Privacy Policy
Last updated: October 2, 2026
This Privacy Policy explains how Casbin Inc. ("Casbin", "we", "us") collects, uses and shares personal data when you visit casdoor.com, sign up for or use Casdoor Cloud, or contact us. It does not cover open-source Casdoor that you run on your own infrastructure: we receive no data from self-hosted deployments.
1. Our two roles
- Controller. For our website visitors, our customers' account and billing contacts, and people who contact us, we decide how personal data is used.
- Processor. Each Casdoor Cloud instance stores the users, organizations, applications and logs that our customer puts into it ("Customer Data"). We process Customer Data only on our customer's behalf and under their instructions. If you are a user of an application that signs in with a Casdoor Cloud instance, please contact that application's owner about your data.
2. Data we collect
When you visit casdoor.com
- Technical data such as IP address, browser type, pages visited and referring URL, collected by our hosting provider in server logs.
- If you accept analytics cookies: usage data collected by Google Analytics, Hotjar (including session recordings and heatmaps) and Baidu Tongji. These tools are not loaded unless you click "Accept all".
- Messages and contact details you share through our live chat (tawk.to) or by email.
When you sign up for Casdoor Cloud
- Account data: name, username, email address, phone number (if provided), password (stored as a hash), and sign-in records.
- Purchase data from our payment partner Gumroad: name, email address, country, plan, license key and payment status. Gumroad processes your card details; we never see or store full card numbers.
- Plan settings you choose, such as instance name, region and custom domain.
When you use a Casdoor Cloud instance
- Customer Data that you or your users enter into your instance.
- Request logs at our gateway (IP address, time, requested host and path, user agent), which we use to operate, secure and debug the service.
3. How we use personal data
- To provide, provision, maintain, upgrade and support Casdoor Cloud (performance of our contract with you).
- To process payments and renewals and keep billing records (contract and legal obligations).
- To send service messages such as verification codes, renewal and security notices (contract and legitimate interests).
- To protect the service, detect abuse and investigate security incidents (legitimate interests).
- To understand how our website is used and improve it, only with your consent for analytics cookies.
- To answer your questions and sales enquiries (legitimate interests).
We do not sell personal data, and we do not use Customer Data for advertising or to train machine learning models.
4. Who we share data with
We share personal data only with service providers that help us run Casdoor, and only as needed for the purposes above:
- Gumroad: payment processing, subscriptions and sales tax (Gumroad acts as merchant of record).
- Infrastructure providers: servers that host Casdoor Cloud instances and their databases.
- Alibaba Cloud: DNS, content delivery and file storage.
- Vercel: hosting of the casdoor.com website.
- Tencent Exmail: sending email from our own accounts.
- Twilio: sending SMS verification codes for Casdoor Cloud accounts.
- tawk.to: live chat on our website.
- Google Analytics, Hotjar and Baidu Tongji: website analytics, only if you consent.
Providers that you configure inside your own Casdoor instance (for example, social login, SMS, email or storage providers) are chosen and controlled by you, under your own agreements with them.
We may also disclose data if required by law, to protect our rights or users, or as part of a merger or acquisition, subject to this policy.
5. International transfers
We and our providers process personal data in several countries, which may be outside your own. When personal data is transferred across borders, we take steps required by applicable data protection law to protect it. If your data must stay in a specific country, contact us before subscribing.
6. How long we keep data
- Account data: for as long as your account exists, and afterwards as needed for legal, tax and dispute purposes.
- Billing records: as long as required by tax and accounting law.
- Customer Data: for as long as your subscription is active. After a subscription ends, the instance may be suspended and its data deleted, as described in our Terms of Service. Export your data before your subscription ends.
- Gateway request logs and website analytics: for a limited period needed to operate and secure the service.
7. Security
We use measures such as HTTPS for all instances, a separate database for each Cloud instance, access controls on our infrastructure and request filtering at our gateway. No system is completely secure. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and as required by law. Please report vulnerabilities to admin@casdoor.org.
8. Your rights
Depending on where you live (including the EU, the UK and California), you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent at any time. You can withdraw analytics consent by clearing this site's cookies and local storage and choosing "Reject all". To exercise your rights, email support@casbin.com. You may also complain to your local data protection authority. For Customer Data, we will forward requests to the customer that controls it.
9. Children
Casdoor Cloud is a business service and is not directed at children under 16. We do not knowingly collect their personal data.
10. Changes
We may update this policy. We will post the new version on this page and update the date above, and notify customers by email of material changes.
11. Contact
Casbin Inc. · Email: support@casbin.com.