Legal

Privacy Policy

Effective date: June 7, 2026

This policy explains how Softever (“we,” “us”) collects, uses, shares, and protects personal data when you use the QuickPatch website, dashboard, CLI, and code-push service (together, the “Service”). It also explains the limited data exchanged with End-User devices that receive patches.

1. Who we are

Softever, Rampur, Uttar Pradesh, India, is the controller of personal data described in this policy for our own customers and website visitors. Where we process personal data on behalf of a business customer (for example, telemetry from their Application’s End Users), we act as a processor under the Data Processing Addendum and that customer is the controller.

2. Data we collect

  • Account data - your name and email (for example, via Google sign-in), organization, and the API keys we issue to you.
  • Project data - application identifiers, Release and Patch metadata, version numbers, and the build and patch artifacts you upload to deliver updates.
  • Billing data - if you purchase a paid plan, billing contact and transaction records (payment-card data is handled by our payment processor, not stored by us).
  • Telemetry and update-delivery data - operational events such as patch availability checks, download and install outcomes, and errors, used to operate and secure the Service.
  • Technical and log data - IP address, device and browser information, and request logs collected when you use the website, dashboard, CLI, or API.

End-User devices that receive patches contact our servers to check for and download updates. This may include the device IP address and basic application and Release identifiers. We do not intend the Service to collect End-User personal data beyond what is necessary to deliver updates, and we do not use it to build profiles of End Users.

3. How we use data

  • To provide, maintain, secure, and improve the Service;
  • To authenticate you and communicate about your account, including service and security notices;
  • To meter usage, bill paid plans, and prevent abuse and fraud;
  • To monitor, investigate, and enforce our Terms and the Acceptable-Use Policy;
  • To comply with legal obligations and respond to lawful requests.

4. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal data on the bases of: performance of a contract (to provide the Service); our legitimate interests (to secure and improve the Service and prevent abuse, balanced against your rights); compliance with a legal obligation; and, where required, your consent (which you may withdraw at any time).

5. Sharing and subprocessors

We share personal data with service providers who help us operate the Service - including cloud hosting and compute, object storage and content delivery, authentication, analytics, error monitoring, and payment processing - under contracts that require them to protect the data and use it only to provide their service to us. Our current subprocessors include Vercel (website and dashboard hosting), Railway (API hosting), Cloudflare R2 (object storage and content delivery), Google (account sign-in), and Razorpay (payment processing); an up-to-date list is available on request. We may also disclose data to comply with law or to protect rights, safety, and the integrity of the Service. We do not sell personal data and do not share it for cross-context behavioral advertising.

6. International transfers

We operate from India and may process and store data in India and in the regions where our cloud providers operate. Where we transfer personal data out of the EEA, UK, or other regulated regions, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum.

7. Retention

We retain personal data for as long as your account is active and as needed to provide the Service, then delete or anonymize it within 90 days, unless a longer period is required by law, to resolve disputes, or to enforce our agreements. Operational logs and telemetry are retained for up to 12 months.

8. Your rights

Depending on where you live (for example, under the GDPR/UK GDPR or the CCPA/CPRA), you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. You may also have the right to lodge a complaint with a supervisory authority. To exercise these rights, contact support@quickpatch.dev; we will respond as required by applicable law. We will not discriminate against you for exercising your rights.

9. Security

We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and cryptographically signed patch artifacts that are verified on-device. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. See our Trust & Safety policy for how to report a vulnerability.

10. Children

The Service is intended for businesses and is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact support@quickpatch.dev and we will delete it.

11. Changes and contact

We may update this policy; we will post the updated version here with a new effective date and, for material changes, provide additional notice. Questions or requests: support@quickpatch.dev.