STSaaS Tracker
PricingInteractive demoProduct tourUse casesResourcesAboutSecurityFAQSign in
Menu
PricingInteractive demoProduct tourUse casesResourcesAboutSecurityFAQSign in
← All terms & policies
03 / 07

Terms & Policies

Terms of ServicePrivacy PolicySecurity and Data-Handling OverviewAI Limitations and Human-Review StatementSubprocessor and Third-Party Service Provider ListSupport and ContactData Export and Deletion Procedure

SaaS Tracker legal document

Security and Data-Handling Overview

Effective dateSeptember 5, 2026

This overview describes SaaS Tracker's current security and data-handling practices for the Service. It is intended to support customer diligence and public website transparency. It is not a certification, warranty, service-level agreement, or substitute for a customer-specific security assessment, order form, or data processing addendum. This overview is provided for informational purposes only, “as is,” without any representation or warranty of any kind. SaaS Tracker reserves the right to modify these practices at any time without prior notice. No third party is entitled to rely on this overview.

1. Service architecture and data stores

SaaS Tracker runs on Cloudflare's application infrastructure. Structured workspace data and metadata are stored in Cloudflare D1. Preserved source-document snapshots and logical backups are stored in private Cloudflare R2 object storage. Authentication-related infrastructure is supplied through Cloudflare and the hosting platform, and application authorization maps authenticated identities to a workspace and role.

2. Tenant isolation and access control

Every application read and write is designed to be scoped server-side to the authenticated user's workspace; however, no isolation mechanism is guaranteed to be free of defects. The browser does not choose a trusted workspace identifier. Roles are owner, administrator, reviewer, contributor, and viewer, with progressively narrower permissions. Owners and administrators manage membership, settings, exports, and integration credentials. Machine API credentials are randomly generated, stored as SHA-256 hashes rather than plaintext, scoped to one workspace, and checked for revocation on each request. SaaS Tracker maintains audit records for important team, policy, export, monitor, review, and integration actions. Customers are responsible for appropriate invitations, role assignment, credential protection, access review, and timely revocation.

3. Network and application safeguards

  • HTTPS protects data in transit between supported clients and the Service (meaning the SaaS Tracker application platform and related infrastructure described in this overview).
  • Browser mutations use origin and same-site checks designed to reduce cross-site request forgery.
  • Security headers include a content security policy, HTTP Strict Transport Security, anti-framing rules, MIME-sniffing protection, a restrictive referrer policy, cross-origin policies, and a permissions policy.
  • Private workspace and API responses are marked private and no-store.
  • Rate limits apply to account registrations, source additions, imports, reads, document checks, AI reruns, and digest sends.
  • Operational events use structured error categories and alerts to help investigate retrieval, AI, email, job, backup, and restoration failures.

4. Monitored-source retrieval

Customer-supplied URLs are treated as untrusted. Retrieval is limited to supported public HTTP or HTTPS destinations. Application controls reject private, loopback, link-local, metadata, credential-bearing, internal-name, non-standard-port, and overlong URLs; apply the same checks to redirects; limit redirect chains to five hops; and reject supported document bodies larger than 6 MB. Retrieval records include source and resolved URLs, HTTP status, redirect history, timestamps, hashes, and bounded errors. Residual risk remains for DNS rebinding or resolution behavior outside the application's atomic control. Customers should use known publisher domains where possible. Remote files are size-limited, privately stored, and served as attachments, but preserved originals may not be malware-scanned when scanning infrastructure is unavailable or a scan cannot be completed. SaaS Tracker disclaims all liability for malicious or harmful content in retrieved files. Customers should not download or open an unfamiliar original without appropriate endpoint protection.

5. Version integrity and evidence handling

Each observed version records retrieval metadata and a content hash. Source snapshots are stored under workspace-specific private object keys. Factual document comparisons are separated from AI-generated potential-impact analysis so users can inspect the underlying additions and removals. Monitoring is designed to be idempotent to reduce duplicate versions and alerts. Permanent links remain access-controlled workspace records.

6. AI data handling

For AI analysis, SaaS Tracker sends its third-party AI provider (currently OpenAI, as identified in the Subprocessor and Third-Party Service Provider List) only the relevant text from a preserved document version or relevant document differences, bounded relationship context, section identifiers, prompts, and instructions needed to produce the requested output where practicable. Requests use the configured business/API service with storage disabled through the request setting where supported. The response, model and token metadata, associated source version or change record, citation and extraction-coverage data, user or workspace identifiers needed for traceability, and provider request identifier may be stored by SaaS Tracker for traceability, quality, operations, cost monitoring, customer review, and audit history. AI output is not legal advice, is provided without any warranty of accuracy, completeness, or fitness for any purpose, and requires independent human review before any legal, commercial, compliance, or operational reliance. SaaS Tracker disclaims all liability for decisions made in reliance on AI output. Customers should not place unnecessary personal, confidential, privileged, regulated, or sensitive information in free-text context fields.

