Privacy Policy

Last updated: June 18, 2026

Template document. Boilerplate to adapt per product: replace the [bracketed] placeholders, confirm the data practices and subprocessors match this app, and have counsel review before launch. This is not legal advice.

1. Overview

This Privacy Policy explains how [Company legal name] (“Deadbolt,” “we”) collects, uses, and protects information when you use deadbolt.com (the “Service”). We aim to collect only what we need to run the Service well.

2. Information we collect

  • Account data — name, email, and password (hashed), handled via our auth provider, Supabase.
  • Billing data — subscription status and the last four digits / card brand of your payment method. Full card details are collected and stored by Stripe, not by us.
  • Customer Data — the content you create or upload while using the Service.
  • Usage & device data — log data, IP address, browser/device type, and product analytics (via Vercel Analytics) to understand and improve the Service.
  • Support data — messages you send us at info@tryhalfstack.com.

3. How we use information

  • Provide, secure, and maintain the Service;
  • Process payments and manage subscriptions;
  • Respond to support requests and send service-related notices;
  • Improve features, performance, and reliability;
  • Detect, prevent, and address fraud or abuse, and comply with law.

4. Legal bases (EEA/UK)

Where applicable, we process personal data to perform our contract with you, for our legitimate interests (e.g., securing and improving the Service), to comply with legal obligations, and with your consent where required.

5. Subprocessors & sharing

We don’t sell your personal data. We share it only with service providers that help us run the Service:

  • Supabase — database & authentication;
  • Stripe — payment processing;
  • Resend — transactional email;
  • Vercel — hosting & analytics.

We may also disclose information to comply with law or to protect rights, safety, and security.

6. Data retention

We retain personal data while your account is active and as needed to provide the Service. After account closure we delete or anonymize data within [30–90] days, except where we must retain it for legal, tax, or security reasons.

7. Security

We use industry-standard measures including encryption in transit, row-level access controls on our database, and least-privilege access. No method of transmission or storage is 100% secure, but we work to protect your information and review our practices regularly.

8. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact info@tryhalfstack.com. You can also access and update much of your data directly in your account settings.

9. International transfers

We and our subprocessors may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers.

10. Cookies

We use essential cookies to keep you signed in and to operate the Service, and limited analytics cookies to understand usage. [Add a cookie banner / preferences link here if your jurisdiction requires consent.]

11. Children

The Service isn’t directed to children under 16, and we don’t knowingly collect their data.

12. Changes

We may update this Policy from time to time. Material changes will be notified in-app or by email, and the “last updated” date above will change.

13. Contact

For privacy questions or requests, contact info@tryhalfstack.com or [Company legal name], [mailing address]. [Name a data-protection contact/DPO if required.]