Codecov Privacy Policy
Last Updated: November 12, 2019
Protection SOC 2
Codecov is SOC 2 Type II certified, which means a third-party audits and attests to our practices to secure our systems and your data.
Who We Are:
Codecov LLC is a leading, dedicated code coverage solution that helps developers test, strengthen, and improve their software code. We are headquartered in San Francisco, California, and serve customers around the world. When we use the terms “Codecov”, “we”, “us” or “our” in this Privacy Notice, we are referring to Codecov LLC.
Our Services:
When we use the term “services,” we are referring to:
- The highly integrated tools we provide to code developers to help them group, merge, archive, and compare code coverage reports; and
- The website, Codecov.io.
Region-Specific Disclosures
We may choose or be required by law to provide different or additional disclosures relating to the processing of personal information about residents of certain countries, regions or states. Please refer below for disclosures that may be applicable to you:
Europe.
- If you are based in the European Economic Area (“EEA”), Switzerland or the United Kingdom (“UK”), please click here for additional European-specific privacy disclosures.
What is Personal Information?
When we use the term “personal information” in this Privacy Notice, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you. It does not include aggregated or anonymized information that is maintained in a form that is not reasonably capable of being associated with or linked to you.
Our Collection of Personal Information
From the first moment you interact with us, we are collecting personal information about you. Sometimes we collect personal information automatically when you interact with our services and sometimes we collect the personal information directly from you. At times, we may collect personal information about you from other sources and third parties, even before our first direct interaction.
Personal Information You Provide
We collect the following personal information you provide in connection with our services:
- Contact Information, including your name, email address, phone number, and address;
- Professional/Employment Information, including your employer and team affiliation, and company connections;
- Account Information, including your username, password, other log-in credentials, repository access permissions, coverage reports and Oauth tokens;
- Payment Information, including your credit card information;
- Inquiry Information, including your comments, questions, and opinions about our services; and
- Job Applicant Information, including your resume, and any other information you choose to provide as part of your job application.
Personal Information Automatically Collected
As is true of most digital platforms, we collect certain personal information automatically when you visit our online services, including:
- Log File Data, including your internet protocol (IP) address, operating system, domain, browser type, browser id, date/time of visit, and pages visited.
- Analytics Data, including the electronic path you take to our services, through our services and when exiting our services, as well as your usage and activity on our services, such as the links and object you view, click or otherwise interact with (also known as “Clickstream Data”), and your impact on the repositories.
- Location Data, including your general geographic location based on your IP address.
For information about our and our third-party partners’ use of cookies and related technologies to collect information automatically, and any choices you may have in relation to its collection, please visit our Cookie Notice.
Personal Information from Other Sources and Third Parties We also obtain personal information from other sources, which we often combine with personal information we collect either automatically or directly from you.
We receive personal information from the following sources and third parties:
- Software Development Platforms: When you log in to our services through third party software development platforms, such as Github, you may allow us to have access to certain information in your profile, such as your name, email address, photo, location, username or ID, and password. In addition, when you sign up for Codecov you permit Codecov access to your archives on such third-party platforms. Codecov does not make any adjustments to repository source code.
- Social Media Platforms: When you choose to interact with us on social media, we may collect personal information from the account you make public or share with us, such as your photos, videos, list of friends or connections, followers or people you follow, posts, or “likes.”
Our Use of Personal Information
We use personal information we collect to:
- Provide you our services and fulfill your requests;
- Register and service your account with us;
- Communicate with you about our services, your account with us, or other products that we believe may be of interest to you;
- Respond to your inquiries about our services;
- Provide technical support for our services;
- Process your payments for access to our services;
- Evaluating your candidacy for employment;
- Perform analysis on how you use our services;
- Enhance our services, including to build new features;
- Enforce the legal terms that govern your use of our services, including but not limited to our policies and terms of service;
- Prevent, detect, or investigate fraud or potentially illegal activities, such as copyright infringement;
- Protect the safety of our users;
- Comply with legal obligations.
If you choose to contact us, we may need additional information to fulfill your request or respond to your inquiry. We may provide additional privacy disclosures where the scope of the inquiry and personal information we require fall outside the scope of this Privacy Notice. In that case, the additional privacy disclosures will govern how we may process the information you provide at that time.
