Notice of Updates to Privacy Policy
MacStadium Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Overview

Welcome to MacStadium's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.

If you need to request that our GRC team complete a custom questionnaire or online assessment as part of your vendor evaluation process, please submit the document or URL through this trust center after requesting portal access above and then create security@macstadium.com as the user account in your vendor platform. Please be advised that email requests will not be fulfilled without a registered account and submission of your request through the trust center portal.

  • ING
  • Delta
  • Pandora
  • Sauce Labs
  • Dropbox
  • Shopify
  • Delta Air Lines
  • Capital One
  • AppDynamics
  • Nubank
  • J.P. Morgan & Co.
  • Johnson & Johnson
  • Accenture
  • GitLab
  • Bitrise
  • Homebrew
  • Box
  • Thumbtack
  • iFood
  • Slack
  • Wix.com
  • Jamf
  • Swift App School
  • Glovo

Documents

Featured Documents

REPORTSISO 27001 Audit Report

Trust Center Updates

Notice of Updates to Privacy Policy

Copy link
General

MacStadium has updated our Privacy Policy, effective 08/07/2026. These updates strengthen your privacy rights and reflect current legal requirements. We encourage you to review the full policy here: https://macstadium.com/privacy-policy

Summary of key updates:

  • Legal bases for processing (GDPR/UK GDPR): We've clarified the legal bases we rely on to process your personal data, and added specific provisions for handling special category data where applicable.

  • Opt-out preference signals (GPC): We now recognize and honor Global Privacy Control (GPC) signals as a valid method of opting out of the sale/sharing of personal information, in addition to other opt-out methods.

  • Right to lodge a complaint: If you're in the EU/UK, we've clarified your right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.

  • CCPA response timing: We've updated the timeframes in which we respond to consumer requests under the California Consumer Privacy Act (CCPA), and clarified your right to limit the use of sensitive personal information.

  • International data transfers: We've added detail on the safeguards we use when transferring personal data internationally (e.g., Standard Contractual Clauses or other approved mechanisms).

  • Cookie consent: We've updated our cookie practices and consent mechanisms to give you clearer choices over non-essential cookies and tracking technologies.

  • Notice of future changes: We've clarified how we'll notify you of material changes to this policy going forward.

What this means for you:

No action is required on your part. Your continued use of MacStadium’s products/services after 08/07/2026 constitutes acceptance of the updated Privacy Policy.

Have questions?

If you have questions about these changes or want to exercise any of your privacy rights, contact us at privacy@macstadium.com or visit https://macstadium.com/privacy-policy-opt-out

Thank you for trusting us with your information.

Best regards,

MacStadium Data Privacy Team
3340 Peachtree Rd NE, Suite 2330, Atlanta, GA 30326

React2Shell (CVE-2025-55182)

Vulnerabilities

MacStadium received initial intelligence of a proof-of-concept on this threat Thursday December 4th at 12:00 noon ET and began conducting internal vulnerability scans and threat hunting activities in coordination with our SOC team. No unpatched systems or indicators of compromise were detected in any of our infrastructure environments at that time. Internal and external vulnerability scans were executed again over the weekend and confirmed that no vulnerable instances of Next.js exist within MacStadium’s infrastructure environment.

MacStadium's devops team has confirmed that there were no vulnerable instances of Next.js within any of our software development projects. As part of our CI/CD processes, we have branch protection rules that utilize Renovate to update libraries and Trivey to identify vulnerabilities in the enforcement of our zero-cve policy for all software releases.

Our GRC team has also been engaging with our third-party critical vendors and sub processors to inquire about their potential exposure to the threat and no potential for impact has been identified at this time. We continue to monitor responses from our Nth party vendors for any additional risk exposure and will provide any updates as they are received.

ISO 27001 Annual Report

Compliance

MacStadium's latest ISO 27001/27017/27018 second surveillance audit report is now available for review and download. We are pleased to announce that no major or minor control nonconformities were identified in the review period, reinforcing a high level of confidence in MacStadium's processes and security controls designed to protect our client's systems, users, and data.

Please reach out to security@macstadium.com with any questions or to initiate a vendor risk analysis.

The MacStadium Security & Compliance Team

2025 Annual Orka Penetration Testing

Vulnerabilities

MacStadium's 2025 annual penetration testing engagement performed by 4Armed Limited (https://4armed.com/) has been completed and the report is now available for review and download within the trust center.

Sub-Processor Addition Notification: HubSpot

Subprocessors

MacStadium is committed to protecting the security and privacy of the personal data you entrust with us. To continue delivering the highest quality of service, we periodically update the third-party vendors and service providers ("sub-processors") that assist us in providing MacStadium services. These sub-processors help us to deliver product features, improve customer support, maintain critical infrastructure, and enhance service reliability.

In accordance with our contractual obligations, this notice is to inform you of the addition of the following subprocessor, with the intent to commence on September 5th, 2025:

Sub-processor: HubSpot
Headquarters Location: United States
Location of hosting: United States and European Union

Service Provided: HubSpot is used for marketing automation, including email campaigns, lead capture, customer engagement tracking, and CRM integration.

Data Handled: First name. last name, email address, physical address, and phone number

HubSpot’s primary security focus is to safeguard our customers’ data. To this end, HubSpot has implemented a comprehensive security program, with teams dedicated to Corporate, Product, Infrastructure, and Physical Security that partner with Compliance, Legal, and Privacy to own the governance process. Our Chief Information Security Officer oversees the implementation of security safeguards across the HubSpot enterprise.

More information on HubSpot's security practices can be found at https://trust.hubspot.com

Effective Date: September 05, 2025 Reason for Use: The MacStadium marketing department is implementing HubSpot's marketing automation and customer engagement platform

What You Need to Do

No action is required on your part if you agree to these updates. However, if you wish to object to our use of this new MacStadium sub-processor for reasons related to data protection, please send an email to privacy@macstadium.com within thirty (30) days of this notification with both:

  • The subject “Sub-processor Objection”, and
  • The grounds for the objection.

Please note that MacStadium has undertaken appropriate due diligence to ensure any requirements of MacStadium as it relates to its use of subprocessors has been considered and satisfied. Please also note that this subprocessor update does not result in any changes to the personal data types or categories referenced in any applicable Data Processing Agreement (DPA) or similar such agreement between you and MacStadium.

You may view the full list of MacStadium’s subprocessors in the MacStadium Trust Center by visiting https://trust.macstadium.com/

Thank you for trusting MacStadium to manage your data with the highest standards of security and compliance.

The MacStadium Privacy Team
privacy@macstadium.com

If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo