Privacy Policy
Last updated: [EFFECTIVE DATE]
This is a template, not legal advice.
Every bracketed placeholder below (company name, jurisdiction, notice address, effective date, sub-processor list) needs to be filled in, and the whole document needs review by a licensed attorney in your jurisdiction — including EU/UK counsel if you have or expect clients there — before it governs a real customer relationship.
This Privacy Policy describes how [LEGAL COMPANY NAME] (“we”, “us”) collects and uses personal data in connection with the [PRODUCT NAME] Service. It covers two different relationships, kept separate below because they carry different obligations:
- Customer account data — information about the businesses and staff who sign up for and use the Service directly (account holders, admins, workers).
- End-customer data processed on a Customer’s behalf— the names, phone numbers, and order records a Customer’s own clients generate inside that Customer’s account. For this category, the Customer is the data controller and we act only as processor — see our Data Processing Addendum, which takes precedence over this policy for that data.
1. What we collect
Account data
Name, email address, hashed password, role, and product-usage data for anyone who creates or is invited into a Customer account. Billing contact and payment details are collected and stored by our payment processor, [PAYMENT PROCESSOR NAME] — we do not store full card numbers ourselves.
End-customer data (processed on a Customer’s behalf)
Names, phone numbers, and rental/order history that a Customer’s own staff enter into the Service. We do not decide what this data is used for or how long it’s kept — the Customer does, as controller.
2. How we use it
- To provide, operate, and maintain the Service.
- To communicate with account holders about their account, billing, and material changes to the Service.
- To monitor for security issues, abuse, and to debug and improve the Service.
- To comply with legal obligations.
We do not sell personal data, and do not use end-customer data (processed on a Customer’s behalf) for our own marketing.
3. Where data is stored
Each Customer’s data lives in its own separate database — see [PRODUCT NAME]’s architecture — hosted with [HOSTING/DATABASE PROVIDER, e.g. Fly.io / Turso], located in [DATA CENTER REGION(S)]. [State whether EU Customer data can be kept in an EU region, if that’s offered.]
4. Sub-processors
We use the following categories of sub-processor to provide the Service:
- Application hosting: [PROVIDER]
- Database hosting: [PROVIDER]
- Payment processing: [PROVIDER, e.g. Stripe]
- Transactional email: [PROVIDER, e.g. Resend]
An up-to-date sub-processor list is available on request at [CONTACT EMAIL].
5. Data retention and deletion
Account and end-customer data is retained for as long as the Customer’s account is active, and for [RETENTION PERIOD] after termination to allow export, after which it is deleted. Customers can export all their data at any time via the Service’s built-in export feature.
6. Your rights
If you are an end-customer of one of our Customers (e.g. someone who rented from a shop using this Service) and want to exercise a data-protection right (access, correction, deletion), contact that shop directly — they control that data. If you are an account holder, contact us at [CONTACT EMAIL].
7. Changes to this policy
Material changes will be notified with at least [NOTICE PERIOD] notice before taking effect.
8. Contact
[LEGAL COMPANY NAME], [ADDRESS]. [CONTACT EMAIL].
