Privacy Policy

Last updated: 22 July 2026 · Effective immediately

This privacy policy explains how CRA Shield ("we", "us", "our") collects, uses, and protects personal data when you use our website at cra-shield.com and our application at app.cra-shield.com. We follow the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

Short version: we only collect what we need to run the service (your email, your apps' classification & assessment data, dependency files you upload), we never sell your data, we host on Cloudflare in the EU, and you can delete your account at any time by emailing [email protected].

1. Who is the data controller

CRA Shield is the controller of your personal data within the meaning of Article 4(7) GDPR. For privacy questions, data subject requests, or to contact our data protection contact, write to [email protected].

2. What data we collect and why

CategoryDataPurposeLawful basis (Art. 6)
Account Email, display name, avatar URL, OAuth provider ID (Google or GitHub) Authenticate you, provide the service Contract performance, 6(1)(b)
Session Session token (HttpOnly cookie), IP address (for rate-limit + abuse prevention only) Keep you signed in, prevent abuse Legitimate interest, 6(1)(f)
Application data App names, classification answers, assessment notes, uploaded dependency files (SBOM source) Deliver the compliance toolkit Contract performance, 6(1)(b)
Billing Stripe customer ID, billing name, address and country, VAT ID where you supply one, plan, subscription status, invoice records. We never see your card. Take payment, determine the applicable VAT, issue invoices, manage subscriptions Contract performance, 6(1)(b); legal obligation for tax records, 6(1)(c)
Logs Aggregate request logs (path, status, duration, IP). Retained ~30 days. Operate the service, debug, security monitoring Legitimate interest, 6(1)(f)

We do not use advertising pixels and we never sell your data. Strictly necessary cookies (session and CSRF) are always set so the service can function. In addition, our website uses Google Analytics 4 to measure usage — but only after you consent through our cookie banner. Until then, Google Consent Mode keeps analytics storage disabled and no analytics cookies are set.

2a. Website analytics (Google Analytics)

With your consent, we use Google Analytics 4 (provided by Google LLC) to understand how visitors use cra-shield.com and app.cra-shield.com, so we can improve them. We have configured it with Google Consent Mode v2: analytics is set to denied by default and only activates when you click “Accept” in the cookie banner. If you click “Reject” (or simply ignore the banner), no analytics cookies are stored and no analytics data is sent.

What it collects (only after consent): pages viewed, referring links, approximate location derived from a truncated IP address, and general device/browser information. This data is pseudonymous — it is not linked to your account, and we do not use it for advertising or share it for advertising purposes.

Cookies set (only after consent):

CookiePurposeExpiry
_gaDistinguishes unique visitors2 years
_ga_<id>Persists analytics session state2 years

Lawful basis: your consent (Article 6(1)(a) GDPR). International transfer: Google may process this data in the USA under the European Commission’s Standard Contractual Clauses and its certification under the EU–US Data Privacy Framework. Withdrawing consent: you can withdraw at any time — clear the cra_consent value your browser stored (clear this site’s data) to see the banner again and choose “Reject”, or email [email protected]. You can also install Google’s opt-out browser add-on.

3. Sub-processors and where data is stored

We use the following sub-processors, each with their own GDPR posture and Standard Contractual Clauses where applicable:

Sub-processorPurposeRegion
Cloudflare, Inc.Hosting (Workers, Pages), database (D1), object storage (R2), session store (KV), CDN, DDoS, transactional email (Email Routing)EU (primary region)
Stripe Payments Europe, Ltd.Payment processingEU / global
Google Ireland Ltd.OAuth sign-in (only if you choose Google)EU / global
GitHub, Inc.OAuth sign-in (only if you choose GitHub)USA (with SCCs)
OSV.dev (Google)Public vulnerability database queried with package name + version (no personal data)USA
Google LLCWebsite analytics (Google Analytics 4) — only loaded after you consentUSA (SCCs + EU–US Data Privacy Framework)

4. International transfers

Where a sub-processor is based outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (SCCs) and supplementary technical measures including TLS-in-transit and at-rest encryption. We do not transfer data to jurisdictions without adequate protection beyond these mechanisms.

5. Retention

6. Your GDPR rights

Under Articles 15-22 GDPR you have the right to:

To exercise any of these rights, email [email protected]. We respond within one month (Article 12(3)).

7. Security

We follow industry-standard practices, including:

8. Data breach notification

If a personal data breach occurs and is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (Article 33) and, where the risk is high, notify affected users without undue delay (Article 34).

9. Children

CRA Shield is intended for use by software developers and businesses. We do not knowingly collect personal data from children under 16. If you believe a child has provided data to us, please contact [email protected] and we will delete it.

10. Changes to this policy

We will update the "Last updated" date at the top of this page when material changes are made and, where the change is significant, notify users by email. Continued use of the service after the effective date constitutes acceptance of the revised policy.

11. Contact

Privacy questions and data subject requests: [email protected]
Security issues: [email protected]
General contact: [email protected]

CRA Shield is a compliance toolkit, not legal advice. This privacy policy describes how we handle your personal data; it is not a substitute for professional advice on your own GDPR or CRA obligations as a software vendor.