SourceTrust

Legal

Privacy Policy

How we handle information on this website and in the application.

Last updated: July 14, 2026

This privacy policy describes how SourceTrust ("us", "we", "our") handles personal data when you visit https://sourcetrust.dev, use the application at https://app.sourcetrust.dev, or otherwise interact with us.

For business use of the application, our Data Processing Agreement describes how we process personal data on your organization's behalf. This policy should be read together with the DPA, Terms of Service, Acceptable Use Policy, and cookie policy.

Roles: controller and processor

When you use the application to upload organizational, repository, or compliance data, you are typically the data controller for that data and SourceTrust acts as a processor - see the DPA.

We act as an independent controller for account registration, billing, service emails, security and abuse prevention, and marketing website operations (including optional analytics when you consent).

What user data we collect

Depending on how you interact with us, we may collect:

  • contact information (for example, name and work email);
  • account and organization details (organization name, membership, role, authentication events);
  • billing and transaction metadata for paid subscriptions;
  • project, repository, and compliance data you submit in the application;
  • technical data such as IP address, browser type, device identifiers, and usage logs;
  • marketing website analytics when you choose Accept analytics in the cookie banner;
  • URLs and related metadata if you use the public site scan, including CAPTCHA verification data;
  • device and interaction signals processed by Cloudflare Turnstile when you view published license attestation pages (including password-protected pages); and
  • information you send when contacting support or requesting a demo.

Legal bases (EEA and UK)

Where the GDPR or UK GDPR applies, we process personal data on the following bases:

  • Contract - to provide the service, manage your account, process subscriptions, and deliver features you request;
  • Legitimate interests - to secure the service, prevent abuse, improve the product, and communicate about your account, balanced against your rights (you may object where applicable);
  • Consent - for optional marketing website analytics cookies/tags and, where required, promotional email (you may withdraw consent at any time); and
  • Legal obligation - where we must retain or disclose data to comply with law.

When we process data on your organization's behalf in the application, you determine the lawful basis as controller - see the DPA.

Why we use your data

We use personal data to:

  • operate account, import, review, publish, and monitoring features;
  • send transactional service and security communications;
  • process payments and manage subscriptions;
  • secure the website and application and prevent abuse;
  • understand how the marketing website is used (only with analytics consent); and
  • respond to support requests and improve the service.

Retention

We keep personal data only as long as needed for the purposes above, unless a longer period is required by law:

  • Account and application data - while your organization maintains an active account, then deleted within a reasonable period after termination (see DPA Exhibit A for Customer Data);
  • Backup copies - deleted on rolling backup cycles, typically within 90 days after primary deletion;
  • Billing and tax records - as required by applicable accounting and tax law (often several years);
  • Security and abuse logs - for a limited period appropriate to investigate incidents and protect the service;
  • Marketing analytics - according to the relevant provider's configuration when you have consented; and
  • Support correspondence - as long as needed to resolve the request and maintain a reasonable support history.

Sub-processors and sharing

We use service providers ("sub-processors") to operate the service. A current list with vendor names, purposes, and processing locations is published at our sub-processor list and forms part of our DPA. Application sub-processors include:

  • Cloudflare - hosting, CDN, security, and Turnstile (CAPTCHA) on the marketing site and published attestation pages;
  • Convex - application database and backend hosting (stored in the European Union / Ireland);
  • Resend - transactional email (customer data stored in the United States; Resend’s DPA includes Standard Contractual Clauses for EU transfers);
  • Paddle - payment processing and subscription billing;
  • GitHub - repository connections and code import;
  • GitLab - repository connections and code import;
  • Microsoft (Azure DevOps) - repository connections and code import;
  • WorkOS - authentication and organization sign-in;
  • Functional Software (Sentry) - application error monitoring and performance diagnostics;
  • OpenAI - AI-assisted classification of license text; and
  • Google (OSV.dev) - vulnerability advisory lookups for the optional security monitoring add-on.

We do not sell personal data. We may disclose data when required by law or to protect rights, safety, and security. Sub-processor changes are reflected on the sub-processor list.

International transfers

We are based in Denmark. Sub-processors may process data in the European Economic Area and other countries. Application data hosted with Convex is stored in the European Union (Ireland). Some sub-processors - including Resend - store customer data in the United States; where required, we use appropriate safeguards such as Standard Contractual Clauses in the vendor’s DPA or equivalent mechanisms.

Safeguarding and securing the data

SourceTrust is committed to securing your data and keeping it confidential. SourceTrust has done all in its power to prevent data theft, unauthorized access, and disclosure by implementing appropriate technologies and software to help us safeguard the information we collect online.

Cloudflare Turnstile

We use Cloudflare Turnstile on the public site scan and on published license attestation pages (including password-protected pages) to reduce automated abuse and scraping.

When Turnstile runs in invisible mode, Cloudflare may process device and interaction signals as described in the Cloudflare Turnstile Privacy Policy. That policy is incorporated by reference into this privacy policy for Turnstile processing.

Public page view statistics (vendors)

When you publish a license attestation page, we count aggregate page views so your organization can see how often buyers open that page in the authenticated SourceTrust application.

These counts are server-side totals only. We do not show buyer names, email addresses, or IP addresses in the vendor dashboard. We may store coarse metadata (for example referrer host and country code) internally for rollups.

Counts work whether buyers use sourcetrust.app or your verified custom domain, because both routes are served by the same application.

Cookies

When you use our marketing website, we use cookies and similar technologies as described in our cookie policy. That page explains what we set, when analytics load, and how to change your choice.

Links to other websites

Our website contains links that lead to other websites (for example, customer compliance pages, documentation, or third-party services). If you click on these links, we are not responsible for your data and privacy protection on those sites. Visiting those websites is not governed by this privacy policy. Make sure to read the privacy policy of any website you visit from our website.

Restricting the collection of your personal data

At some point, you might wish to restrict the use and collection of your personal data. When you are filling out forms on the website or in the application, you may choose not to provide optional fields. If you have already agreed to share your information with us and wish to limit or change how we use it, please contact us and we will work with you where possible.

SourceTrust will not lease, sell, or distribute your personal information to third parties for their marketing, unless we have your permission. We may share information with service providers who assist us in operating the site and application (for example, hosting, analytics, and security), subject to appropriate confidentiality and use restrictions. We may also disclose information when required by law.

Your rights (EEA and UK)

If you are in the European Economic Area or United Kingdom, you may have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase data in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests;
  • data portability for data you provided, where processing is based on contract or consent and carried out by automated means; and
  • withdraw consent at any time where processing is based on consent (without affecting prior lawful processing).

You also have the right to lodge a complaint with your local supervisory authority. In Denmark, the Datatilsynet (datatilsynet.dk) is the competent authority for SourceTrust as controller.

If you are an end user of a customer's published compliance page, contact that organization first - they control that content. For processor requests relating to data in a customer account, contact the customer; we assist them as described in the DPA.

To exercise rights relating to data we control directly, email hello@sourcetrust.dev. We may ask you to verify your identity before responding.

Changes

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. We advise you to visit this page periodically to stay informed.