Firezone logo light

Privacy Policy

Last updated

This Privacy Policy explains how Firezone, Inc. ("Firezone," "we," "us," or "our") handles personal information when you use:

  • the Firezone service, admin portal, APIs, and client applications;
  • firezone.dev and other sites that link to this policy; or
  • our sales, support, marketing, and event channels.

We collect only the personal information reasonably needed to provide, secure, support, and improve Firezone, meet our legal obligations, and run our business. We do not sell personal information.

If you do not agree with this policy, do not use the Services. If you already have an account, you may stop using the Services and ask us to close it. This does not limit any privacy rights you have under applicable law.

Key Points

  • We cannot see the contents of your network traffic. Traffic through Firezone is end-to-end encrypted. In limited cases, encrypted traffic may pass through Firezone relays, but Firezone cannot decrypt it.
  • We collect data needed to operate the service. This includes account and contact details, service configuration, authentication and security data, billing records, support communications, and technical logs.
  • Basic website measurement is enabled without cookies. Persistent analytics and marketing technology remain off until you choose them using the "cookies" link in the footer.
  • We do not sell personal information. Optional advertising technology may be considered "sharing" under some US state privacy laws. You can opt out at any time.
  • You can ask to access, correct, export, or delete your information. Email privacy@firezone.dev.

1. Personal Information We Collect

What we collect depends on how you use Firezone.

CategoryExamplesWhy we need itRetention criteria
Account and contact dataName, work email, job title, organization, account ID, and account roleTo create and manage accounts, authenticate users, and communicate with youWhile the account or business relationship is active, plus a limited closure period
Service configurationUsers, groups, identity-provider details, Resources, Sites, Policies, Gateway and Client identifiers, and other settings chosen by account administratorsTo configure, secure, and provide the serviceWhile the account is active, then according to account-deletion and backup schedules
Service activity and security dataSign-in events, IP address, approximate location derived from IP address, device and browser details, session and API activity, audit logs, and fraud or abuse signalsTo operate the service, apply access policies, troubleshoot, and protect accountsFor the service-log period provided by the plan, then as needed for security or legal claims
Support and sales dataMessages, form submissions, meeting details, support tickets, and related contact historyTo answer questions, provide support, and manage our relationship with youWhile useful to serve the customer, honor choices, or resolve a dispute
Billing dataBilling contact, business address, plan, invoices, payment status, and transaction historyTo bill for paid plans and keep financial recordsFor the period required by tax, accounting, and financial laws
Website and app diagnosticsPages and features used, referring page, browser and operating system, performance data, crash reports, and similar technical eventsTo maintain reliability, understand usage, and improve FirezoneUntil the identifier expires or is withdrawn, or while needed for reliability and security

Stripe processes full payment-card or bank details for us. Firezone receives only the billing details and payment status needed to manage your subscription; we do not store full card numbers or security codes.

We do not ask you to provide health, biometric, government-identification, or other special-category information. Authentication and session information may be treated as sensitive under some laws; we use it only to provide and secure the Services. Please do not put sensitive personal information in free-text fields unless we specifically request it.

Where the information comes from

We receive personal information:

  • from you, when you create an account, configure the Services, complete a form, pay for a plan, or contact us;
  • from your organization, including its administrators, identity provider, or enabled integrations; and
  • automatically, from the Services, applications, devices, browsers, and cookies or similar technology.

When a customer controls the data

An organization that provides Firezone to its workforce usually decides which end-user data is submitted to the service and how it is used. For that data, the organization is the controller or business and Firezone acts as its processor or service provider. The organization's privacy notice and its agreement with Firezone govern that processing. Direct questions about organization-controlled data to that organization first.

Firezone is the controller or business for data we use for our own purposes, such as account administration, billing, website operations, security, and sales.

2. How and Why We Use Personal Information

We use personal information to:

  • provide, configure, authenticate, and administer the Services;
  • apply access controls and keep the Services, users, and networks secure;
  • process payments and manage subscriptions;
  • provide support and send important service messages;
  • monitor reliability, fix problems, and improve features;
  • understand website use and measure marketing, when you have allowed the relevant optional technology;
  • comply with law, respond to lawful requests, and establish or defend legal claims; and
  • complete a financing, merger, acquisition, reorganization, or sale of all or part of our business.

We do not use personal information to make decisions that have legal or similarly significant effects on you without human involvement.

Where a law requires a legal basis, we rely on:

  • Contract: processing needed to provide the Services or take steps you request before entering a contract.
  • Legitimate interests: securing, supporting, and improving Firezone, performing limited website audience measurement, communicating with business contacts, and running our business, where those interests are not overridden by your rights.
  • Consent: persistent analytics, advertising, or other processing for which we ask permission. You may withdraw consent at any time.
  • Legal obligation: tax, accounting, regulatory, law-enforcement, and other legal requirements.
  • Vital interests: protecting a person's life or physical safety in an emergency.

Withdrawing consent does not affect processing that already occurred or processing based on another lawful ground.

3. When We Disclose Personal Information

We disclose only what is reasonably necessary to:

  • Vendors and subprocessors: cloud hosting, payments, customer relationship management, support, analytics, email, security, and error monitoring. They may process data only under contracts and instructions appropriate to their role. See our current subprocessor list.
  • Your organization and its administrators: account, user, device, activity, and audit information needed to administer its Firezone account.
  • Integrations you choose: data needed to connect an identity provider, log sink, or other service that an account administrator enables.
  • Authorities and other parties for legal or safety reasons: when we reasonably believe disclosure is required by law or necessary to protect rights, safety, and the Services.
  • A business successor: in connection with a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality protections.

