Privacy Policy & Data Protection.
At Pair2FA, we treat security and privacy as inseparable. This policy details how we collect, process, encrypt, and safeguard your team’s sensitive information in full compliance with global standards.
AES-256-GCM Vault
2FA secrets are encrypted at rest with authenticated AES-256-GCM keys.
Zero Data Monetization
We never sell user data, profile behavior, or share records with advertisers.
1-Click Right to Erasure
Delete your workspace or export seed keys anytime without vendor lock-in.
GDPR & CCPA Ready
Full compliance with EU GDPR, UK DPA, and California CCPA/CPRA regulations.
Information We Collect & Process
Pair2FA collects only the minimal set of data necessary to authenticate users, manage workspace memberships, and securely generate 30-second TOTP verification codes for your team. We divide collected data into four distinct categories:
Account & Identity Data
Full name, email address, password hash (Bcrypt), and OAuth profile tokens provided during registration or Google sign-in.
Vault Metadata & Secrets
Account titles, service labels (AWS, GitHub, Supabase), and encrypted 2FA secret keys. Raw secret keys are encrypted before storage.
Audit & Access Logs
Timestamps, IP addresses, user agent details, and user IDs recording code copy actions for workspace security auditing.
Billing Metadata
Stripe customer and subscription IDs, subscription status, seat counts, and invoice history. Payment card numbers are processed directly by Stripe and never reach our servers.
Zero-Knowledge Vault Encryption Architecture
We implement defense-in-depth cryptographic security to ensure your 2FA secret keys are protected even in the unlikely event of physical infrastructure compromise:
- Authenticated AES-256-GCM: All seed keys are encrypted using Galois/Counter Mode (GCM), ensuring both confidentiality and cryptographic data integrity.
- In-Memory TOTP Processing: Generated 30-second verification passcodes are computed ephemerally in RAM and are never written to server logs or disk storage.
- TLS 1.3 In-Transit Security: All client-to-server traffic is enforced using HTTPS with HSTS and TLS 1.3 encryption.
Third-Party Subprocessors & Infrastructure
Pair2FA partners strictly with enterprise cloud subprocessors meeting SOC 2 Type II and ISO 27001 compliance standards. Data is shared only to maintain service operations:
| Subprocessor | Purpose | Location | Compliance |
|---|---|---|---|
| Vercel Inc. | Edge Hosting & Serverless Execution | United States / Global CDN | SOC 2 Type II, ISO 27001 |
| Amazon Web Services (AWS) | Encrypted Database Vault Storage | US-East (N. Virginia) | SOC 1/2/3, ISO 27001, HIPAA |
| Stripe, Inc. | Payment Processing & Subscription Billing | United States / Global | PCI-DSS Level 1 |
| Resend / SendGrid | Transactional Member Invite Notifications | United States | SOC 2 Type II, GDPR Compliant |
Data Retention & Immediate Erasure Rights
We retain workspace data only as long as your workspace remains active. When an owner initiates workspace deletion:
- All encrypted TOTP keys, shared accounts, and access roles are permanently purged from primary production databases within 24 hours.
- Backup snapshots rotate and hard-expire completely within 14 business days.
- You may request a raw JSON/CSV export of all stored secrets prior to workspace closure to prevent lock-in.
Global Privacy Rights (GDPR & CCPA/CPRA)
Depending on your location, you hold explicit statutory privacy rights under EU GDPR, UK DPA, or California CCPA/CPRA:
Data Protection Officer (DPO)
Questions about our privacy compliance or exercising legal rights?
