This Privacy Policy explains what GitPromo ("GitPromo", "we", "us"), operated by [LEGAL ENTITY], collects when you use git.promo (the "Site") and the promotion service described in our Terms & Conditions (the "Service"), why we collect it, who we share it with, and the choices you have.
The short version: we collect what we need to publish and bill an endorsement, we use standard analytics to understand how the Site is used, we never sell personal data, and you can ask us to delete yours at any time.
1. Who we are
GitPromo is a media distribution service for open-source repositories. We run social media accounts on Instagram, TikTok, and YouTube that post short videos about GitHub repositories, and we sell placements on those accounts to the people who maintain the repositories. The data controller for the purposes of this policy is [LEGAL ENTITY], [REGISTERED ADDRESS]. You can reach us at hello@git.promo.
2. What we collect
We collect three kinds of information.
Information you give us when you order an endorsement:
- ▸The GitHub repository URL you want promoted.
- ▸The angle or hook you write for the video.
- ▸Your email address, which we use to confirm the order, tell you the publish date, and send you the post links.
- ▸An Instagram handle, only if you choose to be tagged as a collaborator.
- ▸The accounts you selected and the amount you paid.
Information collected automatically when you use the Site:
- ▸Usage data such as pages viewed, buttons clicked, the form being started or submitted, and the referring page, collected through Google Analytics 4 and a GoHighLevel tracking pixel.
- ▸Technical data such as IP address, browser type, device type, operating system, language, and approximate location derived from the IP address.
- ▸Campaign parameters (for example utm_source and utm_campaign) when you arrive from one of our social posts.
- ▸Server logs kept by our hosting provider for security and debugging.
Information from third parties:
- ▸Payment confirmation from Stripe. Stripe collects and processes your card details directly; we never see or store your full card number.
- ▸Public repository metadata from the GitHub API, such as the repository name, description, star count, license, and README, which is public information about the repository rather than about you.
- ▸Public engagement metrics from Instagram, TikTok, and YouTube about the posts we publish, such as view and like counts.
If you reached us by commenting on one of our social media posts and handing over your email through a lead form, that data is collected and processed through GoHighLevel under the notice shown in that flow. This policy covers what happens once that data reaches us.
3. How we use it
- ▸To deliver the Service: create the video, schedule and publish it on the accounts you selected, tag you as a collaborator if you asked, and send you the publish date and post links.
- ▸To take payment and keep the records the law requires us to keep.
- ▸To publish results: the Site shows, for every repository we have promoted, the repository name, public repository metadata, the posts we made, and their public engagement metrics. This is about the repository, not about you, and it is how we show prospective customers what the Service does.
- ▸To answer your questions and handle refunds.
- ▸To understand how the Site is used, fix problems, and improve it.
- ▸To send you service messages about your order. We do not send marketing email to promoters unless you separately opt in.
- ▸To detect and prevent fraud, abuse, and misuse of the Service.
4. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- ▸Performance of a contract: processing your order details, email, and payment to deliver the endorsement you bought.
- ▸Legitimate interests: analytics, security, fraud prevention, publishing results pages, and improving the Service. We balance these interests against your rights and you may object at any time.
- ▸Legal obligation: keeping tax and accounting records.
- ▸Consent: analytics cookies where your jurisdiction requires consent, and any marketing communications. You can withdraw consent at any time.
6. What is public
The videos we publish are public on the social platforms and may be embedded on the Site. Results pages on the Site show the repository name, its public metadata, and the public metrics of our posts. If you asked to be tagged as a collaborator, your Instagram handle is public on that post. Your email address, the angle you wrote, and your payment details are never published.
If you no longer want a results page for your repository to appear on the Site, email us and we will remove it. Posts already published on social platforms are covered by the Terms & Conditions.
7. International transfers
Our providers operate globally, and your data may be processed outside the country you live in, including in the United States. Where we transfer data out of the EEA or UK we rely on the providers' standard contractual clauses or an adequacy decision.
8. How long we keep it
- ▸Order records, including your email and what you bought, for as long as tax and accounting law requires, typically seven years.
- ▸Analytics data according to the retention settings of Google Analytics and GoHighLevel, currently 14 months for GA4 event data.
- ▸Server logs for up to 30 days.
- ▸Results pages and public metrics for as long as the Site exists, unless you ask us to remove yours.
9. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent. You also have the right to complain to your local data protection authority.
To exercise any of these rights, email hello@git.promo from the address you used to order. We respond within 30 days. We may ask you to confirm your identity first.
If you are a California resident, the California Consumer Privacy Act gives you the rights described above. We do not sell or share personal information as those terms are defined in the CCPA.
11. Children
The Service is for adults who maintain software projects. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, email us and we will delete it.
12. Security
We use reputable providers, encrypt data in transit, restrict access to order data to the people who need it, and keep card details out of our systems entirely. No system is perfectly secure; if we learn of a breach affecting your data we will tell you and the relevant authority as the law requires.
13. Changes to this policy
We will post any changes on this page and update the date at the top. If a change materially affects how we use data you already gave us, we will email you before it takes effect.
14. Contact
[LEGAL ENTITY], [REGISTERED ADDRESS]. Email: hello@git.promo.