Privacy

Last updated 16 August 2026

A security product that is careless with data has no business selling anything. Here is exactly what we collect, why, and for how long.

What we collect from your site

Only requests that were already suspicious. A normal visitor to your site never reaches our reporting path at all. For a request that hits a trap path or carries an exploit pattern, the installed package sends:

  • The path and query string requested
  • The HTTP method
  • The source IP address
  • The user-agent and referer headers
  • The time it happened

Source IP addresses and user agents are personal data under GDPR. We process them for the sole purpose of detecting threats to your site, on the basis of legitimate interest in network and information security.

What we never collect

  • Request bodies from your real routes — the package does not read them
  • Cookies, session tokens, or authentication headers
  • Form field contents, including anything a guest types
  • Your guests' names, emails, payment details, or booking records

Body capture is available for trap paths only, is off by default, and must be switched on deliberately by whoever installs the package.

The clone beacon

The beacon script reads three values that are already public: the hostname serving the page, its path, and the referrer. It sends them once. It does not set cookies, does not read storage, does not fingerprint the device, and does not track anyone across sites.

Your account data

Your email address, a hash of your password, your organisation name, and the domain you registered. Passwords are stored as scrypt hashes and cannot be read back by anyone, including us.

How long we keep it

  • Observations not linked to an incident — 14 days
  • Evidence attached to an incident — 30 days on Watch, 90 days on Guard and Managed
  • Account and billing records — for as long as the account exists, then as required by tax law

Deletion is enforced by the database itself rather than by a scheduled job somebody could forget to run.

Who else sees it

We use a small number of processors, each for one job:

  • A database provider, to store your data
  • An email provider, to deliver your alerts
  • A payment provider, to take payment — they receive your card details directly, we never do
  • An IP reputation service, which receives only the IP addresses of sources that already behaved suspiciously

We do not sell data, and we do not share it for advertising. There is no ad tech here.

Your rights

You may request a copy of your data, ask us to correct it, or ask us to delete it, by emailing support@pharoshub.cloud. We will respond within 30 days. Deleting your account removes your sites, evidence, and incidents; billing records are retained where law requires.

Where it is stored

Data is held on managed infrastructure. If you need a specific region for a compliance reason, tell us before you install — it is a configuration choice, not something we can change afterwards without moving your account.