We may use aggregated or de-identified information that cannot reasonably be linked to a person. We do not try to re-identify it.

We do not sell personal information

Firezone does not exchange personal information for money and has not done so in the previous 12 months.

Some US state laws define "sharing" separately from a sale. If you allow marketing cookies, Google Ads may receive online identifiers and website activity to measure ads across different services. That activity may be considered sharing for cross-context behavioral advertising. We do not share personal information for this purpose unless you opt in, and you may opt out through the cookie settings or a supported Global Privacy Control signal.

4. Cookies and Similar Technology

We use limited cookieless analytics for basic website measurement. If you allow persistent analytics, PostHog uses local storage to recognize the same browser across visits. Marketing technology does not load until you allow it. A necessary cookie remembers your choices.

Cookie or storage keyProviderCategoryPurposeTypical duration
firezone_cookie_consentFirezoneNecessaryRemembers your privacy choices180 days
ph_firezone_analytics and related browser storagePostHogAnalyticsMeasures website usage and conversions across visitsUntil consent is withdrawn or browser storage is cleared
gcl and related cookiesGoogle AdsMarketingAttributes ad clicks and measures campaignsUp to 90 days
hubspotutk, __hstc, __hssc, __hssrc, and related storageHubSpotMarketingAssociates permitted website activity and form submissions with contacts and measures interactionsFrom the browser session up to six months

Use the "cookies" link in the website footer to accept, reject, or change persistent analytics and marketing. Rejecting or withdrawing consent removes their first-party cookies and browser-storage identifiers where technically possible. Basic website measurement remains enabled.

Firezone also treats a supported Global Privacy Control (GPC) browser signal as an opt-out of marketing-related sharing. Other "Do Not Track" signals do not have a common legal or technical standard, so we do not respond to them.

5. How Long We Keep Information

We keep personal information only as long as needed for the purposes in this policy. Retention depends on the type of record, whether an account or business relationship remains active, security needs, and legal requirements.

In general:

  • account, configuration, and service records are kept while the account is active and for a limited period afterward to close the account and meet legal or security obligations;
  • billing and transaction records are kept as required by tax, accounting, and financial laws;
  • support, sales, and security records are kept while reasonably useful to serve the customer, prevent abuse, or resolve a dispute; and
  • optional website identifiers remain until they expire, you withdraw consent, or you clear browser storage.

When we no longer need personal information, we delete or de-identify it. Information in backups is isolated from ordinary use and removed through the normal backup-rotation process. We may keep a limited record of a deletion or opt-out request to prove compliance and prevent unwanted contact.

6. International Data Transfers

Firezone is based in the United States, and our vendors and infrastructure operate in the United States and other countries. This means personal information may be processed outside the country where you live.

Where required, we use recognized safeguards for international transfers, such as approved contractual clauses and transfer addenda. You may contact privacy@firezone.dev to ask about the safeguard that applies to your information.

7. Security

We use reasonable technical and organizational measures designed to protect personal information. These include encryption in transit, access controls, monitoring, and security review. See our security documentation and vulnerability disclosure policy.

No system is completely secure. You are responsible for protecting your credentials and devices and for promptly reporting suspected unauthorized access.

8. Your Privacy Rights and Choices

Depending on where you live, you may have the right to:

  • know whether we process your personal information and access it;
  • receive a portable copy of information you provided;
  • correct inaccurate information;
  • delete information, subject to legal exceptions;
  • restrict or object to processing;
  • withdraw consent;
  • opt out of a sale, targeted advertising, or certain profiling;
  • appeal our decision about a request; and
  • receive equal service and pricing when you exercise a privacy right.

You may also unsubscribe using the link in a marketing email. We may still send necessary account, security, billing, and support messages.

Email requests to privacy@firezone.dev. You may use an authorized agent where the law allows. We may ask for information reasonably needed to verify your identity or the agent's authority. We use verification information only to process the request.

We respond within the period required by applicable law. If we deny a request, we will explain why and, where required, how to appeal. You may also complain to your local data protection or privacy regulator.

Additional information for US residents

In the previous 12 months, we collected the following categories described by California law:

Statutory categoryExamples Firezone collectsDisclosed for a business purpose
IdentifiersName, email, IP address, account and device identifiersYes
Customer-record informationName, business contact and billing detailsYes
Commercial informationPlan, invoices, and transaction historyYes
Internet or network activityWebsite, application, sign-in, API, and audit activityYes
Approximate geolocationCountry or region derived from IP addressYes
Professional informationEmployer, organization, and job titleYes
Sensitive personal informationAccount authentication and session data used to provide and secure accessYes

We disclose these categories to the service providers and other recipients described in Section 3. If marketing cookies are enabled, we may share identifiers and Internet activity for cross-context behavioral advertising as described above. We do not use sensitive personal information to infer characteristics about you.

California residents may also ask once per calendar year whether we disclosed personal information to third parties for their direct-marketing purposes under California's "Shine the Light" law. Firezone does not make such disclosures.

9. Children

The Services are for people age 18 and older. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@firezone.dev, and we will take appropriate steps to delete it.

10. Changes and Contact

We may update this policy as our Services or legal obligations change. We will update the "Last updated" date and provide additional notice when a material change requires it.

Questions, complaints, and privacy requests may be sent to:

Firezone, Inc.
Attn: Privacy
2261 Market Street, Suite 4574
San Francisco, CA 94114
United States
Phone: (+1) 313-355-2645
privacy@firezone.dev