Privacy Policy
Last updated: June 28th, 2026
Danique Wijnalda ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use the GitPort service ("Service"). If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR).
1. Who We Are
GitPort is operated by Danique Wijnalda, an individual established in the Netherlands. Danique Wijnalda is the data controller responsible for your personal data. For questions about this policy or to exercise your rights, contact us via our support centre.
2. Data We Collect
We collect the following categories of data:
- Account data: your name, email address, and profile information obtained from your OAuth provider when you sign up, or provided directly when registering with email and password.
- Provider data: repositories, pull requests, issues, notifications, and related metadata retrieved from the Git providers you connect (e.g., GitHub, GitLab). This data is stored in our database to power the unified view.
- OAuth tokens: access tokens issued by connected providers, stored securely and used solely to make API requests on your behalf.
- Usage data: log data, IP addresses, browser type, and interactions with the Service, collected for security and performance purposes.
3. How We Use Your Data
We use your data to:
- Provide, operate, and improve the Service;
- Sync and display your Git provider data in the unified interface;
- Authenticate you and secure your account;
- Send transactional emails (e.g., account-related notifications, support responses);
- Send optional email notifications about your repositories and activity, if you have opted in;
- Comply with legal obligations.
We do not sell your personal data to third parties.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): providing the Service, syncing provider data, authenticating you, and sending transactional emails necessary for your account.
- Legitimate interests (Art. 6(1)(f)): security logging, abuse prevention, monitoring service performance and stability, and improving the Service. Our legitimate interest is in operating a secure and reliable service; we have balanced this against your rights and do not believe it overrides them. You may object to processing on this basis — see §9.
- Consent (Art. 6(1)(a)): optional email notifications about repository activity, where you have opted in. You may withdraw consent at any time — see §9.
- Legal obligation (Art. 6(1)(c)): retaining records where required by applicable law (e.g., accounting or tax obligations).
IP addresses and log data collected for security and service monitoring are processed under the legitimate interests basis described above.
5. Third-Party Services and Sub-Processors
The Service integrates with third-party Git providers (currently GitHub and GitLab). When you connect an account, that provider's privacy policy also applies to the data they share with us. We use your OAuth token to make API calls on your behalf; we do not share your token with any other party.
We use a small number of third-party service providers to operate GitPort, including providers for hosting, email delivery, and error monitoring. These providers process data only on our instructions and under data processing agreements. We do not sell or rent your personal data, and we do not share your OAuth tokens with any third party.
Key categories of sub-processors include:
- Hosting / infrastructure: Hetzner Online GmbH — Germany, EU
- Email delivery: Lettermint — Netherlands, EU
- Application monitoring / error tracking: Laravel Nightwatch — Europe (Frankfurt), EU
6. International Transfers
The Git providers we connect to — currently GitHub and GitLab — operate from the United States, and some of our infrastructure providers may process limited data outside the European Economic Area (EEA). Where data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's adequacy decisions or Standard Contractual Clauses. The privacy policies of GitHub and GitLab govern how those providers handle data on their own systems.
7. Data Storage and Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure, including encryption of sensitive fields such as OAuth tokens, and encryption of data in transit using TLS. Further details are set out in our Security Policy.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and will inform affected users without undue delay where the breach is likely to result in a high risk to them.
8. Data Retention
We retain your data for as long as your account is active. If you request account deletion, we will mark your account for deletion and permanently erase all associated personal data within 7 days, unless we are required to retain it by law.
Some data in GitPort is shared between multiple users — for example, a repository, pull request, or issue that more than one GitPort user can access. If you request deletion, we remove your account, your OAuth tokens, and the personal data that identifies you. Data also associated with other users' accounts may remain in our database until the last user with access deletes it, but it will no longer be linked to you. Where shared data still contains information that identifies you (such as your name or username on a pull request), we will take reasonable steps to remove or anonymise it on request, subject to any legal retention obligations.
9. Your Rights (GDPR)
If you are in the EEA, you have the right to:
- Access — request a copy of the personal data we hold about you;
- Rectification — request correction of inaccurate data;
- Erasure — request deletion of your data ("right to be forgotten");
- Restriction — request that we limit processing of your data in certain circumstances;
- Portability — request your data in a machine-readable format;
- Objection — object to processing based on legitimate interests (see §4);
- Withdraw consent — where processing is based on consent (such as optional email notifications), you may withdraw it at any time without affecting the lawfulness of prior processing. Withdraw via your account notification settings or by contacting us;
- Lodge a complaint — with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl), or your local supervisory authority.
You can delete your account and all associated data at any time through Settings > Account. For other requests, contact us via our support centre.
10. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, as required by GDPR Art. 34.
11. Children
The Service is not directed at children under 18 years of age, and we do not knowingly collect personal data from children under that age. If you believe we have inadvertently collected data from a child, please contact us via our support centre.
12. Cookies
The Service uses strictly necessary cookies to maintain your authenticated session. We do not use tracking or advertising cookies. If we introduce optional cookies in the future, we will ask for your consent.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page. Your continued use of the Service after changes become effective constitutes your acknowledgement of the revised policy.
14. Contact
For any privacy-related questions or to exercise your rights, contact us via our support centre.