Rampsight

Privacy Policy

This policy explains what personal data Rampsight collects, why we collect it, where it is stored, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR). The short version: we collect only what the Service needs, we host customer data in the EU, and we do not track you.

1. Who we are

The data controller for personal data processed through Rampsight is [PLACEHOLDER: legal entity name and registered address — decide with a lawyer]. For anything in this policy, contact privacy@rampsight.com.

2. Data we collect

We collect only what the Service needs to work:

  • Account data — your name, email address, and password. Passwords are stored only as salted hashes, never in plain text.
  • Agency branding — the logo, brand color, and language you configure for white-label reports.
  • Operational data — the site URLs you register, the page URLs found while crawling them, scan results (accessibility issues, scores), and the details you enter when generating accessibility statements (such as an organization name and contact email).
  • Support communications — emails you send us.

Payments are handled by Paddle, our merchant of record, which acts as an independent data controller for checkout and billing data. We never receive or store your full payment card details. Scan results describe page structure — which rules failed and where — and are not designed to collect personal data from the pages scanned.

3. Cookies — none that track you

Rampsight sets no tracking or advertising cookies and runs no third-party analytics. We use exactly two things in your browser:

  • an httpOnly session cookie that keeps you signed in; and
  • a small preference that remembers whether your dashboard sidebar is collapsed.

Neither follows you across the web, which is why you will not find a cookie consent banner here — there is nothing to consent to.

5. Subprocessors

These providers process data on our behalf to run the Service. Customer data lives in the EU:

Subprocessors, their purpose, and where they process data
ProviderPurposeLocation
VercelWeb application hostingGlobal edge network
SupabaseDatabase (all customer data)Frankfurt, EU
RailwayScan worker infrastructureEU
ResendTransactional email (sign-in, password reset, notifications)Ireland, EU
GoDaddyDNS and email routingGlobal

Paddle (payments, as merchant of record) is an independent controller rather than a subprocessor. We will update this table before adding a new subprocessor.

6. Retention

  • Account and operational data — kept for as long as your account is active.
  • After account deletion — personal data is deleted within 30 days; residual copies in encrypted backups expire within 90 days.
  • Billing records — kept as long as tax and accounting law requires, by us and by Paddle.

7. Your rights

You can ask us at any time to exercise your GDPR rights over your personal data:

  • access a copy of the data we hold about you;
  • correct inaccurate data;
  • delete your data (“right to be forgotten”);
  • receive your data in a portable, machine-readable format;
  • restrict or object to certain processing.

Write to privacy@rampsight.com from your account email and we will respond within one month. You also have the right to lodge a complaint with your local data protection authority.

8. International transfers

Rampsight is operated from Brazil, while customer data is stored and processed on servers in the EU (see Subprocessors). Where personal data is accessed from outside the European Economic Area — for example by our team, or by a provider operating globally — we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

9. Security

We protect your data with measures appropriate to a service of this kind: passwords stored as salted hashes, httpOnly session cookies, encryption in transit (TLS), EU-hosted infrastructure, and access limited to what operating the Service requires. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authority as the GDPR requires.

10. Changes to this policy

We will update this policy when our practices change — for example, when a subprocessor is added. Material changes will be announced by email or inside the product before they take effect. The date at the top always reflects the latest revision.

11. Contact

Privacy questions and data requests: privacy@rampsight.com. General questions: hello@rampsight.com. See also our Terms of Service and Refund Policy.