Privacy Policy
FinOps Beacon is operated by Bryan Wrinkle, an individual based in Fentress County, Tennessee, United States ("FinOps Beacon," "we," "us," or "our"). This policy explains how we handle personal information when you visit or use the Azure cost-analysis service. If your employer or another organization provides your account, that organization also controls your use of its workspace and Azure data.
Information we collect
We collect information you or your organization provide, including names, email addresses, organization names, team roles, alert destinations, support messages, account activity, and subscription and billing status. To connect Azure, we process tenant, application, and subscription identifiers and either an encrypted application secret or an encrypted Microsoft refresh credential. When you purchase a paid plan, Stripe collects and processes payment-card and billing details on its hosted pages; FinOps Beacon receives identifiers, plan, payment status, renewal dates, and limited billing contact details, but not full card numbers.
At your direction, we retrieve Azure resource inventory, tags, usage metrics, cost records, budgets, recommendations, and subscription details. We also create scan history, recommendation decisions, notifications, and audit records. Cloudflare and the application receive routine technical information such as IP address, browser and device information, request time, request identifiers, security events, and errors.
Sources of information
Information comes directly from users and organization administrators, from Microsoft when an authorized user connects Azure, and automatically from browsers, servers, and security systems as the service is used. We do not purchase personal information from data brokers.
How we use information
We use information to create and secure accounts, provide tenant-scoped reports, perform requested read-only Azure analysis, maintain cost history, send account and alert messages, provide support, prevent misuse, diagnose failures, maintain backups, meet legal obligations, and improve service reliability. We do not sell personal information, share it for cross-context behavioral advertising, or use customer Azure data for advertising.
Service providers and disclosures
Cloudflare provides application hosting, traffic protection, email relay, and operational logging. Supabase provides PostgreSQL database, backups, and authentication. Microsoft provides identity and Azure APIs at your direction. Stripe provides payment processing, subscription management, invoices, and its hosted customer portal. These providers process information to operate the service. We may also disclose information when required by law, to protect the service or users, or in connection with a merger, financing, acquisition, or sale of assets, subject to appropriate protections.
Browser storage and tracking
The application stores the signed-in Supabase session in the browser and stores a local flag indicating that the onboarding guide has been completed. Cloudflare may use essential cookies or similar technologies for security and traffic management. FinOps Beacon does not currently use third-party advertising trackers. Because there is no advertising or cross-site profiling, browser “Do Not Track” signals do not change the service's behavior.
Security
Connections use HTTPS. Azure application secrets and delegated refresh credentials are encrypted before database storage, while encryption keys are held separately as Cloudflare secrets. Access is tenant-scoped, browser-facing database access is protected by row-level security, and administrative operations require an administrator role. No internet service can promise absolute security.
Retention and deletion
Service data is retained while the organization account is active so the requested historical analysis remains available. Administrators can export an organization summary or permanently delete the organization from Settings. Deleted records can remain in encrypted daily backups for the provider backup window before expiring. Security, fraud-prevention, billing, dispute, or legal records may be retained when reasonably necessary. More detail is in the Data Retention Policy.
Your choices and rights
You may request access, correction, export, or deletion of personal information by emailing support@finopsbeacon.com. Organization administrators control team membership and connected Azure configuration. You may disconnect Microsoft access in the product or revoke it through Microsoft. Depending on where you live, you may also have rights to object, restrict processing, withdraw consent, appeal a request decision, or complain to a privacy regulator. We do not discriminate against users for exercising applicable privacy rights.
International processing
Cloud services may process information in the United States and other countries where their infrastructure or personnel operate. Those locations may have different data-protection laws. Where required, we use contractual and provider safeguards intended to protect transferred information.
Children
FinOps Beacon is a business service and is not directed to children. We do not knowingly collect personal information from children under 13.
Contact and changes
Privacy and security questions can be sent to Bryan Wrinkle, FinOps Beacon, Fentress County, Tennessee, United States, at support@finopsbeacon.com. We may update this policy as the service changes. The effective date identifies the current version, and material changes will be communicated through the service or by email when practical.