Our Disclosure of Personal Information
We disclose personal information in the following ways:
- Within Codecov: We are able to offer you our services because of the hard work of our team members across Codecov. We disclose personal information across Codecov for purposes and uses that are consistent with this Privacy Notice. For example, we may disclose your contact information to process and fulfill your subscription order or to facilitate communication between you and a local Codecov representative.
- To Service Providers: We may disclose personal information to service providers who we have engaged to perform business-related functions on our behalf. These functions include: conducting research and analytics; providing customer, technical, or operational support; fulfilling orders and user requests; handling payments; hosting our services; maintaining our databases; and otherwise supporting our services.
- As Part of a Business Transaction or Reorganization: We may take part in or be involved with a corporate business transaction, such as a merger, acquisition, joint venture, or financing or sale of company assets. We may disclose personal information to a third party during negotiation of, in connection with or as an asset in such a corporate business transaction. Personal information may also be disclosed in the event of insolvency, bankruptcy, or receivership.
In Accordance with Our Legal Obligations and Rights: We may disclose personal information to third parties, such as legal advisors and law enforcement:- in connection with the establishment, exercise, or defense of legal claims;
- to comply with laws or to respond to lawful requests and legal process;
- to protect the rights and property of us, our agents, customers, and others, including to enforce our agreements, policies, and terms of use;
- to detect, suppress, or prevent fraud;
- to reduce credit risk and collect debts owed to us;
- to protect the health and safety of us, our customers, or any person; or
- as otherwise required by applicable law.
- Otherwise with Your Consent: We may disclose personal information about you to certain other third parties with your consent.
Access to Your Information
Access to certain personal information that is collected from our services and that we maintain may be available to you. For example, if you create a password-protected account within our services, you can access that account to review the information you provided. You may also send an email to the following e-mail address, support@codecov.io , to gain access to or to correct your personal information. Please include your registration information for the services such as first name, last name, and email address in the request. If for some reason you wish to remove a repository, you may do so. Please contact support at support@codecov.io to remove all reports and data collected on a repository. On the off chance you wish to terminate your account, please contact staff at support@codecov.io to erase your account data.
Children’s Personal Information
Our websites and online services are not directed to, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 13. If you are under the age of 13, please do not use our websites or online services or otherwise provide us with any personal information either directly or by other means. If a child under the age of 13 has provided personal information to us, we encourage the child’s parent or guardian to contact us to request that we remove the personal information from our systems. If we learn that any personal information we collect has been provided by a child under the age of 13, we will promptly delete that personal information.
Third-Party Websites
Our websites and online services may include links to third-party websites, plug-ins and applications. Except where we post, link to or expressly adopt or refer to this Privacy Notice, this Privacy Notice does not apply to, and we are not responsible for, any personal information practices of third-party websites and online services or the practices of other third parties. To learn about the personal information practices of third parties, please visit their respective privacy notices.
Updates to This Privacy Notice
We will update this Privacy Notice from time to time. When we make changes to this Privacy Notice, we will change the “Last Updated” date at the beginning of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify you by prominent posting a notice on this website. All changes shall be effective from the date of publication unless otherwise provided.
Contact Us
If you have any questions or requests in connection with this Privacy Notice or other privacy-related matters, please send an email to hello@codecov.io
Alternatively, inquiries may be addressed to:
Codecov LLC
9450 SW Gemini Drive #32076
Beaverton, OR 97008-7105 United States
European Privacy Disclosures
Last Updated: November 12, 2019
Unless otherwise expressly stated, capitalized terms in these Disclosures have the same meaning as defined in the Privacy Notice.
Scope of Disclosures
These Additional European Economic Area (“EEA”), Switzerland and United Kingdom (“UK”) Privacy Disclosures supplement the information contained in our Privacy Notice These Disclosures apply only to our processing of your personal data where you are based in Europe.
Codecov LLC is the data controller responsible for the collection and use of such personal data.
Personal Data Disclosures
When we use the term “personal data” in these Disclosures, we mean any information relating to an identified or identifiable natural person.
Legal Bases for Processing
We rely on the following legal grounds to process Personal Data about you, whether it is obtained from you or a third party:
- For the performance of a contract (Art. 6 para. 1 lit. b GDPR);
- For the purpose of legitimate interests (Art. 6 para. 1 lit. f GDPR), as described in more detail in the Our Collection of
- Personal Information section of the Privacy Notice;
- For compliance with legal obligations and legal claims (Art. 6 para. 1 lit. c GDPR); and
- Consent to the extent you have provided consent (Art. 6 para. 1 lit. a GDPR)
You are not required to provide personal data to us, but we do rely on your personal data to provide certain of our services and products. For example, we need your personal data to facilitate and deliver an order that you request. If you choose not to provide us with your personal data, we may not be able to provide you with a service or product you request.
