Privacy Policy
Effective: 7 May 2026
1. Data We Collect
We collect the following categories of data:
- User profile — email address, name, and optional avatar, managed through your Clerk account.
- Organisation — company name provided at sign-up.
- Project content — building names, floor names, floor plan PDFs, pin coordinates, survey data, and equipment photos you upload.
- Billing reference — Stripe customer ID and subscription ID. We do not store card numbers; payment details are held by Stripe.
- Audit metadata — creation and modification timestamps and project membership records.
- Server logs — IP address and request timestamps, retained for security and debugging.
2. Legal Basis for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
- Contract performance — processing your email, name, and account data is necessary to provide the FloorPins service you signed up for.
- Legitimate interests — server logs and error monitoring are processed to maintain the security and reliability of the service. This processing does not override your rights and freedoms.
- Legal obligation — we may retain certain data if required by applicable law.
3. How We Use Your Data
Your data is used solely to provide the FloorPins service — storing your projects, rendering floor plans, and generating exports. We do not sell your data or use it for advertising.
4. Sub-processors
We use the following third-party services to deliver FloorPins:
- Clerk (clerk.com) — authentication and identity management, US-hosted, SOC 2 Type II certified. Clerk stores hashed passwords, manages email verification, and issues JWT tokens. We do not store passwords directly.
- Stripe (stripe.com) — billing and subscription management, US-hosted, SOC 2 Type II and PCI DSS Level 1 certified. Your email address is shared to create a billing customer.
- Amazon Web Services (aws.amazon.com) — application hosting, object storage, and backups, US-hosted (us-east-1), SOC 2 certified.
- Resend (resend.com) — transactional email delivery, US-hosted, SOC 2 Type II certified. Your email address is shared to deliver verification, invite, and billing emails.
- Sentry (sentry.io) — error monitoring, US-hosted, SOC 2 Type II certified. Request bodies, cookies, and authentication headers are scrubbed before transmission to Sentry.
5. Data Retention
Your data is retained for as long as your account is active. Upon account deletion, your tenant data is removed from active databases within 7 days. Backups containing your data age out within 365 days per our retention schedule (30-day Glacier transition, 365-day expiry).
6. Your Rights
You have the following rights regarding your personal data. To exercise any of them, contact support@floorpins.com.
- Access — request an export of your data.
- Deletion — request account deletion. Tenant data is removed from active databases within 7 days; backups containing the data age out within 365 days per our retention schedule.
- Correction — edit profile data directly in the app; contact support for corrections to data you cannot edit yourself.
- Portability — CSV export of all pin data is available from project pages at any time.
- Objection / restriction — contact support@floorpins.com to object to or restrict processing.
If you are in the European Economic Area, you also have the right to lodge a complaint with your local supervisory authority.
7. Security Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users without undue delay via email to the address on file.
8. Cookies
FloorPins uses session cookies set by Clerk to maintain your authentication state. We do not use third-party tracking pixels, advertising cookies, or analytics cookies that share data with marketing platforms.
9. Security
We implement the following security controls to protect your data:
- Authentication is handled by Clerk (SOC 2 Type II). Clerk manages hashed credential storage, email verification, and JWT issuance. Multi-factor authentication is available and can be enabled from your account settings.
- TLS 1.2 or higher for all data in transit (Caddy with Let's Encrypt certificates).
- AES-256 server-side encryption on all uploaded files.
- EBS volume encryption at rest for the database and object storage.
- Photo and document URLs are presigned with a 10-minute expiry; CSV exports use a 30-minute expiry. The object storage bucket is private — files are never publicly accessible.
- Rate limiting and API authentication on all endpoints.
- Parameterised queries and content security policies to guard against injection and cross-site scripting.
Infrastructure
Application infrastructure runs on AWS US East (Northern Virginia, us-east-1). The database is PostgreSQL on encrypted EBS volumes. Object storage is MinIO (S3-compatible) on encrypted EBS volumes. Daily gzipped backups are stored in AWS S3 with versioning, a 30-day Glacier transition, and a 365-day expiry.
10. Email Communications
We send transactional emails (account verification, project invites, billing notices, and support replies) via Resend with DKIM-signed delivery from floorpins.com. We do not send marketing emails without explicit opt-in. Unsubscribe links are included in any non-transactional email.
11. Children
FloorPins is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
12. Changes
We may update this Privacy Policy from time to time. Material changes will be communicated via email to account owners at least 30 days before taking effect.
13. Contact
Privacy questions or data requests? Email us at support@floorpins.com.