Effective date: March 14, 2026
Last updated: August 16, 2026
Hijack Security LLC (“we,” “us”) operates www.hijacksecurity.com. This policy explains what data we collect, why, and what we do with it.
What We Collect
Contact form
- Name, email, company, and message
- Submitted voluntarily when you reach out to us
Server logs
- IP address, user agent, request path, and timestamps
- Collected automatically on every request
- Used for security monitoring and abuse prevention
- Retained for 30 days, then deleted
Product analytics
- Page views, including navigation within the site
- Clicks on the “Start free” button
- Campaign redirects, when you arrive through a /go/ link
- Campaign tags in the URL (utm_source, utm_medium, utm_campaign, utm_content, utm_term), recorded alongside those events
- Which environment the event came from, so test traffic stays out of production numbers
- Processed by PostHog Cloud in the US region
How the analytics work: Analytics run without cookies. Nothing is written to your browser that outlives the tab — no cookie, no localStorage entry, no identifier that follows you to your next visit. Session recording is off. Behavioural autocapture is off. Surveys are off. We record the events listed above, and nothing else.
If your browser sends Do Not Track, the analytics script is never downloaded. That check runs in our own code before any request to PostHog is made, so a Do Not Track visitor loads nothing at all.
What we don't collect: No tracking pixels. No ad networks. No social media widgets. No advertising or cross-site profiles, and no profile at all for anonymous visitors. Form contents never reach our analytics provider — anything you type into the contact or waitlist forms goes to us and stops there. The only client-side storage on this site is a theme preference (light/dark mode) in your browser's localStorage, which contains no personal information.
How We Use Your Data
- Contact submissions: To respond to your inquiry. We don't add you to marketing lists.
- Server logs: To detect abuse, debug issues, and monitor uptime.
- Product analytics: To see which pages people read and which campaigns bring them here. Aggregate only — we're measuring the site, not the visitor.
We don't sell your data. We don't share it with advertisers. We don't use it to build profiles.
Where We Store It
Form submissions are stored in AWS DynamoDB in the us-east-1 (N. Virginia) region. Data is encrypted at rest using AWS-managed keys and in transit via TLS 1.2+.
Access is restricted to authorized personnel only, secured through IAM roles and least-privilege policies.
Analytics events are processed and stored by PostHog in the United States. They contain the event details listed above and no form contents, email addresses, or account identifiers.
Who We Share It With
We don't sell or rent your personal information.
We use these service providers to operate the site:
- AWS (hosting, database, infrastructure) — AWS Privacy Notice (opens in new tab)
- PostHog (product analytics, US region) — PostHog Privacy Policy (opens in new tab)
If required by law — a valid subpoena, court order, or legal process — we will disclose information as necessary. We'll notify you if legally permitted to do so.
Your Rights
If you're in the EU/EEA (GDPR): You have the right to access, correct, delete, port, or restrict processing of your personal data. Our lawful basis for processing is consent (you chose to submit the form), legitimate interest (responding to your inquiry, and understanding how the site is used through cookieless, non-identifying analytics), and legal obligation where one applies.
If you're in California (CCPA): You have the right to know what data we've collected, request deletion, and opt out of sale. We don't sell personal information, so there's nothing to opt out of.
Everyone: You can request access to, correction of, or deletion of your data at any time.
To exercise any of these rights: Email us at privacy@hijacksecurity.com. We'll respond within 30 days. No verification hoops — we'll confirm your identity via the email address on file and process your request.
Children
This website is not directed at anyone under 13. We don't knowingly collect data from children. If we learn we've collected information from a child under 13, we'll delete it immediately.
Changes
If we make material changes to this policy, we'll update the “Last updated” date at the top and post the revised policy here. For significant changes, we'll notify anyone who has contacted us via email at the address they provided.
Contact
Questions about this policy or your data?
Email: privacy@hijacksecurity.com
