Privacy Policy

Last updated 2 September 2026.

GingerBeard Security is an independent penetration testing practice. This policy covers two separate things: what this website does with visitor data, and what we do with client data during an engagement. They’re governed differently, so they’re described separately.

The short version

This website sets no cookies for ordinary visitors. It runs no analytics, no advertising, and no third-party tracking of any kind. There are no user accounts, no comments, no shopping cart. The only personal information it collects is what you deliberately type into the contact form.

What this website collects

The contact form

If you submit the contact form we collect the name, work email address, organization, phone number, area of interest, and message that you enter. Your IP address gets recorded alongside the submission so we can investigate abuse.

These submissions are not stored in this website’s database. They’re sent straight to our email and live only in our mailbox, which means the data isn’t sitting on a public-facing web server waiting to be stolen. We keep inquiry emails as long as we need them to respond and to maintain a record of business correspondence. We don’t sell, rent, or share them with anyone.

Abuse prevention

To limit automated spam, the site briefly stores a one-way cryptographic hash of the submitting IP address along with a count of recent submissions. It expires automatically after fifteen minutes. The original IP address isn’t recoverable from the stored hash.

Server logs

Like any web server, ours records standard request logs: IP address, timestamp, the page requested, the referring page, and the browser user agent string. We use these for security monitoring and troubleshooting. They aren’t combined with any other data or used to build a profile of you.

Cookies

No cookies get set for ordinary visitors. Cookies are only issued to administrators who log in to manage the site, and they’re strictly necessary for that login session.

Third parties

We use as few as possible, and we’d rather name the one we have than pretend it doesn’t exist.

  • Google Fonts. This site loads its typefaces from Google’s font service. Doing that discloses your IP address and browser user agent to Google when the page loads. Nothing else is shared, and no cookie is set by the request.
  • Our email provider. Contact form submissions are delivered through a third-party mail service, which necessarily processes the contents of your message in transit.
  • Our hosting provider. The site runs on a virtual server, whose operator has the access to the underlying machine that any infrastructure provider does.

There’s no Google Analytics, no advertising network, no social media pixel, no session recording, no heat mapping, and no consent-management platform, because none of it is needed.

Client engagement data

This is separate from the website, and it’s the part that matters most if you’re considering hiring us.

Penetration testing produces sensitive material by its nature. Network diagrams, credentials, extracted data samples, screenshots of systems mid-compromise, and a written record of exactly how to break into your environment. We treat that material as the most sensitive thing we hold.

  • Engagement data is governed by the contract and any non-disclosure agreement signed for that engagement. Where those terms differ from this page, the contract governs.
  • Testing is only ever performed against systems for which we hold written authorization from a party entitled to grant it.
  • Findings, evidence, and reports are held encrypted, and access is limited to the personnel working the engagement.
  • Client data is never used to train machine learning models, never sold, and never shared with other clients.
  • We don’t name clients publicly, or use them as references, without their written permission.
  • Evidence and working data get destroyed at the end of the retention period agreed in the contract. If no period is agreed, we ask before keeping anything beyond delivery of the final report and its retest.
  • Any personal data we run into incidentally during testing is treated as the client’s data, reported only to the extent needed to demonstrate the finding, and not retained afterwards.

Vulnerability reports about us

If you’ve found a security issue in our own infrastructure, we want to hear about it and we’ll respond within 72 hours. We won’t pursue legal action against anyone acting in good faith who reports a genuine issue and gives us a reasonable opportunity to fix it before disclosing it.

Your rights

You can ask us what personal data we hold about you, ask for it to be corrected, or ask for it to be deleted. Contact us and we’ll action it. We don’t require you to justify the request, and we won’t charge you for it.

Depending on where you live, you may have additional statutory rights, including under the GDPR or the CCPA. We’ll honor those rights whether or not we’re strictly required to.

Contact

Questions about this policy, or about how we handle data on an engagement, can be sent through our contact page.

Changes to this policy

If this policy changes materially we’ll update the date at the top of the page. We won’t quietly broaden what we collect and backdate the change.