Privacy Policy
Last updated: September 5, 2026
1. Who we are
Upgrade Drupal (upgradedrupal.com) is a service that automates Drupal codebase upgrades by connecting to your Git repository, applying dependency and code changes, and opening a Pull Request on your behalf. The service is operated by Vitars S.R.L.
For the purposes of the EU General Data Protection Regulation (GDPR), Vitars S.R.L. is the data controller for personal data processed through this service.
2. Information we collect
- GitHub account information — your GitHub username, email address, and avatar, obtained via OAuth when you sign in.
- OAuth access token — a temporary GitHub OAuth token used to clone your repository and open Pull Requests. This token is stored server-side for the duration of your session and deleted when you sign out.
- Repository URL — the Git repository URL you submit for upgrade.
- Job logs — output produced by the upgrade process (git operations, file changes, Rector output) stored in our database so you can review them.
- Payment information — billing is handled entirely by Stripe. We never see or store your card number, CVV, or full billing details. We receive a Stripe session ID and payment confirmation status.
- Session cookie — a
session_idcookie stored in your browser to keep you signed in for up to 7 days. - Analytics data (with your consent) — if you accept analytics via our cookie banner, Google Analytics 4 collects your IP address (truncated by Google before storage), device and browser information, referring URL, pages viewed, and session duration. This data is used in aggregate to understand how visitors use the site.
3. How we use your information
- To authenticate you and associate upgrade jobs with your account.
- To clone your repository, apply automated changes, push the upgrade branch, and open a Pull Request — all using your OAuth token on your behalf.
- To display your job history and logs on your dashboard.
- To process payments via Stripe and fulfill your upgrade order.
- To send optional follow-up emails about your upgrade (you may opt out at any time).
We do not use your data for advertising, profiling, or sell it to third parties.
3a. Legal basis for processing (GDPR)
Where the GDPR applies, we process your personal data on the following legal bases:
- Performance of a contract — processing your account information, OAuth token, and repository URL is necessary to deliver the upgrade service you have requested.
- Legal obligation — retaining payment records for accounting and tax compliance.
- Legitimate interests — retaining job logs to allow you to review upgrade history and to operate the service securely.
- Consent — sending optional follow-up emails about your upgrade, and loading Google Analytics, where you have opted in.
4. Information disclosure
We disclose your information only to the following parties:
- GitHub — we interact with the GitHub API on your behalf using your OAuth token to perform git operations and create Pull Requests.
- Stripe — your email address and payment amount are passed to Stripe to process payments. Stripe's privacy policy applies to data they collect: stripe.com/privacy.
- Cloudflare — our infrastructure runs on Cloudflare Pages, Workers, Containers, and D1 (database). Data is stored and processed within Cloudflare's network.
- Google (Google Analytics) — if you consent to analytics cookies, Google Ireland Limited (for EEA/UK visitors) or Google LLC (for other regions) processes analytics data on our behalf as a data processor. Google's privacy policy: policies.google.com/privacy.
We do not disclose your data to any other third parties without your explicit consent, except when required by law.
5. Data retention
- Session data (including your OAuth token) is stored for up to 7 days and deleted on sign-out.
- Job records and logs are retained for 90 days, then automatically deleted.
- Payment records (Stripe session IDs and amounts) may be retained for up to 7 years for accounting and compliance purposes.
- Google Analytics data is retained by Google for 14 months, after which it is automatically deleted.
6. Security
We take the following measures to protect your information:
- All data in transit is encrypted using TLS (HTTPS).
- OAuth tokens are stored in a server-side database (Cloudflare D1) and never exposed to the browser after the initial OAuth callback.
- Session cookies are set as
HttpOnly,Secure, andSameSite=Laxto prevent client-side access and CSRF attacks. - Stripe webhook signatures are verified on every incoming request.
- We do not store your repository source code — only the job logs produced during the upgrade run.
7. Your rights (GDPR)
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data. Signing out deletes your session and OAuth token immediately. For full account deletion including job history, contact us.
- Right to restriction — request that we restrict processing of your data in certain circumstances.
- Right to data portability — request your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent (e.g. follow-up emails), you may withdraw at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at info[at]upgradedrupal.com. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection supervisory authority. In Romania, this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) at dataprotection.ro.
8. International data transfers
Our infrastructure runs on Cloudflare's global network. Data may be processed in data centres outside the European Economic Area. Cloudflare relies on Standard Contractual Clauses and other approved transfer mechanisms to ensure an adequate level of protection. See Cloudflare's Privacy Policy for details.
If you consent to analytics, Google Analytics data may be transferred to and processed by Google in the United States. Google relies on Standard Contractual Clauses and the EU-US Data Privacy Framework as approved transfer mechanisms.
9. Cookies
We use two categories of cookies:
- Strictly necessary — a single first-party
session_idcookie required for authentication. This cookie is always set when you sign in and does not require your consent. - Analytics (optional, consent required) — if you accept via our cookie banner, Google Analytics 4 sets first-party cookies (
_ga,_ga_V44CW9M8H9) to distinguish visitors and measure site usage. These cookies expire after 2 years. We do not load Google Analytics or set these cookies unless you have given consent.
We keep additional anonymous, aggregate counters for a small number of product events (for example, how many times the free Scanner or D7 Migration page is used). These counters store only an event name, an optional coarse category, and a timestamp — never a cookie, IP address, session identifier, or anything else that could be tied back to you or your visit.
You can withdraw your analytics consent at any time by clearing your browser's localStorage for this site, which will cause the cookie banner to reappear on your next visit. We do not use advertising cookies or third-party tracking cookies of any kind.
10. Contact
For any privacy-related questions or data deletion requests, contact us at: info[at]upgradedrupal.com