Privacy Policy

Effective October 1, 2026.

This policy describes how QA Audit (“we”, “us”) collects and uses information when you use QA Audit website QA audits, related checkout, optional accounts, CLI/API access, and operator outreach.

Who we are

The controller for this service is QA Audit. Contact: [email protected].

What we collect

Why we use it (legal basis)

How we share information

We do not sell personal information. We share data only as needed to run the Service:

Report links you choose to share give recipients access to that report. That sharing is under your control.

Cookies

We use a strictly necessary session cookie when you log in ( httpOnly, SameSite=lax, Secure in production). It keeps you signed in. We do not set advertising or analytics cookies and we do not load Google Analytics, GTM, or similar marketing pixels.

Display fonts are bundled at build time with next/font and served from this site. Your browser does not request fonts from Google when you visit.

Shareable report links

Each report lives at a URL that includes a random job id. Anyone who has that URL can view the findings and change finding status. Treat the link as a secret. Do not post it publicly if you do not want others to see the report.

Launch, Essential, Team, and Engineering reports can be viewed via the report link without logging in. Security Pro is different: checkout requires an account, and actions such as DNS verification and network scans are limited to the purchasing account (or our operators). Viewing a shared report link does not grant permission to run scans on your behalf.

How long we keep it

International transfers

We may process and store information in the United States and other countries where we or our processors operate. If you access the Service from elsewhere, you understand that your information may be transferred to jurisdictions with different data-protection rules.

Security

We use industry-standard measures appropriate to the nature of the Service (HTTPS, hashed passwords, access controls on operator tools, and secret report URLs). No method of transmission or storage is completely secure; you use the Service at your own risk regarding residual security risk.

Outreach email

Operator outreach is sent only to business contact addresses found on public websites. Messages include a physical mailing address when configured and a link to opt out. Reply “remove” or use that page to stop future messages.

Your choices and rights

Email [email protected] to ask for a copy of the personal data we hold about you, to correct it, or to delete an account or a specific job sooner than the retention period. Use /opt-out to stop outreach.

Depending on where you live (for example the EEA/UK or certain U.S. states such as California), you may have additional rights to access, delete, correct, or obtain a portable copy of personal information, and to appeal a denial. We will not discriminate against you for exercising privacy rights. To submit a request, contact us at the email above; we may need to verify your identity and the email on the account or order.

Children

This service is for businesses. It is not directed at children under 16.

Changes

We will update this page when our practices change. The effective date at the top is the latest revision. Material changes will be posted here; continued use after the effective date means you acknowledge the updated policy.

Contact

Privacy questions: [email protected].