/privacy

Privacy Policy

Version
v1.6
Last updated
2026-07-17
Effective date
2026-07-17

This policy describes how SpidyOps processes personal information through this website and the services we offer. SpidyOps is the brand of SpidyOps Inc., a software and security company incorporated in Ontario, Canada, which is the data controller for the purposes of this policy.

What SpidyOps collects

  • Newsletter email. If you opt in to the newsletter, your email is stored at our email service provider (see sub-processors below). One-click unsubscribe in every email.
  • Contact form. Name, email, subject, and message — used solely to reply. We retain a partial network identifier (first three IP octets) used solely to detect spam patterns.
  • Authentication. If you sign in to your account dashboard, an authentication library stores a database session keyed to your email. If you choose the GitHub option, your GitHub OAuth profile (id, name, avatar URL) is stored.
  • Session metadata. Each active sign-in stores its IP address, User-Agent string, and approximate city + country. Only you and the site operator can see your own session list. Sessions auto-expire after 30 minutes of inactivity, or when you sign out — the row and its metadata are deleted at that point.
  • Activity log. Authenticated requests (page renders and server actions) are recorded with timestamp, path, method, IP, and User-Agent. Visible to you and to the site operator. Rows older than 90 days are pruned automatically.
  • Audit log. State-change events (sign-in, role changes, content publish, MFA changes, session revocations, admin actions) are recorded with full forensic context. See the Audit log section below.
  • Multi-factor authentication. When you enable MFA on your account, we store a TOTP secret encrypted with AES-256-GCM. The secret is used only to verify the 6-digit codes generated by your authenticator app. We also store hashed backup codes for account recovery. Retained until you disable MFA or delete your account.
  • Tool usage logs. When you use one of the interactive tools (/tools), we may record an anonymous usage row (tool name, input type, result count, IP, UA). Sanitised at write-time and pruned after 90 days. Used to improve the tools.
  • Analytics. Plausible Analytics counts page views and referrers. See the analytics section below for what Plausible processes.

Categories of personal data

Under GDPR Article 4, the data we process falls into these categories:

  • Identity: email address, display name, username, GitHub identifier when applicable.
  • Authentication: session tokens, encrypted TOTP secret, hashed backup codes.
  • Network: IP address, User-Agent, approximate geolocation (city + country derived from IP).
  • Behavioural:page paths visited, server actions invoked, timing. All authenticated only — anonymous browsing produces no per-user record beyond Plausible's aggregate counts.
  • Content: contact submissions and newsletter subscription state.

We do not process special-category data under GDPR Article 9 (race, ethnicity, political opinions, religion, health, sexual orientation, biometric or genetic data). If you submit such data via the contact form despite this notice, it is treated under the same retention rules as any other contact submission and deleted on triage.

Sub-processors

We use the following sub-processors to operate this site. Each handles only the data described and only for the listed purpose. The hosting and database regions determine where your data is at rest.

ServicePurposeRegionData kinds
VercelWeb hosting + CDNUnited States, multi-regionrequest logs (IP, UA, path, timing) — see Audit log section
SupabasePostgres databaseCanada (ca-central-1)all application data (account, sessions, audit log, contact submissions)
CloudflareDNS + DDoS protectionglobal anycastrequest metadata (IP, UA) at edge; no persistent storage by spidyops
ResendTransactional + newsletter emailUnited Statesrecipient email, message body, bounce + delivery events
UpstashRedis (rate limiting, session metadata)United StatesIP-keyed rate buckets, ephemeral; auto-expire
hCaptchaBot mitigation on contact + newsletter formsglobal edgeIP, UA, challenge response — held by hCaptcha per their policy
PlausiblePrivacy-respecting page analyticsEU (Germany)IP processed server-side to count unique visitors; not stored. No cookies, no fingerprinting.
SentryError monitoringUnited StatesJS exceptions (stack traces, browser, URL); IPs scrubbed; no request bodies captured
GitHubOAuth identity provider (optional sign-in)United StatesGitHub profile (id, username, name, avatar URL) when you choose GitHub sign-in

We will update this list ahead of any new sub-processor going live. Material changes (new region, new processor) are also flagged in the changelog.

Analytics

We use Plausible Analytics (EU-hosted, GDPR-clean by default). Plausible processes visitor IPs server-side to detect unique visitors, but does not store IP addresses and does not use cookies. We see aggregate page views, referrers, and country counts — no individual visitor profile.

Cookies and similar technologies

We use the minimum cookies required to operate the site:

  • Session cookie (when you sign in) — required for authenticated functionality. Httponly, Secure, SameSite=Lax, signed by Auth.js.
  • Theme preference — remembers your light/dark choice. No personal data.
  • Locale preference— remembers the user's language selection. No personal data.
  • CSRF token — short-lived, per-form anti-forgery. No personal data.

We do not use third-party tracking cookies. Plausible (analytics) is cookieless. We do not run advertising trackers, social-media pixels, or fingerprinting libraries.

