Cloud Approver logo
Cloud Approver Cloud architecture, security, and risk guidance
Privacy

Privacy Policy

Last updated: June 5, 2026

This Privacy Policy explains how Cloud Approver collects, uses, retains, and protects information when visitors use the website, request an invite, use the live demo, create an account, connect supported cloud accounts, request assistance, or use subscription services.

Information we collect

Cloud Approver may collect information such as:

  • Names, email addresses, company names, and invite request details.
  • Cloud Approver user account records needed to operate access, such as encrypted password hashes, confirmation or reset tokens, session identifiers, user preferences, and audit metadata.
  • Connected cloud account identifiers and read-only connection metadata, such as AWS account numbers, Azure subscription IDs, Google Cloud project IDs, role ARNs, external IDs, scanner principals, expected role assignments or IAM bindings, and connection status. Cloud Approver does not collect customer cloud console login credentials.
  • Billing addresses, subscription status, subscription history, and payment-related account details.
  • Usage logs, session information, IP addresses, browser information, and audit events.
  • Connected cloud account metadata, scanner results, inventory records, recommendations, approval records, reports, and support correspondence.
  • Messages, screenshots, notes, and files provided through support or assistance workflows.

Payments and Stripe

Cloud Approver uses Stripe, Inc. for payment processing. Sensitive financial information such as credit card numbers, CVV codes, and raw payment credentials is collected directly by Stripe through Stripe-hosted or Stripe-secured payment flows. Cloud Approver does not store or process raw card credentials on local servers.

Stripe's privacy practices are described in the Stripe Privacy Policy.

Cookies and tracking

Cloud Approver uses essential cookies required for login sessions, security, demo sessions, and Stripe checkout functionality. Cloud Approver does not use advertising pixels, retargeting pixels, or third-party advertising tracking IDs. Cloud Approver does not sell, lease, or share personal information with third-party data brokers.

How information is used

Information is used to operate the service, authenticate users, maintain connected account reviews, generate recommendations, process subscriptions, respond to support requests, improve reliability, prevent abuse, maintain audit records, and comply with legal and tax obligations.

Retention

User profile information, billing history, subscription records, and access data may be retained for the active duration of the subscription plus a statutory recordkeeping period of up to seven years for internal auditing, tax, accounting, chargeback, dispute, and legal compliance purposes.

Scanner evidence, recommendations, reports, audit logs, and operational records may be retained according to the active service tier and applicable legal, security, and business requirements.

Vendors and subprocessors

Cloud Approver may use vendors for hosting, databases, email delivery, payment processing, logging, support, and related infrastructure. Vendors that process customer information are expected to maintain reasonable safeguards and operate under written terms, data processing terms, or contractual obligations appropriate for their role.

Security

Cloud Approver is designed to use modern Transport Layer Security (TLS/SSL) for public and account pages. Payment flows are handled through Stripe-secured infrastructure so Cloud Approver does not receive or store unencrypted cardholder data.

No online service can guarantee absolute security, but Cloud Approver uses access controls, audit records, and operational safeguards intended to protect customer information.

Breach notification

If Cloud Approver determines that a security incident has compromised personal information, Cloud Approver will provide notices required by applicable law. For District of Columbia residents, if a breach affects 50 or more residents, Cloud Approver will make required reports to the Office of the Attorney General for the District of Columbia before or at the same time as affected resident notifications when required by law.

Contact

Customers can use in-app requests for account-specific questions. Public visitors can request an invite from the home page.