Privacy policy
What Third Party Index collects about the people who use it, why, for how long, and what you can do about it. Last updated 2026-09-29.
Third Party Index (thirdpartyindex.com) is run by Yellow Camper Industries, LLC, in the United States (“we”). We are the controller of the personal data described here. In short: you can read the whole site without an account; if you sign in, we keep your email address and what’s needed to run your API keys; we have no advertising, sell nothing and track no one across sites.
When you visit
- Server logs. Our web server records each request: your IP address, the time, the page, the referring page and your browser’s user agent. We use them to keep the site running and secure (errors, abuse, rate limits). They are deleted after 14 days.
- Cloudflare. The site is delivered through Cloudflare, which handles every request on our behalf (network delivery, caching, protection from attacks) and processes your IP address to do so.
- Analytics. We count page views with Cloudflare Web Analytics, which uses no cookies and doesn’t identify or follow you. We see totals (pages, referrers, countries, browsers), not individuals.
- No cookies are set when you just read the site.
When you sign in
An account is only needed for API keys. You sign in with Google or GitHub; we never see your password there.
- Account: your verified email address, the name your provider shares (if any), which provider you used and its id for your account, and when you last signed in. We ask the provider for no more than that (Google:
openid email profile; GitHub:read:user user:email). - Sessions: a cookie keeps you signed in for up to 30 days. We store only a hash of it, with your browser’s user agent, until you sign out or it expires.
- API keys: each key’s name, its prefix, a hash of the key (never the key itself), when it was created and last used, its daily request counts, and whether you deleted it (a deleted key stops working but stays listed in our records until you delete your account).
We use this to run your account and keys: signing you in, authenticating and rate-limiting requests, showing you your usage, and contacting you about your account or the service if we must.
Cookies
Only two, both needed for signing in, neither used for tracking:
| Cookie | Purpose | Lasts |
|---|---|---|
vti_oauth | Protects the sign-in round trip to Google or GitHub | 10 minutes |
vti_session | Keeps you signed in | 30 days, or until you sign out |
Who else handles it
We don’t sell or rent personal data, share it for advertising, or use it to profile you. Service providers process it for us, under their terms:
- Cloudflare: delivery, security and page-view counts (every visit).
- DigitalOcean: hosting; our server and database are in the United States.
- Google or GitHub: only if you sign in with them, under their own privacy policies.
We may disclose data if the law requires it, or to protect the site and its users from abuse. If Yellow Camper Industries, LLC or the site changes hands, this policy goes with it and we will say so here.
Legal bases
If you are in the EU, UK or a similar jurisdiction: account and API-key data are processed to provide the service you asked for (a contract with you); server logs and page-view counts on our legitimate interest in running a secure, working website. Your data is processed in the United States.
Your choices and rights
- Delete your account yourself on your account page: your email address, name, sign-in identities, sessions, API keys and their usage are erased at once. Server logs expire within 14 days.
- You can ask us for a copy of your data, to correct it, or to stop processing it. Depending on where you live (for example the EU, UK or California), these are legal rights; we honour them for everyone. You may also complain to your data-protection authority.
- We don’t sell or “share” personal information as California law defines those terms.
Companies’ documents on the site
The rest of the site is about companies, not people: vendors’ public security and privacy documents, kept as evidence, and what we read from them. Those documents can include what a company chose to publish, such as a security contact address. If something about you appears in them and you want it removed from our copies, write to us.
Children
The site is for professionals and isn’t directed at children under 16. We don’t knowingly keep their data.
Changes
We will update this page when what we collect changes, with a new date at the top. If a change matters for account holders, we will tell them by email before it applies.
Contact
A contact address for privacy requests will be published here shortly. Meanwhile, account holders can delete their account themselves on the account page.