Privacy
Last updated 16 August 2026
A security product that is careless with data has no business selling anything. Here is exactly what we collect, why, and for how long.
What we collect from your site
Only requests that were already suspicious. A normal visitor to your site never reaches our reporting path at all. For a request that hits a trap path or carries an exploit pattern, the installed package sends:
- The path and query string requested
- The HTTP method
- The source IP address
- The user-agent and referer headers
- The time it happened
Source IP addresses and user agents are personal data under GDPR. We process them for the sole purpose of detecting threats to your site, on the basis of legitimate interest in network and information security.
What we never collect
- Request bodies from your real routes — the package does not read them
- Cookies, session tokens, or authentication headers
- Form field contents, including anything a guest types
- Your guests' names, emails, payment details, or booking records
Body capture is available for trap paths only, is off by default, and must be switched on deliberately by whoever installs the package.
The clone beacon
The beacon script reads three values that are already public: the hostname serving the page, its path, and the referrer. It sends them once. It does not set cookies, does not read storage, does not fingerprint the device, and does not track anyone across sites.
Your account data
Your email address, a hash of your password, your organisation name, and the domain you registered. Passwords are stored as scrypt hashes and cannot be read back by anyone, including us.
How long we keep it
- Observations not linked to an incident — 14 days
- Evidence attached to an incident — 30 days on Watch, 90 days on Guard and Managed
- Account and billing records — for as long as the account exists, then as required by tax law
Deletion is enforced by the database itself rather than by a scheduled job somebody could forget to run.
Who else sees it
We use a small number of processors, each for one job:
- A database provider, to store your data
- An email provider, to deliver your alerts
- A payment provider, to take payment — they receive your card details directly, we never do
- An IP reputation service, which receives only the IP addresses of sources that already behaved suspiciously
We do not sell data, and we do not share it for advertising. There is no ad tech here.
Your rights
You may request a copy of your data, ask us to correct it, or ask us to delete it, by emailing support@pharoshub.cloud. We will respond within 30 days. Deleting your account removes your sites, evidence, and incidents; billing records are retained where law requires.
Where it is stored
Data is held on managed infrastructure. If you need a specific region for a compliance reason, tell us before you install — it is a configuration choice, not something we can change afterwards without moving your account.