This Privacy Policy explains how Macan ("we", "us", "our") collects, uses, and protects information when you use our vulnerability assessment and penetration testing management platform (the "Service").
1. Information We Collect
We collect the following categories of information:
- Account information: name, email address, password (stored as a salted hash, never in plain text), and workspace/organization name.
- Scan data: targets you submit for scanning (IP addresses, domains, hostnames), scan results, and findings generated by the Service.
- Payment information: we do not store your card or bank details ourselves. Payments are processed by our third-party payment processors — Xendit for Indonesian Rupiah transactions and Creem for international transactions. Each processor's own privacy policy governs how they handle your payment details.
- Usage data: log data such as IP address, browser type, and pages visited, collected automatically to operate and improve the Service.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service, including running the scans you request.
- Process subscription payments and manage your billing.
- Communicate with you about your account, service updates, or support requests.
- Detect, prevent, and address technical issues, abuse, or unauthorized use of the Service.
- Comply with legal obligations.
3. Scan Data and Authorization
The Service is designed to scan network and web assets for security vulnerabilities. By submitting a target for scanning, you confirm that you own the target or have obtained explicit authorization from its owner to scan it, consistent with our Terms of Service. Scan results and findings are stored within your workspace and are only accessible to members of that workspace.
4. Third-Party Service Providers
We share information with third parties only as necessary to operate the Service:
- Payment processors: Xendit (Indonesia) and Creem (international) — to process subscription payments.
- Infrastructure providers: our hosting and infrastructure providers, who process data on our behalf under appropriate confidentiality and security obligations.
We do not sell your personal information to third parties.
5. Data Retention
We retain account and scan data for as long as your account remains active, and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated data at any time by contacting us (see Section 9).
6. Data Security
We take reasonable technical and organizational measures to protect your information, including encrypted password storage, access controls scoped to your workspace, and restricted internal access to scan data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal information, or to object to or restrict certain processing. To exercise these rights, contact us using the details in Section 9.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
9. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at admin@xrisko.com or via our Contact page.