Privacy Policy
Effective date: July 5, 2026
This Privacy Policy explains how GreenOps (“we,” “us,” or “our”) collects, uses, stores, and protects information when you use the GreenOps website, CLI scanner, and platform services (collectively, the “Services”).
By using the Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Services.
1. Information We Collect
1.1 Information You Provide to Us
- Account information: name, email address, and authentication provider details when you sign in.
- Billing information: payment details processed by our billing provider; we do not store full payment card numbers.
- Communications: messages, support requests, and feedback you send to us.
1.2 Information We Collect Automatically
- Usage data: pages visited, features used, and interactions with the Services.
- Device and log data: IP address, browser type, operating system, and timestamps.
- Error and performance data: logs and diagnostics to help us operate and improve the Services.
1.3 Information from Cloud Integrations
When you connect a cloud account, our scanner reads metadata and usage metrics using read-only APIs. We do not collect:
- Source code or application data stored in your cloud services,
- Credentials or long-lived access keys to your cloud accounts,
- Payment or billing data from your cloud provider.
The scanner runs locally by default (the npx greenops-scan CLI) and does not send your cloud data to us unless you explicitly connect the account to the GreenOps platform.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Services,
- Generate optimization reports, cost estimates, and carbon impact calculations,
- Process payments and manage subscriptions,
- Communicate with you about your account, updates, and support requests,
- Improve the security, reliability, and performance of the Services,
- Comply with legal obligations and enforce our terms.
3. How We Store and Protect Information
- Encryption: data in transit is protected using TLS, and sensitive data at rest is encrypted using industry-standard methods.
- Access controls: access to production systems is limited to authorized personnel and protected by multi-factor authentication.
- Cloud infrastructure: our platform is hosted on AWS, and we follow AWS security best practices for networking, IAM, and logging.
- Data retention: we retain your data only as long as necessary to provide the Services or as required by law.
Despite our safeguards, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
4. Sharing and Disclosure
We do not sell your personal information. We may share information only in the following circumstances:
- Service providers: with trusted third parties that help us operate the Services (e.g., hosting, payment processing, authentication). These providers are contractually obligated to protect your data.
- Legal compliance: when required by law, regulation, legal process, or governmental request.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
- With your consent: when you explicitly authorize us to share information.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Keep you authenticated,
- Remember your preferences,
- Analyze usage and improve the Services.
You can manage cookie preferences through your browser settings. Disabling cookies may affect certain features of the Services.
6. Your Rights and Choices
Depending on your location, you may have the right to:
- Access, correct, or delete your personal information,
- Object to or restrict certain processing activities,
- Withdraw consent where processing is based on consent,
- Export your data in a portable format,
- Lodge a complaint with a data protection authority.
To exercise these rights, contact us at the email address below. We will respond within a reasonable timeframe.
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We use appropriate safeguards, such as standard contractual clauses and adequate protection measures, to protect your data during international transfers.
8. Children’s Privacy
The Services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the effective date and, where appropriate, by email or through the Services. Your continued use of the Services after changes constitutes acceptance of the revised policy.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
GreenOps
Email: privacy@greenops.cloud
Thank you for trusting GreenOps with your cloud optimization and sustainability goals.