2442sso
2442sso Privacy Policy

Privacy Policy

Last updated: September 9, 2026  ·  Effective immediately

2442sso is an enterprise Single Sign-On (SSO) platform. This Privacy Policy explains how we collect, use, and protect information when you use our identity and authentication services.

1. Information We Collect

When you use 2442sso, we collect:

2. How We Use Your Information

3. Data Storage & Security

All data is stored in encrypted databases. Passwords are hashed using industry-standard algorithms and are never stored in plain text. Sessions are secured with cryptographically random tokens and expire automatically.

All timestamps are stored in UTC. Audit logs are retained for security and compliance purposes and may be reviewed by authorized administrators.

4. Data Sharing

We do not sell your personal data. User identity information (name, email, roles) is shared with connected applications only when you explicitly authenticate via SSO. The data shared is defined by the OpenID Connect standard scopes you authorize.

5. Cookies & Sessions

We use a single secure session cookie to maintain your authenticated state. No tracking or advertising cookies are used. Session data is stored server-side and automatically expires based on the configured session timeout.

6. Your Rights

7. Data Retention

Account data is retained while your account is active. Audit logs are retained for up to 12 months. Expired sessions are purged automatically after 90 days.

8. Contact

For privacy-related requests or questions, contact your system administrator or the organization operating this 2442sso instance.