VantraOpsBeta

VantraOps Privacy Policy

Status: DRAFT — for internal legal review. Not yet published or binding.

Last updated: July 30, 2026


Placeholders to fill in before publishing: legal entity name, registered address, and Data Protection Officer/EU representative (if applicable) are marked [ ]. Confirm applicability of GDPR, the Philippine Data Privacy Act (given Xendit billing), CCPA/CPRA, and any other regimes covering your actual customer base before publishing.

1. Who we are

This Privacy Policy explains how [Company Legal Name] (“VantraOps,” “we,” “us,” “our”), located at [Registered Address], collects, uses, discloses, and protects information in connection with the VantraOps Kubernetes fleet-monitoring platform (the “Service”). It applies to visitors of our marketing site, registered Customers and their invited team members (“Users”), and data received from the in-cluster agent Customers install.

This policy should be read together with our Terms and Conditions.

2. Information we collect

2.1 Account and identity information

  • Name, email address, and profile information from Google or GitHub when you sign up or sign in via OAuth (or username/password for legacy accounts).
  • Tenant/organization details, role (Admin or Member), and team-invite records (inviter, invitee email, acceptance status).
  • Multi-factor authentication data, including WebAuthn/passkey public-key credential metadata (we do not receive or store your private key or biometric data — that stays on your device/security key).

2.2 Billing information

  • Plan selection, subscription status, billing cycle dates, and invoice history.
  • Payment method metadata we retain ourselves: card brand and last four digits, and provider-side identifiers (e.g., Stripe customer/ subscription IDs, or a reference to the most recent Xendit invoice).
  • We do not collect or store your full card number, CVV, or bank account number. Those are entered directly with, and held by, our payment processors — Stripe and Xendit — each of which maintains its own PCI-DSS compliant environment and privacy practices. Review their policies at their respective websites for how they handle data you submit directly to them.

2.3 Cluster and telemetry data (“Customer Data”)

  • When you register a cluster, we store cluster metadata (name, cloud provider, region, status) and issue enrollment tokens (stored only as irreversible hashes, never in plaintext).
  • Once the in-cluster agent is installed, it pushes: node/pod/workload resource usage (requests vs. actual CPU/memory), counts and versions, cluster health/heartbeat signals, and configuration metadata used for architecture-health checks (e.g., presence/absence of PodDisruptionBudgets, IAM/Workload Identity binding scope, taints/ node-pool topology).
  • The agent is designed to send operational/infrastructure metadata, not your application’s business data or end-user content — it does not read application logs, database contents, or the payloads flowing through your workloads.
  • If you configure the optional AI Assistant with your own API key (BYOK), that key is encrypted at rest and used only to make requests to the AI provider on your behalf; if you use the platform-funded key instead, your prompts are sent to our AI provider subject to their data processing terms.

2.4 Usage and technical data

  • Log data (IP address, browser/device type, timestamps, pages/endpoints accessed), session and refresh token metadata (not the raw token values in logs), and error/diagnostic data used to operate and secure the Service.
  • Cookies or local storage used by the Angular portal for session persistence; see Section 8.

3. How we use information

We use the information above to:

  • create and administer your account, Tenant, and team-invite workflow;
  • provide the Service: display dashboards, compute cost/utilization/ architecture-health results, evaluate and deliver alerts;
  • process payments, manage subscriptions, and handle recurring billing, including sending renewal, past-due, and receipt notifications;
  • authenticate requests and secure accounts, clusters, and agent credentials, including detecting and responding to suspicious activity;
  • provide customer support and respond to inquiries;
  • send service-related communications (e.g., security notices, incident disclosures, billing notices) and, where you’ve opted in, product updates;
  • comply with legal obligations (e.g., tax, accounting, fraud prevention); and
  • improve the Service’s reliability, performance, and features.

We do not use Customer Data (Section 2.3) to train third-party AI models beyond what is necessary to service your own AI Assistant requests, and we do not sell Customer Data or account information.

Where GDPR or similar law applies, we process personal data on the following bases: performance of a contract (providing the Service you signed up for), legitimate interests (securing the Service, preventing fraud, improving the product), consent (e.g., optional marketing communications, non-essential cookies), and compliance with legal obligations (e.g., tax records).

