We use information to operate, secure, support, and bill for Merge Preflight. We do not sell personal information, run behavioral advertising, or add analytics cookies to the public website. The signed-in console uses an essential session cookie. We do not clone or host your source repositories.
1. Who we are and what this policy covers
Merge Preflight is a product of Senseisoft LLC ("Senseisoft," "we," "us," or "our"). This Privacy Policy applies to the Merge Preflight website, GitHub App, administrative console, webhooks, connected integrations, support interactions, and related services (collectively, the "Service").
In many business deployments, the organization that installs or configures Merge Preflight decides why and how repository and integration data is processed. That organization may be the controller of that information, and Senseisoft acts as its service provider or processor. Senseisoft remains responsible for the account, security, operational, and billing information it processes for its own purposes. A separately signed data processing agreement controls if it conflicts with this Policy.
2. Information we collect and process
Account and authentication information
When you sign in with GitHub, we may receive and store your provider user ID, username, display name, avatar URL, primary email address when GitHub makes it available, granted scopes, authentication timestamps, and repository permission information. We process OAuth credentials and session identifiers to authenticate you. Credential material is protected and is not displayed back through the Service.
GitHub App, installation, and repository information
We process GitHub App installation identifiers, organization and repository names and identifiers, installation status, repository permissions, repository settings, policy configuration, selected protected repositories, webhook delivery metadata, and related configuration needed to operate the Service.
Merge Preflight does not clone or host your source repositories. It reads the configured Merge Preflight policy file when you choose repository-file policy and processes pull-request metadata and change summaries supplied through GitHub. It may also publish a GitHub Check Run and, depending on your settings, a pull-request comment or review summary.
Pull-request and evaluation information
To make and explain a merge decision, we may process:
- Pull-request number, title, body, author, labels, source and target branches, head commit, commit messages, changed-file summaries, review state, check state, and relevant comment metadata.
- Policy configuration, rule inputs, evaluation results, blockers, warnings, remediation text, external references, and the identifiers of checks or comments published by Merge Preflight.
- Settings changes and audit information, including who changed a policy or setting and when.
- Emergency bypass records, including the actor, stated reason, pull-request and commit reference, original blockers, and time of the bypass.
Connected Jira, Linear, and Sentry information
When an administrator connects an integration, we process the selected Jira site, Linear workspace, or Sentry organization identity, display name, canonical URL, connection settings, scopes, health state, and related audit records. OAuth access and refresh tokens are encrypted before storage. If an administrator connects a supported self-managed Jira or Sentry instance using an API token, that token is also encrypted before storage.
During an evaluation, we query only the external state needed by enabled rules. This may include an issue identifier, title or summary, status, assignee, project or team, and URL, or a Sentry issue or incident identifier, title, severity, status, project, environment, and URL. Relevant results and references may become part of the decision and audit trail. We do not use connected-provider data for advertising or to build unrelated profiles.
Subscription and billing information
We may process payer identity, billing-provider customer and subscription references, plan or price references, repository-license quantity, subscription state and term, repository entitlements, provider event metadata, management URLs, and transaction or payload hashes. Paddle or Microsoft processes payment details for purchases made through its channel; Senseisoft does not receive full payment card numbers from those providers.
If you purchase directly from Senseisoft, we may also collect the billing contact, company name, billing address, tax information, purchase order details, invoice and payment status, and other records reasonably required to fulfill the order and meet tax and accounting obligations.
Technical, security, and support information
Our systems may process IP address, request ID, request method and path, response status, timestamps, duration, browser or client information supplied in request headers, error category, job and delivery identifiers, and other operational metadata. Logs and alerts are designed to exclude tokens, cookies, authorization headers, webhook signatures, private keys, and raw provider credentials.
We do not retain full raw webhook request bodies as historical delivery records. We retain limited webhook metadata and a cryptographic payload hash; a background processing record may contain a field-redacted representation needed for processing, retry, and diagnostics. If you contact us, we also process the contact details, message, and attachments you choose to provide.
