Privacy Policy
Last Updated: 2025-10-09
This Privacy Policy describes how Next Hat Inc. ("Next Hat", "we", "us", or "our") collects, uses, discloses, and protects information in connection with our websites, products, and services (collectively, the "Services"). By using the Services, you agree to this Policy.
If you have questions, contact [email protected]. For security issues, contact [email protected]. For abuse reports, contact [email protected].
Scope
This Policy applies to:
- Visitors to our websites (including next-hat.com) and web applications;
- Account holders and users of our platform and APIs;
- Individuals who interact with us for support or marketing.
This Policy does not apply to our customers' end users' content that customers process through our platform. Customers are responsible for their own privacy notices and practices.
Information We Collect
We collect information directly from you, automatically through your use of the Services, and from third parties.
Information You Provide
- Account and Profile: name, email address, organization, role, avatar, preferences.
- Authentication: when you sign in with GitHub OAuth, we receive your GitHub user ID, username, primary email (if shared), avatar URL, and profile metadata permitted by your consented scopes. We do not receive or store your GitHub password. We store OAuth access tokens (and refresh tokens, if applicable) securely and use them only to provide the Services.
- Communications: support requests, survey responses, and other communications with us.
- Billing (if applicable): contact and billing details. Card data is processed by our payment processor and not stored in our systems beyond tokens/identifiers.
- Content You Upload: source code, configuration, deployment artifacts, logs you submit, and other materials you provide ("Customer Content").
Information Collected Automatically
- Usage and Device Data: IP address, device identifiers, browser type, user agent, language, referring/exit pages, operating system, date/time stamps, pages viewed, links clicked, and interactions.
- Service Logs and Security Signals: request/response metadata, HTTP headers, error/diagnostic logs, and telemetry used to secure, operate, and improve the Services.
- Cookies and Similar Technologies: we use essential cookies for security and operation (including Cloudflare cookies) and, with consent where required, analytics cookies (Google Analytics). See Cookies below.
Information from Third Parties
- Identity Providers: GitHub provides profile information per your authorization.
- Service Providers and Partners: limited data to operate features (e.g., abuse prevention, hosting, analytics).
- Email Delivery Provider (Resend): delivery status, bounces, spam complaints, and, if enabled, open/click events related to emails we send. We receive this data to ensure reliable delivery, diagnose issues, and prevent abuse.
How We Use Information
We use information to:
- Provide, operate, and maintain the Services;
- Authenticate users (including via GitHub OAuth);
- Secure the Services, prevent fraud and abuse, and investigate incidents;
- Process deployments and host content and APIs;
- Provide support and communicate with you;
- Send transactional, security, and administrative emails (via Resend), and process related delivery/engagement events (opens/clicks if enabled);
- Analyze usage to improve the Services (Google Analytics, in aggregate);
- Comply with law and enforce our Terms, including responding to lawful requests.
Legal bases for processing (EEA/UK): performance of a contract, legitimate interests (e.g., securing and improving the Services), compliance with legal obligations, and consent (for non-essential cookies/analytics where required).
Cookies and Similar Technologies
- Essential/Strictly Necessary: set by us and by Cloudflare to provide security, bot detection, and availability (e.g., __cf_bm, cf_clearance, Turnstile-related cookies). These are required for the Services.
- Analytics (Google Analytics): used to understand aggregate usage and improve the Services. Where required, we obtain consent before setting analytics cookies. You can opt out via your browser or Google's opt-out tools: https://tools.google.com/dlpage/gaoptout and learn more here: https://policies.google.com/technologies/partner-sites.
You can manage cookies via browser settings. Blocking essential cookies may break functionality.
Third Parties We Use
- Cloudflare (CDN, DDoS/edge security, Turnstile anti-bot): processes IP addresses, request headers, and security signals to protect our Services. Privacy: https://www.cloudflare.com/privacypolicy/
- Google Analytics (usage analytics): collects pseudonymous usage and device data. Privacy: https://policies.google.com/privacy
- GitHub (OAuth sign-in): provides identity data subject to your authorization. Privacy: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
- Hetzner Cloud (infrastructure/hosting): hosts certain systems and data in the EU. Privacy: https://www.hetzner.com/legal/privacy-policy/
- Resend (email delivery): processes recipient and sender identifiers, message metadata and content to send emails on our behalf; processes delivery events (delivered, bounced, deferred, spam complaints) and, if enabled, open/click events. Privacy: https://resend.com/legal/privacy
We disclose information to these providers only as needed to operate the Services, subject to contractual safeguards.
How We Share Information
We may share information:
- With service providers and subprocessors under contract who act on our behalf;
- With integration partners you authorize (e.g., GitHub) as needed to provide the integration;
- With competent authorities when required by law or in response to valid legal process, or to protect the rights, property, or safety of Next Hat, our users, or the public;
- In connection with a merger, acquisition, financing, or sale of assets (we will provide notice where required);
- With your consent or at your direction.
We do not sell personal information. We may share limited data for security, operations, and analytics as described.
Security
We implement administrative, technical, and physical safeguards appropriate to the nature of the data we process. No system is perfectly secure. If you believe your account or data has been compromised, contact [email protected] immediately.
Data Retention
We retain information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Logs used for security and operations are retained for limited periods unless extended for investigation or legal reasons. We may anonymize data for analytics and service improvement.
International Transfers
We operate with providers and infrastructure in multiple jurisdictions (including the United States and the EU). Where required, we use appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses and technical measures.
Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, and to data portability. For requests, email [email protected]. Where we process data on behalf of a customer, we will direct requests to that customer.
You can opt out of marketing emails at any time by using the unsubscribe link. You may control cookies via your browser and consent preferences.
Children
The Services are not directed to individuals under 16. We do not knowingly collect personal information from children under 16. If we learn that we have, we will delete it.
Abuse, Fraud, and Illegal Activity
We have zero tolerance for abuse or illegal activity. We may monitor for abuse signals, rate-limit or block traffic, and preserve or disclose logs and account information when we have a good-faith belief it is necessary to comply with law, enforce our Terms, protect users or the public, or detect, prevent, and address fraud, security, or technical issues. We cooperate with infrastructure providers (including Cloudflare and Hetzner) and competent authorities consistent with applicable law.
Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last Updated" date. Material changes will be notified as appropriate. Your continued use of the Services after an update signifies acceptance.
Contact
Next Hat Inc.
Email: [email protected]
Security: [email protected]
Abuse: [email protected]
Mailing: 560 N Barranca Avenue #4133, Covina, CA 91723, United States