v2026-09-30Last updated: 2026-09-30Change history

Privacy Policy

What personal data we collect, why, how long we keep it, and the rights you have over it.

Who we are

[Company] ([legal entity], [address], [jurisdiction]) is the data controller for the personal data described in this policy. Contact us at [privacy@your-saas.com] with any privacy question or to exercise your rights.

What we collect

We collect only what we need to run the service:

  • Account data — your name, email, and (if you sign in with a provider) your provider profile and avatar.
  • Authentication data — a password hash and/or OAuth identifiers, plus session records (token, browser/user-agent, and a coarse network location used to flag new-device sign-ins).
  • Organization data — your workspace membership and role, where applicable.
  • Billing data — your billing contact and subscription status. Payments are handled by our payment processor; we never see or store raw card numbers.
  • Product usage — pseudonymous analytics (see below).
  • Content you create — feedback, form submissions, and anything you store in the product.

Information we receive from others

Some data reaches us from third parties you choose to involve: identity providers (if you sign in with Google/GitHub/etc. we receive the profile you authorize), and our payment processor (your subscription and payment status — never raw card details). We don't buy personal data or enrich your profile from data brokers.

Analytics are cookieless and self-hosted

We use a self-hosted analytics tool (Umami) that sets no cookies and builds no cross-site profile. We do not embed third-party ad pixels or marketing trackers of any kind.

Guests are never identified and can opt out at any time. For signed-in users we may attach a server-computed, pseudonymous identifier (a 'sid') so we can understand product usage per account. This identifier is pseudonymous personal data — it is derived from a key that is destroyed when you delete your account, after which the analytics data can no longer be linked back to you.

Session replays and heatmaps are off unless you switch them on (the cookie button → Session replays & heatmaps). When on, the same self-hosted Umami records how you use our pages — clicks, scrolling and what is shown on screen — so we can find and fix confusing pages. What you type into form fields is masked and never recorded. No cookie is set; switch it off at any time and recording stops immediately.

No automated decisions

We do not use your data to make solely automated decisions that produce legal or similarly significant effects about you, and we do not profile you for advertising. Abuse/anti-bot checks may flag activity for a human to review — they never decide anything important about you on their own.

Children

The service is not directed to children. You must be at least [16] (or the digital-consent age in your country; [13] in the United States) to use it. We don't knowingly collect data from children under that age — if you believe a child has given us data, contact us at [privacy@your-saas.com] and we'll delete it.

Who we share it with

Your data touches two companies beyond us: our infrastructure provider (Cloudflare) and our payment processor (Polar). The complete, current list lives at /legal/subprocessors. We do not sell your data and we do not share it with advertisers or data brokers.

Marketing and communications

We send service emails you can't opt out of while you have an account (security alerts, billing, policy updates) — these are required to run your account. Any marketing or product-update emails are separate: we only send them with your consent and every one has a one-click unsubscribe. Unsubscribing from marketing never affects service emails.

How long we keep it

We keep account data for the life of your account and delete or anonymize it when you delete your account. Sessions expire automatically. Billing records are retained as required by tax law. Backups roll off on their own schedule.

Deletion is real

When you delete your account we remove or anonymize your personal data across the platform. Where crypto-shredding is enabled for the deployment, per-account keys are destroyed so the underlying data becomes permanently unreadable — even in backups — not merely flagged as deleted.

Your rights

Under the GDPR (and similar laws) you can:

  • Access and export your data — available as a self-service export in your settings.
  • Correct inaccurate data — edit it in your profile or ask us.
  • Delete your account and data — self-service in settings.
  • Object to or restrict certain processing, and withdraw consent.
  • Lodge a complaint with your supervisory authority ([authority for your jurisdiction]).

Exercising your rights

Most rights are self-service in your settings; for anything else, email [privacy@your-saas.com]. We respond within one month (extendable by two for complex requests) and never charge except where the law allows.

Our data-protection contact is [DPO or privacy contact, email]. [If [Company] is NOT established in the EU/UK but offers the service there, also name your Article 27 representative here — an EU-established company does not need one.]

Security

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We keep a real, append-only audit log, and the slice relevant to you is visible in your own settings. See /security for the full picture.

International transfers

We host in the [region] region where available. Where data is processed outside your region by a subprocessor, it is covered by appropriate safeguards (e.g. Standard Contractual Clauses) — see each subprocessor's DPA at /legal/subprocessors.

California residents

If you're a California resident, the CCPA/CPRA gives you the rights to know, access, correct, and delete the personal information we collect, and to not be discriminated against for exercising them. The categories we collect and why are described above (identifiers, commercial/billing info, internet activity, and the content you create).

We do NOT sell or share your personal information as those terms are defined by the CCPA, and we have not in the preceding 12 months — so there is no "Do Not Sell or Share" action to take. We also do not use or disclose sensitive personal information beyond what's needed to provide the service. Exercise any of these rights the same way as above; you may use an authorized agent.

Do Not Track & Global Privacy Control

Because our analytics are cookieless and we set no advertising trackers, there is very little to "track" in the first place. Browsers send no universal Do Not Track standard, so we don't act on the legacy DNT header; where required we honor the Global Privacy Control (GPC) signal as an opt-out of any sale/sharing — which we don't do anyway.

Changes to this policy

We version this policy and keep a change summary for each update. For material changes we'll ask you to review and re-accept before you continue using the service.

Privacy questions?

Email our privacy contact or send us a message.