Privacy Policy

Effective Date: June 10, 2026

1. Introduction

Kamyab Infotech ("CleanShift") is committed to protecting your privacy. This policy explains how we collect, use, store, share, and protect information when you use the CleanShift security platform.


2. Information We Collect

2.1 Account Information

Data PointDetails
EmailUsed for account identification and communication
PasswordStored as bcrypt hash — never in plaintext
Organization NameUsed for account labeling and multi-tenant isolation
API KeysStored as hashed values — originals are not retained
Billing InformationProcessed via pay.kamyab.co.in — we do not store card details
Login IPRecorded for security audit and abuse prevention
Browser User AgentRecorded for session security and device identification

2.2 Server & Scan Metadata

Data PointDetails
Server HostnameIdentifies the managed server
IP AddressesServer IPs for connectivity and identification
Operating SystemOS type and version
PHP VersionRuntime environment details
Control PanelServer management panel type (e.g. cPanel, Plesk)
Agent UUIDUnique identifier for the installed agent instance
WordPress Site PathsFile system paths to WordPress installations
WordPress VersionInstalled WP core version
Plugins & ThemesNames and versions of installed plugins and themes
File PathsPaths of scanned files
File Hashes (SHA-256)Cryptographic hashes for integrity verification
File Sizes & TimestampsMetadata for change detection
File OwnershipUnix owner/group for permission auditing
Threat DetailsDetection signatures, severity, and classification
Rogue Admin UsernamesUsernames flagged as unauthorized administrators
Malicious wp_options EntriesDatabase options flagged as injected or malicious
Security StackDetected security plugins and configurations
Scan Mode & DurationType of scan performed and execution time
Heartbeat DataAgent health and connectivity status

2.3 What the Agent Does NOT Collect

  • ❌ File contents
  • ❌ Database row content
  • ❌ Passwords
  • ❌ Email addresses of your users
  • ❌ Customer PII (personally identifiable information)
  • ❌ User-generated content
  • ❌ SSL/TLS private keys
  • ❌ SSH keys
  • ❌ Environment variables

2.4 Guard Activity Logs

Data PointRetentionStorage
Blocked IP90 daysStored locally on your server
User Agent90 daysStored locally on your server
Request URI90 daysStored locally on your server
Block Reason90 daysStored locally on your server
Timestamp90 daysStored locally on your server
Guard Component90 daysStored locally on your server

2.5 Dashboard Technical Data

Data PointPurpose
IP AddressSecurity and rate limiting
BrowserCompatibility and session security
Device TypeResponsive experience optimization
Pages ViewedUsage analytics and UX improvement
TimestampsSession tracking and audit
Referral SourceUnderstanding how users find the dashboard

3. How We Use Your Information

3.1 Primary Uses

  • Threat detection, analysis, and automated remediation
  • Intelligence correlation across anonymized datasets
  • Scan reporting and dashboard visualization
  • Account management and authentication
  • Service improvement and feature development
  • Security monitoring and incident response
  • Communication regarding your account and the Service

3.2 What We Do NOT Use Data For

  • ❌ We do not sell your data to anyone
  • ❌ We do not use your data for advertising
  • ❌ We do not share individual scan results with other customers
  • ❌ We do not mine your data for commercial purposes

3.3 Legal Basis for Processing (GDPR)

Legal BasisDescription
Contract PerformanceProcessing necessary to deliver the Service you subscribed to
Legitimate InterestsSecurity monitoring, fraud prevention, and service improvement
ConsentCrowd intelligence participation and optional communications
Legal ObligationCompliance with applicable laws, regulations, and legal processes

4. Data Retention

Data CategoryRetention Period
Account Information90 days after account deletion
Scan Results90 days
Aggregated Statistics24 months
Threat IntelligenceIndefinitely (anonymized and aggregated)
Guard Logs90 days (stored locally on your server)
Billing Records7 years (legal and tax requirements)
Dashboard Logs12 months
API Logs30 days

4.1 Data Deletion

You may request deletion of your account and associated data at any time by contacting privacy@cleanshift.osg.co.in. Upon receiving a valid deletion request, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

4.2 Scan Result Purging

Scan results are automatically purged after 90 days. You may request early deletion of specific scan results through the dashboard or by contacting privacy@cleanshift.osg.co.in. Aggregated, anonymized statistics derived from scan results may be retained beyond this period.


5. Data Sharing and Disclosure

5.1 We Do Not Sell Data

CleanShift does not sell, rent, or trade your personal information or scan data to any third party, under any circumstances.

5.2 Limited Disclosure

We may share data only in the following limited circumstances:

  • Sub-Processors: Third-party infrastructure providers necessary to deliver the Service, bound by data processing agreements.
  • Law Enforcement: When required by a valid legal order, subpoena, or applicable law. We will notify you unless legally prohibited.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity.
  • With Your Consent: When you explicitly authorize us to share specific data.
  • Aggregated Data: We may share anonymized, aggregated statistics that cannot identify any individual customer or server.

5.3 Current Sub-Processors

ProviderPurposeLocation
RailwayAPI hosting and backend infrastructureUS (Oregon)
VercelDashboard hosting and deliveryGlobal CDN
pay.kamyab.co.inBilling and payment processing

6. Data Security

6.1 Technical Measures

MeasureDescription
TLS 1.2+All data in transit is encrypted with TLS 1.2 or higher
Encryption at RestAll stored data is encrypted at rest
RBACRole-based access control for all internal systems
bcrypt PasswordsAll user passwords hashed with bcrypt
Rate LimitingAPI and authentication rate limiting to prevent abuse
Audit LoggingComprehensive audit trails for all administrative actions
0600 File PermissionsAgent configuration files restricted to owner-only access
Atomic WritesFile operations use atomic writes to prevent corruption
Cryptographic VerificationAgent updates and intelligence feeds are cryptographically signed
CORS/SSRF ProtectionStrict cross-origin and server-side request forgery controls
shlex.quote()All shell arguments are safely escaped to prevent injection

6.2 Organizational Measures

Access to customer data is restricted to authorized personnel on a need-to-know basis. All team members undergo security awareness training. We conduct regular security reviews and follow the principle of least privilege across all systems.

6.3 Breach Notification

In the event of a data breach affecting your personal data, we will notify you and any applicable supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Notification will include the nature of the breach, data affected, and remediation steps taken.


7. International Data Transfers

CleanShift's infrastructure is hosted in the United States. If you are located outside the US, your data will be transferred to and processed in the US.

For transfers of personal data from the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection.

Enterprise customers may opt for a self-hosted deployment to keep all data within their own infrastructure and jurisdiction.


8. Your Rights

8.1 Rights for All Users

Regardless of your location, you have the right to:

  • Access the personal data we hold about you
  • Export your data in a portable format
  • Delete your account and associated data
  • Correct inaccurate information
  • Object to specific types of data processing

8.2 GDPR Rights (EEA Residents)

RightGDPR ArticleHow to Exercise
Right of AccessArt. 15privacy@cleanshift.osg.co.in
Right to RectificationArt. 16privacy@cleanshift.osg.co.in
Right to ErasureArt. 17privacy@cleanshift.osg.co.in
Right to RestrictionArt. 18privacy@cleanshift.osg.co.in
Right to Data PortabilityArt. 20privacy@cleanshift.osg.co.in
Right to ObjectArt. 21privacy@cleanshift.osg.co.in
Withdraw ConsentArt. 7(3)privacy@cleanshift.osg.co.in
Lodge a ComplaintArt. 77Your local supervisory authority

8.3 CCPA Rights (California Residents)

RightStatusHow to Exercise
Right to KnowSupportedprivacy@cleanshift.osg.co.in
Right to DeleteSupportedprivacy@cleanshift.osg.co.in
Right to CorrectSupportedprivacy@cleanshift.osg.co.in
Right to Opt-Out of SaleN/A — we do not sell data
Right to Non-DiscriminationSupportedprivacy@cleanshift.osg.co.in

8.4 Other Jurisdictions

If you are located in a jurisdiction with data protection laws not specifically addressed above (e.g., Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act), we will honor equivalent rights under your local law. Contact privacy@cleanshift.osg.co.in with your request.


9. Children's Privacy

CleanShift is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly. If you believe a child under 16 has provided us with personal information, please contact privacy@cleanshift.osg.co.in.


10. Cookies and Tracking

10.1 Authentication

The CleanShift Dashboard uses JWT authentication tokens stored as HTTP-only cookies for secure session management.

10.2 What We Do NOT Use

  • ❌ Third-party tracking scripts or pixels
  • ❌ Advertising cookies
  • ❌ Cross-site tracking

10.3 Essential Cookies Only

CookieDurationPurpose
JWT Auth Token24 hoursStrictly necessary — user authentication
CSRF TokenSessionStrictly necessary — cross-site request forgery protection

Note: Because we use only strictly necessary cookies, no cookie consent banner is required under GDPR.


11. Crowd Intelligence

CleanShift offers an opt-in Crowd Intelligence program that enables participants to contribute to a shared threat intelligence network, improving detection accuracy for all users.

When enabled, the program shares only:

  • File hashes (SHA-256)
  • Malicious domain names
  • Threat detection patterns and signatures

The program never shares:

  • ❌ Server hostnames or IP addresses
  • ❌ File paths or directory structures
  • ❌ Usernames or account information

12. Hosting Providers

When CleanShift is installed on a managed hosting server, the hosting provider remains the data controller for the data on that server. CleanShift acts as a data processor on behalf of the hosting provider.

Hosting provider obligations:

  • Ensure appropriate legal basis for deploying CleanShift on customer servers
  • Inform end-users about the use of CleanShift as a security tool
  • Respond to end-user data subject access requests as the data controller
  • Maintain their own privacy policy addressing CleanShift usage

A Data Processing Agreement (DPA) is available on request for hosting providers. Contact legal@cleanshift.osg.co.in.


13. Third-Party Intelligence

CleanShift integrates publicly available threat intelligence data from the following sources:

  • NVD / MITRE: CVE vulnerability data from the National Vulnerability Database
  • WordPress.org: Plugin and theme version data, checksums, and known vulnerability advisories
  • Public Security Advisories: Published security advisories from reputable sources

All matching and analysis using third-party intelligence is performed locally on your server by the CleanShift Agent. No customer data is sent to these third-party sources.


14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.

  • Material changes: We will notify you at least 30 days in advance via email and a prominent notice on the dashboard before the changes take effect.
  • Non-material changes: Minor clarifications or formatting changes may be made without advance notice. The "Effective Date" at the top of this page will always reflect the date of the latest revision.

15. Contact

Kamyab Infotech

— End of Privacy Policy —