Privacy Policy
This Privacy Policy explains what information ConfigTrace ("we," "us," or "our") collects when you use configtrace.org and the ConfigTrace application at app.configtrace.org (together, the "Service"), and how that information is used, stored, and shared.
1. Account and Workspace Information
When you create an account, we collect information such as your name, email address, and the workspaces you create or join. Workspace Owners and Admins can invite other members by email; we store the email address, assigned role (Owner, Admin, or Member), and invitation status for each member.
2. Provider Configuration Metadata
When you connect a third-party provider (such as AWS, Azure, Google Cloud, Kubernetes, Okta, Microsoft Entra ID, GitHub, GitLab, Cloudflare, Vercel, Firebase, Supabase, Stripe, Shopify, Datadog, PagerDuty, or others), we collect and store configuration and security-relevant metadata from that provider on a read-only basis — for example, IAM policies, security group rules, DNS records, webhook endpoint configuration, branch protection settings, OAuth grants, and directory role assignments. We do not collect customer data, order or payment contents, source code contents, database rows, or secret values from connected providers. The exact fields read and excluded for each provider are documented per-provider in our Data Access & Permissions guide.
3. Credentials and Secret Handling
To connect to a provider, you supply connector credentials (such as API tokens, service account JSON, access keys, or client secrets) scoped to read-only access where the provider supports it. These credentials are encrypted at rest, are never displayed in the product after you save them, are never logged in plaintext, and are transmitted only over HTTPS. Credentials are used solely to authenticate ConfigTrace's read-only requests to the provider you connected them to.
4. Usage, Audit, Security, and Operational Logs
We maintain a workspace audit log recording administrative actions such as member invitations, role changes, integration connections and removals, and billing events, visible to Owners and Admins at Settings → Workspace → Audit Log. We also maintain internal operational and security logs (such as sign-in activity and API request logs) to operate, secure, and troubleshoot the Service.
5. Billing Information
For paid plans, billing is handled by Paddle.com Market Limited ("Paddle"), our payment provider and merchant of record. Paddle collects and processes payment card or other payment method details directly; we do not receive or store your full payment card number. We receive limited billing-related information from Paddle necessary to manage your subscription, such as your plan, billing status, and transaction history. Paddle's own privacy policy governs its handling of payment data.
6. Cookies and Analytics
The configtrace.org marketing website does not use analytics, tracking, or advertising cookies. The ConfigTrace application at app.configtrace.org uses strictly necessary session cookies to keep you signed in; it does not use third-party advertising trackers. If this changes, we will update this Policy.
7. Processors and Service Providers
We use a limited number of third-party service providers to operate the Service, including Paddle for payment processing and billing (as our merchant of record), and infrastructure and email-delivery providers necessary to host and operate the application and send account-related email. These providers act on our behalf and are bound by confidentiality and data-protection obligations appropriate to the data they process.
8. Retention and Deletion
We retain workspace configuration timeline data for the period associated with your plan (30, 180, or 365 days depending on plan, as described on our Pricing page), and account and billing records for as long as needed to operate the Service and meet legal and tax obligations. You can disconnect a provider integration at any time, which stops further data collection from that provider. To request deletion of your account or workspace data, contact support@configtrace.org.
9. Security Practices
We encrypt connector credentials at rest, transmit data over encrypted (HTTPS) connections, and scope provider access to read-only permissions wherever a provider supports it. We do not collect secret values, source code, payment details, or database contents from connected providers. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
10. Your Rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. To exercise these rights, contact support@configtrace.org. We will respond to verifiable requests within a reasonable time and in accordance with applicable law.
11. International Data Processing
We and our service providers, including Paddle, may process and store information in countries other than your own. Where required by applicable law, we rely on appropriate safeguards for such transfers, including those provided by our processors' own compliance frameworks.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by email or an in-product notice, before the changes take effect.
13. Contact
Questions about this Privacy Policy can be sent to support@configtrace.org.
See also: Terms of Service · Refund Policy · Pricing