𓂀[DRAFT — pending legal review.] Bracketed items must be completed before publishing.
Data controller: [NEEDS MATTHEW: legal entity + address]. Effective date: [NEEDS MATTHEW]. Privacy contact: [NEEDS MATTHEW: DPO/privacy email].
Account & identity data (name, email, phone, address), business records you enter (contacts, invoices, schedules, inventory, etc.), and usage/analytics data.
Personal identity data (email, phone, address) is encrypted at rest; all traffic is encrypted in transit; tenant data is isolated at the data layer. See our Security page. [IN PROGRESS: extending field-level encryption to order-captured contact/address data.]
We use the third parties listed on our Sub-processor page to provide the service.
Account and tenant data is retained while your account is active. If your subscription is canceled, your data remains recoverable for 30 days — reactivate any time during that window to restore full access — after which it is permanently deleted through a dependency-ordered cascade across the platform's data stores. A small set is retained by design per the schedule below — the tamper-evident audit trail and legally-required financial records. Operational audit logs are kept 90 days in the primary database and then archived to cold object storage for 7 years (integrity-hashed archive manifests; Object Lock / WORM dual-write is not yet enabled on the live store — see launch plan); change-history snapshots are kept 30 days and then 2 years. AI prompts and generated outputs are processed transiently to serve your request and are not retained for model training.
Export and deletion are supported. [NEEDS MATTHEW + counsel: GDPR/CCPA rights, international-transfer mechanism, children’s-data position.]