1. Who We Are (Data Controller)
The data controller responsible for your personal information is Rani Rangari, operating EdgeCaseExchange at edgecaseexchange.com.
For any privacy questions, data-rights requests, or concerns regarding how your data is handled, please contact us directly at support@edgecaseexchange.com.
2. What We Collect, Why, and Legal Basis
We aim to collect as little personal data as possible to operate the platform. The data we process includes:
- Account & Authentication Data: Your email address, display name, profile image (from Google or GitHub OAuth), and session tokens. We collect this to create your account, manage your access, keep you signed in, and prevent abuse. (Legal basis: Contract performance and Legitimate interest in platform security)
- GitHub Username: Collected when you purchase a product requiring access to our private GitHub repositories. We use this to grant repository access via the GitHub API and maintain your access permissions. (Legal basis: Contract performance)
- Purchase & Billing Data: Order IDs, purchased items, transaction amounts, currency, and country details provided by our payment processor. We use this to fulfill your order and satisfy mandatory tax and accounting obligations. (Legal basis: Legal obligation and Contract performance)
- Server & Security Logs: Basic technical logs (such as IP address, browser user-agent, and request paths) retained briefly to detect abuse, protect against attacks, and maintain service stability. (Legal basis: Legitimate interest in maintaining security)
We explicitly do NOT collect: Payment card numbers (handled entirely by Stripe), passwords (we use OAuth exclusively), government IDs, precise location data, or any special categories of sensitive personal data.
3. Sub-Processors
We use the following third-party services to run the Service. Each has access only to the data needed to perform its function and is contractually bound to handle it under their own published terms and Data Processing Agreement.
- Stripe: Processes all payment transactions directly so card details never touch our servers.
- Google & GitHub OAuth: Authenticates your identity securely without us ever handling or storing passwords.
- GitHub API: Receives your GitHub username to dispatch collaborator invitations to private code repositories upon purchase.
- Neon PostgreSQL: Hosts our primary database for storing account records, order metadata, and access permissions.
- Arcjet: Provides rate limiting, bot protection, and security shielding across platform endpoints.
We will keep this list current. Material changes (adding a new sub-processor that significantly changes the data flow) will be announced by updating the "Last updated" date above.
4. Retention
- Account Data: Kept for as long as your account remains active. Deleted from our primary Neon PostgreSQL database within 30 days of a confirmed account deletion request.
- Purchase Records: Kept for 7 years after purchase to comply with applicable tax and accounting laws. Deleting your account does not delete financial transaction records; we anonymize them (removing your name, email, and profile details) while retaining the order ID, transaction amount, and tax metadata.
- Security & Server Logs: IP addresses and Arcjet security event logs are retained for up to 30 days for abuse detection and system safety, after which they are automatically pruned.
6. Your Privacy Rights
Depending on your jurisdiction, you have specific legal rights regarding your personal data:
- Right of Access & Portability: You can request a copy of the personal information we hold about you in a structured, commonly used format.
- Right to Erasure: You can request the permanent deletion of your account and personal data, subject to mandatory tax and accounting retention requirements.
- Right to Correction: You can request that we correct or update any inaccurate or incomplete personal records.
Exercising Your Rights: To submit a privacy request or request account deletion, send an email to support@edgecaseexchange.com. We will respond within 30 days. We may need to verify your identity before acting on a request.
7. Contact
For privacy questions, data-rights requests, or anything else about how we handle your data, - write to support@edgecaseexchange.com. The full Terms of Service and License continue to apply alongside this privacy policy - read them at Terms of Service and License .