Legal
Privacy Policy
Effective Date: April 27, 2026
1. Information We Collect
We collect the following information when you use our Service:
- –Account information: your name, email address, and profile picture when you sign up directly or via Google OAuth.
- –Payment information: processed securely by Stripe. We do not store your credit card number or banking details on our servers. We receive and store your Stripe customer ID and subscription status.
- –Usage data: uploaded image files (processed in memory and not permanently stored), saved campaigns, custom dimension presets, export history, and session activity.
- –Technical data: IP address, browser type, device information, and referring URLs collected automatically through server logs.
2. How We Use Your Information
- –To provide, operate, and maintain the Service, including processing your image files and delivering exports.
- –To manage your account, subscriptions, and billing.
- –To send service-related communications such as confirmations, invoices, security alerts, and product updates.
- –To monitor and analyze usage trends to improve the Service.
- –To detect, prevent, and address fraud, abuse, or technical issues.
3. Google OAuth
If you sign in using Google, we receive your name, email address, and profile picture from Google. We use this information solely to create and manage your account. We do not access your Google Drive, Gmail, contacts, or any other Google services. You can revoke access at any time through your Google account security settings.
4. Cookies and Tracking
We use essential cookies required for the Service to function, including authentication session cookies managed by Supabase. We do not use third-party advertising cookies or tracking pixels. We do not sell your data to advertisers. Analytics, if used, are limited to aggregate, non-personally-identifiable usage metrics.
5. Third-Party Services
We share data with the following third-party service providers, each of which has its own privacy policy:
- –Stripe — payment processing and subscription management.
- –Supabase — authentication, database, and data storage.
- –Vercel — application hosting and edge delivery.
6. Data Retention
- –Uploaded files: processed in memory during your session and not permanently stored on our servers. Exported files are delivered to your browser for download and are not retained.
- –Account data: retained for as long as your account is active. Upon account deletion, your personal data is removed within 30 days, except where retention is required by law (e.g., billing records).
- –Server logs: retained for up to 90 days for security and debugging purposes, then automatically deleted.
7. Data Security
We implement industry-standard security measures to protect your data, including encrypted connections (TLS/SSL), secure authentication, and access controls. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- –Access: request a copy of the personal data we hold about you.
- –Correction: request that we correct inaccurate or incomplete data.
- –Deletion: request that we delete your personal data. You can delete your account directly from the Account page in the app, or by contacting us.
- –Portability: request a machine-readable copy of your data.
- –Objection: object to our processing of your personal data in certain circumstances.
9. GDPR (European Economic Area)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases: (a) your consent, which you may withdraw at any time; (b) performance of our contract with you to provide the Service; and (c) our legitimate interests in operating and improving the Service, provided those interests are not overridden by your rights. You have the right to lodge a complaint with your local data protection authority.
10. CCPA (California Residents)
If you are a California resident, you have the right to: (a) know what personal information we collect and how it is used; (b) request deletion of your personal information; (c) opt out of the sale of your personal information — we do not sell your personal information; and (d) not be discriminated against for exercising your privacy rights. To exercise these rights, contact us at hello@aspctratio.com.
11. International Data Transfers
Your information may be transferred to and processed in the United States or other countries where our service providers operate. By using the Service, you consent to the transfer of your data to jurisdictions that may have different data protection laws than your country of residence. Where required, we ensure appropriate safeguards are in place for such transfers.
12. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at hello@aspctratio.com.
13. Do Not Sell My Information
We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. This applies to all users regardless of location.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on the Service. The "Effective Date" at the top of this page indicates when this policy was last revised.
15. Contact
For privacy-related questions or to exercise your data rights, contact us at: hello@aspctratio.com