Data Retention
We retain personal data about you for as long as is necessary for the purposes set out in these Disclosures, unless a longer period is required under applicable law or is needed to resolve disputes or protect our legal rights.
The criteria used to determine the period for which personal data about you will be retained varies depending on the legal basis under which we process the personal data:
Legitimate Interests | Where we are processing personal data based on our legitimate interests, we generally will retain such information for a reasonable period of time based on the particular interest, taking into account the fundamental interests and the rights and freedoms of data subjects |
---|---|
Consent | Where we are processing personal data based on your consent, we generally will retain the information for the period of time necessary to fulfill the underlying agreement with you, subject to your right, under certain circumstances, to have certain of your data erased (please see the Your Privacy Rights section below) |
Contract | Where we are processing personal data based on contract, we generally will retain the information for the duration of the contract plus some additional limited period of time that is necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship |
Legal Obligation | Where we are processing personal data based on a legal obligation, we generally will retain the information for the period of time necessary to fulfil the legal obligation |
Legal Claim | We may need to apply a “legal hold” that retains information beyond our typical retention period where we face threat of legal claim. In that case, we will retain the information until the hold is removed, which typically means the claim or threat of claim has been resolved. |
In all cases, in addition to the purposes and legal bases, we consider the amount, nature and sensitivity of the personal data, as well as the potential risk of harm from unauthorized use or disclosure of your personal data.
International Data Transfers
We may transfer personal data about you among us and to our subsidiaries or affiliates, as well as to the categories of third parties identified in the Our Disclosure of Personal Information Our Disclosure of Personal Information section of the Notice. Personal data may be transferred to, stored and processed in a country other than the one in which it was collected, including, but not limited to, the United States. The country to which personal data is transferred may not provide the same level of protection for personal data as the country from which it was transferred.We may transfer personal data about you outside the EEA and when we do so, we rely on appropriate or suitable safeguards recognized under the GDPR including adequacy decisions and standard contractual clauses.
Your Privacy Rights
You have the following rights in relation to your personal data (subject to certain limitations at law):
Access | The right to access and obtain a copy of personal data about you, as well as information relating to its processing. |
---|---|
Rectification | The right to correct or update any personal data about you that is inaccurate or incomplete. |
Restriction of Processing | The right to require us to limit the purposes for which we process your personal data if the continued processing of the personal data in this way is not justified, such as where the accuracy of the personal data is contested by you. |
Erasure | The right to request the deletion or erasure of personal data about you without undue delay if the continued processing of that personal information is not justified. |
Portability | The right to obtain a copy of personal data about you in an easily accessible format and the right to transmit that personal data to another controller. |
Objection to Processing | You also have the right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your personal data, and we will assess and inform you if that is the case. You can object to marketing activities for any reason. |
Please note that if the exercise of these rights limits our ability to process personal data, we may not be able to provide our products or services to you, or otherwise engage with you going forward.
Right to Withdraw Consent
Where we rely on your consent for processing of your personal data, you also have the right to withdraw your consent to such processing, subject to certain limitations at law. Please contact us to request to withdraw any consent you may have provided to us.
Submitting Requests
To submit a request, please contact us as set forth in the Contact Us section below. We may need to verify your identity before processing your request, which may require us to obtain additional personal data from you. In certain circumstances, we may decline a request to exercise the rights described above.Right to
Lodge a Complaint
If you have any complaints regarding our privacy practices, you have the right to lodge a complaint with your national data protection authority (i.e., supervisory authority).
Updates to These Disclosures
We may update these Disclosures from time to time. When we make changes to these Disclosures, we will change the “Last Updated” date at the beginning of these Disclosures. If we make material changes to these Disclosures, we will notify you by email to your registered email address, by prominent posting on our online services, or through other appropriate communication channels. All changes shall be effective from the date of publication unless otherwise provided in the notification.
Contact Us
If you have any questions or requests in connection with this Notice or other privacy-related matters, please send an email to hello@codecov.io
Alternatively, inquiries may be addressed to: