Legal
Privacy Policy
How RedPick Inc. collects and uses personal data. We keep this deliberately small: no advertising, no third-party tracking, no selling of your data.
Last updated: August 27, 2026
1. Controller
The data controller is RedPick Inc., a Delaware corporation with registered office at 8 The Green, Suite A, Dover, DE 19901, USA. For any privacy request, contact [email protected].
2. What we collect
Information you give us
When you submit the contact or start-a-pentest form we collect the details you provide: name, company, email address, your message, and — for pentest requests — optional phone number, target URL, and application type. When you request a sample report we collect your name and email.
Privacy-preserving analytics
We run our own cookieless, first-party analytics to understand how the site is used. It does not set tracking cookies, does not follow you across other sites, and does not store your IP address. We derive only coarse, aggregate signals: page visited, the referring site (host and path, never query strings), approximate country/region, device type, browser language and timezone, and a daily-rotating, non-reversible visitor hash that cannot be tied back to you or persisted across days. For aggregate business analytics we also derive the visiting organization (the company or network operator that owns the IP) from your IP address transiently; the IP is used only for that lookup and then discarded, so it is never stored. If you later submit a form, we link that submission to the visit for attribution.
Technical data
Our infrastructure providers process standard technical data (such as IP address) transiently to deliver and secure the site — for example Cloudflare for content delivery, DDoS protection, and bot mitigation (Turnstile) on our forms. We do not use advertising or social-media tracking pixels.
3. Cookies
We do not use analytics, advertising, or cross-site tracking cookies. Our security provider may set strictly-necessary cookies required to protect the site (for example, bot-mitigation challenges). Because there is no tracking, the site shows no cookie-consent banner.
4. Why we use it, and our legal bases (GDPR)
- To respond to you and provide the service — taking steps at your request to enter into or perform a contract.
- To run and secure the site and measure aggregate usage — our legitimate interest in operating a secure, well-functioning service, balanced against your rights (which is why the analytics are cookieless and IP-free).
- To send transactional email (confirmations, replies) — contract and legitimate interest. We do not send marketing email without your consent.
5. Who we share it with
We do not sell or rent personal data. We share it only with sub-processors that help us operate, under data-processing agreements:
- Amazon Web Services (SES) — sending transactional email.
- Cloudflare — content delivery, security, and bot mitigation.
- Hetzner — EU-based hosting of the site and its data.
- Google (Search Console) — aggregate search-performance data (no personal data).
- BeDefended — our founding partner, acting as a sub-processor when it delivers a managed penetration test that involves your data, under equivalent obligations.
6. International transfers
Some providers (e.g. AWS, Cloudflare, Google) may process data in the United States. Where personal data of EU/UK individuals is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. Retention
We keep the details you submit only as long as needed to handle your request and our business relationship, plus any period required by law. Analytics data is rolled up into anonymous aggregates on an ongoing basis, and lead email addresses are anonymized after the retention window, so older analytics carries no personal data.
8. Your rights
Under the GDPR you may request access to, correction, or erasure of your personal data; restrict or object to processing; request portability; and withdraw consent at any time. You may also lodge a complaint with your local supervisory authority. Under the CCPA/CPRA, California residents may request to know, delete, or correct their personal information and to opt out of “sale” or “sharing” — which we do not do. To exercise any right, email [email protected]; we respond within the timeframes the law requires.
9. Children
RedPick is a business product not directed to children, and we do not knowingly collect data from anyone under 16.
10. Changes
We may update this policy; the current version and its date are always on this page. Material changes will be highlighted here.
See also our Terms of Service.
