Privacy Statement
Last updated: March 2, 2025
1. Introduction
SBOMCheck ("we," "our," or "us") respects your privacy. This Privacy Statement describes how we collect, use, and protect information when you use our service at sbomcheck.online.
2. Information We Collect
We may collect:
- Account information: name, email address, and authentication data (including when you sign in with Google or Microsoft).
- SBOM and enrichment data: SBOM files you upload and the resulting enriched data (e.g., component names, versions, maintenance status, end-of-support dates) to provide the Service and allow you to view and export results.
- Usage data: how you use the Service (e.g., features used, upload and export activity) to operate and improve the Service.
- Payment information: processed by Lemon Squeezy; we do not store full payment card details.
3. How We Use Your Information
We use the information to provide, maintain, and improve SBOMCheck; to process your account and subscriptions; to communicate with you about the Service; and to comply with legal obligations. We do not use your SBOM content to train machine learning models or sell it to third parties.
4. Data Retention
We retain account and SBOM/enrichment data for as long as your account is active and as needed to provide the Service. You may request deletion of your account and associated data; we will delete or anonymize it in accordance with our data retention practices and applicable law.
5. Sharing and Disclosure
We may share data with service providers that help us operate the Service (e.g., hosting, authentication, payment processing). We require them to protect your data and use it only for the purposes we specify. We may disclose information if required by law or to protect our rights and safety.
6. Security
We use reasonable technical and organizational measures to protect your data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
7. Your Rights
Depending on your location, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict certain processing. You can update account details in the Service; for other requests, contact us using the contact options on our website.
8. Cookies and Similar Technologies
We use session and authentication-related technologies necessary for the Service to function. We may use analytics to understand usage; you can control cookie preferences through your browser settings.
9. Changes to This Statement
We may update this Privacy Statement from time to time. We will post the updated version on this page and indicate the last updated date. Continued use of the Service after changes constitutes acceptance.
10. Contact
For privacy-related questions or requests, contact us via the contact or support options on our website.