Privacy Policy
Last updated: August 7, 2025
At PullRule (“PullRule”, “we”, “our”, or “us”), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information when you use our service at https://pullrule.com (the “Service”).
We process your data in accordance with the General Data Protection Regulation (GDPR) and other applicable laws.
-
Who We Are
PullRule is a company based in the Netherlands. We provide a SaaS platform that allows users to score and evaluate pull requests using custom-defined rules.
For privacy-related questions, contact us at: legal@pullrule.com
-
What Information We Collect
We collect and process the following types of data:
-
Account Information
- Name, email address, profile photo
- Login credentials via OAuth (GitHub, Google, Bitbucket)
-
Git & Pull Request Data
- PR titles, descriptions, changed files, commits, branches, reviewers
- Associated metadata (authors, timestamps, comments, status)
-
Usage Data
- IP address, browser type, device type
- Actions within the application (e.g., rule creation, PR scoring)
-
Billing Data (for paid users)
- Billing address (if applicable)
- Payment info handled by Stripe — we do not store card details.
-
Account Information
-
How We Use Your Data
We use your data to:
- Provide and improve the PullRule Service
- Authenticate your account
- Connect with third-party services like GitHub and Google
- Score pull requests based on your custom rules
- Respond to support requests
- Manage subscriptions and payments
- Comply with legal obligations
-
Legal Bases for Processing
Under GDPR, we rely on the following legal bases:
- Contract: to provide the Service
- Consent: for optional features (e.g., profile photo uploads)
- Legal obligation: for compliance and tax reporting
- Legitimate interest: for service improvement and fraud prevention
-
Third-Party Integrations
We use secure integrations with:
- GitHub – for pull request and repo metadata
- Bitbucket – same as above
- Google – for account sign-in
- Stripe – for secure payment processing
Each provider has its own privacy policy. We do not control or assume liability for their practices.
-
Data Storage & Retention
Your data is stored securely in EU-based or GDPR-compliant cloud infrastructure. We retain your data:
- For as long as your account is active
- Up to 90 days after deletion for backup and legal purposes
You may request deletion at any time.
-
Your Rights Under GDPR
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request data deletion (“right to be forgotten”)
- Restrict or object to processing
- Data portability (receive your data in a structured format)
- Lodge a complaint with your local Data Protection Authority (DPA)
To exercise your rights, contact: legal@pullrule.com
-
Cookies
We use strictly necessary cookies for login sessions and security. We do not use tracking or advertising cookies.
If analytics cookies are introduced in the future, we will request your consent.
-
Data Security
We use encryption (in transit and at rest), access controls, and best practices to secure your data. While no system is 100% secure, we continuously monitor and improve our protections.
-
International Data Transfers
Data may be processed outside the EU (e.g., via sub-processors like GitHub or Google), but always in compliance with GDPR using appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions.
-
Changes to This Policy
We may update this Privacy Policy occasionally. Major changes will be notified via email or in-app messaging. Continued use of PullRule after changes implies your acceptance.
-
Contact Us
If you have questions or requests regarding your data: PullRule legal@pullrule.com