PrivateNPM.com operates the private npm registry service (the "Service") and is the contact for this Privacy Policy. This policy explains what personal data we collect, why we use it, and what you can do about it. It applies to visitors and account holders. Contact us at [email protected] about privacy requests.
What we collect
- Account data: your email address, name, time zone and display preferences, password hash, passkeys, and linked identity providers. Passwords are stored as Argon2id hashes, not plaintext.
- Organization and registry data: the organizations you belong to, your role and invitations, and the packages, files, registry settings and access keys your organization stores. Key secrets are stored in protected form so they can authenticate later.
- Usage and security data: sign-ins, browser sessions, IP address and user agent, audit records, registry usage and technical logs used to run and protect the Service.
- Billing data: the plan and subscription status and, when Stripe billing is enabled, Stripe customer and subscription identifiers and invoice information. Payment card details are entered with Stripe; we do not store full card numbers.
- Communication data: account and notification emails, delivery status, support requests, and any information you send us when asking for help.
We do not use advertising trackers. Operational logs and error monitoring may be used to diagnose problems.
Why we use it
- To provide the Service and perform our agreement with you: sign you in, host packages, control registry access, process subscriptions, send necessary account messages, and answer support requests.
- To protect the Service and our users under our legitimate interests: prevent abuse, throttle sign-in attempts, investigate failures and keep security and audit records.
- To meet legal obligations, such as accounting and responding to lawful requests.
You can change notification email preferences in your account. We use those choices to decide which optional messages to send.
We send account email (verification, password reset, security notices) because the Service cannot work without it. Notification email is optional: every message carries an unsubscribe link and you can choose channels per notification type under your account's notification settings.
Who sees your data
- Admins of an organization you belong to see your name, email, role and the audit trail of that organization.
- Providers for hosting, object storage, email delivery, error monitoring and billing process data needed for their services. When Stripe billing is enabled, Stripe handles payment card entry and billing. Some providers may process data outside your country; contact us for details relevant to your organization.
- We do not sell personal data.
How long we keep it
- Account data stays while your account exists. You can delete your account from your profile; organizations where you are the only member are deleted with it.
- Organization and registry data stays while the organization exists. Admins can configure retention for audit logs, notifications, event history, and expired or revoked share links. An unpaid trial organization is scheduled for deletion after its trial ends; a completed checkout before then keeps it active.
- Deleting an account or organization removes its active records and starts background cleanup of related files and data. Backups and records required for accounting, security or legal claims may remain for their applicable retention periods.
- Sessions and temporary sign-in tokens expire and are removed automatically. Email delivery logs, webhook records and exhausted background jobs have separate operational retention periods.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to some uses of it. You can export your own account data and request account deletion from your profile. For other requests, email [email protected]. If you are in a jurisdiction with a data protection authority, you may also lodge a complaint with that authority.
Cookies
The Service uses necessary cookies for sign-in sessions and short-lived security or identity-provider flows. They are not advertising cookies.
Changes to this policy
We may update this policy. Each version carries an effective date, and material changes are announced in the Service.
Contact
Contact PrivateNPM.com at [email protected] with privacy questions or requests.