Draft — not reviewed by a lawyer. This is placeholder text describing what the software actually does with data, written to be accurate to this codebase — but it is not a substitute for jurisdiction-specific legal review (e.g. GDPR, CCPA, Australian Privacy Principles, whichever apply to your subscribers). Have it reviewed before relying on it with real, paying subscribers.

Privacy Policy

Last updated: [DATE]

1. What we collect at registration

When you register: business name, your name, email, phone, chosen subdomain, and a password (stored as a one-way hash, never in plain text). Payment details are collected and processed directly by our payment processor (Stripe) — we never see or store your card details.

2. What your instance stores

Once provisioned, your instance is an isolated environment that stores whatever business data you put into it: leads, buyer/vendor records, generated content, and any third-party credentials you choose to connect. This data is not shared with, or accessible from, any other subscriber's instance.

DataWhere it livesWho can access it
Registration details, billing statusPlatform databasePlatform operator only
Your leads, content, business recordsYour own isolated instanceYou (and the platform operator, only as needed for support/maintenance)
Third-party credentials you connect (social, email, etc.)Your own instance's configuration, not the platform databaseYour instance only — used to act on your behalf as you've configured

3. Third-party services

Depending on what you connect, your instance may send data to: your chosen AI provider (for content generation), social media platforms you authorize, your email provider, and — if enabled — a video-generation service. Each of those is governed by that provider's own privacy policy; connecting them is optional and entirely your choice.

4. How we use platform-level data

We use your registration and billing data to operate your subscription (provisioning, billing, support) and to send you service-related email (e.g. your login link, password resets, billing notices). We do not sell your data.

5. Data retention

Active subscriptions: for as long as your subscription is active. Cancelled subscriptions: your instance is paused, and data is retained for [RETENTION PERIOD] to allow reactivation or export, after which it's permanently deleted.

6. Your rights

You can request a copy of your platform-level registration data, or request account deletion, by contacting [SUPPORT EMAIL]. [Add jurisdiction-specific rights language here — GDPR/CCPA/APP rights differ and should be drafted by a lawyer for the jurisdictions you actually operate in.]

7. Security

Passwords are stored as salted one-way hashes, never in plain text. Each subscriber's instance runs in its own isolated environment. [Describe your actual infrastructure security practices here once finalized — encryption at rest/in transit, access controls, etc.]

8. Contact

Questions about this policy or your data: [SUPPORT EMAIL].