SPECTARI

Privacy Policy

Spectari · Draft · Not in effect · Last updated 2026-07-30

What we collect

(1) Contact data — the email you provide when you order. (2) Order data — the Target Domain(s) you authorize and your plan. (3) Assessment data — technical results about the internet-facing hosts under your authorized domains. (4) Payment data — handled entirely by Stripe; we do not store card numbers.

How we use it

To perform the assessment you purchased, deliver your report, send service email, and provide support. We do not sell your data.

Sharing

We use processors to operate the Service — notably Stripe (payments) and our email/hosting providers. They process data on our behalf under their own terms. We disclose data if required by law.

Third-party discovery sources. Passive asset discovery works by querying public and commercial internet-intelligence sources — certificate transparency logs and similar OSINT providers. Performing your assessment therefore means sending your domain name to those third-party services. They are not acting as our processors: they are independent services answering a query, under their own terms and privacy policies. Only the domain name is sent — never your email address, your order, or your results.

Retention

We retain assessment data — the scan artifacts and the report — for 180 days, after which it is deleted.

You may request deletion at any time by emailing us, and we will carry it out without waiting for the window to expire. Two things survive a deletion: a skeleton payment record (order reference, plan, date, status — with your email address and results stripped), and anything we are independently required by law to retain.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. To exercise them, contact hello@spectari.io.

Security

We limit access to assessment data and treat your reports as confidential. No method of storage or transmission is perfectly secure.