This Privacy Policy explains how Firezone, Inc. ("Firezone," "we," "us," or "our") handles personal information when you use:
- the Firezone service, admin portal, APIs, and client applications;
- firezone.dev and other sites that link to this policy; or
- our sales, support, marketing, and event channels.
We collect only the personal information reasonably needed to provide, secure, support, and improve Firezone, meet our legal obligations, and run our business. We do not sell personal information.
If you do not agree with this policy, do not use the Services. If you already have an account, you may stop using the Services and ask us to close it. This does not limit any privacy rights you have under applicable law.
Key Points
- We cannot see the contents of your network traffic. Traffic through Firezone is end-to-end encrypted. In limited cases, encrypted traffic may pass through Firezone relays, but Firezone cannot decrypt it.
- We collect data needed to operate the service. This includes account and contact details, service configuration, authentication and security data, billing records, support communications, and technical logs.
- Basic website measurement is enabled without cookies. Persistent analytics and marketing technology remain off until you choose them using the "cookies" link in the footer.
- We do not sell personal information. Optional advertising technology may be considered "sharing" under some US state privacy laws. You can opt out at any time.
- You can ask to access, correct, export, or delete your information. Email privacy@firezone.dev.
1. Personal Information We Collect
What we collect depends on how you use Firezone.
| Category | Examples | Why we need it | Retention criteria |
|---|---|---|---|
| Account and contact data | Name, work email, job title, organization, account ID, and account role | To create and manage accounts, authenticate users, and communicate with you | While the account or business relationship is active, plus a limited closure period |
| Service configuration | Users, groups, identity-provider details, Resources, Sites, Policies, Gateway and Client identifiers, and other settings chosen by account administrators | To configure, secure, and provide the service | While the account is active, then according to account-deletion and backup schedules |
| Service activity and security data | Sign-in events, IP address, approximate location derived from IP address, device and browser details, session and API activity, audit logs, and fraud or abuse signals | To operate the service, apply access policies, troubleshoot, and protect accounts | For the service-log period provided by the plan, then as needed for security or legal claims |
| Support and sales data | Messages, form submissions, meeting details, support tickets, and related contact history | To answer questions, provide support, and manage our relationship with you | While useful to serve the customer, honor choices, or resolve a dispute |
| Billing data | Billing contact, business address, plan, invoices, payment status, and transaction history | To bill for paid plans and keep financial records | For the period required by tax, accounting, and financial laws |
| Website and app diagnostics | Pages and features used, referring page, browser and operating system, performance data, crash reports, and similar technical events | To maintain reliability, understand usage, and improve Firezone | Until the identifier expires or is withdrawn, or while needed for reliability and security |
Stripe processes full payment-card or bank details for us. Firezone receives only the billing details and payment status needed to manage your subscription; we do not store full card numbers or security codes.
We do not ask you to provide health, biometric, government-identification, or other special-category information. Authentication and session information may be treated as sensitive under some laws; we use it only to provide and secure the Services. Please do not put sensitive personal information in free-text fields unless we specifically request it.
Where the information comes from
We receive personal information:
- from you, when you create an account, configure the Services, complete a form, pay for a plan, or contact us;
- from your organization, including its administrators, identity provider, or enabled integrations; and
- automatically, from the Services, applications, devices, browsers, and cookies or similar technology.
When a customer controls the data
An organization that provides Firezone to its workforce usually decides which end-user data is submitted to the service and how it is used. For that data, the organization is the controller or business and Firezone acts as its processor or service provider. The organization's privacy notice and its agreement with Firezone govern that processing. Direct questions about organization-controlled data to that organization first.
Firezone is the controller or business for data we use for our own purposes, such as account administration, billing, website operations, security, and sales.
2. How and Why We Use Personal Information
We use personal information to:
- provide, configure, authenticate, and administer the Services;
- apply access controls and keep the Services, users, and networks secure;
- process payments and manage subscriptions;
- provide support and send important service messages;
- monitor reliability, fix problems, and improve features;
- understand website use and measure marketing, when you have allowed the relevant optional technology;
- comply with law, respond to lawful requests, and establish or defend legal claims; and
- complete a financing, merger, acquisition, reorganization, or sale of all or part of our business.
We do not use personal information to make decisions that have legal or similarly significant effects on you without human involvement.
Legal bases for the EEA, UK, and similar jurisdictions
Where a law requires a legal basis, we rely on:
- Contract: processing needed to provide the Services or take steps you request before entering a contract.
- Legitimate interests: securing, supporting, and improving Firezone, performing limited website audience measurement, communicating with business contacts, and running our business, where those interests are not overridden by your rights.
- Consent: persistent analytics, advertising, or other processing for which we ask permission. You may withdraw consent at any time.
- Legal obligation: tax, accounting, regulatory, law-enforcement, and other legal requirements.
- Vital interests: protecting a person's life or physical safety in an emergency.
Withdrawing consent does not affect processing that already occurred or processing based on another lawful ground.
3. When We Disclose Personal Information
We disclose only what is reasonably necessary to:
- Vendors and subprocessors: cloud hosting, payments, customer relationship management, support, analytics, email, security, and error monitoring. They may process data only under contracts and instructions appropriate to their role. See our current subprocessor list.
- Your organization and its administrators: account, user, device, activity, and audit information needed to administer its Firezone account.
- Integrations you choose: data needed to connect an identity provider, log sink, or other service that an account administrator enables.
- Authorities and other parties for legal or safety reasons: when we reasonably believe disclosure is required by law or necessary to protect rights, safety, and the Services.
- A business successor: in connection with a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality protections.
