/privacy
Privacy Policy
- Version
- v1.8
- Last updated
- 2026-07-27
- Effective date
- 2026-07-27
- Changes
- Full changelog
This policy describes how SpidyOps processes personal information through this website and the services we offer. SpidyOps is the brand of SpidyOps Inc., a software and security company incorporated in Ontario, Canada, which is the data controller for the purposes of this policy.
What SpidyOps collects
- Newsletter email. If you opt in to the newsletter, your email address is stored in our own database and mirrored to our email service provider (see sub-processors below). We also store the timestamps of your signup, your double-opt-in confirmation, and — if you leave — your unsubscribe. Unsubscribing sets your record to unsubscribed and stops all mail; it does not delete the row, so that we can honour the opt-out permanently rather than re-adding you later. Ask us and we will delete it outright.
- Contact form. Name, email, subject, and message — used solely to reply. We retain a partial network identifier (first three IP octets) used solely to detect spam patterns.
- Analytics. Plausible Analytics counts page views and referrers. See the analytics section below for what Plausible processes.
Categories of personal data
Under GDPR Article 4, the data we process falls into these categories:
- Identity: the name and email address you type into the contact form, or the email address you give the newsletter.
- Network:a truncated IP address (the first three octets only — enough to rate-limit a network, not enough to identify a household) and your browser's User-Agent string, capped at 256 characters. We do not derive geolocation.
- Behavioural:none per-visitor. Browsing this site produces no per-user record beyond Plausible's aggregate counts.
- Content: contact submissions and newsletter subscription state.
We do not process special-category data under GDPR Article 9 (race, ethnicity, political opinions, religion, health, sexual orientation, biometric or genetic data). If you submit such data via the contact form despite this notice, it is treated under the same retention rules as any other contact submission and deleted on triage.
Sub-processors
We use the following sub-processors to operate this site. Each handles only the data described and only for the listed purpose. The hosting and database regions determine where your data is at rest.
| Service | Purpose | Region | Data kinds |
|---|---|---|---|
| Vercel | Web hosting + CDN | United States, multi-region | standard hosting request logs (IP, UA, path, timing), held by Vercel |
| Supabase | Postgres database | Canada (ca-central-1) | contact submissions and newsletter subscriptions |
| Cloudflare | DNS + DDoS protection | global anycast | request metadata (IP, UA) at edge; no persistent storage by spidyops |
| Resend | Transactional + newsletter email | United States | recipient email, message body, bounce + delivery events |
| Upstash | Redis (rate limiting) | United States | rate-limit counters, ephemeral and auto-expiring. Keyed by a truncated IP range or email address for the public forms, and by the full IP for the pre-launch access gate. |
| hCaptcha | Bot mitigation on the contact, careers and newsletter forms | global edge | IP, UA, challenge response — held by hCaptcha per their policy. Loaded only once you interact with one of those forms, so simply reading a page never contacts them. |
| Cal.com | Scheduling — the "book a scoping call" booking window | United States / EU | loaded only when you move to book (hover, focus or click the booking button), not on page load. Cal.com then receives your IP and browser details; if you complete a booking it also receives the name, email and notes you enter there. |
| Plausible | Privacy-respecting page analytics | EU (Germany) | IP processed server-side to count unique visitors; not stored. No cookies, no fingerprinting. |
| Sentry | Error monitoring | United States | exceptions and stack traces (file and line, not source code). Before anything is sent we strip IP, cookies, headers, query strings and request bodies, and redact email addresses and token-shaped strings from every remaining text field, including the error message itself. |
We will update this list ahead of any new sub-processor going live. Material changes (new region, new processor) are also flagged in the changelog.
Analytics
We use Plausible Analytics (EU-hosted, GDPR-clean by default). Plausible processes visitor IPs server-side to detect unique visitors, but does not store IP addresses and does not use cookies. We see aggregate page views, referrers, and country counts — no individual visitor profile.
Cookies and similar technologies
We use the minimum cookies required to operate the site:
- Pre-launch access cookie (only while the site is gated) — records that you entered the access password. HttpOnly, Secure, SameSite=Lax, signed.
- Theme preference — remembers your light/dark choice. No personal data.
