Privacy Policy
Last updated: July 14, 2026
Contents
- Scope of this policy
- Two roles: controller & processor
- Information we collect from developers
- Information processed about end-users
- Cookies & local storage
- How we use information
- How we share information
- Subprocessors & third-party services
- How we protect information
- Data retention & deletion
- Your rights
- International data transfers
- Children's privacy
- Changes to this policy
- Contact us
1. Scope of this policy
This Privacy Policy explains how Avanest ("Providame," "we," "us") collects, uses, and shares information in connection with the Providame authentication platform (the "Service"). It covers two distinct groups of people:
- Developers — the people who create Providame platform accounts, workspaces, and apps; and
- End-users — the people who sign up and sign in to applications built by our developer customers, using Providame as the underlying authentication layer.
2. Two roles: controller & processor
For developer account data (your name, email, workspace configuration, billing information), Providame acts as the data controller and this policy describes our own collection and use of that data directly.
For end-user data (the people who use applications built by our developer customers), Providame acts as a data processor / service provider, processing that data solely on behalf of and under the instructions of the developer customer who operates the application. If you are an end-user with questions about how your data is used, please contact the developer or company whose application you signed up through — they control that relationship, and this policy explains our processing role on their behalf.
3. Information we collect from developers
When you create a Providame account and use the dashboard, we collect:
- Account information: name and email address. Your password is stored as a salted hash within our authentication infrastructure — never in plain text, and never accessible to us directly.
- Workspace & app configuration: workspace names, app names, environment settings, branding assets, custom claims, webhook endpoints, and identity-provider configuration you enter.
- Billing information: processed and stored by our payment processor — we do not store your full payment card details ourselves.
- Usage & audit data: an audit log of workspace actions (who did what and when), used for security and support purposes.
- Support communications: anything you send us via email or our contact channels.
4. Information processed about end-users
On behalf of our developer customers, the Service processes the information their applications collect during sign-up and sign-in, which may include:
- Email address, phone number (if SMS sign-in is enabled), and name;
- Authentication credentials (passwords are stored only as salted hashes; passkey public keys; TOTP secrets);
- Social login profile information from providers the end-user chooses to connect (e.g. Google, GitHub, Apple, Facebook);
- Session and device information used to secure and manage active sessions;
- Custom metadata the developer's application chooses to store (public, private, or end-user-editable "unsafe" metadata);
- Role and permission grants configured by the developer.
We never access or use end-user data for our own purposes beyond operating, securing, and supporting the Service on behalf of the developer customer who controls that data.
5. Cookies & local storage
Providame uses a small number of strictly necessary cookies to operate authentication sessions — for both developer dashboard sessions and end-user application sessions. These cookies are HttpOnly (not readable by JavaScript) and are used solely to keep you signed in; we do not use third-party advertising or tracking cookies on the Service itself. One non-HttpOnly cookie is used purely as a presence marker, so client-side code can check whether a session exists without ever reading the underlying token.
6. How we use information
We use the information described above to:
- Provide, maintain, and secure the Service;
- Authenticate developers and end-users and manage sessions;
- Process payments and manage subscriptions;
- Send transactional emails (verification codes, password resets, invitations) and, for developer accounts, service-related announcements;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Provide customer support;
- Comply with legal obligations.
We do not sell personal data, and we do not use end-user data to train any third-party models or for advertising purposes.
7. How we share information
We share information only in the following circumstances:
- With subprocessors who help us operate the Service, listed below;
- Between a developer customer's own workspace and their own end-users, as instructed by that developer;
- If required by law, regulation, or valid legal process;
- To protect the rights, property, or safety of Providame, our customers, or the public;
- In connection with a merger, acquisition, or sale of assets, subject to the same privacy commitments described here.
8. Subprocessors & third-party services
The Service relies on the following categories of subprocessors:
- Identity infrastructure — the underlying identity engine that stores authentication credentials on our behalf, operated within our own infrastructure.
- Email delivery — used to send verification codes, password resets, and invitation emails.
- SMS delivery — used only if a workspace enables SMS one-time-code sign-in.
- Payment processing — used to process subscription payments; card details are handled directly by the processor and never touch our own servers.
- Bot detection — used at sign-up to distinguish humans from automated abuse, where enabled.
- Breach-password checking — used to check chosen passwords against known-breached password lists. Only a short, irreversible hash prefix of a password is ever transmitted for this check — never the password itself, and never a full hash.
A full, current list of subprocessors is available on request via legal@providame.com.
9. How we protect information
We apply industry-standard technical and organizational measures to protect information in our care, including: hashing of passwords and API keys, encryption of data in transit, strict tenant isolation between environments and workspaces, short-lived access tokens, and rate limiting on all public-facing endpoints. More detail is available on our Security page. No system can guarantee perfect security, and we encourage you to use strong, unique passwords and enable additional authentication factors where available.
10. Data retention & deletion
We retain developer account and workspace data for as long as your account is active. When an application is deleted, it enters a temporary retention period before the underlying data is permanently and irreversibly removed, giving you a window to restore it if the deletion was made in error. Audit log entries may be retained for a longer period for security and compliance purposes.
11. Your rights
Depending on your location, you may have rights to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing.
- Developers can exercise these rights directly through the dashboard, or by contacting legal@providame.com.
- End-users should contact the developer or company whose application they use — Providame processes end-user data only on that developer's instructions, and the developer is best positioned to handle these requests. We will assist our developer customers in fulfilling verified end-user requests where required.
12. International data transfers
Information may be processed in countries other than your own. Where required, we rely on appropriate safeguards — such as standard contractual clauses — to ensure information transferred internationally continues to receive an adequate level of protection.
13. Children's privacy
The Service is not directed at children, and we do not knowingly collect personal information from children. If a developer customer's application is directed at children, that developer is solely responsible for complying with applicable children's-privacy laws, such as obtaining any required parental consent.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by email to developer account holders or a notice on this page, before the changes take effect.
15. Contact us
Questions about this Privacy Policy can be sent to legal@providame.com, or via our contact page.