PRIVACY POLICY
This Privacy Policy explains how SmartRuns collects, uses, stores, and protects information about you when you use our test management platform (the “Service”). We are committed to protecting your privacy and handling your data transparently and responsibly.
By using the Service, you agree to the collection and use of information as described in this Privacy Policy.
1. Who We Are
We operate a web-based Software-as-a-Service (SaaS) test management tool that allows individual users to manage test cases, execute test runs, generate reports and analytics, and integrate with third-party tools such as Jira and GitHub.
If you have any questions about this Privacy Policy or our data practices, please contact us at: privacy@smartruns.io
2. Information We Collect
2.1 Information You Provide Directly
When you register for an Account or use the Service, we may collect:
- Account information: your name, email address, and password.
- Profile information: any additional details you choose to add to your profile.
- Billing information: payment method details, billing address, and transaction history (processed securely via our payment provider; we do not store full card numbers).
- Content you create: test cases, test runs, test results, reports, comments, and any other data you input into the Service.
- Support communications: messages you send to our support team.
2.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain technical information, including:
- Log data: IP address, browser type and version, operating system, referring URLs, pages visited, and timestamps.
- Usage data: features used, actions performed, frequency and duration of use.
- Device information: device type, screen resolution, and language settings.
- Cookies and similar technologies: see Section 6 for details.
2.3 Information from Third-Party Integrations
If you connect the Service to third-party tools (such as Jira or GitHub), we may receive data from those services necessary to enable the integration, such as project names, issue identifiers, repository names, and authentication tokens. We only access the minimum data required to provide the integration functionality you have requested.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: to operate, maintain, and deliver the features of our test management platform.
- Account management: to create and manage your account, authenticate your identity, and communicate with you about your account.
- Billing and payments: to process subscription payments, issue invoices, and manage your plan.
- Product improvement: to analyze usage patterns, diagnose technical issues, and develop new features.
- Customer support: to respond to your inquiries and resolve issues.
- Security: to detect, prevent, and investigate fraud, abuse, or unauthorized access.
- Legal compliance: to comply with applicable laws, regulations, and legal processes.
- Communications: to send you service-related notifications, security alerts, and (where you have opted in) product updates or promotional content.
We do not sell your personal data to third parties, and we do not use your Content for training AI models or any purpose other than providing the Service to you.
4. Legal Basis for Processing
Depending on your location, we process your personal data on the following legal grounds:
- Contract performance: processing necessary to provide the Service under our agreement with you (e.g., account management, billing, feature delivery).
- Legitimate interests: processing for our legitimate business interests, such as improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your rights.
- Legal obligation: processing required to comply with applicable laws or regulatory requirements.
- Consent: where we rely on your consent (e.g., for marketing communications), you may withdraw it at any time without affecting the lawfulness of prior processing.
5. How We Share Your Information
We do not sell or rent your personal data. We may share your information only in the following limited circumstances:
5.1 Service Providers
We share data with trusted third-party vendors who assist us in operating the Service, including:
- Cloud infrastructure and hosting providers.
- Payment processors (who handle billing data on our behalf under their own security standards).
- Analytics providers (used to understand usage patterns in aggregated, anonymized form where possible).
- Customer support tools.
All service providers are contractually required to handle your data securely and only for the purposes we specify.
5.2 Third-Party Integrations
When you enable integrations with tools like Jira or GitHub, data is exchanged between the Service and those platforms as required by the integration. Your use of those platforms is governed by their own privacy policies.
5.3 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, your safety, or the safety of others.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
6. Cookies and Tracking Technologies
We use cookies and similar technologies (such as local storage and session tokens) to operate and improve the Service. These include:
- Essential cookies: required for authentication, session management, and core Service functionality. These cannot be disabled.
- Analytics cookies: used to understand how users interact with the Service (e.g., pages visited, features used). These help us improve the product.
- Preference cookies: used to remember your settings and preferences.
You can control non-essential cookies through your browser settings or our cookie consent banner. Please note that disabling certain cookies may affect the functionality of the Service.
7. Data Retention
We retain your personal data for as long as your Account is active or as needed to provide the Service. Specifically:
- Account data is retained for the duration of your Account and deleted within 90 days of account termination, unless a longer retention period is required by law.
- Content (test cases, runs, reports, etc.) is retained for 30 days after account termination, after which it is permanently deleted.
- Billing records may be retained for up to 7 years for legal and tax compliance purposes.
- Log data is typically retained for up to 12 months for security and diagnostic purposes.
You may request deletion of your data at any time by contacting us (see Section 9).
8. Data Security
We implement industry-standard security measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Access controls limiting data access to authorized personnel only.
- Regular security reviews and vulnerability assessments.
- Secure storage of authentication credentials using hashing.
Despite our efforts, no method of data transmission or storage is 100% secure. We cannot guarantee absolute security and will not be liable for unauthorized access resulting from circumstances beyond our reasonable control. In the event of a data breach that affects your rights and freedoms, we will notify you as required by applicable law.
9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: the right to request a copy of the personal data we hold about you.
- Correction: the right to request that we correct inaccurate or incomplete data.
- Deletion: the right to request that we delete your personal data, subject to legal retention obligations.
- Portability: the right to receive your data in a structured, machine-readable format.
- Objection: the right to object to processing based on legitimate interests.
- Restriction: the right to request that we limit how we use your data in certain circumstances.
- Withdrawal of consent: where processing is based on consent, the right to withdraw it at any time.
To exercise any of these rights, please contact us at [privacy@smartruns.com]. We will respond within 30 days. We may ask you to verify your identity before processing your request.
If you are located in the European Economic Area (EEA) or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
10. International Data Transfers
Our Service is operated internationally. Your data may be processed and stored in countries other than your country of residence. Where we transfer data across borders, we take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy and applicable law, including through the use of standard contractual clauses or equivalent mechanisms where required.
11. Children’s Privacy
The Service is not intended for use by individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor without appropriate consent, we will take steps to delete that information promptly. If you believe we may have collected data from a minor, please contact us immediately.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will notify you by updating the “Last Updated” date at the top of this page and, where appropriate, by sending you an email notification or displaying an in-app notice.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
SmartRuns
Privacy inquiries: privacy@smartruns.io
Website: www.smartruns.io