4. Where information comes from
We receive information:
- directly from you or your organization's administrators;
- from GitHub through sign-in, GitHub App APIs, and signed webhooks;
- from Jira, Linear, or Sentry when an administrator authorizes a connection and an enabled policy requests external state;
- from Paddle, Microsoft Marketplace, or a direct order and payment process;
- automatically from devices and systems communicating with the Service; and
- from colleagues or repository administrators who configure access or act on behalf of your organization.
5. How and why we use information
We use information to:
- authenticate users and enforce repository and organization access boundaries;
- install, configure, operate, and maintain the Service;
- evaluate pull requests, publish decisions, and preserve decision and bypass audit trails;
- connect to authorized external systems and maintain connection health;
- provision licenses, process subscriptions, reconcile entitlements, and prevent billing abuse;
- respond to support requests and communicate about service or security matters;
- monitor reliability, debug failures, recover missed work, and protect the Service; and
- comply with law, enforce our Terms, and establish or defend legal claims.
Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in providing and securing a business service, compliance with legal obligations, and consent where you authorize an optional connection or where consent is otherwise required. You may withdraw consent, but doing so does not affect earlier lawful processing and may prevent the connected feature from working.
7. No sale or behavioral advertising
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use Service data to target advertisements. If those practices change, we will update this Policy and provide any choices required by law before the change applies.
8. Retention and deletion
We keep information only for as long as reasonably necessary for the purposes in this Policy. Retention depends on the type of record, the duration of the customer relationship, the need to operate and secure the Service, dispute and audit needs, backup cycles, and legal, tax, and accounting requirements.
- Console sessions are short-lived and expire within the configured session period. OAuth authorization attempts are also short-lived and expire within minutes.
- Account, repository, configuration, connection, evaluation, finding, and audit records may be retained while the Service is active and afterward when needed for continuity, security, customer instructions, or legal claims.
- Billing, invoice, payment, and tax records may be retained for the legally required accounting period even after a subscription ends.
- Deleting or disconnecting an integration removes or disables credentials through the applicable product flow, but information already included in an evaluation or audit record may remain under the retention criteria above.
You may request deletion by contacting us. We may need to verify the request and consult the customer organization that controls the data. We may deny or limit a request where retention is required or permitted by law, necessary to protect the Service, or needed to preserve the integrity of billing and decision audit records.
9. Security
We use technical and organizational safeguards designed for the nature of the information we process. These include encrypted network transport, application-level encryption for managed integration credentials, strict access and ownership checks, signed-webhook verification, bounded input handling, secret redaction, limited data collection, and auditable administrative actions.
No system is perfectly secure. You are responsible for protecting your GitHub and connected-provider accounts, limiting administrator access, reviewing requested App permissions, and promptly notifying us of suspected unauthorized use.
10. International data transfers
Senseisoft and its service providers may process information in the United States and other countries where we or they operate. Those countries may have different data-protection laws from your country. Where required, we use recognized transfer mechanisms and contractual or organizational safeguards appropriate to the transfer.
11. Your privacy rights and choices
Depending on your location, you may have the right to request access to, correction of, deletion of, or a copy of personal information; to object to or restrict certain processing; to withdraw consent; or to appeal a denied request. You may also have the right to complain to a local data-protection authority.
You can disconnect integrations, uninstall the GitHub App, sign out, or ask your organization's administrator to change repository access. These actions can stop future collection for the affected feature but do not automatically delete retained audit or billing records, and uninstalling or disabling Merge Preflight does not by itself cancel a paid subscription.
To exercise a privacy right, email [email protected]. Tell us the request, your relationship to the relevant organization, and enough information to verify your identity. Authorized agents may submit requests where permitted by law. We do not discriminate against anyone for exercising a privacy right.
12. Business users and children
Merge Preflight is a business service intended for organizations and their authorized personnel, not for personal or household use. If you use an account provided by an employer or other organization, that organization may administer the account and control associated data.
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to the Service, contact us so we can investigate and take appropriate action.
13. Changes and contact
We may update this Policy as the Service or law changes. We will post the revised version here and update the effective date. If a change is material, we will provide additional notice when required by law.
Questions, requests, or concerns about this Policy or Merge Preflight's data practices may be sent to [email protected].