Legal

Privacy Policy

Last Updated: June 15, 2025 ·  Effective Date: June 15, 2025

bottomlire ("we", "us", or "our") operates the bottomlire platform at bottomlire.com. This Privacy Policy explains what personal data we collect, why we collect it, and how you can exercise your rights. We are committed to transparency and lawful data handling.

1

Data We Collect

  • Account data: name, email address, company name, and billing information provided at registration.
  • Usage data: API key metadata, audit logs, feature interactions, and session telemetry collected automatically.
  • Technical data: IP addresses, browser type, device identifiers, and referral URLs.
2

How We Use Your Data

  • To provide, maintain, and improve the bottomlire platform and its security auditing features.
  • To process payments, send transactional emails, and respond to support requests.
  • To detect fraud, enforce our Terms of Service, and comply with legal obligations.
3

Cookies & Tracking

  • We use strictly necessary cookies for authentication and session management.
  • Analytics cookies (e.g., via PostHog) help us understand feature usage — these can be disabled in your account settings.
  • We do not use advertising or cross-site tracking cookies.
4

Third-Party Sharing

  • We share data only with trusted sub-processors (e.g., Stripe for payments, AWS for infrastructure) under data processing agreements.
  • We never sell, rent, or trade your personal data to third parties for marketing purposes.
  • We may disclose data if required by law, court order, or to protect rights and safety.
5

Your Rights (GDPR & CCPA)

  • GDPR (EEA/UK residents): You have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing.
  • CCPA (California residents): You have the right to know, delete, and opt out of the sale of personal information (we do not sell data).
  • To exercise any right, email [email protected]. We will respond within 30 days.
6

Data Retention

  • We retain account data for the duration of your subscription plus 90 days after closure.
  • Audit logs are retained for up to 12 months by default; enterprise plans may configure custom retention periods.
  • Anonymized, aggregated analytics data may be retained indefinitely.
7

Security

  • All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • We conduct regular penetration testing and third-party security audits.
  • Despite these measures, no transmission over the internet is 100{20160502c07174839a5b17a84cff805c1e68f69f7d3dbe57159271d5cb837e34} secure; use our platform responsibly.
8

Children's Privacy

  • bottomlire is intended for business use by individuals aged 18 and over.
  • We do not knowingly collect personal data from children under 13. If we become aware of such collection, we will delete it promptly.
9

Changes to This Policy

  • We may update this Privacy Policy periodically; the "Last Updated" date at the top will reflect changes.
  • Material changes will be communicated via email or an in-app notice at least 14 days before taking effect.
  • Continued use of bottomlire after changes constitutes acceptance of the revised policy.
10

Contact Us

  • Data Controller: bottomlire Ltd., 22 Finsbury Square, London, EC2A 1DX, United Kingdom.
  • Privacy inquiries: [email protected]
  • For urgent data breach notifications, contact [email protected].

If you have questions about this Privacy Policy or how bottomlire handles your data, please email us at [email protected]. We take every inquiry seriously and respond within 30 calendar days.

bottomlire

Your API Keys, Audited.
Your Bottom Line, Protected.

Enterprise-grade API key auditing and lifecycle management for security-first teams.

© 2026 bottomlire Inc.

[email protected]+1 (415) 800-2290340 Pine St, Suite 800, San Francisco, CA 94104
SOC 2 Type IIISO 27001GDPR CompliantCCPA Ready