Privacy Policy

Privacy Policy

At Varpath, protecting your privacy is central to how we operate. This policy explains what data we collect, what we don’t collect, how we use it, and the choices you have when interacting with our website, purchasing products, or using our managed cybersecurity services.


1. Information We Collect

Personal and Account Information (When You Purchase or Contact Us)

  • Name, email, phone number

  • Billing and shipping address

  • Payment details

  • Optional account login credentials

Service Information (When You Use Our Security Services)

To deliver, maintain, and secure your environment, we may collect:

  • System logs and configuration data

  • IP addresses associated with your business systems

  • Security-related event data needed to detect and stop threats

Automatically Collected Website Data

  • Cookies and analytics

  • General browsing behavior on our website (not tied to your employees’ internal browsing)


2. What We Do Not Collect

Our solution is intentionally built to protect employee privacy. We do not:

  • Monitor individual employee web-browsing patterns

  • Track specific URLs visited by employees

  • Build profiles of employee internet usage

  • Record personal browsing history

  • Surveil individual online activity

The only exception is in the case of a verified malware or security incident, where a malicious source URL may be briefly retained as part of threat analysis. This data is stored only temporarily.


3. What We Do Collect for Security Purposes

To provide effective cybersecurity and help you maintain compliance readiness, we collect only what is necessary:

  • Security threat data
    Blocked malicious domains, phishing attempts, and critical alerts.

  • Policy-enforcement metrics
    Anonymous, aggregated counts of rule triggers (e.g., “5 attempts to access a blocked category today”).

  • System configuration data
    The guardrails and policies you define for how business resources should be used.

Whenever possible, data is anonymized and aggregated to protect individual privacy while ensuring security accuracy.


4. How We Use Your Information

We use collected data only to:

  • Protect your business by detecting, blocking, and reporting security threats

  • Enforce the guardrails you define for safe use of business resources

  • Generate security reports containing aggregated insights, not individual behavior profiles

  • Support compliance readiness by maintaining short-term logs for legitimate security purposes

  • Improve our platform and support experience

We do not use service data for marketing.


5. Your Control

As a business owner or manager, you decide:

  • Which security policies and guardrails are active

  • What content categories are restricted

  • How long certain security logs are retained (beyond the default, if required)

  • Who within your organization can access security reporting


6. Data Retention

Security-event data is kept for 30 days to support investigations and compliance needs. After this period, it is automatically deleted unless you extend retention for compliance reasons.

Malicious-source URLs related to confirmed threats are held only temporarily.


7. Data Security

We apply strong safeguards including encryption, secure infrastructure, and limited-access controls—to protect your information. While we maintain high security standards, no system can guarantee absolute protection.


8. Cookies

Cookies help us understand website performance and improve your experience. You may adjust your browser settings to limit or block cookies.


9. Sharing Your Information

Varpath is a privacy-focused organization. We:

  • Do not sell or rent your personal data

  • Do not retain or share individual browsing URLs, except temporarily during a verified malware event

  • Do not share personal data with shipping partners, IT vendors, or similar service providers

We may disclose information only when legally required (e.g., subpoena or court order).


10. Your Rights

Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the right to:

  • Access, correct, or delete your personal data

  • Opt out of marketing communications

  • Request a copy of your data in a portable format


11. Contact Us

If you have questions about this policy or how we protect both your business and employee privacy, please contact us:

Email: help@varpath.com
Address: 50 California St., Suite 1500, San Francisco, CA 94111