Alignbase Inc. ("Alignbase," "we," "us," or "our") operates FileGRC, a Git-native GRC workspace for SOC 2 work.
This Privacy Policy explains how we collect, use, disclose, and retain personal information when you use:
- the FileGRC website at filegrc.com;
- the hosted notification service at app.filegrc.com;
- FileGRC applications, integrations, APIs, and related software;
- support, sales, and other business communications; and
- other services that link to this Privacy Policy.
We refer to these collectively as the "Services."
"Personal information" means information that identifies, relates to, describes, or could reasonably be linked with an individual. It does not include information that has been aggregated or deidentified so that it cannot reasonably be linked to an individual.
The Services are offered for business and professional use. If you use FileGRC for an organization, its administrators may control your access and activity associated with their accounts, repositories, workspaces, and integrations. That organization may have its own privacy notice and may be responsible for some requests about personal information in its repositories.
For account information, website activity, direct communications, and our own business operations, Alignbase decides why and how personal information is processed. For repository content that we process for a customer, we generally process that information to provide the Services at the direction of the customer and its authorized users. A separate written agreement may describe these roles in more detail.
1. Personal information we collect
Account and integration information
When you create or use a FileGRC account or integration, we may collect:
- your name, email address, profile information, and account identifiers;
- organization, repository, workspace, and integration identifiers;
- connected-service user, application, channel, and installation identifiers;
- your role, permissions, installation scope, and account settings;
- OAuth credentials and other connection credentials, stored in encrypted form; and
- subscription status and billing account references.
When you sign in through or connect a third-party service, it provides information allowed by the permissions shown during authorization. We do not receive the password you use with that service.
Repository content
FileGRC is designed around customer-controlled Git repositories. Those repositories may hold obligations, owners, dates, contacts, notification policy, linked identities, and related records. JSON holds structured records, Markdown holds long-form work, and Git supplies the change history. We access repository content to provide requested features, such as evaluating work, preparing notifications, and making changes approved by an authorized user.
Repository content may contain personal information about you or other people. The person or organization that submits or connects it is responsible for having the rights and permissions needed to do so. We limit our collection and retention of repository content to what is reasonably needed to provide, secure, support, and improve the Services, follow customer instructions, and meet legal obligations.
Service activity and delivery information
We collect information needed to operate, secure, and audit the Services, including:
- repository and installation details, schedules, and synchronization state;
- notification, delivery, deduplication, retry, and failure information;
- sign-ins, OAuth flows, installation changes, webhook deliveries, billing events, and account changes;
- feature use, status, timing, and related operating metadata; and
- timestamps, account identifiers, session identifiers, request identifiers, and audit metadata.
Device, network, and technical information
When you access the Services, we and our infrastructure providers may automatically receive IP address, browser and device type, operating or client type, requested pages or routes, request time, response status, performance data, Cloudflare request identifiers, cookie and session identifiers, error reports, logs, metrics, and diagnostic information. We do not use precise location from your device.
Communications and business information
If you contact us or obtain a paid plan, we may collect your name, business contact details, company and job information, messages and attachments, support history, feedback, subscription, invoice, transaction, and contract information.
Stripe collects payment details under its own privacy notice. We do not receive or store full payment-card numbers. We receive billing and transaction information needed to manage your subscription.
2. Sources of personal information
We collect personal information directly from you; from authorized users and administrators; from GitHub and Slack when an authorized user connects them; from Stripe when you start or manage a paid subscription; automatically from your browser, device, network, and use of the Services; from providers that help us operate, secure, monitor, and support the Services; and from business partners, public sources, or professional contacts in connection with sales and business operations.
3. How we use personal information
We use personal information to:
- provide, operate, maintain, and support the Services;
- create and manage accounts, installations, and subscriptions;
- authenticate users and apply tenant and repository access controls;
- connect repositories, communication tools, and other services at an authorized user's direction;
- evaluate configured repositories and send notifications under customer policy;
- link identities across connected services with authorized confirmation;
- prevent duplicate delivery, retry failures, and maintain delivery history;
- send security, account, billing, service, notification, and support messages;
- respond to support requests, diagnose errors, monitor availability, and improve the Services;
- detect and respond to fraud, abuse, unauthorized access, and security incidents;
- enforce agreements and protect Alignbase, our users, and others;
- comply with law, legal process, and valid government requests; and
- complete a financing, acquisition, reorganization, sale of assets, or similar transaction.
