Privacy Policy
Effective date: August 23, 2026
1. Overview
Ridgeline Software LLC ("we," "us," or "our") operates CostRadar ("the Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.
We seek to collect only data reasonably necessary for the purposes described in Section 3. We do not sell your data or use it for cross-context behavioral advertising.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (via Clerk authentication)
- Name (optional, from your Clerk profile)
- Authentication identifiers (Clerk user ID)
- Billing information (payment method details processed by Stripe — we do not store raw card numbers)
2.2 Azure Resource Data
To provide the Service, we retrieve and store the following from your Azure environment using a customer-created read-only service principal and, when Storage Export is enabled, read-only access to the configured export container:
- Daily cost amounts per service and resource from configured Azure Cost Management export files
- Resource names, resource group names, and subscription names
- Azure subscription IDs and tenant IDs
- Azure resource tags (key/value pairs attached to resources), used to break down cost by team, department, or environment
- Azure Advisor optimization recommendations (cost, reliability, and performance suggestions generated by Microsoft) — including rightsizing suggestions and Reserved Instance/Savings Plan opportunities
- Service principal credentials you provide (tenant ID, client ID, client secret — stored encrypted)
We do not retrieve or store virtual machine images, application data, arbitrary storage contents, or network traffic from within your Azure resources, and we do not retrieve resource configuration except as reflected in resource metadata, resource tags, and Azure Advisor recommendations. When Storage Export is enabled, we read only the configured Azure Cost Management export blobs.
2.3 Usage Data
We automatically collect limited usage information, including:
- Selected feature and product events generated by the Service
- Server request and dependency telemetry (route, timestamp, response code, duration, and error details — not application request bodies)
- IP address and browser type, used for security monitoring and recorded on a best-effort basis in the audit log alongside account actions (anomaly acknowledgements, settings changes, team member changes, etc.)
- Server-side telemetry collected via Microsoft Application Insights, including requests, dependencies, exceptions, performance timing, selected product events, and account or tenant identifiers when attached to an event
2.4 Support Conversations
If you use the AI support chat, your messages and the assistant's responses are stored to provide conversation history and may be reviewed by our team to improve the Service. Conversations are retained for the duration of your account and then deleted upon account deletion.
Support conversations are routed through OpenRouter to the model provider configured for the Service. See Section 4 for details on third-party processors. Do not include passwords, client secrets, or sensitive personal information in support conversations.
2.5 Cookies and Local Storage
We use strictly necessary cookies and local storage for:
- Maintaining your authentication session (managed by Clerk)
- Remembering dashboard preferences (e.g., filter states)
We do not use advertising cookies or third-party tracking pixels.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service — pulling, storing, and analyzing your Azure cost and resource optimization data to surface anomalies, generate reports, and deliver alerts
- Send notifications — email digests and anomaly alerts through Slack or Teams webhooks you configure
- Process payments — managing subscriptions and billing through Stripe
- Provide support — responding to inquiries and powering the AI support assistant
- Improve the Service — analyzing aggregated or de-identified usage patterns and reviewing support interactions to identify product improvements
- Security and fraud prevention — detecting abuse, unauthorized access, and suspicious activity
- Legal compliance — meeting our obligations under applicable law
We do not use your data to train our own AI models. When you use AI support chat, we may send up to the most recent 20 sanitized conversation messages, relevant excerpts from our public support knowledge base, and limited account context needed to answer support questions, such as plan, connected subscription count, subscription display names and sync dates, recent anomaly summaries, and estimated 30-day cost totals. We do not send Azure client secrets. OpenRouter routes this material to the model provider configured for the Service. Those providers process the material under their applicable terms and privacy commitments.
We do not profile you for advertising purposes. We do not sell, rent, or trade your personal data.
3.1 Legal Bases and Roles for EEA/UK Processing
Where the GDPR or UK GDPR applies, Ridgeline Software LLC is the controller for account, billing, usage, support, security, and trial-eligibility data for which we determine the purposes and means of processing. We process personal data as needed to perform our contract with you; for our legitimate interests in operating, securing, supporting, and improving the Service, preventing fraud and trial abuse, and resolving disputes; to comply with legal obligations; and with consent where we specifically request it.
