Privacy Policy
Cybersecurity Incident Disclosure Policy

Privacy Policy

At Netmaker, accessible from www.netmaker.io, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by Netmaker and how we use it.

If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in Netmaker.

This policy is not applicable to any information collected offline or via channels other than this website.

Consent

By using our website, you hereby consent to our Privacy Policy and agree to its terms.

Information we collect

The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.

If you contact us directly, we may receive additional information about you such as your name, email address, phone number, the contents of the message and/or attachments you may send us, and any other information you may choose to provide.

When you register for an Account, we may ask for your contact information, including items such as name, company name, email address and payment history through third party services such as Stripe.Payment history information is solely charge amount and date of purchase.

How we use your information

We use the information we collect in various ways, including to:

  • Provide, operate, and maintain our websiteImprove, personalize, and expand our website
  • Understand and analyze how you use our websiteDevelop new products, services, features, and functionality
  • Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the website, and for marketing and promotional purposes
  • Send you emails
  • Find and prevent fraud

Log Files

Netmaker follows a standard procedure of using log files. These files log visitors when they visit websites. All hosting companies do this and a part of hosting services' analytics.

The information collected by log files include internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks.

These are not linked to any information that is personally identifiable. The purpose of the information is for analyzing trends, administering the site, tracking users' movement on the website, and gathering demographic information.

Third Party Privacy Policies

Netmaker's Privacy Policy does not apply to other advertisers, websites or web services. Thus, we are advising you to consult the respective Privacy Policies of these third-party services for more detailed information.

It may include their practices and instructions about how to opt-out of certain options.

You can choose to disable cookies through your individual browser options. To know more detailed information about cookie management with specific web browsers, it can be found at the browsers' respective websites.

CCPA Privacy Rights (Do Not Sell My Personal Information)

Under the CCPA, among other rights, California consumers have the right to:

Request that a business that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about consumers.

Request that a business delete any personal data about the consumer that a business has collected.

Request that a business that sells a consumer's personal data, not sell the consumer's personal data.If you make a request, we have one month to respond to you.

If you would like to exercise any of these rights, please contact us.

GDPR Data Protection Rights

We would like to make sure you are fully aware of all of your data protection rights.

Every user is entitled to the following:

The right to access – You have the right to request copies of your personal data. We may charge you a small fee for this service.

The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.

The right to erasure – You have the right to request that we erase your personal data, under certain conditions.

The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.

The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.

The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.

Children's Information

Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.

Netmaker does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.

Cybersecurity Incident Disclosure Policy

Purpose

At Netmaker, we prioritise the security of our systems and users. This policy outlines our approach to handling cybersecurity incidents that may affect the availability, integrity, or confidentiality of our infrastructure, services, or customer data.

Reporting a Security Incident or Vulnerability

We encourage responsible disclosure of security vulnerabilities or incidents that may affect Netmaker software or services. If you discover a security issue, please report it directly to the email : security@netmaker.io

Please include:

  • A detailed description of the issue
  • Steps to reproduce (if applicable)
  • Any supporting screenshots or logs
  • Your contact information for follow-up

Please avoid public disclosure until we've had a reasonable opportunity to address the issue.

Scope

This policy applies to:

  • ✅ All Netmaker employees, contractors, and vendors.
  • ✅ All production and customer-facing systems.
  • ✅ Any incident that impacts the confidentiality, integrity, or availability of Netmaker systems or customer data.

When We Disclose Incidents

Netmaker is committed to transparent, timely, and responsible disclosure of significant security incidents. We will notify affected customers and stakeholders when:

  • There is unauthorised access to customer data.
  • A serious vulnerability has been exploited.
  • Service availability or integrity is significantly impacted.
  • Disclosure is legally or contractually required.

Roles & Responsibilities

Role Responsibility
CTO / Security Lead Leads incident investigation, confirms need for disclosure
Incident Response Team Coordinates technical response and documents findings
Legal (if applicable) Advises on regulatory or contractual implications
CEO / Founders Approves any public or customer-facing disclosures
Marketing / Comms Drafts clear communications and handles external messaging

How We Communicate

Based on the incident's nature and severity, we notify users through:

  • Direct email to affected customers
  • Postmortems or announcements via our website or documentation
  • Security advisories for open source users (e.g., GitHub Security Advisories)

Timeline for Disclosure

We aim to:

  • Acknowledge valid reports within 48 hours
  • Provide regular updates on impact assessment and mitigation steps
  • Disclose confirmed customer-impacting incidents within 72 hours, when feasible
  • Publish public postmortems (if applicable) within 5–10 business days.

Recordkeeping

All reported incidents are documented internally and retained for a minimum of 2 years, including investigation notes, communications, and resolution history.

Our Commitment

We believe in building trust through proactive and transparent communication. We value the dedication of security researchers and partners who help maintain the security of our ecosystem.

Star us on GitHub
Can we use Cookies?  (see  Privacy Policy).