We may create aggregated or deidentified information and use it for lawful business purposes, such as measuring service performance. We will not try to reidentify information that we maintain as deidentified.
4. Repository content and service improvement
We use repository content only as needed to provide, secure, maintain, support, and improve the Services; follow authorized user instructions and repository policy; prevent or address fraud, abuse, or security incidents; and comply with law, subject to this policy and our agreements.
We may use service activity, feedback, and aggregated or deidentified information to maintain and improve the Services. Connected services may process information under their own terms and privacy notices. Authorized users decide which systems to connect and which permissions and repositories to make available.
5. How we disclose personal information
Authorized users and administrators
Information associated with an account or installation may be available to authorized users based on their GitHub, repository, or Slack roles and permissions. Administrators may manage installations, repositories, channels, permissions, and billing within the systems they control.
Connected services
When an authorized user connects another service, we disclose information to it as needed to follow the user's instructions and configured permissions. Connected services use that information under their own terms and privacy notices.
Service providers
We disclose personal information to vendors and contractors that help us provide cloud hosting, databases, storage, content delivery, network security, source control, authentication, integrations, communications, monitoring, logging, subscription billing, payment processing, customer support, business communications, accounting, legal, and professional services.
Providers may include Amazon Web Services, Cloudflare, GitHub, Slack, and Stripe, along with other providers that support the Services. Our providers and their functions may change as the Services change.
Legal, safety, and enforcement disclosures
We may disclose personal information to comply with law or valid legal process; respond to lawful requests; enforce our agreements; detect or address fraud, abuse, or security issues; or protect the rights, safety, and property of Alignbase, our users, or others. When legally allowed and appropriate, we may notify the affected customer or user before responding to a legal demand.
Business transactions and your direction
We may disclose or transfer personal information in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, including during due diligence. We may also disclose information when you ask us to, direct us to, or give us permission.
6. Cookies and similar technologies
We use cookies and similar technologies for authentication, session management, OAuth security, fraud prevention, request correlation, debugging, reliability, and measuring service use and performance.
Our authentication cookie is needed for signed-in use of the hosted service. It is protected from client-side script access and, in production, travels only over secure connections. Cookie duration depends on its purpose and may end sooner after expiration, revocation, or for security reasons.
Cloudflare and connected providers may use their own cookies or similar technologies when their services are used. Their processing is governed by their own privacy notices. We do not currently use cookies for cross-context behavioral advertising. Blocking essential cookies may prevent parts of the Services from working.
Do Not Track and Global Privacy Control
There is no uniform standard for responding to Do Not Track signals, so the Services do not currently change behavior in response to them. We honor legally recognized opt-out preference signals, such as Global Privacy Control, when applicable. Because we do not currently sell personal information or share it for cross-context behavioral advertising, such a signal does not otherwise change how the Services operate.
7. Sale, targeted advertising, and profiling
We do not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, and we do not process personal information for targeted advertising as those terms are defined by applicable US state privacy laws.
We do not use personal information to profile individuals for decisions that produce legal or similarly significant effects. We have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 18.
8. Data retention
We retain personal information for as long as reasonably needed for the purposes described in this policy. The period depends on the type of information, customer instructions, the business relationship, security and audit needs, and legal requirements.
- Account, installation, and subscription information remains while active and for a reasonable period afterward.
- Repository working copies and other temporary processing data remain only as long as reasonably needed for the Services, security, support, and legal obligations.
- Customer-controlled repository content remains subject to the customer's own Git retention and history.
- Session authorization ends when the session expires or is revoked, while related records may remain for a limited period for security and operating needs.
- Service activity, delivery, integration, and diagnostic records remain as reasonably needed to operate and secure the Services, investigate issues, and enforce agreements.
- Support, contract, invoice, and business records remain for the relationship and afterward as needed for tax, accounting, dispute, and legal purposes.
- Backup copies may remain for a limited period after deletion until ordinary backup cycles overwrite them.
We may retain information longer to comply with law, preserve evidence, resolve a dispute, collect fees, enforce an agreement, or protect the Services and our users. We may retain aggregated or deidentified information that cannot reasonably be linked to an individual.
9. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information. These measures include access controls, secure authentication, encrypted network connections, protected credential storage, tenant-scoped data access, logging, monitoring, backups, and incident-response practices appropriate to the Services.
No system is fully secure. You are responsible for protecting your credentials, reviewing integration permissions, and choosing what information to store in your repository. Contact [email protected] promptly if you believe an account or credential has been compromised.