Our legitimate interests include indefinitely retaining the pseudonymous trial-eligibility marker described in Section 5 so we can enforce one free trial per Azure subscription and ensure the marker is recorded before customer data is deleted. For Azure cost and resource data that we process on a business customer's instructions, our controller or processor role depends on the applicable law and our agreement with that customer.
4. Third-Party Service Providers
We share data with the following service providers to operate the Service. Their processing is subject to applicable contract terms and data-protection commitments.
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | User authentication and account management | Email, name, session data |
| Microsoft Azure | Hosting (Cosmos DB, Azure Functions) | All stored data — hosted in Azure datacenters |
| Microsoft Application Insights | Server-side platform health monitoring and telemetry | Request routes, response status and timing, dependencies, exceptions, selected product events, account or tenant identifiers when attached to an event |
| Stripe | Payment processing | Email, billing address, payment method tokens |
| OpenRouter and configured model providers | AI chat routing and inference | Up to 20 sanitized recent conversation messages, public support-knowledge excerpts, and limited account context described in Section 3 |
| Resend | Transactional email delivery | Email address, digest content |
We do not share data with any other third parties except as required by law or in connection with a business transfer (see Section 12).
5. Data Retention
We retain personal data for the following periods:
- Account and billing data — Duration of your account plus up to 90 days after termination, except records retained longer for tax, accounting, legal, fraud-prevention, or dispute purposes
- Azure cost snapshots — Rolling 12 months (365 days) while your account is active; deleted within 90 days after termination or account deletion
- Anomaly data — Duration of your account; deleted within 90 days after termination or account deletion
- Audit logs — Up to 12 months from each action while the workspace exists; deleted with customer data during account deletion or unpaid-trial cleanup unless a limited record must be retained for legal, fraud-prevention, security, or dispute purposes
- Support conversation history — Duration of your account; deleted with customer data during account deletion or unpaid-trial cleanup
- Trial-eligibility markers — Retained indefinitely to enforce one free trial per exact Azure subscription and ensure the marker is recorded before customer data is deleted. Each marker is a pseudonymous keyed HMAC-SHA-256 value. It contains no raw Azure subscription ID, Azure tenant ID, CostRadar tenant or user ID, credentials, Azure cost data, or account content. It is not anonymous because we can compare a newly supplied subscription identifier with it using our secret key.
- Viewer invite tokens — 7 days from creation or until used, whichever comes first
- Trial accounts not converted to paid plans — 30 days after trial expiration
- Deletion-safety tombstones — 90 days after deletion; may contain CostRadar tenant/user IDs, Stripe customer/subscription IDs, a pending-checkout token when present, deletion reason, and timestamps, but no Azure identifiers, credentials, cost data, or account content
- Risk and delivery records — Up to 90 days for fraud prevention, rate limiting, and delivery safety
- Support suppression identifiers — One-way hashed identifiers may be retained indefinitely to prevent messages after an opt-out or suppression event
- Tax, accounting, and payment records — As required for applicable tax, accounting, legal, and dispute obligations, generally up to 7 years
Unpaid trial-account customer data is deleted 30 days after trial expiration. For other terminated accounts, customer, cost, and operational data is deleted within 90 days. We may retain payment records required by law, a minimal one-way trial-eligibility marker used to enforce one free trial per Azure subscription, and limited billing, tax, accounting, legal, fraud-prevention, security, dispute, and deletion-safety records as described above. The marker may prevent a second trial, but a returning customer may pay before connecting Azure and then reconnect the same subscription; deleted customer data is not restored. You may request prompt deletion of cost and operational data by contacting support@costradar.io.
6. Security
We implement security measures appropriate to the sensitivity of the data we hold:
- Azure service principal credentials are stored encrypted using AES-256-GCM encryption at rest
- All data in transit is encrypted via TLS 1.2+
- Access to production data is restricted to authorized personnel only
- Authentication is handled by Clerk with industry-standard session management
- Authorized support impersonation actions are logged with an audit trail
Authorized administrators may temporarily view a customer workspace to investigate a support or security issue. This access is restricted, authenticated, and recorded in a separate impersonation audit log.
