Privacy Policy
Last updated: February 9, 2026
1. Introduction
GitShine ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and service ("Service"). Please read this policy carefully. By using the Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: When you register, we collect your email address. If you sign up via GitHub OAuth, we also receive your GitHub username and profile information as authorized during the OAuth flow.
- Repository Information: When you add repositories to track, we store the repository names and your commit configuration settings.
- Payment Information: If you subscribe to a paid plan, payment details are collected and processed by Stripe. We store your Stripe customer ID, subscription ID, and billing cycle dates, but we do not store your full credit card number or banking details.
- Communications: If you contact us for support, we may retain the content of your communications along with your email address.
2.2 Information Collected Automatically
- Log Data: Our servers automatically record information when you access the Service, including your IP address, browser type, operating system, referring URLs, pages viewed, and timestamps.
- Cookies and Session Data: We use cookies and similar technologies to maintain your session, remember your preferences, and enable authentication. Session tokens are used to keep you logged in.
2.3 Information from Third Parties
- GitHub: When you connect your GitHub account, we receive an OAuth access token and your GitHub profile information (username, email, profile URL). We use this token to access your repositories and perform commits on your behalf.
- Stripe: Our payment processor may provide us with limited billing information such as the last four digits of your card, card brand, and billing address for record-keeping and support purposes.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and operate the Service: To authenticate your identity, connect to your GitHub repositories, execute scheduled commits, and manage your account.
- Process payments: To manage subscriptions, process billing, and send transaction-related communications.
- Send transactional emails: To deliver magic link authentication emails, account notifications, and service-related updates via our email provider (Resend).
- Improve the Service: To analyze usage patterns, diagnose technical issues, and improve Service performance and features.
- Ensure security: To detect and prevent fraud, abuse, and unauthorized access to the Service.
- Comply with legal obligations: To respond to legal requests and prevent harm as required by applicable law.
4. How We Protect Your Information
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption at Rest: GitHub OAuth access tokens are encrypted using AES-256-GCM encryption before storage in our database. The encryption key is stored separately from the database.
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
- Secure Authentication: We use NextAuth.js with industry-standard session management. Passwords are never stored as we use passwordless (magic link) and OAuth-based authentication.
- Payment Security: Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified payment processor. Sensitive payment data never touches our servers.
- Access Controls: Access to user data is restricted to authorized personnel and systems on a need-to-know basis.
While we strive to protect your personal information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following limited circumstances:
- Service Providers: We share data with third-party service providers who assist in operating the Service, including:
- GitHub – To access repositories and perform commits (via OAuth token).
- Stripe – To process payments and manage subscriptions.
- Resend – To deliver transactional emails (magic links, notifications).
- Database hosting provider – To store account and repository data.
- Legal Requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website of any such change.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. Specifically:
- Account data: Retained until you request account deletion.
- GitHub OAuth tokens: Retained in encrypted form until you disconnect your GitHub account or delete your account.
- Payment records: Retained as required for accounting, tax, and legal compliance purposes (typically up to 7 years).
- Log data: Retained for up to 90 days for security and debugging purposes, then automatically deleted.
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law.
7. Cookies and Tracking Technologies
We use the following types of cookies:
- Essential Cookies: Required for the Service to function. These include session cookies for authentication and CSRF protection tokens. These cannot be disabled.
- Preference Cookies: Used to remember your settings, such as dark mode preferences.
We do not use third-party advertising or tracking cookies. We do not participate in cross-site tracking or targeted advertising.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Data Portability: Request a copy of your data in a structured, machine-readable format.
- Objection: Object to certain processing of your personal data.
- Withdrawal of Consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
9. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information is collected, used, shared, or sold.
- The right to delete personal information held by us.
- The right to opt out of the sale of personal information.
- The right to non-discrimination for exercising your CCPA rights.
We do not sell personal information. To exercise your CCPA rights, contact us at [email protected].
10. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Contract Performance: Processing necessary to provide the Service you requested (account management, commit automation, payment processing).
- Legitimate Interests: Processing necessary for our legitimate business interests (security, fraud prevention, service improvement), where these interests are not overridden by your rights.
- Consent: Where you have given explicit consent for specific processing activities.
- Legal Obligation: Processing necessary to comply with applicable laws and regulations.
You have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates applicable law.
11. International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those of your jurisdiction. We take appropriate safeguards to ensure that your personal data remains protected in accordance with this Privacy Policy, including the use of Standard Contractual Clauses or other approved transfer mechanisms where required.
12. Children's Privacy
The Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal information, we will take steps to delete such information promptly. If you believe a child under 16 has provided us with personal information, please contact us at [email protected].
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a revised "Last updated" date. For significant changes, we may also send you a notification via email. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
You may also review our Terms of Service for additional information about using our Service.