- Locale — set automatically by the site framework and always
en, the only language we currently publish. Nobody selects it. No personal data.
We do not use third-party tracking cookies. Plausible (analytics) is cookieless. We do not run advertising trackers, social-media pixels, or fingerprinting libraries.
Retention schedule
| Data | Retention | Trigger / mechanism |
|---|---|---|
| Contact submission | Kept until deleted on request, or in our periodic clear-out | Email privacy@spidyops.com to have yours erased — we action it directly in the database. |
| Newsletter subscription | Until you unsubscribe (record kept as an opt-out marker) or ask for deletion | Unsubscribe link in every email; deletion on request. |
International data transfers
SpidyOps operates from Canada. Some sub-processors store data in the United States and the European Union (see Sub-processors table). For transfers from the EEA / UK to the United States, we rely on Standard Contractual Clauses (SCCs) where available, supplemented by service-provider commitments. For transfers from Canada, our processors are bound by their own privacy commitments (GDPR-aligned for the EU-based ones, CPRA-aligned for the US-based ones).
What SpidyOps doesn't collect
- No advertising trackers, no third-party ad networks.
- No browser fingerprinting libraries.
- No social-media tracking pixels.
- No sale or sharing of your personal information. We do not sell it, and we do not share it for cross-context behavioural advertising. Under the CCPA and CPRA there is nothing to opt out of, because we do neither.
- Plausible analytics processes visitor IPs server-side to detect unique visitors, but does not store IP addresses or use cookies. The only IP-derived data we keep is the contact form's partial network identifier (first three octets) for spam triage.
- No automated decision-making or profiling that produces legal or similarly significant effects on you (GDPR Article 22). The only automated rules on this site are spam and rate-limit checks on the public forms; there is no individual profiling.
Children's data
This site is intended for adults working in security, software, and adjacent technical fields. We do not knowingly collect personal data from children under 16. If you believe a child has submitted data, email privacy@spidyops.com and we will delete it.
Your rights (GDPR + CCPA)
- Access: email us and we will send you everything we hold about you. In practice that is any contact-form submissions you sent and your newsletter subscription state — there are no user accounts on this site.
- Rectification: ask us to correct inaccurate data.
- Erasure: ask us and we delete your contact submissions and your newsletter record from our database, and remove you from our email provider. One honest caveat: every contact submission is also emailed to us when you send it, so a copy sits in our own mailbox. We delete that too on request — it is a manual step rather than an automatic one, and mail backups may retain it briefly afterwards.
- Portability: we will send your data in a machine-readable format (JSON) on request, suitable for transfer to another service.
- Object / restrict: tell us to stop processing your data for a given purpose.
- Right to lodge a complaint:if you believe we've mishandled your data, you can complain to your supervisory authority. In Canada, the Office of the Privacy Commissioner (priv.gc.ca). In the EU/EEA, your national data protection authority. In the UK, the Information Commissioner's Office (ico.org.uk).
Email privacy@spidyops.com for any of these. We respond within 30 days.
Data Protection Officer + Data Processing Addendum
SpidyOps does not currently operate a separate DPO role. Privacy queries are handled directly by our team at privacy@spidyops.com.
For B2B contracts where you need a Data Processing Addendum (DPA), we provide one on request — email privacy@spidyops.com with your contracting entity name and use case.
Breach notification
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware (GDPR Article 34). Notification will include: the nature of the breach, approximate categories and number of records concerned, likely consequences, and mitigation steps. We will also notify the relevant supervisory authority within the same window.
Client engagement data
When you contract SpidyOps for security services (penetration testing, vulnerability assessment, software development, design, branding, or SEO), data we process on your behalf is governed by the separate engagement contract and accompanying Data Processing Addendum, not this public privacy policy. Client data is segregated from the public-platform dataset, accessed only by the people assigned to your engagement (SpidyOps staff or partners bound by confidentiality), retained per the engagement contract, and deleted or returned at engagement close per your instruction. We do not aggregate, anonymise, or reuse client engagement data for any other purpose.
Changes to this policy
When this policy changes, the version, last-updated, and effective dates above are bumped and the change is recorded in the changelog. We do not currently push notifications about policy changes, so check back here if it matters to you. A full changelog is available at /privacy/changelog.