Legal

Privacy Policy

Last updated: September 4, 2026

Who we are

The data controller for the Service is Horas Eye, a business name registered in Ireland under the Registration of Business Names Act 1963 (registration No. 792459, registered 3 September 2026). The product and website are branded as HorasEye. In this policy, "HorasEye," "we," "us," and "our" refer to that registered business.

Introduction

HorasEye provides a honeytoken and deception detection platform. This Privacy Policy explains how we collect, use, and safeguard information when you visit our website at horaseye.com or use our services (together, the "Service").

By accessing the site or using the Service, you accept this Privacy Policy and our Terms of Service. Essential cookies and similar technologies are used to operate the Service; optional analytics on our public marketing pages run only if you accept them in the cookie banner.

Bot protection (Cloudflare Turnstile)

We use Cloudflare Turnstile on account sign-up, sign-in, and the contact form to distinguish humans from automated bots. Turnstile runs in invisible mode and does not display a visible challenge under normal conditions. Cloudflare processes limited technical signals (such as IP address, TLS fingerprint, and user agent) solely for bot detection. Cloudflare's processing for Turnstile is described in the Cloudflare Turnstile Privacy Addendum.

Information we collect

We collect two broad categories of information:

  • Personal Information that identifies you, such as your email address, organization name, and contact details you provide when you register or contact us.
  • Non-Personal Information that does not identify you on its own, such as anonymous usage data, browser type, referring pages, general device information, and aggregated product usage patterns.

Information collected through technology

When you view or use the Service, we may receive information from your browser or application, including the referring URL, browser type, device type, timestamps, and pages visited.

Cookies and analytics

We use cookies and similar technologies for two purposes:

  • Essential cookies to keep you signed in, protect your session, and operate core product features. These are required for the Service to work and are not optional.
  • Optional analytics on our public marketing site (for example, anonymous page-visit counts). We only load this telemetry after you choose "Accept analytics" in the cookie banner. If you choose "Essential only," we do not send marketing-site visit analytics.

Session cookies expire when you close your browser; persistent cookies and your cookie preference remain until you delete them or clear site data in your browser.

Information you provide when registering

To use the Service, you create an account with an email address, organization details, and a password. By registering, you authorize us to collect, store, and use that information in line with this policy.

Children's privacy

The Service is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe we have received information from a child without appropriate consent, contact us at info@horaseye.com and we will delete it promptly.

How we use and share information

Personal Information

We do not sell, rent, or trade your Personal Information to third parties for their own marketing. We use it to operate the Service, respond to support requests, send security and product notices, and communicate with you about your account.

We may share Personal Information with service providers who help us run the platform (for example, email delivery or hosting). Those providers may use your information only to perform services for us and must protect it in line with this policy.

We may also disclose information when we believe in good faith that disclosure is required to comply with law, enforce our terms, investigate fraud or security issues, or protect the rights and safety of HorasEye, our users, or the public.

Non-Personal Information

We use Non-Personal Information to improve the Service, understand usage trends, and maintain reliability. We may share aggregated or de-identified information that cannot reasonably identify you.

How we protect information

We apply administrative, technical, and organizational safeguards designed to protect your information from unauthorized access. Your account is protected by your password; please keep it confidential and sign out on shared devices. We use encryption in transit, access controls, and other industry-standard measures where appropriate.

No method of transmission or storage is completely secure. By using the Service, you acknowledge that you understand and accept those risks. As a security-focused company, we work continuously to protect customer data.

Subprocessors

We use trusted third parties to operate the Service. They process data only on our instructions and under appropriate safeguards:

  • Stripe: payment processing, subscription billing, and Customer Portal (see Stripe Privacy Policy).
  • Cloudflare: DNS, CDN, bot protection (Turnstile), and optional Zero Trust Access for internal admin access.
  • Email provider (Namecheap Private Email): transactional email delivery (verification, alerts, invitations, contact form).
  • Amazon Web Services (AWS): honeytoken CloudTrail ingest pipeline in HorasEye's platform AWS account only. Customer AWS accounts are accessed via cross-account IAM roles you configure; we do not store your AWS root credentials.

We may update this list as our infrastructure evolves. Material changes will be reflected in an updated version of this policy.

Billing data

When you subscribe to a paid plan, Stripe collects and processes payment card details, billing address, and transaction history. HorasEye receives limited billing metadata from Stripe (such as customer ID, subscription status, plan tier, and invoice references) to provision your account. We do not store full payment card numbers on our servers.

Data retention and deletion

We retain account and security event data for as long as your organization is active and as needed to provide the Service, comply with law, resolve disputes, and enforce our agreements. You may request access, correction, or deletion of personal information by emailing info@horaseye.com. Organization deactivation and tenant removal can also be performed by HorasEye administrators upon verified request.

After deletion, some information may remain in backups for a limited period or where retention is required for legal or billing purposes (for example, records retained by Stripe).

You may opt out of promotional emails by using the unsubscribe link in those messages. Even if you opt out of marketing, we may still send administrative messages such as security alerts, billing notices, or updates to this policy.

Depending on where you live, you may have additional rights to access, correct, or delete personal information. Contact info@horaseye.com to make a request.

Links to other websites

The Service may link to third-party sites or integrations. We are not responsible for their privacy practices or content. We encourage you to review their policies before using those services.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice on the site before the changes take effect. Non-material clarifications may take effect immediately. Please review this page periodically for updates.

Contact

For privacy questions or data-subject requests, contact us at info@horaseye.com. Horas Eye is based in Ireland.

Questions? Contact us or email info@horaseye.com.