Package Shield

Privacy Policy

Last updated: 17 August 2026

This Privacy Policy explains how [LEGAL ENTITY NAME] sp. z o.o. ("Package Shield", "we", "us") collects, uses, and protects personal data when you use the Package Shield platform and websites (the "Service").

We are the controller of the personal data described here. We process data in accordance with the EU General Data Protection Regulation (GDPR) and Polish data-protection law.

1. Who we are

The data controller is [LEGAL ENTITY NAME] sp. z o.o., [ul. ____, 00-000 ____, Poland] ([KRS 0000000000], NIP [0000000000]).

For any privacy matter, contact us at [email protected]. We have not appointed a Data Protection Officer; privacy requests are handled by the contact above.

2. Data we collect

Account and identity data

Your name, email address, hashed password, organization name, role, and team-membership details.

Billing data

Payments are processed by Stripe. We do not store full card numbers. We retain billing metadata such as your Stripe customer identifier, plan, subscription status, billing country, and VAT identifier where provided.

Cloud connection metadata

Configuration needed to operate your gateway: cloud account identifiers (e.g. AWS account ID and role ARN, or Google Cloud project ID and service-account email), region, and the CodeArtifact domain. We assume a role you grant us; we do not store long-lived cloud credentials or secret keys.

Package and usage metadata

Names, versions, and ecosystems of Packages routed through the Service, quarantine and approval decisions, policy configuration, and audit logs recording who performed which action and when.

Technical and communication data

IP address, browser/user-agent, session and authentication cookies, server logs, and the content of any messages you send to support or sales.

3. How we collect it

  • Directly from you when you register, connect a Cloud Account, configure policies, or contact us.
  • Automatically as you use the Service (logs, cookies, usage metadata).
  • From Stripe, our payment processor, for billing status and metadata.

4. Why we process it (purposes and legal bases)

PurposeLegal basis (GDPR)
Provide and operate the Service; manage your Account and Cloud Accounts; process PackagesPerformance of a contract - Art. 6(1)(b)
Process payments and manage subscriptionsPerformance of a contract - Art. 6(1)(b)
Secure the Service, prevent abuse and fraud, maintain audit logs, improve and develop the productLegitimate interests - Art. 6(1)(f)
Keep accounting and tax recordsLegal obligation - Art. 6(1)(c)
Send product/marketing communications (where applicable)Consent - Art. 6(1)(a), or legitimate interest for existing customers

Where we rely on legitimate interests, we balance them against your rights and freedoms. You may object at any time (see "Your rights").

5. Cookies

We use strictly necessary cookies to operate the Service: session and authentication cookies (to keep you signed in and to remember your active organization), interface-preference cookies (theme, sidebar), and a cookie that stores your cookie-consent choice. These do not require consent. We do not use third-party advertising or cross-site tracking cookies.

For product analytics we use PostHog (EU cloud). PostHog scripts and their analytics cookies are loaded only after you opt in to the analytics category, and you can withdraw that consent at any time via Cookie settings in the page footer - withdrawal stops all further analytics capture.

6. Sharing and subprocessors

We do not sell personal data. We share it only with service providers ("subprocessors") who process it on our behalf under data-processing agreements, and where required by law.

SubprocessorPurposeRegion
Amazon Web Services (AWS)Cloud infrastructure; CodeArtifact provisioningEU / US
Google CloudArtifact Registry provisioningEU / US
StripePayment processing and billingEU / US
ResendTransactional and notification emailEU / US
OVHcloudApplication hosting infrastructureEU
PostHog (EU cloud)Product analytics (only with your consent)EU

Note: when you connect a Cloud Account, the package repositories and stored artifacts reside in your own cloud account, under your control and your provider agreement - not on our infrastructure.

7. International transfers

Some subprocessors may process data outside the European Economic Area (e.g. in the United States). Where they do, transfers are safeguarded by appropriate measures such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. You may request details of the safeguards in place.

8. Data retention

  • Account and configuration data - for as long as your Account is active, and a reasonable period afterward to handle wind-down and disputes.
  • Audit logs - retained for the period applicable to your plan and our security needs.
  • Billing and accounting records - retained for the period required by Polish tax law (generally 5 years from the end of the relevant year).
  • After the applicable period, we delete or anonymize the data.

9. How we protect data

  • Encryption of data in transit (TLS).
  • Role-based access controls and the principle of least privilege.
  • We never store long-lived cloud credentials - access to your Cloud Account is obtained by assuming a role you grant, scoped to what the Service needs.
  • Operational logging and monitoring to detect and respond to incidents.

No system is perfectly secure, but we take appropriate technical and organizational measures proportionate to the risk.

10. Your rights

Under the GDPR you have the right to:

  • access your personal data and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erasure ("right to be forgotten") in the circumstances provided by law;
  • restrict or object to processing, including processing based on legitimate interests;
  • data portability - receive your data in a structured, commonly used format;
  • withdraw consent at any time, without affecting prior lawful processing.

To exercise any right, email [email protected]. You also have the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, Poland (https://uodo.gov.pl).

11. Automated decision-making

The Service applies the screening and approval policies you configure for your Packages. We do not make decisions producing legal or similarly significant effects concerning you that are based solely on automated processing within the meaning of Art. 22 GDPR.

12. Children's data

The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

13. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material, we will give reasonable notice (for example, by email or in-product). The "Last updated" date above reflects the latest version.

14. Contact

Privacy questions or requests: [email protected]. Postal address: [LEGAL ENTITY NAME] sp. z o.o., [ul. ____, 00-000 ____, Poland].