Retention schedule

DataRetentionTrigger / mechanism
Account record (User row)Until deletion requestGDPR erasure: anonymised within 30 days; identifiers replaced.
Active session metadata30 minutes idle / max 7 daysAuto-expire on idle; row deleted at sign-out or revocation.
Activity log (per-request audit)90 daysPruned by daily cron; not recoverable after window.
Audit log (state-change events)Indefinite (security record)Append-only at the database layer; lawful basis: legitimate interest in security/forensics. See Audit log section.
Contact submissionUntil operator deletes (manual triage)Hard-delete via /admin/contact when handled.
Newsletter subscriptionUntil you unsubscribeOne-click unsubscribe link in every email.
TOTP secret + backup codes (when MFA enabled)Until you disable MFACleared on disable; only hashes/encrypted bytes stored at rest.
Tool usage logs (anonymous)90 daysPruned by daily cron; sanitised at write-time.

International data transfers

SpidyOps operates from Canada. Some sub-processors store data in the United States and the European Union (see Sub-processors table). For transfers from the EEA / UK to the United States, we rely on Standard Contractual Clauses (SCCs) where available, supplemented by service-provider commitments. For transfers from Canada, our processors are bound by their own privacy commitments (GDPR-aligned for the EU-based ones, CPRA-aligned for the US-based ones).

Audit log

For incident response and security forensics, every state-change event in the platform writes a row to an internal audit log. The row captures, where applicable: actor identity (id, email, role at action time), action type, target resource, previous and new state (the diff), IP address, User-Agent (with parsed browser/OS/device), approximate geolocation, request id, referrer, session id, session MFA status, action duration, success/error, and a cryptographic chain linking each entry to the prior one. The chain makes tampering with row N invalidate every row written after it.

Retention: indefinite (immutable security record). Lawful basis: legitimate interest in security, fraud prevention, and forensic readiness — Article 6(1)(f) GDPR. Your right of access still applies: you can request a redacted export of the audit rows that concern your account by emailing privacy@spidyops.com.

What SpidyOps doesn't collect

  • No advertising trackers, no third-party ad networks.
  • No browser fingerprinting libraries.
  • No social-media tracking pixels.
  • No sale or sharing of your personal information. We do not sell it, and we do not share it for cross-context behavioural advertising. Under the CCPA and CPRA there is nothing to opt out of, because we do neither.
  • Plausible analytics processes visitor IPs server-side to detect unique visitors, but does not store IP addresses or use cookies. We only store IPs for authenticated activity and the contact form's partial network identifier for spam triage.
  • No automated decision-making or profiling that produces legal or similarly significant effects on you (GDPR Article 22). All access decisions are made by code rules (e.g. role-based authorisation, rate limits) without individual automated profiling.

Children's data

This site is intended for adults working in security, software, and adjacent technical fields. We do not knowingly collect personal data from children under 16. If you believe a child has submitted data, email privacy@spidyops.com and we will delete it.

Your rights (GDPR + CCPA)

  • Access: request a copy of the personal data we hold about you. Delivered as a JSON export covering account record, sessions, activity log, audit-log entries that concern you, contact submissions, and newsletter state.
  • Rectification: ask us to correct inaccurate data.
  • Erasure: request hard deletion. Soft-delete is applied immediately; PII is anonymised within 30 days. The audit log retains non-identifying records of the deletion event under our security retention basis.
  • Portability: machine-readable JSON export of your data, suitable for transfer to another service.
  • Object / restrict: tell us to stop processing your data for a given purpose.
  • Right to lodge a complaint:if you believe we've mishandled your data, you can complain to your supervisory authority. In Canada, the Office of the Privacy Commissioner (priv.gc.ca). In the EU/EEA, your national data protection authority. In the UK, the Information Commissioner's Office (ico.org.uk).

Email privacy@spidyops.com for any of these. We respond within 30 days.

Data Protection Officer + Data Processing Addendum

SpidyOps does not currently operate a separate DPO role. Privacy queries are handled directly by our team at privacy@spidyops.com.

For B2B contracts where you need a Data Processing Addendum (DPA), we provide one on request — email privacy@spidyops.com with your contracting entity name and use case.

Breach notification

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware (GDPR Article 34). Notification will include: the nature of the breach, approximate categories and number of records concerned, likely consequences, and mitigation steps. We will also notify the relevant supervisory authority within the same window.

Client engagement data

When you contract SpidyOps for security services (penetration testing, vulnerability assessment, software development, design, branding, or SEO), data we process on your behalf is governed by the separate engagement contract and accompanying Data Processing Addendum, not this public privacy policy. Client data is segregated from the public-platform dataset, accessed only by the people assigned to your engagement (SpidyOps staff or partners bound by confidentiality), retained per the engagement contract, and deleted or returned at engagement close per your instruction. We do not aggregate, anonymise, or reuse client engagement data for any other purpose.

Changes to this policy

When this policy changes, the version, last-updated, and effective dates above are bumped. Material changes are also announced to newsletter subscribers and surfaced via a banner on the site. A full changelog is available at /privacy/changelog.