Privacy Policy

Last updated: September 5, 2026

1. Introduction

StackShield ("we", "our", "us") scans Laravel applications from the outside and reports what it finds. This policy explains what personal data we collect when you visit stackshield.io, use the dashboard, the REST API or the MCP server, who processes it on our behalf, how long we keep it and how you can exercise your rights. We are the data controller for the personal data described here.

2. What we collect

  • Account data: your name, email address, password hash and, if you sign in with GitHub or Google, the identifier and email address those providers share with us.
  • Billing data: your plan, invoices and the last four digits and expiry of your card. Full card details go directly to Stripe and never touch our servers.
  • Application data: the domains you ask us to monitor, the scan results, issues and scan history for those domains, and any notes you attach to issues.
  • Integration data: API keys you create, OAuth grants you approve for connected assistants such as ChatGPT or Claude, and any Slack webhook or notification channel you configure.
  • Technical data: IP address, browser and device type, pages visited and the actions you take in the dashboard, collected through server logs and our analytics tools.
  • Correspondence: anything you send to our support or newsletter addresses.

3. Why we use it

  • To provide the service (performance of a contract): running scans against your domains, storing the results, showing them in the dashboard and returning them through the API and MCP server.
  • To notify you (performance of a contract): emails, push notifications and Slack messages about new issues, scan failures and account events.
  • To bill you (performance of a contract and legal obligation): processing subscriptions and keeping invoice records for as long as tax law requires.
  • To keep the service secure (legitimate interest): rate limiting, abuse detection, audit logs of API and MCP access.
  • To improve the service (legitimate interest): aggregated usage analytics that tell us which features are used and where people get stuck.
  • To send you the newsletter (consent): only if you subscribe, and every issue has an unsubscribe link.

We do not sell personal data and we do not use your scan results or domains to train machine learning models.

4. Connected assistants (MCP)

You can connect StackShield to an AI assistant such as ChatGPT, Claude, Cursor or VS Code through our MCP server. When you do, the assistant asks for your consent on our OAuth screen and receives a token limited to your team. Each request the assistant makes is logged with the tool called and the team it acted on. The data a tool returns, for example a list of your domains or the issues found in a scan, is sent to the assistant you connected, and from that point on it is handled under that provider's privacy policy, not ours. We do not receive your conversations with the assistant, only the tool calls it makes. You can revoke an assistant's access at any time from the Connected Assistants list on the API Keys page in your settings.

5. Who processes data on our behalf

We use the following providers. Each one is bound by a data processing agreement and only receives the data needed for its job.

Provider Purpose Data
Laravel CloudHosting, database and queuesAll data listed above
StripePayments and invoicingName, email, billing address, card details
Our email delivery providerSending issue alerts, scan summaries and account emailsEmail address, notification content
OneSignalPush notifications and the newsletterEmail address, name, last active date
PostHog (EU)Product analyticsUsage events, device and browser data
Google AnalyticsWebsite analyticsPages visited, device and browser data
GitHub and GoogleSign-in, if you choose itYour identifier and email at that provider
CloudflareDNS and bot protection on formsIP address, request metadata
SecurityTrails and AbuseIPDBDNS history and IP reputation lookups during scansThe monitored domain and its IP addresses only
SlackIssue notifications, if you connect a channelNotification content

Some of these providers process data outside the UK and EEA. Where they do, transfers rely on adequacy decisions or standard contractual clauses. We will update this list before adding a provider that handles personal data.

6. How long we keep it

  • Account and application data: for as long as your account exists. When you delete your account, or ask us to, we delete your account, domains, scan results and issues within 30 days.
  • Billing records: seven years after the transaction, as tax law requires.
  • Server and access logs: 90 days.
  • Analytics data: kept in aggregated form; identifiable events are deleted after 12 months.
  • Correspondence: two years after the thread closes.

7. How we protect it

Data is encrypted in transit and at rest. API keys are stored hashed and shown once. Access to production systems is limited to the people who operate the service and is logged. If we become aware of a breach that affects your personal data we will tell you and, where required, the relevant authority without undue delay.

8. Your rights and how to use them

Under UK and EU data protection law you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we process it, or transfer it to another provider. You can also withdraw consent to the newsletter at any time.

  • Delete your account: Settings, then Profile, then Delete Account. This removes everything listed under account and application data.
  • Revoke an API key or a connected assistant: Settings, then API Keys.
  • Export your data, or anything else: email privacy@stackshield.io from the address on your account. We answer within 30 days.

If you are not happy with how we handled a request, you can complain to the Information Commissioner's Office in the UK or your local supervisory authority in the EU.

9. Cookies

We set a session cookie and a CSRF token to keep you signed in, and analytics cookies from PostHog and Google Analytics to understand how the site is used. Your browser lets you block or delete cookies; blocking the session cookie will sign you out.

10. Changes to this policy

When we change this policy we update the date at the top. If a change affects how we use your data in a way you would not expect, we email account holders before it takes effect.

11. Contact us

Questions about this policy or your data: privacy@stackshield.io. Anything else: hello@stackshield.io.