Privacy Policy

Last updated: August 25, 2026

1. Introduction

JS Security Audit (operated by Eter Group LLC, headquartered in Albuquerque, New Mexico) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website jssecurityaudit.com and use our services.

When we process your personal data on the basis of consent, we collect that consent explicitly (for example, through a consent checkbox when you submit our contact form or customize your cookie preferences). We do not infer consent from mere use of the website.

2. Information We Collect

Contact and Inquiry Data

When you fill out our contact form, request a quote, or communicate with us, we may collect:

  • Full name
  • Email address
  • Company name
  • Project details, technology stack, and message content

Purchase and Checkout Data

When you purchase a service through our website, we collect:

  • Full name and email address
  • Company name
  • Repository URL you wish to be audited
  • Technology stack (e.g., Next.js, React, Node.js)
  • Project description and specific security concerns
  • Payment information is processed directly by Stripe — we do not store full credit card numbers or bank details on our servers.

Technical Information

We may automatically collect certain technical information when you visit our website, including:

  • Browser type and version
  • IP address
  • Pages visited and time spent on each page
  • Referring website URLs

3. How We Collect Information

We collect information when you:

  • Submit our contact form
  • Purchase a service through our Stripe checkout
  • Send us an email
  • Interact with our website (via cookies and similar technologies)

4. How We Use Your Information

We use the collected information for the following purposes:

  • Respond to your inquiries and service requests
  • Process payments and fulfill purchased services
  • Provide, maintain, and improve our security audit services
  • Send administrative information (e.g., purchase confirmations, invoices, proposal documents)
  • Comply with legal obligations and enforce our agreements
  • Detect and prevent fraudulent or unauthorized activity

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

5. Data Sharing and Disclosure

We may share your information only in the following circumstances:

  • Payment Processing (Stripe): When you make a purchase, your payment information is transmitted directly to Stripe. Stripe is a PCI-DSS compliant payment processor. We do not store full credit card numbers on our servers. Stripe's use of your data is governed by their Privacy Policy at stripe.com/privacy.
  • Service Providers: We may share data with trusted third-party providers who help us operate our website and deliver services (e.g., email delivery, web hosting). These providers are contractually bound to protect your data.
  • Legal Compliance: We may disclose information if required by law, subpoena, or legal process, or to protect our rights, property, or safety.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

6. Data Security

We implement industry-standard security measures to protect your personal information, including SSL/TLS encryption for data transmitted between your browser and our servers, and restricted access to personal data to authorized personnel only. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

International Data Transfers: Our website is hosted on servers located in the United States. If you access our website from the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal information may be transferred to and processed in the United States. By submitting your information, you acknowledge and consent to this transfer. We rely on appropriate safeguards, including standard contractual clauses where required by applicable law.

7. Data Retention

We retain your personal information only as long as necessary for the purpose for which it was collected:

  • Non-converted inquiries: 24 months since the last interaction.
  • Client data: for the duration of the business relationship and, afterwards, 5 years to comply with tax and accounting obligations.
  • Marketing communications: until you withdraw your consent.

Retention periods are reviewed periodically; once they expire, your data is securely deleted or anonymized.

8. Your Rights (GDPR & CCPA)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) grants you the following rights:

  • Right of Access: obtain confirmation of whether we process your data and a copy of it.
  • Right to Rectification: request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("right to be forgotten"): request deletion of your personal data.
  • Right to Restriction of Processing: request that we limit how we process your data.
  • Right to Data Portability: receive your data in a structured, machine-readable format.
  • Right to Object: object to processing based on legitimate interest or for direct marketing.
  • Right to Withdraw Consent: withdraw your consent at any time, without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: file a complaint with your local data protection authority (in Spain, the AEPD — aepd.es).

If you are a California resident, the CCPA/CPRA additionally grants you the right to know, delete, correct, and opt out of the sale or sharing of your personal information (we do not sell data).

To exercise any of these rights, contact us at hello@jssecurityaudit.com. We will respond within the timeframe required by applicable law.

9. Cookies

Our website uses a cookie consent system. Functional cookies — including those set by Stripe for payment processing and fraud prevention — are always active as they are necessary for the checkout to work.

Analytics cookies (Google Analytics 4 via Google Tag Manager) and marketing cookies (Google Ads) are only loaded after you give your consent through our cookie banner. If you decline, these cookies are not set and no analytics or advertising data is collected.

Our security verification widget (ALTCHA) operates without cookies or tracking — it is a privacy-first alternative to traditional CAPTCHA services.

You can accept, reject, or customize your preferences at any time through our cookie banner. For more details, see our Cookie Policy.

10. Third-Party Links

Our website may contain links to third-party websites (e.g., GitHub). We are not responsible for the privacy practices or content of those sites. We encourage you to review their privacy policies before submitting personal information.

11. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us, and we will take steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.

13. Contact Information

Eter Group LLC

Albuquerque, New Mexico

United States

Email: hello@jssecurityaudit.com

Website: jssecurityaudit.com