytics (Plausible/Fathom). This includes page views, referrer URLs, browser type, and general geographic location. No personal identifiers are associated with this data.
2. How We Use Your Information
- Provide the Service: Perform security scans, generate findings, produce compliance reports, and deliver notifications.
- Improve the Platform: Train and refine our AI models for false positive detection, risk scoring, and remediation generation using aggregated, de-identified data.
- Security Notifications: Send email alerts for critical vulnerabilities, scan completions, and account security events.
- Compliance: Respond to legal requests and comply with applicable laws and regulations.
3. Data Retention
- Findings and Reports: Retained indefinitely while your account is active. You may request deletion at any time.
- Raw Scan Artifacts: Raw scan data (Nuclei output, raw HTTP responses, raw DNS records) is retained for 90 days, then automatically purged.
- Account Data: Deleted within 30 days of account closure. You will receive a confirmation email when deletion is complete.
4. Data Security
We implement industry-standard security measures to protect your data:
- Encryption at Rest: AES-256 encryption for all stored data.
- Encryption in Transit: TLS 1.2+ for all network communications.
- Multi-Tenant Isolation: Row-level security (RLS) policies ensure strict data isolation between organizations.
- Infrastructure: Hosted on Google Cloud Platform with private networking, distroless containers, and no public database endpoints.
5. GDPR Compliance
For users in the European Economic Area (EEA), we process your data under the following lawful bases:
- Contract Performance: Processing necessary to provide the Service you have subscribed to.
- Legitimate Interest: Improving our platform and ensuring the security of our Service.
- Consent: For optional marketing communications (you may opt out at any time).
You have the following rights under GDPR:
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements).
- Right to Portability: Receive your data in a structured, machine-readable format.
- Right to Rectification: Correct inaccurate personal data.
- Right to Object: Object to processing based on legitimate interest.
To exercise these rights, contact privacy@redwipe.com. We will respond within 30 days.
6. CCPA Compliance
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request that we delete the personal information we have collected from you.
- No Sale of Personal Information: We do not sell your personal information to third parties. We have not sold personal information in the preceding 12 months.
7. Cookie Policy
We use only strictly necessary session cookies for authentication purposes. We do not use advertising, analytics, or tracking cookies. For full details, see our Cookie Policy.
8. Third-Party Processors
We use the following third-party services to deliver and support the platform:
| Provider | Purpose | Data Processed |
|---|---|---|
| Google Cloud Platform | Infrastructure hosting | All application data |
| Firebase Authentication | User authentication | Email, name, auth tokens |
| Stripe | Payment processing | Billing details, payment method |
| Resend / SendGrid | Transactional email | Email address, notification content |
9. Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
11. Contact
For privacy-related inquiries or to exercise your data rights, contact us at:
12. Data Sub-Processors
We use the following sub-processors to deliver the Service:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Infrastructure hosting | United States |
| Firebase | Authentication | United States |
| Stripe | Payment processing | United States |
| Plausible Analytics | Cookieless analytics | European Union |
| Crisp (if enabled) | Live chat support | European Union |
| Resend | Transactional email | United States |
13. International Data Transfers
REDWIPE is based in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. For users in the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for your data during transfer.
14. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours of discovery, as required by GDPR.
- Notify relevant supervisory authorities as required by applicable law.
- Provide a description of the breach, the data affected, and the measures taken to address it.
- For users in jurisdictions with state breach notification laws (e.g., California), we will comply with applicable notification timelines.
15. Do Not Track Disclosure
We do not track users across third-party websites. Our analytics solution (Plausible) is cookieless and privacy-preserving — it does not use cookies, local storage, or any form of cross-site tracking. We honor Do Not Track (DNT) browser signals by default.
16. California Shine the Light
Under California Civil Code Section 1798.83, California residents may request information regarding the disclosure of their personal information to third parties for direct marketing purposes. REDWIPE does not disclose personal information to third parties for their direct marketing purposes. For questions, contact privacy@redwipe.com.