Privacy Policy

Last updated: April 2026

Digital Passport ("the Service", "we", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.

1. What We Collect

1.1 Account Data

DataPurposeRetention
Email addressAuthentication, billing notifications, account recoveryUntil account deletion
Password (hashed)AuthenticationUntil account deletion
Company nameDisplay in admin, Stripe billingUntil account deletion
MFA secret (encrypted)Two-factor authenticationUntil MFA disabled or account deletion
Backup codes (hashed)MFA account recoveryUntil used or account deletion

1.2 PIM Connection Data

DataPurposeRetention
Akeneo PIM URLAPI connectionUntil account deletion
OAuth client IDAPI authenticationUntil account deletion
Client secret, username, password (encrypted)API authenticationEncrypted at rest; deleted on account deletion
Access/refresh tokens (encrypted)Active API sessionsRotated automatically; deleted on disconnect

1.3 Product Data (Cached)

Product attribute values fetched from your PIM are temporarily cached in Redis for performance. Cached data expires based on your configured TTL (default: 1 hour). We do not permanently store your product data.

1.4 Passport Configuration Data

Your Passport configurations (selected attributes, branding, channel, locale, compliance mappings) are stored in our database to generate Passport pages.

1.5 Billing Data

Payment processing is handled by Stripe. We store your Stripe customer ID and subscription ID but never store credit card numbers, bank details, or payment method information. See Stripe's Privacy Policy.

1.6 Audit & Security Logs

We record an audit trail of actions (configuration changes, logins, subscription changes) including timestamps and IP addresses. This is for your security and regulatory compliance. Audit logs are deleted when you delete your account.

1.7 What We Do NOT Collect

2. How We Store Data

3. How We Use Data

Your data is used exclusively to:

4. Third-Party Services

ServicePurposeData shared
Akeneo PIMProduct data sourceWe read your product data via API using credentials you provide
StripePayment processingEmail, company name, subscription metadata
SentryError monitoringError context (URL, HTTP status). Never product data or credentials
ResendTransactional emailEmail address, email content
CloudflareCDN, DDoS protectionIP addresses, HTTP headers (standard CDN operation)

We do not share your data with any other third parties.

5. Data Retention & Deletion

5.1 While Active

5.2 On Account Deletion

When you delete your account (Settings > Danger Zone > Delete Account):

5.3 On Subscription Cancellation

When you cancel your subscription, your account reverts to the free plan. Your data is retained but features beyond the free plan are disabled. Excess Passport configurations are deactivated (not deleted).

6. Security

7. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

8. Cookies

The admin interface uses a single session cookie for authentication. We do not use advertising cookies, analytics cookies, or third-party tracking cookies. Public Passport pages use no cookies at all.

9. Children

The Service is not directed at individuals under 18. We do not knowingly collect data from children.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email at least 30 days before they take effect. The "last updated" date at the top of this page reflects the latest revision.

11. Contact

For privacy-related questions: [email protected]

For general enquiries: [email protected]

Digital Passport · Privacy Policy · Terms of Service