7. Email and payment handling

Resend receives recipient details, message content, and delivery metadata needed to deliver invitations, alerts, digests, support, and service communications. Resend’s handling of such data is governed by its own terms and privacy practices, and SaaS Tracker is not responsible for Resend’s acts or omissions. Email may contain summaries and links, so customers should use suitable recipients and workspace permissions. Stripe processes payment instruments, transactions, fraud signals, and related billing information. SaaS Tracker receives limited billing and transaction records needed to administer subscriptions and does not intend to store complete payment-card numbers or card security codes. Stripe’s handling of payment data is governed by its own terms and privacy practices, and SaaS Tracker is not responsible for Stripe’s acts or omissions. Provider roles, locations, safeguards, and downstream service providers may vary, and SaaS Tracker's Subprocessor and Third-Party Service Provider List provides more current provider detail.

8. Website analytics, authentication, and necessary telemetry

SaaS Tracker does not currently use optional website analytics, Google Ads, Meta advertising tools, advertising pixels, conversion APIs, remarketing, audience matching, or signup-event measurement. Necessary service delivery may still generate limited network, device, browser, authentication, security, fraud-prevention, diagnostic, and operational data through SaaS Tracker and its infrastructure providers. WorkOS Hosted AuthKit separately processes account, device, network, security, challenge, and diagnostic information needed for authentication, reliability, fraud and bot prevention, and service operations. That necessary hosted-authentication processing is not optional website analytics and is not controlled through an analytics-consent interface.

9. Backups and recovery

The scheduled operations process is designed to create a private logical workspace backup approximately once every 24 hours during normal operation, though this frequency is a target and not a guaranteed service level. Backups include workspace-scoped database records, schema and row-count metadata, and a SHA-256 checksum, but exclude API credential hashes. Preserved source snapshots remain in private object storage and are referenced by key. Each automated backup is followed by a non-destructive restoration drill that verifies the checksum, schema version, workspace identity, required tables, duplicate keys, row counts, and availability of referenced snapshots. A production restoration follows a controlled operator process that generally includes: freezing writes, preserving current state, restoring a previously verified backup into a separate recovery environment, recreating credentials, validating representative records, and obtaining owner approval before traffic is redirected. SaaS Tracker may adapt this process as circumstances require.

10. Retention and deletion

Active workspace data is retained while needed to provide the Service and according to customer settings. After a verified and authorized deletion request, SaaS Tracker uses commercially reasonable efforts to delete or de-identify active-service data within 30 days, and residual backup copies ordinarily age out within 90 days, though actual timelines may vary due to technical, legal, or operational circumstances. Legal, tax, accounting, fraud-prevention, security, dispute, enforcement, proof-of-deletion, or third-party rights records may be retained longer where necessary. The Data Export and Deletion Procedure explains export scope, verification, deletion effects, and limitations.

11. Security monitoring and testing

The application has automated tests covering role decisions, tenant isolation, invited-user access, API-token revocation, malicious URLs, redirects, oversized documents, browser request controls, security headers, backups, and operational contracts. Internal security review references industry frameworks, including OWASP ASVS, as non-binding guides rather than mandatory standards. The current result supports operation of the Service, subject to ongoing verification, and is not an independent certification, audit, penetration test, or vulnerability-free assurance. Deployed authentication behavior, network egress protections, and hostile-file controls require continuing verification before high-sensitivity enterprise use.

12. Incident and vulnerability reporting

Report suspected vulnerabilities or security incidents to hello@saastracker.co with the subject "Security Report." Include a non-destructive description, affected URL or feature, reproduction steps if applicable, and potential impact, but do not include secrets or sensitive production data in the first message. We endeavor to acknowledge reports and investigate in light of severity, credibility, legal obligations, and available information, but reserve discretion over the scope and timing of any response. Any response target is a goal, not a service-level agreement. We do not authorize destructive testing, privacy violations, social engineering, denial-of-service activity, exfiltration, public disclosure before a reasonable opportunity to investigate, or access to another customer's data. SaaS Tracker reserves all rights and remedies, including referral to law enforcement, with respect to unauthorized testing or disclosure.

13. Customer responsibilities

  • Use the Service only for authorized public sources and lawful purposes.
  • Apply least privilege, review memberships, protect accounts and API credentials, and revoke access promptly.
  • Maintain independent copies of critical contracts and documents; do not use SaaS Tracker as the sole system of record.
  • Review AI output and source evidence before making decisions.
  • Avoid unnecessary sensitive, privileged, regulated, or confidential information in monitored sources, uploads, prompts, instructions, support messages, and free-text fields.
  • Assess whether the Service and current safeguards meet the customer's legal, regulatory, contractual, and risk requirements.

14. Contact

SaaS Tracker LLC 30 N. Gould St., Ste R, Sheridan, WY 82801, United States Email: hello@saastracker.co

← Return to all terms & policiesQuestions? hello@saastracker.co →
STSaaS Tracker

Legal change intelligence, built one reliable record at a time.

Interactive demoProduct tourPricingUse casesResourcesAboutSecurityFAQContactTerms & Policies
© 2026 SaaS Tracker LLC.
Security and Data-Handling Overview — SaaS Tracker