Privacy Policy
Effective October 1, 2026.
This policy describes how QA Audit (“we”, “us”) collects and uses information when you use QA Audit website QA audits, related checkout, optional accounts, CLI/API access, and operator outreach.
Who we are
The controller for this service is QA Audit. Contact: [email protected].
What we collect
- Information you submit to order an audit: website URL, email address, and company name.
- Audit results: crawled pages, findings, scores, and optional screenshots from deeper checks. Finding status (open / dismissed / in progress / done) is stored on that job.
- If you create an account: email, name, password hash, session cookie, and optional CLI API tokens.
- Payment metadata from Stripe (session id, paid status, customer/email metadata Stripe provides). We do not store full card numbers. Stripe is an independent processor.
- Operator logs used to prevent abusive crawling (host, page count, timestamps) and to record network surface scans (host, open port counts, job id, timestamp).
- For Security Pro: DNS ownership verification metadata (hashed verification token, verification timestamp, method used) and network scan results (open ports, service banners, scan timestamp) stored on your audit job and report.
- For outbound email: publicly listed business contact addresses and an opt-out / suppression list.
- Technical data needed to run the site: IP address, user agent, and basic request logs for security, abuse prevention, and debugging.
Why we use it (legal basis)
- Contract. To take payment and deliver the audit report, account, or API access you ordered.
- Legitimate interests. To operate and secure the service, prevent crawl abuse, improve product quality, and send limited outreach to publicly listed business contacts. You can opt out of outreach at any time.
- Account administration. To keep you signed in, show jobs attached to your account, and gate Security Pro purchases and post-purchase scan actions to the purchasing account.
- Security testing. For Security Pro, to verify domain control before network scans and to deliver surface-scan findings you ordered.
- Legal obligations. To comply with applicable law, enforce our Terms, and respond to lawful requests.
How we share information
We do not sell personal information. We share data only as needed to run the Service:
- Stripe — payment processing and fraud prevention.
- Email delivery providers (for example Resend) — transactional mail (report-ready, verification, password reset) and permitted outreach.
- Hosting and infrastructure (for example Railway or equivalent cloud hosts) — application hosting, storage volumes, and logs.
- Service providers under contract who help us operate the Service, bound to use data only on our instructions.
- Legal / safety — when required by law, or to protect rights, safety, and integrity of the Service, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with appropriate confidentiality protections.
Report links you choose to share give recipients access to that report. That sharing is under your control.
Cookies
We use a strictly necessary session cookie when you log in ( httpOnly, SameSite=lax, Secure in production). It keeps you signed in. We do not set advertising or analytics cookies and we do not load Google Analytics, GTM, or similar marketing pixels.
Display fonts are bundled at build time with next/font and served from this site. Your browser does not request fonts from Google when you visit.
Shareable report links
Each report lives at a URL that includes a random job id. Anyone who has that URL can view the findings and change finding status. Treat the link as a secret. Do not post it publicly if you do not want others to see the report.
Launch, Essential, Team, and Engineering reports can be viewed via the report link without logging in. Security Pro is different: checkout requires an account, and actions such as DNS verification and network scans are limited to the purchasing account (or our operators). Viewing a shared report link does not grant permission to run scans on your behalf.
How long we keep it
- Anonymous jobs (no account attached): deleted after 30 days, including report JSON, finding status, and screenshots.
- Jobs attached to an account: kept while the account exists.
- Login sessions: up to 30 days, or until you sign out.
- Stripe records: kept by Stripe under their terms.
- Outreach suppression (opt-out) entries: kept so we do not email you again.
- Security and abuse logs: kept for a limited period needed for operations and investigation, then deleted or aggregated.
International transfers
We may process and store information in the United States and other countries where we or our processors operate. If you access the Service from elsewhere, you understand that your information may be transferred to jurisdictions with different data-protection rules.
Security
We use industry-standard measures appropriate to the nature of the Service (HTTPS, hashed passwords, access controls on operator tools, and secret report URLs). No method of transmission or storage is completely secure; you use the Service at your own risk regarding residual security risk.
Outreach email
Operator outreach is sent only to business contact addresses found on public websites. Messages include a physical mailing address when configured and a link to opt out. Reply “remove” or use that page to stop future messages.
Your choices and rights
Email [email protected] to ask for a copy of the personal data we hold about you, to correct it, or to delete an account or a specific job sooner than the retention period. Use /opt-out to stop outreach.
Depending on where you live (for example the EEA/UK or certain U.S. states such as California), you may have additional rights to access, delete, correct, or obtain a portable copy of personal information, and to appeal a denial. We will not discriminate against you for exercising privacy rights. To submit a request, contact us at the email above; we may need to verify your identity and the email on the account or order.
Children
This service is for businesses. It is not directed at children under 16.
Changes
We will update this page when our practices change. The effective date at the top is the latest revision. Material changes will be posted here; continued use after the effective date means you acknowledge the updated policy.
Contact
Privacy questions: [email protected].
