Privacy Policy
Last updated
1. Who we are
GreenLight is operated by Gold Finger (“we,” “us,” “our”). This policy explains what personal data we collect when you use GreenLight and how we handle it.
2. What we collect
- Account information — your email, and optionally your name, when you create an account.
- Scan data — the URLs you scan and the findings we generate, with timestamps and scores.
- Usage data — basic logs (such as IP address, browser type, and actions taken) used for security, abuse prevention, and improving the Service.
- Payment information — handled by our processor, Stripe. We never see or store your full card number; we store only a Stripe customer/subscription reference and your plan status.
3. How we use it
To provide and improve the Service, save your scan history, process payments and subscriptions, communicate with you (service messages, and product updates you can opt out of), prevent abuse and fraud, and comply with legal obligations. We do not sell your personal data.
4. Cookies
We use cookies that are necessary for sign-in and your session, and a referral cookie if you arrive through a referral link. We don’t use third-party advertising cookies.
5. Who we share with (processors)
We share only what’s needed with the service providers that run the product: Stripe (payments), Supabase (authentication), our hosting and database provider, and our email provider (Resend). These providers process data on our behalf under their own security and privacy commitments.
6. Data retention
Account data is kept while your account is active. Scan detail is kept in full for 60 days, then rolls up into a score-over-time trend retained for as long as your account is active; aggregate and technical data may be kept longer for security and product metrics. You can export any scan (JSON, CSV, PDF) at any time, and you can request deletion (below).
7. Your rights
You can access, correct, export, or delete your data. To delete your account or data, use the Contact option in the app or email [email protected]. Depending on where you live (for example the EU, UK, or California), you may have additional rights such as access, portability, deletion, and objection; contact us and we’ll honor applicable requests.
8. Security
We use HTTPS, hashed passwords, and access controls to protect your data. No system is perfectly secure, but we take reasonable measures to safeguard it.
9. Children
The Service isn’t directed to children under 16, and we don’t knowingly collect their personal data.
10. International users
We’re based in the United States. By using the Service, you understand your data will be processed in the United States and other locations where our providers operate.
11. Changes
We may update this policy. We’ll post the revised version here with a new date and, for material changes, provide notice.
12. Contact
Questions about your privacy? Email [email protected] or use the Contact option in the app.