Privacy Policy

Last updated: November 8, 2025

Introduction

GitHub Deployment Freeze ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our GitHub App and web dashboard.

Information We Collect

Information from GitHub

When you install our GitHub App or authenticate with our web dashboard, we collect:

  • GitHub username and profile information - Used to identify you and verify permissions
  • Repository information - Repository names, owners, and environment configurations where the app is installed
  • Organization membership - To display your organization's repositories and enforce access control
  • Deployment event data - Environment names, deployment requests, and protection rule events
  • Installation metadata - Information about when and where the GitHub App is installed

Important: We do NOT access your repository code or file contents. Our app only requires permissions for deployment protection rules and does not read, modify, or store any source code.

Freeze Management Data

When you create deployment freezes, we store:

  • Repository owner and name
  • Environment name
  • Freeze status (active/inactive)
  • Freeze reason and expiration time (if set)
  • Timestamps of freeze creation and modifications

Automatically Collected Information

Our web server automatically collects:

  • IP addresses and request metadata for security purposes
  • Browser type and operating system information
  • Request logs including timestamps, endpoints accessed, and response codes

How We Use Your Information

We use the collected information to:

  • Provide the Service - Manage deployment freezes, respond to deployment protection rule events, and enforce freeze policies
  • Authentication and Authorization - Verify your identity and ensure you have appropriate permissions to manage deployment freezes
  • Display Your Data - Show your repositories, environments, and freeze status in the web dashboard
  • Security and Fraud Prevention - Detect and prevent unauthorized access, abuse, and security incidents
  • Service Improvement - Analyze usage patterns to improve performance, reliability, and user experience
  • Compliance - Comply with legal obligations and respond to lawful requests

Data Storage and Security

Your data is stored securely with the following protections:

  • Encrypted connections (HTTPS/TLS) for all data transmission
  • Access controls limiting who can view and modify data
  • Regular security updates and monitoring
  • Webhook signature validation to prevent unauthorized requests

While we implement industry-standard security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your information.

Data Sharing and Disclosure

We do NOT sell, rent, or trade your personal information. We may share your information only in the following circumstances:

  • With GitHub - We interact with GitHub's API to provide the service, which is governed by GitHub's own privacy policy
  • With Your Consent - When you explicitly authorize us to share information
  • For Legal Reasons - When required by law, court order, or to protect our rights and safety
  • Service Providers - With trusted third-party service providers who assist in operating our service (e.g., hosting providers), under strict confidentiality agreements

Data Retention

We retain your information for as long as necessary to provide the service:

  • Active freezes - Stored until you unfreeze the environment or the freeze expires
  • Installation data - Stored while the GitHub App is installed; automatically deleted when you uninstall the app
  • Logs - Typically retained for 90 days for security and debugging purposes

Your Rights and Choices

You have the following rights regarding your information:

  • Access - You can view your freeze data through the web dashboard or API
  • Deletion - You can delete individual freezes through the dashboard or uninstall the GitHub App to remove all associated data
  • Correction - You can update freeze reasons and settings at any time
  • Revoke Access - You can revoke OAuth permissions or uninstall the GitHub App at any time through GitHub's settings

Third-Party Services

We use the following third-party service providers to operate and improve our service. Each provider has its own privacy policy governing how they handle your data:

  • GitHub - Authentication, API integration, and deployment protection rules. Our service is built on GitHub's platform. Privacy Policy
  • Google Cloud - Cloud infrastructure for secure data processing and application hosting. Privacy Policy
  • Neon - Serverless PostgreSQL database platform. Our databases are hosted and managed by Neon. Privacy Policy
  • Vercel - Frontend hosting and deployment platform for the web dashboard. Privacy Policy
  • Grafana Cloud - Application monitoring, observability, and performance metrics. Privacy Policy
  • Cloudflare - Content delivery network (CDN), DDoS protection, and security services. Privacy Policy

These service providers may have access to your information only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Children's Privacy

Our service is not intended for users under the age of 13. We do not knowingly collect information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our service, you consent to the transfer of your information to these countries.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Email: support@deployfreeze.com