TomonagiTomonagi

Privacy Policy

Effective: [DATE] · Version: 2026-06-23-draft

This is a template — have qualified legal counsel review before relying on it. DRAFT — not legal advice and not final. A product-accurate placeholder pending attorney review and completion of the bracketed items. Confirm the Sub-processor list matches what you actually deploy before relying on it.

1. Introduction & Scope

This Privacy Policy explains how [LEGAL ENTITY NAME] (“we”, “us”) collects, uses, and shares personal information when you use our service (the “Service”). It applies to account holders and visitors. It does not govern how our customers handle their own End Customers’ data — for that, the customer is the controller and its own privacy notice applies.

2. Information We Collect

  • Account information — name, email, password (stored hashed by our auth provider), and your acceptance of our Terms.
  • Billing information — your plan, subscription status, and billing identifiers. Card details are handled by our payment processor; we do not store full card numbers.
  • Usage and device data — log data, IP address, browser/device information, and product interactions, used to operate, secure, and improve the Service.
  • Customer Data — content you and your Authorized Users put into the Service, including information about your End Customers. You control this data; we process it on your behalf to provide the Service.
  • Communications — messages you send to us (e.g., support), and metadata about messages you send to your End Customers through the Service’s email/SMS features.

3. How We Use Information

We use personal information to: provide, maintain, and secure the Service; authenticate accounts; process subscriptions and billing; provide support; detect and prevent abuse, fraud, and security incidents; comply with legal obligations; and improve the Service (including with aggregated, de-identified data). [If applicable, state your legal bases under GDPR/UK GDPR: contract, legitimate interests, consent, legal obligation.]

4. How We Share Information — Sub-processors

We share personal information with service providers that help us run the Service, under contracts that limit their use of it. Confirm this list matches your live deployment:

  • PayPal — subscription payment processing. [paypal.com/privacy]
  • Supabase — database hosting, authentication, and storage. [supabase.com/privacy]
  • [HOSTING — e.g., Render] — application hosting/infrastructure.
  • [EMAIL PROVIDER — e.g., Resend] — sending transactional and customer emails.
  • [SMS PROVIDER — e.g., Plivo] — sending SMS messages, where you use that feature.
  • [AI PROVIDER(S)] — powering AI-assisted features; inputs you submit may be processed to generate output.

We may also disclose information to comply with law or protect rights/safety, and in connection with a merger, acquisition, or asset sale (with notice where required).

5. Customer Data & Your End Customers

For Customer Data you submit (including your End Customers’ information), you are the controller and we act as a processor on your instructions, as described in our Terms and any Data Processing Addendum. You are responsible for having a lawful basis and appropriate notices/consents for the data you process through the Service.

6. Cookies & Similar Technologies

We use cookies and similar technologies to keep you signed in, remember preferences, and understand usage. [Describe essential vs. optional cookies and any analytics; provide cookie controls/consent where required in your jurisdiction.]

7. Data Retention

We retain personal information for as long as your account is active and as needed to provide the Service. If your plan lapses, data is retained in a locked/read-limited state rather than deleted. After account termination, data is retained for [RETENTION WINDOW] and then deleted, except where we must keep it to meet legal obligations.

8. Security

We use commercially reasonable administrative, technical, and organizational measures to protect personal information. No system is perfectly secure; we cannot guarantee absolute security. We will notify affected parties of security incidents as required by applicable law.

9. International Transfers

We and our Sub-processors may process information in countries other than yours. Where required, we use appropriate safeguards for international transfers. [Specify mechanisms — e.g., Standard Contractual Clauses — if you serve EU/UK customers.]

10. Your Rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to opt out of certain communications. You can update account details in the app and exercise other rights by contacting us below. [Add jurisdiction-specific rights/appeals language as advised by counsel — e.g., GDPR/UK GDPR, CCPA/CPRA.]

11. Children’s Privacy

The Service is not directed to children, and you must be 18+ to hold an account. We do not knowingly collect personal information from children. [If your customers might collect minors’ data through the Service, address your customers’ COPPA/age-related responsibilities in the Terms/DPA.]

12. Changes to This Policy

We may update this Policy; material changes will be notified (e.g., email or in-app) and take effect on the stated date.

13. Contact

Questions or requests: [SUPPORT/LEGAL EMAIL], [LEGAL ENTITY NAME], [ADDRESS].