Privacy Policy
Effective August 4, 2026
1. Scope
This Policy explains how mr.technology, operated from Maine, United States, handles personal information when you browse the public registry, use an account, join a mailing list, purchase an assessment, or submit assessment intake.
2. Information we collect
- Public-source data: repository URLs, source paths, ecosystem labels, public metadata, license evidence, hashes, commits, and scanner outputs.
- Account data: email address, an opaque account access key, a session token, tier state, and generated API-key records. mr.technology does not maintain account passwords.
- Checkout data: Stripe checkout/customer/payment identifiers, offer, amount, currency, payment status, and the email Stripe returns. Stripe—not mr.technology—handles full card details.
- Assessment intake: contact name, organization, repository URLs, private-source indicator, authorization declaration, and optional notes.
- Private assessment material: only if you later provide it through a separately agreed transfer method. Do not submit secrets or source archives through the public intake form.
- Technical data: IP-derived request information, user agent, timestamps, routes, security logs, and operational error data created by hosting and application systems.
- Communications: newsletter subscription/confirmation state and messages you send to support.
3. How we use information
We use information to operate and secure the Service, display public-source evidence, create and verify payments, deliver purchased assessments, contact you about the order, maintain accounting records, support accounts and legacy billing, prevent abuse, troubleshoot errors, and meet legal obligations.
We use optional analytics or advertising measurement only after the consent choice presented on the site permits it.
4. Legal bases
Depending on your location, processing is based on performance of a contract, steps requested before a contract, legitimate interests in operating and securing the Service, consent for optional analytics or marketing, and compliance with legal obligations. You may withdraw consent through “Cookie consent” in the footer without affecting earlier lawful processing.
5. Service providers
Information may be processed by providers that support the Service, including Stripe for checkout and billing, hosting and database providers, email delivery and newsletter providers, and Google analytics/advertising services when consented. These providers process information under their own terms and our service arrangements.
We do not sell personal information. We do not permit optional advertising measurement before consent.
6. Assessment confidentiality and access
Order and intake records are available only to authorized service operators and systems used to deliver the assessment. A repository URL marked private does not itself grant access; a separate method and scope will be agreed before private-source transfer.
Private material is retained only as needed for the purchased work, quality review, dispute handling, security, or an agreed monitoring service, then deleted or returned according to the written intake or statement of work. Accounting and report records may be retained longer where legally or operationally necessary.
7. Retention
We retain information only as long as reasonably needed for the purposes above. Duration depends on account status, contract and accounting requirements, security needs, mailing-list consent, disputes, and applicable law. Public-source registry records may remain while needed for provenance and historical transparency, subject to correction and takedown requests.
8. Cookies and local storage
Essential storage supports sessions, security, and your consent choice. Analytics and advertising measurement remain disabled until the corresponding consent is granted. You can reopen preferences through the footer. Browser controls can also clear stored choices, although doing so may cause the banner to reappear.
9. Security
We use HTTPS, Stripe-hosted checkout, access-controlled operational routes, scoped database access, and reasonable administrative and technical safeguards. No internet service can guarantee absolute security. If you believe data or a credential was exposed, contact us immediately.
10. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; unsubscribe from marketing; or complain to a regulator. Some records must be retained for contracts, accounting, security, legal claims, or lawful public-source purposes.
To make a request, email editor@mr.technology. We may need to verify your identity and authority.
11. International transfers and children
Service providers may process information in the United States and other countries. Where required, transfer safeguards apply through provider terms or legal mechanisms. The Service is not directed to children under 13, and we do not knowingly collect their personal information.
12. Changes and related terms
We may update this Policy and will post a new effective date for material changes. Use of the Service is also governed by the Terms of Service.