Privacy Policy
Effective date: August 10, 2026
This Privacy Policy explains how Magebean ("Magebean," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit magebean.com, use the Magebean Security Dashboard, contact us, or otherwise interact with our services. It also explains the choices and rights available to you.
1. Scope
This policy applies to the Magebean website, hosted dashboard, account services, support channels, and hosted APIs. The Magebean CLI is open-source software that can run locally. Local CLI activity is not sent to Magebean unless you configure a network-backed feature, call a Magebean API, or submit CLI results to the Magebean Security Dashboard.
This policy does not govern third-party websites, Magento extensions, hosting providers, payment services, or other products that you connect to or access from Magebean.
2. Information we collect
Information you provide
We may collect:
- Account information, such as your name, email address, password credentials in hashed form, organization, role, and workspace membership.
- Workspace and service data, such as Magento instance names, environment labels, security baselines, assessments, findings, remediation tickets, evidence, review decisions, reports, and CLI results you choose to submit.
- Billing information, such as plan, billing status, transaction identifiers, and limited billing contact details. Full payment-card details are handled by our payment provider and are not intended to be stored by Magebean.
- Communications, including support requests, feedback, survey responses, and other messages you send to us.
- Subscription information, such as an email address submitted for product or security updates.
Information collected automatically
When you use our website or hosted services, we may collect:
- IP address, browser type, device and operating-system information;
- pages viewed, referring pages, timestamps, and basic interaction data;
- authentication, session, audit, and security logs; and
- cookie or similar technology identifiers required to operate sessions, remember preferences, prevent abuse, and understand service performance.
Information from integrations
If you connect Magebean to a third-party service, we receive the information necessary to provide that integration according to the permissions you grant. You are responsible for ensuring that you have authority to connect the service and provide the associated data.
3. How we use information
We use information to:
- provide, secure, operate, and maintain the website and Magebean Security Dashboard;
- create and administer accounts, workspaces, subscriptions, and plans;
- process CLI results and display assessments, findings, evidence, remediation status, reports, and baseline drift;
- authenticate users, enforce permissions, maintain audit records, and investigate abuse or security incidents;
- provide support and communicate about service, security, billing, and policy updates;
- improve product reliability, usability, documentation, and security controls;
- comply with legal obligations and enforce our agreements; and
- send product communications where permitted, with an option to unsubscribe from non-essential messages.
Where applicable law requires a legal basis, we process information to perform our contract with you, pursue legitimate interests such as securing and improving the service, comply with law, or act with your consent.
4. Cookies and similar technologies
We use essential cookies and similar technologies for authentication, session continuity, preferences, fraud prevention, and security. We may also use limited analytics to understand aggregate website and product usage. Where required by law, we will request consent before using non-essential cookies. You can control cookies through your browser, although blocking essential cookies may prevent account or dashboard features from working.
5. How we disclose information
We may disclose information:
- to infrastructure, hosting, email, customer-support, analytics, security, and payment providers that process information for us under appropriate obligations;
- to members of your Magebean workspace according to their assigned roles and permissions;
- when you direct us to disclose it through an integration or export;
- to comply with law, legal process, or a valid government request;
- to protect the rights, safety, and security of Magebean, our users, or the public; or
- in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
Magebean does not sell personal information or use it for third-party targeted advertising.
6. Security data and sensitive information
Magebean is designed to manage security posture information, but you should not submit secrets, private keys, passwords, payment-card data, health information, government identifiers, or unrelated personal data. Configure evidence and CLI submissions to exclude credentials and sensitive customer information.
Security findings may reveal details about your systems. Limit workspace access, use appropriate roles, and review evidence before uploading it.
7. Retention
We retain personal information and service data for as long as needed to provide the service, maintain security and audit records, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods depend on the type of data, account status, workspace settings, contractual requirements, and applicable law.
When an account or workspace is deleted, we take reasonable steps to delete or de-identify associated information, subject to backups, security records, legal holds, and information we must retain. Backup copies may remain for a limited period before being overwritten.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, alteration, and disclosure. No system is completely secure, and we cannot guarantee absolute security. If you believe your account or data may be at risk, contact us promptly at support@magebean.com.
9. International processing
Magebean and its service providers may process information in countries other than your own. Those countries may have different privacy laws. Where required, we use contractual and other safeguards intended to protect information transferred across borders.
10. Your choices and rights
Depending on where you live, you may have the right to:
- access or obtain a copy of personal information;
- correct inaccurate information;
- request deletion or restriction of processing;
- object to certain processing;
- withdraw consent where processing relies on consent;
- request data portability; and
- complain to an applicable privacy regulator.
You may update certain account information within the service and unsubscribe from non-essential email using the link in the message. To exercise another privacy right, email support@magebean.com. We may need to verify your identity and authority before completing a request.
If you use Magebean through an organization, that organization may control your workspace data. We may direct requests concerning organization-controlled data to the relevant workspace owner.
11. Children's privacy
Magebean is intended for business and professional use and is not directed to children under 16. We do not knowingly collect personal information from children under 16. Contact us if you believe a child has provided personal information to Magebean.
12. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, practices, or legal obligations. We will post the revised policy here and update the effective date. If a change materially affects how we use personal information, we will provide additional notice where required.
13. Contact us
For privacy questions or requests, contact:
Magebean Privacy