← Back to Shieldome

Privacy Policy

Last updated: June 14, 2026

1. Who We Are

Shieldome ("we", "us", "our") is a web security scanning service. Our platform performs passive vulnerability assessments and performance analysis of websites you are authorized to test. We do not perform active exploitation or penetration testing.

2. What Data We Collect

  • Account data: email address, full name, phone number (optional), country/timezone.
  • Scan data: target URLs, scan results, finding summaries. We store this to provide scan history and reports.
  • Usage data: login timestamps, IP addresses, session tokens — for security and fraud prevention.
  • Payment data: billing plan tier; card data is handled by our payment processor and never stored on our servers.
  • Support data: messages you send via the support ticket system.

3. How We Use Your Data

  • To provide and operate the scanning service.
  • To send transactional emails (scan complete, account alerts, password reset).
  • To prevent abuse and ensure authorized use of the scanner.
  • To generate PDF reports you request.
  • We do not sell, rent, or share your personal data with third parties for marketing.

4. Legal Basis (GDPR)

For users in the EU/EEA, we process your data on the following legal bases:

  • Contract performance — to provide the service you subscribed to.
  • Legitimate interest — security logging, fraud prevention.
  • Consent — optional analytics cookies (you can decline via the cookie banner).

5. Cookies

We use strictly necessary cookies (session, language preference) that do not require consent. We may also use optional analytics cookies — you can manage these via the cookie banner shown on your first visit.

6. Data Retention

Scan results are retained for 12 months from the scan date. Account data is retained for the duration of your account plus 30 days after deletion. You can request deletion at any time.

7. Your Rights

Under GDPR (EU users) and applicable data protection laws, you have the right to:

  • Access a copy of your personal data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Object to or restrict processing
  • Data portability

To exercise these rights, open a support ticket or email us at the address in your account settings.

8. Data Security

All data is transmitted over HTTPS/TLS. Passwords are hashed using bcrypt. We use CSRF protection, secure cookie flags (HttpOnly, SameSite), and role-based access controls. Two-factor authentication (TOTP) is available for all accounts.

9. International Transfers

We are based in Serbia and may process data on servers within the EU/EEA. If data is transferred outside the EEA, we use Standard Contractual Clauses to ensure adequate protection.

10. Changes to This Policy

We will notify registered users of material changes via email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

11. Contact

For privacy questions or to exercise your rights, open a support ticket while logged in, or contact us at the email address on your account profile.