Privacy Policy
How SqueHub collects, uses, shares, protects, and retains personal information across its official website and services.
- Published
- 2026-10-08
- Last updated
- 2026-10-08
1. About this policy
This Privacy Policy explains how the operator of the official SqueHub website and SqueHub-operated services (SqueHub, we, us, or our) handles personal information. It applies to squehub.com, official SqueHub forms and editorial systems, and any hosted service that links directly to this policy.
The SqueHub PHP framework is open-source software that developers can install and operate independently. When another person or organization runs a website or application built with SqueHub, that operator—not the SqueHub project—decides how information in that deployment is collected and used. This policy does not govern an independent deployment merely because it uses the framework.
SqueHub is responsible for the processing described in this policy to the extent it determines why and how that processing occurs. Questions or privacy requests may be sent to hello@squehub.com with the subject Privacy request.
2. Information we collect
We collect only information reasonably connected to operating, securing, improving, and communicating about SqueHub.
Information you provide
Depending on how you interact with an official SqueHub service, you may provide:
- your name, email address, username, organization, role, location, or other profile details;
- the contents of messages, support requests, partnership enquiries, policy questions, and other correspondence;
- career-application information, including a résumé or CV, cover letter, work history, skills, portfolio, GitHub or LinkedIn profile, availability, compensation information, and answers submitted for a role;
- account and authentication information for authorized editors or service users, including password hashes, session records, security status, and role assignments;
- content and files submitted through an authorized editorial account, such as posts, profile text, images, videos, metadata, and change history;
- copyright notices, counter-notices, trademark requests, and information needed to assess or respond to a legal request; and
- information supplied under a service agreement, order form, data-processing agreement, or other commercial relationship.
Do not send passwords, private keys, access tokens, production datasets, special-category data, government identifiers, financial account numbers, or other sensitive material unless SqueHub has expressly requested it through an approved secure process.
Information collected automatically
When you access an official SqueHub website or hosted service, the hosting and security infrastructure may process technical information such as:
- IP address and approximate network location;
- request date and time, requested URL, referrer, response status, and transferred bytes;
- browser, device, operating system, language, and user-agent information;
- session and security-cookie identifiers;
- error, availability, rate-limit, abuse-prevention, and diagnostic events; and
- activity associated with an authenticated administrative or service account.
This information is generally generated by the request, the browser, or the infrastructure used to deliver the service. We do not use technical logs to create advertising profiles.
Information from other sources
We may receive information from:
- public source-code, package, issue, pull-request, or community platforms when you interact with an official SqueHub project;
- service providers that help deliver hosting, security, email, support, or recruitment functions;
- a person who refers you for a role or introduces an organization to SqueHub; or
- public professional sources when reasonably necessary to assess a partnership, security report, contribution, or job application.
If another person provides information about you, they should have authority to do so and should direct you to this policy where appropriate.
3. How and why we use information
We may use personal information to:
- Provide requested services. Deliver pages and downloads, operate authenticated features, respond to enquiries, administer accounts, and perform an agreement.
- Operate the project. Maintain documentation, repositories, release information, Packages, Kits, community resources, contribution records, and public attribution.
- Recruit and manage opportunities. Receive applications, communicate with candidates, assess suitability, arrange interviews, verify information with permission, and maintain defensible recruitment records.
- Protect SqueHub and its users. Authenticate users, control access, prevent abuse, investigate suspicious activity, preserve service integrity, enforce policies, and respond to security incidents.
- Maintain and improve services. Diagnose failures, understand aggregate usage, test changes, plan capacity, improve accessibility and performance, and keep records needed for reliable operation.
- Communicate. Send service notices, security messages, requested updates, responses, and information about a relationship with SqueHub. Promotional messages, if introduced, will include legally required choices.
- Meet legal and governance obligations. Handle rights requests, copyright or trademark matters, comply with lawful process, establish or defend claims, maintain financial or compliance records, and protect legal rights.
Where law requires a legal basis, the basis depends on the context. Processing may be necessary to perform a contract or take requested pre-contract steps; comply with law; protect vital interests; pursue legitimate interests such as security, project administration, recruitment, service improvement, and fraud prevention; or act on consent. When consent is the basis, it may be withdrawn for future processing without affecting processing already completed lawfully.
We balance legitimate interests against the rights and reasonable expectations of affected people. You may ask for information about the basis that applies to a specific activity.
4. Public content and open-source activity
Information intentionally submitted to a public repository, issue tracker, discussion, package listing, author page, blog post, release record, or community forum may be visible worldwide and may be copied, indexed, forked, archived, or redistributed by others. Public version-control history is designed to preserve attribution and project integrity; removing it may be technically or legally impractical.
Before publishing, avoid including private contact details, credentials, secrets, third-party personal information, or material you are not authorized to share. If public content exposes a security secret or personal information unexpectedly, contact us promptly and identify the exact URL. We will assess the request, but removal from SqueHub-controlled pages cannot guarantee removal from mirrors, forks, caches, archives, or search indexes controlled by others.
5. Career applications
Career applications are used to evaluate the role identified in the form, communicate with the applicant, maintain interview and decision records, prevent duplicate or abusive submissions, and meet legal obligations. Application materials are not published through the public careers page.
Access is limited to authorized personnel and service providers with a business need. We may retain information about an unsuccessful application for a reasonable period to answer questions, demonstrate a fair process, resolve disputes, or consider the applicant for another role where permitted. If we want to retain an application for materially different future opportunities and consent is required, we will request it.
Applicants should provide professional information relevant to the role and should not include special-category information unless specifically and lawfully requested. References or background checks, if required, will be addressed separately and with appropriate notice.
