Privacy Policy
This policy explains what personal data guarda.net collects, why we collect it, how long we keep it and the rights you have over it.
Last updated: August 2026
Data we collect
- Account data — email address, display name, password hash (or Google sign-in identifier), account creation date.
- Billing data — plan, subscription status, invoices and the last four digits / payment method type. Full card numbers never reach our servers; they are handled by our payment providers.
- Lookup logs — the IP addresses you query, the result summary (risk score, detection flags, country, network owner), timestamp and which API key was used.
- Technical data — request metadata, IP address of API callers, and error logs used for security and abuse prevention.
Why we process it
To provide the Service and authenticate requests (contract), to bill you and meet accounting obligations (legal obligation), to prevent abuse, fraud and platform misuse (legitimate interest), and to send service notices. We do not sell personal data and we do not use lookup data for advertising.
Your customers' IP addresses
When you submit IP addresses through the API you are the data controller and we act as your processor for those lookups. We use them only to produce your result and to populate your own dashboard history. You must have a lawful basis for the lookups and disclose them in your privacy notice.
Processors we use
- Cloud hosting and managed database/authentication infrastructure for the application.
- Stripe and PayPal for payment processing, subscription billing, invoicing and fraud checks. Their own privacy policies apply to data you enter at checkout.
- Third-party IP geolocation and network reputation feeds that receive the IP address being queried and nothing else about you or your end user.
Retention
- Lookup logs: retained for 90 days, then deleted. You can clear your history earlier from the dashboard.
- Account data: kept while your account is open and for 30 days after deletion.
- Invoices and payment records: kept as long as tax and accounting law requires (typically 7–10 years).
Security
Data is encrypted in transit (TLS) and at rest. API keys are stored only as hashes and shown once at creation. Row-level access rules ensure each account can read only its own records. Access to production data is limited to staff who need it.
International transfers
Our infrastructure and payment providers may process data outside your country, including in the United States, under standard contractual clauses or equivalent safeguards.
Your rights
Subject to applicable law you may request access, correction, deletion, restriction, portability, or object to processing, and you can withdraw consent where we rely on it. Email support@guarda.net and we will respond within 30 days. You may also complain to your local data protection authority.
Cookies
We use strictly necessary cookies and local storage for authentication sessions and preferences. We do not use advertising or cross-site tracking cookies.
Contact
Privacy questions go to support@guarda.net, or use the contact form.
