Last updated August 1, 2026

Privacy Policy

We believe privacy is a fundamental right. This policy explains what we collect, why, and how we protect it — in plain language.

Effective August 1, 2026  ·  v2.0

🔒

1. Overview

This Privacy Policy describes how [Company Name] ("we," "us," or "our") collects, uses, stores, and discloses information about you when you use our software, websites, mobile applications, APIs, and any other services we provide (collectively, the "Services").

We designed this policy to be readable. No legalese for the sake of it. If something is unclear, reach out — we'd rather you ask than guess.

By using our Services, you agree to the collection and use of information in accordance with this policy. If you disagree with any part, please discontinue use of the Services.

TL;DR: We collect the minimum data needed to run our Services. We don't sell your data. We use industry-standard security. You control your information.
📋

2. Information We Collect

We collect information in three ways: information you give us, information collected automatically, and information from third parties.

2.1 Information You Provide

  • Account Data: When you create an account, we collect your name, email address, and any profile information you choose to provide.
  • Payment Data: For paid Services, we collect billing details. Payment card numbers are processed entirely by our payment processor (e.g., Stripe) — we never see or store your full card number.
  • Communications: When you contact support, send feedback, or otherwise communicate with us, we retain those messages.
  • Content You Create: Any data, files, text, images, or other content you upload, submit, or generate through our Services.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, actions taken, time spent, and navigation paths within our Services.
  • Device Data: Device type, operating system, browser type, IP address, screen resolution, language settings, and mobile device identifiers.
  • Performance Data: Error logs, crash reports, load times, and API response metrics — used exclusively for debugging and improving reliability.
  • Referral Data: The website or source that referred you to our Services (UTM parameters, referrer headers).

2.3 Information We Do NOT Collect

  • Government-issued identification numbers (SSN, passport, driver's license)
  • Sensitive financial data beyond what is required for billing
  • Biometric data or health information
  • Precise geolocation data (we only see IP-based approximate location)
⚙️

3. How We Use Your Information

We use the information we collect for the following purposes — and only these purposes:

  • To Provide the Services: Operate, maintain, and deliver the features and functionality you expect.
  • To Improve the Services: Analyze usage patterns to understand what's working, what's broken, and what to build next.
  • To Communicate: Send transactional messages (receipts, security alerts, account updates) and, with your consent, product updates and newsletters. You can opt out of marketing at any time.
  • To Protect: Detect, prevent, and address fraud, abuse, security incidents, and violations of our terms.
  • To Comply: Meet legal obligations, respond to lawful requests from authorities, and enforce our agreements.

The legal bases for processing your information include: contractual necessity (to provide the Services), legitimate interest (to improve and protect our Services), consent (for marketing and cookies), and legal obligation (where required by law).

🍪

4. Cookies & Tracking Technologies

We use cookies and similar technologies (pixels, local storage, session storage) to keep you signed in, remember your preferences, understand usage, and keep our Services secure.

Types of cookies we use:

  • Essential Cookies: Required for core functionality — authentication, session management, security. These cannot be disabled.
  • Functional Cookies: Remember your preferences (language, theme, region) to personalize your experience.
  • Analytics Cookies: Help us understand how the Services are used so we can improve them. We use privacy-focused analytics where possible.
  • Marketing Cookies: Used only if you've opted in. We don't serve third-party behavioral advertising.

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Services. We honor Do Not Track (DNT) signals where supported by your browser.

🔗

5. Third-Party Services

We rely on a small number of carefully-vetted third-party services to operate our business. Each is contractually bound to handle your data in accordance with this policy and applicable law.

  • Hosting & Infrastructure: Cloud providers (e.g., AWS, Google Cloud, Cloudflare) host our Services and may process data in their data centers.
  • Payment Processing: Payment processors (e.g., Stripe) handle billing transactions. They receive only the information necessary to process your payment.
  • Analytics: We use analytics services to understand usage. Where possible, we configure them to minimize data collection (e.g., anonymized IPs, no cross-site tracking).
  • Communication: Email delivery services and customer support platforms that help us communicate with you.
  • Authentication: If you choose to sign in via a third-party provider (e.g., Google, GitHub), they share your basic profile information with us as you authorize.

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. Period.

🗄️

6. Data Retention

We keep your information only as long as necessary to fulfill the purposes described in this policy — or as required by law.

  • Account Data: Retained for the life of your account. If you delete your account, we remove or anonymize your personal data within 30 days, except where we have a legal obligation to retain it.
  • Usage Data: Retained in aggregated or anonymized form for analytics and product improvement. Individual usage logs are pruned on a rolling basis.
  • Communications: Support conversations and correspondence are retained for up to 2 years after your last interaction for reference.
  • Backups: Data may persist in encrypted backups for up to 90 days before being permanently purged.
🛡️

7. Security

We take the security of your data seriously and implement industry-standard technical and organizational measures to protect it:

  • Encryption in Transit: All communications with our Services use TLS 1.3. We enforce HTTPS with HSTS.
  • Encryption at Rest: User data is encrypted at rest using AES-256. Backups are encrypted.
  • Access Controls: Strict internal access policies. Employees access user data only when necessary to provide support or resolve issues.
  • Infrastructure Security: Our infrastructure runs on major cloud providers with SOC 2, ISO 27001, and PCI DSS certifications.
  • Monitoring: We use automated detection systems to identify unusual activity and potential breaches.
  • Secure Development: Code is reviewed, dependencies are scanned, and we follow secure development lifecycle practices.

No method of transmission or storage is 100% secure. If a breach occurs, we will notify affected users within 72 hours of discovery, as required by applicable law.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete data we hold about you.
  • Erasure: Request deletion of your personal data (commonly known as the "right to be forgotten").
  • Portability: Receive your data in a structured, machine-readable format and transfer it to another service.
  • Restriction: Request that we limit how we process your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests or for direct marketing purposes.
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email us at privacy@[domain].com. We will respond within 30 days. We may need to verify your identity before processing your request. There is no fee for making a request unless it is manifestly unfounded or excessive.

If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority. If you are a California resident, you have rights under the CCPA/CPRA (see below).

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to: (1) know what personal information we collect, use, disclose, and sell (we don't sell); (2) request deletion of your personal information; (3) correct inaccurate personal information; (4) opt out of the sale or sharing of your personal information (again, we don't do this); and (5) not be discriminated against for exercising these rights. To make a request, contact us at privacy@[domain].com with "CCPA Request" in the subject line.

👶

9. Children's Privacy

Our Services are not directed to anyone under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. If we discover we have collected data from a child without verified parental consent, we will delete it within 48 hours.

🌍

10. International Data Transfers

Our Services are operated globally. Your data may be processed in countries other than where you reside — including the United States, where our primary servers are located. These countries may have data protection laws that differ from your jurisdiction.

When we transfer data across borders, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with all third-party processors
  • Technical measures such as encryption and access controls
📝

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services themselves. When we do:

  • We will post the updated policy on this page and update the "Last updated" date at the top.
  • For material changes, we will notify you via email and/or a prominent notice within the Services at least 14 days before the change takes effect.
  • Your continued use of the Services after the effective date constitutes your acceptance of the updated policy.

We maintain a public changelog of all revisions at /privacy/changelog for complete transparency.

📬

12. Contact Us

We're here to help. If you have questions, concerns, or requests about this Privacy Policy or your data:

  • Email: privacy@[domain].com
  • Mail: [Company Name], [Street Address], [City, State ZIP], [Country]
  • Data Protection Officer: dpo@[domain].com

We aim to acknowledge all inquiries within 2 business days and resolve them within 30 days.