Privacy Policy
This policy explains what personal data Rampsight collects, why we collect it, where it is stored, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR). The short version: we collect only what the Service needs, we host customer data in the EU, and we do not track you.
1. Who we are
The data controller for personal data processed through Rampsight is [PLACEHOLDER: legal entity name and registered address — decide with a lawyer]. For anything in this policy, contact privacy@rampsight.com.
2. Data we collect
We collect only what the Service needs to work:
- Account data — your name, email address, and password. Passwords are stored only as salted hashes, never in plain text.
- Agency branding — the logo, brand color, and language you configure for white-label reports.
- Operational data — the site URLs you register, the page URLs found while crawling them, scan results (accessibility issues, scores), and the details you enter when generating accessibility statements (such as an organization name and contact email).
- Support communications — emails you send us.
Payments are handled by Paddle, our merchant of record, which acts as an independent data controller for checkout and billing data. We never receive or store your full payment card details. Scan results describe page structure — which rules failed and where — and are not designed to collect personal data from the pages scanned.
4. Legal bases
Under the GDPR, we process personal data on these bases:
- Performance of a contract (Art. 6(1)(b)) — operating your account, running scans, generating reports and statements, sending transactional email.
- Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing abuse of the scanner, and improving the product based on aggregate usage.
- Legal obligation (Art. 6(1)(c)) — keeping billing and tax records, together with Paddle.
- Consent (Art. 6(1)(a)) — only where we explicitly ask for it; we do not send marketing email without an opt-in.
5. Subprocessors
These providers process data on our behalf to run the Service. Customer data lives in the EU:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Web application hosting | Global edge network |
| Supabase | Database (all customer data) | Frankfurt, EU |
| Railway | Scan worker infrastructure | EU |
| Resend | Transactional email (sign-in, password reset, notifications) | Ireland, EU |
| GoDaddy | DNS and email routing | Global |
Paddle (payments, as merchant of record) is an independent controller rather than a subprocessor. We will update this table before adding a new subprocessor.
6. Retention
- Account and operational data — kept for as long as your account is active.
- After account deletion — personal data is deleted within 30 days; residual copies in encrypted backups expire within 90 days.
- Billing records — kept as long as tax and accounting law requires, by us and by Paddle.
7. Your rights
You can ask us at any time to exercise your GDPR rights over your personal data:
- access a copy of the data we hold about you;
- correct inaccurate data;
- delete your data (“right to be forgotten”);
- receive your data in a portable, machine-readable format;
- restrict or object to certain processing.
Write to privacy@rampsight.com from your account email and we will respond within one month. You also have the right to lodge a complaint with your local data protection authority.
8. International transfers
Rampsight is operated from Brazil, while customer data is stored and processed on servers in the EU (see Subprocessors). Where personal data is accessed from outside the European Economic Area — for example by our team, or by a provider operating globally — we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
9. Security
We protect your data with measures appropriate to a service of this kind: passwords stored as salted hashes, httpOnly session cookies, encryption in transit (TLS), EU-hosted infrastructure, and access limited to what operating the Service requires. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authority as the GDPR requires.
10. Changes to this policy
We will update this policy when our practices change — for example, when a subprocessor is added. Material changes will be announced by email or inside the product before they take effect. The date at the top always reflects the latest revision.
11. Contact
Privacy questions and data requests: privacy@rampsight.com. General questions: hello@rampsight.com. See also our Terms of Service and Refund Policy.