Legal
Privacy
What we store, where it lives, and how to get it back or deleted.
Last updated: 4 August 2026
Who we are
PatchBee is operated by Elevate Solutions, Bosnia and Herzegovina. For anything in this policy, write to contact@patchbee.io.
The short version
We store what we need to run your workspace and invoice it, nothing more. The marketing site you are reading counts visits with cookieless analytics that cannot identify you and sets no tracking cookies on its own. Two things are strictly opt-in and off unless you say yes: recording a session to show us where the site confuses people (never anything you type), and letting LinkedIn measure whether its ads brought you here. We do not sell data, and we do not use your data to train anything.
What we store when you use the app
From your Microsoft Entra sign-in:
- Your Entra object id, email address and display name
- Your organisation's Entra tenant id
What you type when you set the workspace up:
- Company name, your role, rough fleet size, and how you heard about us
What the product produces as you use it:
- The apps you package and publish, and the packaging jobs behind them
- An activity log of actions taken in your workspace, so you can see who did what
- A count of Intune-managed devices in the tenants you connect, which is what your plan is measured against
- Credentials for the Intune tenants you connect, encrypted at rest
Data about your employees, and our role
When you view install status for an app, PatchBee reads the report from Microsoft Intune and caches it so the screen loads quickly. That cache contains, per device: device name, the user principal name (an email address), install state, any error code, OS version, and the last sync time.
That is personal data about your people, and you are its controller. We hold it only to show it back to you, we do not use it for anything else, and it is deleted with the rest of your workspace. If you need a formal data processing agreement, ask and we will provide one.
Where it is hosted
Microsoft Azure, in the West Europe region. Databases and stored packages stay in that region. Signing in and everything PatchBee does inside your Intune tenant goes through Microsoft Graph, so Microsoft is a processor for that traffic. Email we send you is delivered through Microsoft 365.
Permissions we ask for
PatchBee asks for the least-privilege Microsoft Graph permissions it needs to publish apps and assign them to the groups you pick. It does not request scopes it does not use, and nothing reaches your tenant until you approve it. Connection secrets are encrypted at rest and are never shown back to you or written to logs.
Payments
There is no payment processor and no card details anywhere in PatchBee. Paid plans are invoiced by email, so the only billing data we hold is the contact details above and what we need to raise that invoice.
Cookies and analytics on this website
Unless you opt in below, this marketing site sets no cookies for analytics, advertising or tracking. The one thing it always stores in your browser is your answer to the privacy question, so we can honour it without asking again.
There are three separate things here, and only the last two ask permission: counting visits, which is anonymous and runs for everyone; recording sessions, which is off unless you turn it on; and LinkedIn ad measurement, which is also off unless you turn it on.
To know which pages are worth writing, we count visits using Umami, which we run ourselves on our own servers. Your data is never sent to a third-party analytics company. It records:
- The page you viewed, and the site or campaign you arrived from
- Your country, and approximate region or city derived from your IP address
- Device type, browser, operating system and screen size
- Whether you clicked one of our main buttons, such as "Start free"
It sets no cookies and does no cross-site tracking. Your full IP address is never stored: it is used in passing to derive the country and then discarded.
To avoid counting one person twice, a visit is grouped under a one-way hash of your IP address and browser, mixed with a secret that rotates every day. That hash cannot be reversed into your IP, is not shared between websites, and is useless tomorrow, so we cannot follow you between sites or recognise you on a later visit. We hold no identifier that could single you out, which is why this part needs no consent under GDPR and ePrivacy: there is genuinely nothing to consent to. If you would rather not be counted at all, any tracker blocker will stop it, and we honour your browser's Do Not Track setting.
The app at app.patchbee.io stores sign-in tokens in your browser. Those are strictly necessary to keep you signed in and are not used to track you.
Session recording (off unless you allow it)
Separately from the counting above, we can record a session on this marketing site: mouse movement, clicks and scrolling, replayed as a silent, cursor-level reconstruction of the page, and aggregated into heatmaps. It exists for one reason, to show us where the site confuses people, which no chart ever tells us.
Unlike the counting, this is personal data, so we treat it that way rather than arguing otherwise:
- It is off by default and nothing is recorded until you choose "Allow". Ignoring the question leaves it off.
- Nothing you type is captured. Forms and input fields, including the contact form, are excluded outright, and text on the page is masked in the recording.
- It covers patchbee.io only, never the app at app.patchbee.io, and never anything you do on other websites.
- Recordings are capped at 5 minutes, stored on our own servers, and never sold or shared.
- You can withdraw at any time, below. It stops immediately, not at the end of the visit.
LinkedIn ad measurement (off unless you allow it)
We run ads on LinkedIn. If you allow it, this site loads LinkedIn's Insight Tag, which tells us whether those ads actually bring people here and lets us show follow-up ads on LinkedIn to people who visited. Practically, it means LinkedIn learns that your browser opened pages on patchbee.io; if you are logged in to LinkedIn, LinkedIn can connect that visit to your LinkedIn account. We never see who you are, only aggregate campaign numbers.
- It is off by default and nothing loads, and no request reaches LinkedIn, until you choose "Allow". Ignoring the question leaves it off.
- It covers patchbee.io only, never the app at app.patchbee.io.
- LinkedIn acts as its own controller for this data under LinkedIn's privacy policy.
- You can withdraw at any time, below, separately from session recording. It stops immediately, not at the end of the visit.
Checking…
Checking…
These choices are stored in this browser only, so they do not follow you to another device. Basic cookieless analytics are unaffected either way.
How long we keep it
For as long as your workspace exists. Ask us to delete it and we remove the workspace and its data; apps you already published stay in your own Intune tenant, because they are yours. Invoicing records are kept as long as accounting rules require.
Your rights
If you are in the EU or EEA, you can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to contact@patchbee.io and we will answer, usually within one business day.
Changes
If this policy changes in a way that affects you, we will say so on this page and update the date at the top.