Privacy Policy
Last updated: 10 June 2026
This policy explains what personal data TestQuorum collects, why we collect it, how long we keep it, who we share it with, and the rights you have over it. It applies to the TestQuorum website at testquorum.dev, the dashboard, and the API.
Who we are
TestQuorum Ltd is the data controller for the personal data described in this policy. We are a company registered in England and Wales, company number 17107353.
If you have a question about this policy or want to exercise any of your rights, email us at privacy@testquorum.dev.
Personal data we collect
We collect the following categories of personal data:
- Account details. When you sign in with GitHub we receive your GitHub username, your GitHub user ID, and — where you have made it available to GitHub apps — your primary verified email address.
- Authentication tokens. When you authorise the TestQuorum application on GitHub we receive tokens that allow us to act on your behalf within the scopes you grant. We use these only to provide the service.
- Subscription and billing details. If you take out a paid plan we hold a record of the plan you are on, the billing period, the price, and the currency. Payments are processed by Stripe; we do not see or store your card details.
- Contact details you give us. If you fill in a form on the site — for example to schedule a call — we receive the name, email address, and any other context you choose to include.
- Service usage data. We record how your repositories use the API. We use this to bill you correctly and to show you analytics about your own usage.
- Email preferences and engagement. We record whether you have unsubscribed from our marketing emails. When we send you a marketing email we also record, through our email provider Plunk, whether you opened it, which links you clicked, the timestamp, and the IP address and email client that loaded the tracking pixel. See "Marketing emails" below for what we use this for.
What we do not collect
We do not log the IP address or browser user-agent string of API requests, and authentication tokens are not recorded in our application logs.
Why we use your data, and our lawful basis
We rely on the following lawful bases under UK and EU GDPR Article 6:
- Performance of a contract — to create and operate your account, authenticate you, provide the service, and manage your subscription and billing.
- Legitimate interests — to keep the service secure, prevent fraud and abuse, respond to enquiries you send us, and to send occasional marketing emails to people who have given us their contact details in the course of dealing with us. Every marketing email has an unsubscribe link.
- Consent — for analytics and marketing cookies on the website. You can withdraw consent at any time.
How long we keep your data
- Account and authentication records are kept for as long as your account exists, and are deleted on request as described under "Your rights".
- Session tokens are kept for up to seven days, after which you are asked to sign in again.
- Service usage data is kept while it is needed for billing and to show you analytics.
- Correspondence you send us — for example through forms on the site or by email — may be retained as part of our business records for as long as it remains relevant to our relationship with you.
- Marketing consent and engagement records are kept while they remain operationally useful. When you unsubscribe we retain only the suppression record itself, so we don't accidentally re-add you.
We may keep certain records for longer where the law requires it — for example accounting and tax records.
Who we share your data with
We use the following third-party providers to deliver the service. Each one only receives the data they need for the purpose listed.
- GitHub — to authenticate you and to access the repositories you have authorised. See the GitHub Privacy Statement.
- Stripe — to process payments and manage subscriptions. See the Stripe Privacy Policy.
- Plunk — to send transactional and marketing emails, and to measure engagement (such as opens and link clicks) on the marketing ones so we can gauge interest and stop sending to people who don't want them. See the Plunk Privacy Policy.
- Cloudflare — to serve and protect the website. See the Cloudflare Privacy Policy.
- Google — for website analytics through Google Tag Manager and Google Analytics (GA4). See the Google Privacy Policy.
- LinkedIn — for advertising analytics through the LinkedIn Insight Tag. See the LinkedIn Privacy Policy.
We do not sell your personal data to anyone.
International transfers
The providers above process data in the United States and other countries outside the UK and EEA. Where this happens, transfers are made under appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other recognised adequacy mechanisms.
Cookies and similar technologies
The TestQuorum website uses a small number of cookies and similar technologies:
- Analytics and marketing. Google Tag Manager, Google Analytics (GA4), and the LinkedIn Insight Tag set cookies used for website analytics and advertising measurement. These are loaded only with your consent, which you can give, refuse, or withdraw at any time through the cookie banner.
- Strictly necessary. A short-lived security cookie is set during sign-in to protect against cross-site request forgery.
You can manage your consent to the analytics and marketing cookies at any time through the cookie banner. You can also block or delete cookies through your browser settings, but blocking the strictly necessary cookie will prevent you from signing in.
Marketing emails
If you sign up for a TestQuorum account, or otherwise tell us you'd like to hear from us, we may send you occasional marketing emails about TestQuorum: product updates, changes you might care about, and the occasional pitch. Filling in the schedule-call form on the website is a one-off sales enquiry — it doesn't put you on a marketing list. We rely on legitimate interest under UK and EU GDPR Article 6(1)(f) for the marketing emails we do send. We don't buy or rent email lists, and we don't share your address with anyone else for them to market to you.
Each marketing email contains a small tracking pixel and uses link redirects through our email provider, Plunk. We use these to record whether you opened the email, which links you clicked, when, and which IP address and email client loaded the pixel. We use that engagement data to judge whether the emails are useful, to improve the ones we send, and to decide who to send future emails to — including stopping sends to recipients who consistently don't engage.
Every marketing email includes an unsubscribe link. Clicking it stops marketing emails immediately, and we keep the suppression record itself so we don't accidentally re-add you. Transactional emails — such as a confirmation that we received a form you submitted, or notifications tied to your account — are not marketing emails and aren't covered by the unsubscribe described here.
Your rights
Under UK and EU GDPR you have the right to:
- access the personal data we hold about you,
- rectify data that is inaccurate or incomplete,
- erase your data (the "right to be forgotten"),
- restrict how we process your data,
- object to processing based on legitimate interests,
- port your data to another provider where technically feasible, and
- withdraw consent at any time where we rely on consent.
To exercise any of these rights, email privacy@testquorum.dev. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office. If you are in the EEA you can contact the data protection authority in your country of residence.
Deleting your account
To delete your account, email privacy@testquorum.dev. We will remove your account and the personal data associated with it, except for any records we are required to keep — for example accounting records that we must retain for tax purposes.
Security
We protect your data by encrypting it in transit, by requiring authentication on every API request, and by isolating the data of each customer from that of every other customer.
Changes to this policy
We will update this policy from time to time. When we do, we will change the "Last updated" date at the top of this page. If we make significant changes that affect you, we will also tell you directly.
Contact
TestQuorum Ltd Registered in England and Wales, company number 17107353.
Privacy enquiries: privacy@testquorum.dev