Information we collect
When you sign in, GitHub provides your account identifier, login, profile image, and available email address. We also store the dates, commit-time plan, timezone, price, order status, and Stripe identifiers associated with an order. Stripe handles payment card details; Git Green does not receive or store complete card numbers.
Temporary GitHub credentials
Fulfilling an order requires permission to create and update a repository on your behalf. GitHub OAuth's repository scope can authorize access to public and private repositories that your account can access; Git Green uses it only for the dedicated fulfillment repository. The OAuth access token is encrypted before it is stored with a pending order, expires from that temporary store within seven days, and is deleted sooner after a successful authenticated handoff or terminal checkout failure. We do not expose the token through the client session or place it in Stripe metadata. You can revoke the authorization at any time from GitHub's authorized OAuth apps settings.
How we use and share information
We use information only to:
- authenticate your account and load your contribution calendar;
- calculate, collect, and reconcile payment;
- fulfill the plan you reviewed and show its status;
- prevent abuse, investigate failures, and provide support.
Data is shared only with service providers needed for those purposes, including GitHub, Stripe, database hosting, and the configured fulfillment service. We do not sell personal information or use it for third-party advertising.
Retention and your choices
Order and transaction records are retained as needed for support, fraud prevention, accounting, and legal obligations. You can revoke Git Green from GitHub at any time from your authorized OAuth apps. To request access, correction, or deletion of eligible data, email support@example.com. Deleting an account record does not reverse commits that have already been published to your GitHub repository.
Cookies and security
We use essential session cookies and device-local preferences described in our Cookie Policy. We use encryption in transit, restricted server-side access, signed Stripe webhooks, and encrypted temporary credentials. No online service can promise absolute security, so please contact us promptly if you believe your account or an order has been compromised.