Privacy and store data

PatchChain is designed to need as little store data as possible.

What a scan stores

The uploaded composer.lock and patch-status text are parsed for the scan. PatchChain stores the detected Magento version, findings, ordered work, timestamps, and store name/URL. The raw uploaded files are not stored by the application.

What PatchChain does not need

PatchChain does not require Magento Admin credentials, SSH credentials, customer records, order data, payment data, or database access to run the current scan workflow.

Customer control

Signed-in customers can delete an individual store and its scan history. They can also permanently delete their agency account and associated customer data from the Account page.

This product page describes the current application behavior and is not a substitute for a final production privacy policy reviewed for the jurisdictions where PatchChain is offered.