Privacy Policy

Our privacy policy and how we use your data

Last updated: August 29, 2026

This Privacy Policy explains how Ring Zero Security (“we”, “us”) collects, uses, and protects personal data when you use ShipSafe (the “Service”). We act as the data controller for account data and as your processor for the scan data you submit.

1. Data we collect

  • Account data — your email address and authentication details, and basic profile information.
  • Scan inputs — the target URLs you submit and, for authenticated scans, the login credentials you choose to provide so we can test signed-in behaviour.
  • Scan results — the findings, evidence, grades, and suggested fixes produced for your targets.
  • Billing data — plan, purchase history, and payment status. Card payments are handled by our payment provider; we do not store full card numbers.
  • Usage and technical data — logs, device/browser information, and diagnostics needed to operate and secure the Service.

2. How we use data

  • to run the scans you request and deliver reports and fixes;
  • to authenticate you, provide support, and manage billing;
  • to operate, secure, debug, and improve the Service (including aggregated, de-identified analysis);
  • to comply with legal obligations and enforce our Terms of Service.

3. Credentials and secrets discovered during a scan

Credentials you provide for an authenticated scan are used only to run that scan against the target you authorized. Where a scan surfaces secrets or keys that were exposed by the target application, we use them only to demonstrate the exposure in your report and do not sell them or reuse them for any other purpose. We minimise retention of this sensitive material and take steps to avoid storing it in the clear. Please rotate any exposed credential a report identifies.

4. Service providers (sub-processors)

We share data with vendors who process it on our behalf under contract, only as needed to run the Service — for example: our cloud database and authentication provider, our payment processor, a cloud browser provider used to drive authenticated audits, our large-language-model provider used to analyse findings, and our hosting provider. We do not sell your personal data.

5. Data retention

We keep account and scan data for as long as your account is active or as needed to provide the Service, then delete or de-identify it within a reasonable period, unless a longer period is required by law. You can delete individual scans, and you can request deletion of your account.

6. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Indian users have rights under the Digital Personal Data Protection Act, 2023 as its provisions come into force; users in the EEA/UK have rights under the GDPR. To exercise any right, contact us using the details below. You may also complain to your local data-protection authority.

7. Security

We use technical and organisational measures — encryption in transit, access controls, and tenant isolation enforced at the database layer — to protect personal data. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify you of incidents where required.

8. International transfers

Your data may be processed in countries other than your own. Where it is, we rely on appropriate safeguards for such transfers as required by applicable law.

9. Children

The Service is not directed to children and is intended for use by adults acting for themselves or an organisation.

10. Changes

We may update this Policy from time to time and will post the updated version with a new effective date.

11. Contact

For privacy questions or to exercise your rights, contact our privacy team at abhijit@ringzerosecurity.com.