Privacy Policy
Last Updated: April 4, 2026
1. Introduction
VeeStack ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our code analysis platform.
Please read this privacy policy carefully. By using VeeStack, you consent to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, name, password (hashed)
- Project Data: Project names, configuration files
- Code Snapshots: Hashed signals from your code (NOT source code)
- Payment Information: Billing address, payment details (via Paymob)
- Team Information: Team names, member email addresses
2.2 Information Automatically Collected
- Usage Data: Pages visited, features used, timestamps
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, referrer URL
- Performance Data: API response times, error logs
2.3 What We DO NOT Collect
- Source Code: We never collect or store your original source code
- Passwords: We store only hashed versions of passwords
- Sensitive Files: We do not scan files marked as sensitive (.env, credentials, etc.)
3. How We Use Your Information
3.1 Service Delivery
- Process and analyze code snapshots
- Generate security and quality reports
- Manage your account and projects
- Process payments and subscriptions
3.2 Communication
- Send service notifications
- Respond to support requests
- Send product updates (with opt-out)
3.3 Security & Legal
- Detect and prevent fraud
- Protect against security threats
- Enforce our Terms of Service
- Comply with legal obligations
4. Data Storage & Security
4.1 Storage Location
- Primary: Supabase (hosted in EU/US regions)
- Backups: Automatic daily backups (90 days retention)
- Logs: Axiom cloud logging (90 days retention)
4.2 Security Measures
- Encryption: All data encrypted at rest and in transit (TLS 1.3)
- Access Control: Row-Level Security (RLS) on all database tables
- Authentication: OAuth 2.0 with device binding
- Monitoring: 24/7 security monitoring via Sentry
- Audits: Regular security assessments
4.3 Data Retention
| Data Type | Retention Period |
|---|---|
| Active Account | Indefinite |
| Deleted Account | 30 days |
| Code Snapshots | Account lifetime |
| Logs | 90 days |
5. Your Rights (GDPR)
5.1 Rights You Have
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Portability: Export your data in machine-readable format
- Right to Object: Object to processing of your data
- Right to Restrict: Limit how we use your data
5.2 How to Exercise Your Rights
- Email: privacy@veestack.com
- Dashboard: Settings → Account → Data Export/Delete
- Response Time: Within 30 days
6. Data Sharing
6.1 We Share Data With
| Party | Purpose | Data Shared |
|---|---|---|
| Supabase | Database hosting | All stored data |
| Paymob | Payment processing | Payment details |
| Sentry | Error tracking | Error context |
| Axiom | Logging | Log data |
6.2 We Do NOT
- Sell your personal data
- Share your code snapshots with third parties
- Use your data for advertising
- Allow third-party tracking
7. Cookies & Tracking
7.1 Cookies We Use
| Cookie | Purpose | Duration |
|---|---|---|
| Session | Authentication | Session |
| Preferences | User settings | 1 year |
| Security | CSRF protection | Session |
7.2 What We Don't Use
- No third-party tracking cookies
- No advertising cookies
- No social media tracking
8. Contact Us
Privacy Inquiries
- Email: privacy@veestack.com
- Response Time: Within 48 hours
Data Protection Officer
- Email: dpo@veestack.com
9. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes:
- Method: Email notification + in-app banner
- Notice Period: 30 days before changes take effect
- Continued Use: Constitutes acceptance of changes
10. Consent
By using VeeStack, you consent to:
- Collection and processing of your data as described
- Transfer of your data to third parties as listed
- Storage of your data in our hosting locations
You may withdraw consent at any time by deleting your account.
VeeStack - Privacy Policy v1.0
This policy is effective as of April 4, 2026.