Privacy Policy

Last updated: July 17, 2026

1. Who we are

Upgrade Drupal (upgradedrupal.com) is a service that automates Drupal codebase upgrades by connecting to your Git repository, applying dependency and code changes, and opening a Pull Request on your behalf. The service is operated by Vitars S.R.L.

For the purposes of the EU General Data Protection Regulation (GDPR), Vitars S.R.L. is the data controller for personal data processed through this service.

2. Information we collect

  • GitHub account information — your GitHub username, email address, and avatar, obtained via OAuth when you sign in.
  • OAuth access token — a temporary GitHub OAuth token used to clone your repository and open Pull Requests. This token is stored server-side for the duration of your session and deleted when you sign out.
  • Repository URL — the Git repository URL you submit for upgrade.
  • Job logs — output produced by the upgrade process (git operations, file changes, Rector output) stored in our database so you can review them.
  • Payment information — billing is handled entirely by Stripe. We never see or store your card number, CVV, or full billing details. We receive a Stripe session ID and payment confirmation status.
  • Session cookie — a session_id cookie stored in your browser to keep you signed in for up to 7 days.

3. How we use your information

  • To authenticate you and associate upgrade jobs with your account.
  • To clone your repository, apply automated changes, push the upgrade branch, and open a Pull Request — all using your OAuth token on your behalf.
  • To display your job history and logs on your dashboard.
  • To process payments via Stripe and fulfill your upgrade order.
  • To send optional follow-up emails about your upgrade (you may opt out at any time).

We do not use your data for advertising, profiling, or sell it to third parties.

3a. Legal basis for processing (GDPR)

Where the GDPR applies, we process your personal data on the following legal bases:

  • Performance of a contract — processing your account information, OAuth token, and repository URL is necessary to deliver the upgrade service you have requested.
  • Legal obligation — retaining payment records for accounting and tax compliance.
  • Legitimate interests — retaining job logs to allow you to review upgrade history and to operate the service securely.
  • Consent — sending optional follow-up emails about your upgrade, where you have opted in.

4. Information disclosure

We disclose your information only to the following parties:

  • GitHub — we interact with the GitHub API on your behalf using your OAuth token to perform git operations and create Pull Requests.
  • Stripe — your email address and payment amount are passed to Stripe to process payments. Stripe's privacy policy applies to data they collect: stripe.com/privacy.
  • Cloudflare — our infrastructure runs on Cloudflare Pages, Workers, Containers, and D1 (database). Data is stored and processed within Cloudflare's network.

We do not disclose your data to any other third parties without your explicit consent, except when required by law.

5. Data retention

  • Session data (including your OAuth token) is stored for up to 7 days and deleted on sign-out.
  • Job records and logs are retained for 90 days, then automatically deleted.
  • Payment records (Stripe session IDs and amounts) may be retained for up to 7 years for accounting and compliance purposes.

6. Security

We take the following measures to protect your information:

  • All data in transit is encrypted using TLS (HTTPS).
  • OAuth tokens are stored in a server-side database (Cloudflare D1) and never exposed to the browser after the initial OAuth callback.
  • Session cookies are set as HttpOnly, Secure, and SameSite=Lax to prevent client-side access and CSRF attacks.
  • Stripe webhook signatures are verified on every incoming request.
  • We do not store your repository source code — only the job logs produced during the upgrade run.

7. Your rights (GDPR)

If you are located in the European Economic Area, you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of your personal data. Signing out deletes your session and OAuth token immediately. For full account deletion including job history, contact us.
  • Right to restriction — request that we restrict processing of your data in certain circumstances.
  • Right to data portability — request your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent (e.g. follow-up emails), you may withdraw at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with your national data protection supervisory authority. In Romania, this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) at dataprotection.ro.

8. International data transfers

Our infrastructure runs on Cloudflare's global network. Data may be processed in data centres outside the European Economic Area. Cloudflare relies on Standard Contractual Clauses and other approved transfer mechanisms to ensure an adequate level of protection. See Cloudflare's Privacy Policy for details.

9. Cookies

We use a single first-party cookie (session_id) strictly necessary for authentication. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

10. Contact

For any privacy-related questions or data deletion requests, contact us at: [email protected]