Privacy Policy
Last updated 2026-09-04
ShipGlance is run by Last Ridge LLC. This policy says, in plain language, what data we collect, why, where it lives, and how you get rid of it. The short version: we hold the minimum needed to show you your deployment board, your code contents never touch our servers, each workspace's data is isolated, and deleting your account deletes everything — backups included — within 30 days.
1. What we collect
- Account data: when you sign in with GitHub we receive your GitHub username, display name, avatar, and email address. That's how you log in; there are no passwords to store.
- CI/CD metadata: for repositories you connect via the GitHub App, we receive and store pipeline and workflow-run metadata — repo and workflow names, run status and timing, commit SHAs, branch and tag names, commit messages and authors, and deployment markers. This is what the board, history, and incidents are made of.
- Billing data: if you subscribe, payment is handled by Stripe. We store your plan, billing status, and Stripe customer ID — never your card number.
- Operational logs: standard web server and application logs (IP address, user agent, request paths) kept briefly for security and debugging.
- Product usage analytics: we record first-party product events tied to your account (for example: account created, repositories connected, board activated, plan viewed, and return visits) so we can measure how the product is used and improve it. This is our own first-party analytics — it stays on our infrastructure, is never sold or shared, and is retained for up to 400 days.
- Early-access signups and landing-page analytics: if you leave your email on our landing page we store it, the page variant you saw, and the referring site. The landing page sets two first-party cookies (a page-variant cookie and a short-lived anonymous session id) to measure how the page is used. No IP addresses are stored.
2. What we deliberately don't collect
- No code contents. The GitHub App uses read-only scopes, and what we store is run and pipeline metadata — we do not store the contents of your source files.
- No write access. The app cannot push, merge, or change anything in your repositories.
- No third-party trackers. This marketing site and the app load no third-party analytics, fonts, or ad scripts.
- Short-lived credentials. Access to your repositories uses GitHub installation tokens that expire in about an hour; the app's private key never leaves our control plane.
3. Where your data lives
Each workspace runs as its own isolated instance with its own storage volume — your data is never in a shared database with other tenants. Servers are hosted in the United States. Encrypted backups of each workspace's storage are taken for disaster recovery and kept for up to 30 days.
4. How we use data
Only to provide the service: rendering your board and history, sending notifications you configure (for example to Slack), processing billing, answering support email, and keeping the service secure. We do not sell your data, and we do not use your data to train machine-learning models.
5. Sharing and subprocessors
We share data only with the vendors needed to run the service:
- GitHub — the source of your CI metadata, per your App installation.
- Stripe — payment processing.
- Our hosting and edge providers — the servers and network the service runs on.
Beyond that, we disclose data only if legally required, and we'll tell you when we're allowed to. Share links you create are visible to anyone with the link, but they are redacted and expiring by design.
6. Retention and deletion
- History and incident data is kept for your plan's retention window (3, 90, or 400 days) and rolls off after that.
- Disconnecting a repository stops new data collection for it; existing history rolls off per your retention window, or sooner on request.
- Deleting your account deletes your workspace's instance, storage volume, and backups within 30 days. This is a hard promise: after 30 days we hold nothing of yours except invoices we're legally required to keep.
7. Security
All traffic is encrypted in transit (TLS). Tenant instances are isolated from one another at the process and storage level. Access to production systems is limited to Last Ridge LLC operators and is logged. If we ever discover a breach affecting your data, we will notify affected account holders promptly by email.
8. Your rights
You can export your workspace configuration from the console, request a copy of the data we hold about you, correct your account details, or delete your account entirely. Email [email protected] for any of these and a human will handle it. Depending on where you live (for example, the EU/EEA, UK, or California), you may have additional legal rights to access, correction, deletion, and portability — we honor these requests for everyone, regardless of location.
9. Children
ShipGlance is a professional tool and is not directed at children under 16. We don't knowingly collect data from them.
10. Changes to this policy
If we change this policy in a way that matters, we'll post the update here and email account holders before it takes effect. The "Last updated" date at the top always tells you the current version.
11. Contact
Last Ridge LLC · [email protected]