No security system is perfect. In the event of a security breach affecting your personal data, we will notify affected users and regulators as required by applicable law. Any user notification will be sent to the email address associated with your account and will describe the nature of the breach, what data was affected, and what steps we are taking.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service. This includes:
- Session cookies (via Clerk) required for authentication and login state
- No third-party advertising cookies are used
| Cookie name | Purpose | Duration |
|---|---|---|
| __session | Maintain your authenticated session | Session |
| __client_uat | Maintain your authenticated session | Session |
These cookies are set by Clerk, our authentication provider. Microsoft Application Insights is configured on CostRadar's server rather than as a browser analytics SDK and does not set the listed authentication cookies. Because the Clerk cookies are strictly necessary for authentication to work, they cannot be disabled without breaking your ability to sign in. You can control cookie behavior through your browser settings, but disabling cookies may prevent you from using the Service. Application Insights telemetry is collected server-side in the current implementation and does not add a browser analytics cookie.
8. Do Not Track and Global Privacy Control
We do not respond to browser Do Not Track (DNT) signals, as no universal standard has been established. We also do not engage in the sale of personal data or cross-context behavioral advertising, so Global Privacy Control (GPC) signals do not change our data practices — we do not sell your data regardless of GPC status. We do not track users across third-party websites.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate personal data
- Deletion — Request deletion of your personal data (the "right to be forgotten")
- Portability — Request your data in a machine-readable format
- Objection — Object to certain processing of your data
- Restriction — Request that we restrict processing in certain circumstances
- Withdraw consent — Where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at support@costradar.io. We will respond within 30 days for EEA/UK requests, subject to extensions permitted by law. Other requests are handled within the applicable legal period, including the 45-day periods described in Sections 10 and 11. We may need to verify your identity before processing certain requests.
You can delete your account and customer data through Settings → Account → Delete Account, or by emailing us directly. Limited billing, legal, deletion-safety, and trial-eligibility records may remain as described in Section 5.
If you are located in the European Economic Area or United Kingdom, you have the right to receive a copy of your personal data in a structured, machine-readable format (data portability). To request a data export, contact support@costradar.io.
If you are located in the European Economic Area, you have the right to lodge a complaint with your local supervisory authority if you believe we have not handled your data in accordance with applicable law.
10. Additional State Privacy Rights
Depending on where you live and whether an applicable privacy law covers our processing, you may have rights to access, correct, delete, or obtain a portable copy of personal data, and to opt out of certain processing. We do not sell personal data or use it for targeted or cross-context behavioral advertising.
To exercise these rights, contact us at support@costradar.io. We will respond within 45 days.
11. California Residents — Your Privacy Rights
If you are a California resident and the CCPA applies to our processing, you may have the following rights:
- Right to Know — You may request information about what personal data we collect, use, and disclose.
- Right to Delete — You may request deletion of your personal data, subject to certain exceptions.
- Right to Correct — You may request correction of inaccurate personal data.
- Right to Opt Out of Sale — We do not sell your personal information to third parties.
- Right to Non-Discrimination — We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at support@costradar.io. We will respond within 45 days.
12. Business Transfers
If Ridgeline Software LLC is acquired, merges with another company, or sells substantially all of its assets, your data may be transferred as part of that transaction. We will provide notice before your data becomes subject to a materially different privacy policy.
13. Children's Privacy
The Service is intended for users 18 years of age and older. We do not knowingly collect personal information from persons under 18. If you believe we have inadvertently collected information from a minor, please contact us at support@costradar.io and we will delete it promptly.
14. International Transfers
Ridgeline Software LLC is based in the United States. If you access the Service from outside the United States, your data may be transferred to and processed in the United States and in other countries where our processors operate. Where required by applicable law, we and our processors use an approved transfer mechanism or other appropriate safeguard, which may include standard contractual clauses.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top and notify you through the dashboard or by email before or when changes take effect, as required by applicable law. We may require you to acknowledge the updated policy as part of accepting an updated legal bundle before continuing to use authenticated portions of the Service.
If you do not agree with a material change, you may stop using the Service and request account deletion, subject to the retention periods and exceptions in Section 5.
16. Contact Us
For privacy-related questions, requests, or concerns:
Ridgeline Software LLC
Email: support@costradar.io
Texas, United States