6. Cookies and device storage
Official SqueHub pages may use a first-party session cookie for requested features, security, CSRF protection, and authorized editorial access. Documentation and editorial interfaces may store a theme preference in browser local storage. The current public website does not use third-party advertising cookies or cross-site behavioral advertising trackers.
The Cookie Policy provides the current technology names, purposes, duration, and controls. If non-essential analytics, advertising, or other optional storage is introduced, SqueHub will update that notice and obtain consent where required before enabling it.
7. When we share information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
We may disclose information to:
- hosting, infrastructure, content-delivery, security, email, storage, support, recruitment, and professional-service providers that process information for defined purposes;
- collaborators or maintainers who need access to operate an official project or respond to a request;
- a customer, supplier, or partner where disclosure is necessary for the relationship and consistent with the notice provided;
- law enforcement, regulators, courts, or other parties when required by valid legal process or reasonably necessary to protect rights, safety, security, and service integrity; or
- a successor or participant in a bona fide restructuring, financing, acquisition, or transfer, subject to appropriate confidentiality and notice requirements.
Providers are expected to use information only for authorized services, protect it appropriately, and comply with applicable contractual and legal duties. Links to external websites—including GitHub, LinkedIn, X, Discord, and other community services—are governed by those services' own privacy practices once you visit them.
8. International processing
The internet, open-source collaboration, and infrastructure providers can involve processing in more than one country. Privacy protections and government-access rules differ by location.
Where law restricts an international transfer, we use an available lawful mechanism appropriate to the relationship, which may include an adequacy decision, approved contractual clauses, supplementary safeguards, or a permitted derogation. An executed customer agreement may identify specific hosting locations, subprocessors, and transfer terms. You may contact us for information about safeguards relevant to a specific SqueHub-operated service.
9. Retention
We retain information only for as long as reasonably necessary for the purpose collected, a compatible documented purpose, security, dispute resolution, or a legal obligation. The actual period depends on the record:
| Record | General retention approach |
|---|---|
| Routine web and security logs | Kept for a bounded operational period, then deleted, aggregated, or de-identified unless an incident requires longer preservation. |
| Contact and support correspondence | Kept while the request is active and for a reasonable follow-up and accountability period. |
| Career applications | Kept through the recruitment process and a limited period afterward for follow-up, legal, and process-integrity needs. |
| Authorized account records | Kept while the account or operational need exists, plus a reasonable security and audit period after closure. |
| Public project records | May be retained long term to preserve releases, attribution, licensing, security history, and source integrity. |
| Legal, financial, and agreement records | Kept for the period required by law or reasonably needed to establish, exercise, or defend rights. |
| Backups | Removed through bounded backup rotation unless preservation is required for recovery, security, or law. |
When information is no longer required, we delete it, anonymize it, or place it beyond ordinary use until secure deletion is completed. A deletion request does not require removal of information that must be retained by law, is necessary for legal claims or security, or forms part of an immutable public project history where lawful retention interests prevail.
10. Security
SqueHub uses administrative, technical, and organizational measures designed for the nature of the service and information involved. These may include least-privilege access, password hashing, multifactor or session controls where configured, CSRF protection, rate limiting, secure transport, input validation, audit and diagnostic controls, backups, dependency maintenance, incident response, and restricted administrative routes.
No website, storage system, or transmission method can guarantee absolute security. You are responsible for protecting your own credentials and devices, using unique passwords, applying security updates, and notifying us if you suspect unauthorized access. Never send a password or private key by email.
11. Your privacy choices and rights
Depending on your location and the processing, you may have rights to:
- request access to personal information and information about its use;
- correct inaccurate or incomplete information;
- request deletion in circumstances provided by law;
- restrict or object to certain processing;
- receive certain information in a portable format;
- withdraw consent for future processing;
- opt out of qualifying direct marketing or data sharing; and
- complain to a competent data-protection authority.
To make a request, email hello@squehub.com with the subject Privacy request and describe the service and request. Do not send a password, private key, or unnecessary identity document. We may request proportionate information to verify identity and authority before disclosing, correcting, or deleting information. An authorized agent may be required to demonstrate authority.
Some rights are subject to exceptions. We may retain or withhold information where necessary to protect another person's rights, preserve security, comply with law, maintain privileged material, or establish or defend claims. We will explain a material denial when legally permitted.
12. Children
Official SqueHub services are directed to developers, organizations, contributors, job applicants, and other professional users. They are not designed for children below the age at which they may independently consent to the relevant processing. We do not knowingly solicit personal information from a child through the public website.
If you believe a child submitted personal information without valid authorization, contact hello@squehub.com with enough detail to locate the information. Do not send additional information about the child unless requested through a secure process.
13. Automated decisions, advertising, and browser signals
SqueHub does not currently use personal information from the public website to make solely automated decisions that produce legal or similarly significant effects. We do not currently operate cross-site behavioral advertising on the public website.
Because there is no qualifying advertising sale or sharing to disable, browser signals such as Global Privacy Control do not currently change advertising behavior on this site. We will review this position if our practices change. General “Do Not Track” signals do not have one universally accepted technical meaning; we respond through the controls and rights described in this policy.
14. Changes to this policy
We may update this policy when services, technology, laws, or project practices change. The public page displays its last-updated date. Material changes may also be announced through an appropriate service or project channel. The version in effect when processing occurs governs that processing, subject to mandatory law.
15. Contact
For privacy questions, rights requests, or concerns, email hello@squehub.com with the subject Privacy request. Include the relevant service, URL, account or application reference, and the right or concern involved. Do not include credentials or unrelated sensitive material.
If you are not satisfied with our response, you may contact the data-protection authority or regulator available under the law that applies to you.