We may use aggregated or de-identified information that cannot reasonably be linked to a person. We do not try to re-identify it.
We do not sell personal information
Firezone does not exchange personal information for money and has not done so in the previous 12 months.
Some US state laws define "sharing" separately from a sale. If you allow marketing cookies, Google Ads may receive online identifiers and website activity to measure ads across different services. That activity may be considered sharing for cross-context behavioral advertising. We do not share personal information for this purpose unless you opt in, and you may opt out through the cookie settings or a supported Global Privacy Control signal.
4. Cookies and Similar Technology
We use limited cookieless analytics for basic website measurement. If you allow persistent analytics, PostHog uses local storage to recognize the same browser across visits. Marketing technology does not load until you allow it. A necessary cookie remembers your choices.
| Cookie or storage key | Provider | Category | Purpose | Typical duration |
|---|---|---|---|---|
| firezone_cookie_consent | Firezone | Necessary | Remembers your privacy choices | 180 days |
| ph_firezone_analytics and related browser storage | PostHog | Analytics | Measures website usage and conversions across visits | Until consent is withdrawn or browser storage is cleared |
| gcl and related cookies | Google Ads | Marketing | Attributes ad clicks and measures campaigns | Up to 90 days |
| hubspotutk, __hstc, __hssc, __hssrc, and related storage | HubSpot | Marketing | Associates permitted website activity and form submissions with contacts and measures interactions | From the browser session up to six months |
Use the "cookies" link in the website footer to accept, reject, or change persistent analytics and marketing. Rejecting or withdrawing consent removes their first-party cookies and browser-storage identifiers where technically possible. Basic website measurement remains enabled.
Firezone also treats a supported Global Privacy Control (GPC) browser signal as an opt-out of marketing-related sharing. Other "Do Not Track" signals do not have a common legal or technical standard, so we do not respond to them.
5. How Long We Keep Information
We keep personal information only as long as needed for the purposes in this policy. Retention depends on the type of record, whether an account or business relationship remains active, security needs, and legal requirements.
In general:
- account, configuration, and service records are kept while the account is active and for a limited period afterward to close the account and meet legal or security obligations;
- billing and transaction records are kept as required by tax, accounting, and financial laws;
- support, sales, and security records are kept while reasonably useful to serve the customer, prevent abuse, or resolve a dispute; and
- optional website identifiers remain until they expire, you withdraw consent, or you clear browser storage.
When we no longer need personal information, we delete or de-identify it. Information in backups is isolated from ordinary use and removed through the normal backup-rotation process. We may keep a limited record of a deletion or opt-out request to prove compliance and prevent unwanted contact.
6. International Data Transfers
Firezone is based in the United States, and our vendors and infrastructure operate in the United States and other countries. This means personal information may be processed outside the country where you live.
Where required, we use recognized safeguards for international transfers, such as approved contractual clauses and transfer addenda. You may contact privacy@firezone.dev to ask about the safeguard that applies to your information.
7. Security
We use reasonable technical and organizational measures designed to protect personal information. These include encryption in transit, access controls, monitoring, and security review. See our security documentation and vulnerability disclosure policy.
No system is completely secure. You are responsible for protecting your credentials and devices and for promptly reporting suspected unauthorized access.
8. Your Privacy Rights and Choices
Depending on where you live, you may have the right to:
- know whether we process your personal information and access it;
- receive a portable copy of information you provided;
- correct inaccurate information;
- delete information, subject to legal exceptions;
- restrict or object to processing;
- withdraw consent;
- opt out of a sale, targeted advertising, or certain profiling;
- appeal our decision about a request; and
- receive equal service and pricing when you exercise a privacy right.
You may also unsubscribe using the link in a marketing email. We may still send necessary account, security, billing, and support messages.
Email requests to privacy@firezone.dev. You may use an authorized agent where the law allows. We may ask for information reasonably needed to verify your identity or the agent's authority. We use verification information only to process the request.
We respond within the period required by applicable law. If we deny a request, we will explain why and, where required, how to appeal. You may also complain to your local data protection or privacy regulator.
Additional information for US residents
In the previous 12 months, we collected the following categories described by California law:
| Statutory category | Examples Firezone collects | Disclosed for a business purpose |
|---|---|---|
| Identifiers | Name, email, IP address, account and device identifiers | Yes |
| Customer-record information | Name, business contact and billing details | Yes |
| Commercial information | Plan, invoices, and transaction history | Yes |
| Internet or network activity | Website, application, sign-in, API, and audit activity | Yes |
| Approximate geolocation | Country or region derived from IP address | Yes |
| Professional information | Employer, organization, and job title | Yes |
| Sensitive personal information | Account authentication and session data used to provide and secure access | Yes |
We disclose these categories to the service providers and other recipients described in Section 3. If marketing cookies are enabled, we may share identifiers and Internet activity for cross-context behavioral advertising as described above. We do not use sensitive personal information to infer characteristics about you.
California residents may also ask once per calendar year whether we disclosed personal information to third parties for their direct-marketing purposes under California's "Shine the Light" law. Firezone does not make such disclosures.
9. Children
The Services are for people age 18 and older. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@firezone.dev, and we will take appropriate steps to delete it.
10. Changes and Contact
We may update this policy as our Services or legal obligations change. We will update the "Last updated" date and provide additional notice when a material change requires it.
Questions, complaints, and privacy requests may be sent to:
Firezone, Inc.
Attn: Privacy
2261 Market Street, Suite 4574
San Francisco, CA 94114
United States
Phone: (+1) 313-355-2645
privacy@firezone.dev