5. How we share information

We disclose information only as follows:

  • Payment processors (Stripe, Xendit) — to process your subscription payment and manage recurring billing; they receive the payment details you submit directly to them.
  • Infrastructure and sub-processors — cloud hosting, database, email-delivery (SMTP), and AI providers we use to operate the Service, under contracts requiring appropriate protection of your data.
  • Within your Tenant — Admins can see Tenant-wide billing, cluster, and member information; Members see dashboards and clusters but not billing or tenant-settings data.
  • Legal and safety — where required by law, legal process, or to protect the rights, property, or safety of VantraOps, our Users, or the public.
  • Business transfers — if VantraOps is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this policy or a successor policy with materially similar protections.

We never share one Tenant’s cluster or Customer Data with another Tenant. We do not sell personal information as that term is defined under CCPA/CPRA or similar laws.

6. Tenant isolation and access security

  • Every Tenant’s clusters, metrics, and dashboards are logically isolated and enforced by tenant-scoped access controls throughout the Service — one customer’s data is never visible to another.
  • Access to the portal requires authenticated JWT session tokens (short-lived access tokens, longer-lived rotating refresh tokens that can be revoked/blacklisted on logout) plus, where enabled, multi-factor authentication.
  • Access to cluster telemetry from the agent side requires a distinct, cluster-scoped credential issued only after redeeming a single-use, time-limited enrollment token; this credential cannot be used to access another cluster or Tenant’s data.
  • Internally, access to production data is limited to personnel who need it to operate or support the Service, subject to our internal access controls.

7. Data retention

  • Account data is retained for as long as your account is active, and for a limited period after closure to comply with legal, tax, or dispute-resolution obligations.
  • Billing records (invoices, subscription history) are retained as required by applicable tax/accounting law, typically several years after the relevant transaction.
  • Cluster telemetry is retained to support historical dashboards and trend analysis; when you delete a cluster, we stop collecting new telemetry for it and delete or de-identify the retained history within a reasonable period, except where retention is needed for security logs or legal compliance.
  • Enrollment tokens are single-use and stored only as hashes; expired or redeemed tokens are not reusable and are purged on a routine schedule.
  • Upon account termination, we delete or anonymize personal data and Customer Data within a reasonable period, except data we must retain for legal, security, or billing-record purposes.

8. Cookies and similar technologies

The Angular-based portal uses essential cookies/local storage to maintain your session and authentication state. We may use limited analytics cookies to understand product usage; where required by law, we will request your consent for non-essential cookies and provide a way to manage your preferences.

9. International data transfers

Depending on where you and our infrastructure/sub-processors are located, your information may be transferred to and processed in countries other than your own, including the United States and the Philippines (via our payment and infrastructure providers). Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers. [Counsel to confirm mechanism per region served.]

10. Your privacy rights

Depending on your location, you may have rights to: access, correct, or delete your personal data; export a copy of it; object to or restrict certain processing; withdraw consent (where processing is based on consent); and lodge a complaint with a supervisory authority. Tenant Admins can access and manage most account, billing, and cluster data directly from the portal. To exercise any right not available there, contact us at [privacy@vantra.io]; we will verify your identity before acting on the request and respond within the timeframe required by applicable law.

If you are a Member invited to a Tenant, some data (e.g., your presence in that Tenant) is controlled by the inviting organization’s Admin; we will direct certain requests to them where they are the data controller.

11. Children’s privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children under the age applicable in your jurisdiction (e.g., 13 or 16). Contact us if you believe a child has provided us data so we can delete it.

12. Security

We use administrative, technical, and physical measures designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit (TLS/HTTPS), encryption at rest for sensitive configuration (e.g., BYOK AI credentials), short-lived/rotatable authentication tokens, hashed enrollment tokens, and tenant-scoped access controls. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you as required by applicable law. Report suspected vulnerabilities to [security@vantra.io].

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new “Last updated” date and, for material changes, provide additional notice (e.g., email or in-portal notice) before the change takes effect.

14. Contact us

Questions, requests, or concerns about this Privacy Policy or your data: