Privacy Policy
Last updated: 2026-08-10
This Privacy Policy explains how the person or organization operating this deployment ("Operator," "we," "us") handles personal information when you use this application and its related services (the "Service"). The Operator is the controller or business responsible for the processing described here unless another notice says otherwise.
1. Information we collect
Depending on the features enabled in this deployment, we may collect:
- Account information: name, email address, organization, profile details, authentication status, and account preferences.
- Order information: products, quantities, delivery details, billing status, transaction references, and customer-support history.
- Content and communications: information you submit, upload, publish, or send to the Operator.
- OAuth information: provider identifier, basic profile details, and connection status when you choose Google, GitHub, or another sign-in provider. We do not store provider access tokens unless a feature clearly requires and discloses it.
- Device and usage information: IP address, user agent, timestamps, pages and actions, session identifiers, error reports, and security/audit events.
- Information from providers: payment status from a payment processor, delivery status from an email provider, or account details authorized by an authentication provider.
Do not submit sensitive personal information unless the Service specifically asks for it and explains why it is needed.
2. How we use information
We use personal information to:
- provide accounts, authentication, orders, content, and requested features;
- process and fulfill transactions and send service messages;
- secure the Service, prevent fraud and abuse, and investigate incidents;
- provide support and communicate about changes;
- diagnose errors, measure reliability, and improve the Service;
- comply with legal obligations and enforce agreements; and
- protect users, the Operator, and the public.
Where applicable law requires a legal basis, processing is based on performance of a contract, legitimate interests in operating and securing the Service, compliance with law, or consent. You may withdraw consent where processing depends on consent.
3. Payments
Payments may be processed by a provider such as Stripe. Hosted checkout sends payment details directly to that provider; the Operator generally receives transaction identifiers, status, amount, and limited customer details rather than full card numbers. The payment provider processes information under its own privacy terms.
A clearly labeled Holodex or local preview checkout is a simulator. It does not contact Stripe, move money, request a real card number, or store card data.
4. Authentication and email providers
If you choose third-party sign-in, the provider shares the account information shown during authorization. Connecting an OAuth identity does not automatically merge accounts merely because email addresses match.
Transactional email may be delivered through an email provider. The provider receives the recipient address, message content, and delivery metadata needed to send and protect the message.
5. Cookies and local storage
The Service uses essential cookies or similar storage for authentication, security, preferences, and request integrity. These are required for the Service to function. If analytics, advertising, or other non-essential technologies are added, the Operator must update this Policy and provide consent or opt-out controls where required.
6. How we share information
We may disclose information:
- to processors that provide hosting, database, email, payment, authentication, storage, monitoring, or support services;
- to an organization you join or direct us to share with;
- during a merger, financing, acquisition, reorganization, bankruptcy, or asset transfer, subject to appropriate safeguards;
- when reasonably necessary to comply with law or valid legal process; or
- to protect rights, safety, security, and the integrity of the Service.
We do not sell personal information or share it for cross-context behavioral advertising by default. An operator that enables advertising, data sale, or legally defined sharing must update this Policy and provide required choices before collecting data for that purpose.
7. Retention
We keep information only as long as reasonably needed for the purposes above, including account operation, transaction records, security, dispute resolution, and legal obligations. Retention varies by category and deployment configuration.
When an account or content is deleted, active copies are removed or anonymized within a reasonable period, while limited backup, fraud-prevention, audit, or legal-hold copies may remain until their retention period expires. Temporary demo deployments may delete application containers and databases automatically on the schedule shown by the demo host.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, access controls, isolated credentials, and security logging. No system is perfectly secure. You are responsible for using a strong, unique password and protecting your devices and authentication methods.
9. International processing
The Service and its providers may process information in countries other than yours. Where required, the Operator will use an approved transfer mechanism and appropriate safeguards. Contact the Operator for information about safeguards applicable to a production deployment.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal information; object to certain processing; withdraw consent; and appeal or complain to a regulator. You may also have the right to opt out of sale, sharing, targeted advertising, or certain automated decisions.
Use available account settings or contact us to exercise a right. We may verify your identity and may retain information where legally permitted or required. Authorized agents may submit requests where local law allows.
11. Children's privacy
The Service is not directed to children under 13, and the Operator does not knowingly collect their personal information. A production operator must adopt a higher age threshold or obtain parental consent where required by its audience and jurisdiction. Contact us if you believe a child submitted information.
12. Changes to this Policy
We may update this Policy as the Service or law changes. The "Last updated" date identifies the current version. Material changes will be announced through the Service or another reasonable channel before they take effect where required.
13. Contact
Privacy questions and rights requests may be sent to privacy@example.com. General support requests may be sent to support@example.com. Avoid sending passwords, payment-card numbers, or other sensitive information by email.