10. Your choices and controls
Depending on your account and role, you may manage or remove connected repositories and integrations; change contacts, schedules, and notification policy in Git; review changes before FileGRC commits them; revoke connected applications; manage or cancel your subscription; and ask us to correct or delete information we control.
You may opt out of non-transactional marketing email by using the unsubscribe link or contacting us. We may still send service, security, legal, billing, account, and repository-policy notifications.
11. US state privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to confirm whether we process your personal information; access, correct, delete, or obtain a portable copy of it; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; appeal our decision; and receive equal service for exercising a privacy right.
FileGRC does not currently sell personal information, use it for targeted advertising, or perform the profiling described in Section 7.
To submit a request, email [email protected] with the subject "Privacy Request." Tell us the right you want to exercise and the GitHub login or email associated with your account. If your request concerns repository content controlled by a customer, we may direct it to that customer or its repository administrator.
We may ask for information needed to verify your identity, authority, and relationship to the information. We may deny or limit a request when permitted by law. You may use an authorized agent where applicable law allows it. If we deny a request, you may appeal by emailing [email protected] with the subject "Privacy Appeal."
12. California privacy disclosures
During the preceding 12 months, we have collected the categories below and disclosed them for business purposes. The examples do not mean that we collect every item about every person.
| Category | Examples | Sources | Purposes and recipients | Retention |
|---|---|---|---|---|
| Identifiers | Name, business email, GitHub and Slack IDs, account and installation IDs, IP, session and request IDs | You, administrators, GitHub, Slack, browsers, devices, and providers | Accounts, authentication, integrations, security, support, and communications; authorized users and providers as needed | For the relationship and a reasonable period afterward; sessions and requests may be shorter |
| Customer and commercial records | Profile, company, settings, plan, repository quantity, subscription, invoice, transaction, contract, and support records | You, your organization, Stripe, and providers | Paid Services, support, billing, accounting, and legal relationships; billing and professional providers | For the relationship and afterward as needed for accounting, tax, collection, legal, and disputes |
| Network activity | Routes, interactions, device class, requests, responses, sessions, webhooks, and integration activity | Browsers, devices, networks, connected services, and providers | Operate, secure, monitor, troubleshoot, and improve the Services; cloud, network, security, and monitoring providers | As needed for operations, security, diagnostics, enforcement, and law |
| Professional information | Company, role, repository ownership, permissions, and business contact details | You, administrators, GitHub, Slack, and business contacts | Accounts, permissions, integrations, support, and customer relationships; authorized users and providers | For the account or business relationship and a reasonable period afterward |
| User-provided content and communications | Repository contacts and policy, support messages, feedback, and requested Git commits | You, authorized users, repositories, GitHub, and Slack | Provide, support, and secure the Services; connected services and providers as needed | Repository content remains in Git under customer control; communications remain as needed for support |
| Sensitive personal information | Authentication and integration credentials, and content or messages if they contain sensitive information | You, connected services, and authorized users | Authentication, security, and providing the Services; only as needed or at your direction | Credentials remain while active or until replaced; other data follows its record type |
We do not intentionally collect biometric information, precise geolocation, government identification numbers, health information, or payment-card or bank account numbers through the Services. We use sensitive personal information only as reasonably needed to provide, secure, and support the Services, and not to infer characteristics about individuals.
California residents may exercise the rights described in Section 11. We do not disclose personal information to third parties for their own direct marketing.
13. Children
The Services are not directed to children and are available only to users who are at least 18 years old. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and delete it when appropriate.
14. Processing in the United States
Alignbase is based in the United States, and the Services are intended for US business and professional users. We and our providers process and store information in the United States and may process it in other countries where our providers operate. Privacy laws in those places may differ from the laws where you live.
If an organization needs specific international data-transfer or processing terms, it must enter into a separate written agreement with Alignbase before using the Services for information subject to those requirements.
15. Third-party services and links
The Services may link to or connect with websites and services that Alignbase does not control. This Privacy Policy does not cover their privacy practices. Review a third party's privacy notice before giving it personal information or connecting it to FileGRC.
16. Changes to this policy
We may update this Privacy Policy as the Services and our practices change. We will post the updated policy and change the "Last updated" date above. If a change materially reduces privacy protections or law requires more notice, we will provide notice through the Services, by email, or through another reasonable method before the change takes effect.
17. Contact us
Alignbase Inc.Texas, USA
[email protected]