1. Overview
Acme Inc. ("Acme", "we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform and services ("Services").
By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our Services.
2. Data we collect
We collect information you provide directly, including:
- Account information — name, email address, password (hashed), and profile photo.
- Workspace content — documents, tasks, comments, and files you create or upload.
- Billing information — payment method details (processed and stored by Stripe; we never store card numbers).
- Communications — messages you send to our support team.
We also collect information automatically:
- Usage data — pages visited, features used, time spent, and actions taken.
- Device data — IP address, browser type, operating system, and device identifiers.
- Cookies and tracking — see Section 8 for details.
3. How we use your data
We use the information we collect to:
- Provide, maintain, and improve our Services.
- Process transactions and send related notices (receipts, invoices).
- Send administrative messages, security alerts, and support responses.
- Send product updates and marketing communications (you may opt out at any time).
- Monitor and analyse usage trends to improve user experience.
- Detect, investigate, and prevent fraudulent or illegal activity.
- Comply with legal obligations.
5. Data retention
We retain your personal data for as long as your account is active or as needed to provide Services. If you delete your account, we will delete or anonymise your data within 30 days, except where retention is required by law (e.g. financial records, which we retain for 7 years).
6. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your personal data (subject to legal retention requirements).
- Portability — request your data in a machine-readable format.
- Objection — object to processing of your data for marketing purposes.
- Restriction — request restriction of processing in certain circumstances.
To exercise any of these rights, email legal@acme.com.
7. Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, SOC 2 Type II controls, and regular third-party penetration tests. However, no system is completely secure — we encourage you to use a strong, unique password and enable two-factor authentication.
9. Children's privacy
Our Services are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or via an in-app notice at least 14 days before the change takes effect. Continued use of our Services after the effective date constitutes acceptance of the revised policy.
11. Contact us
Acme Inc. · 340 Pine Street, Suite 800 · San Francisco, CA 94104 · United States
Email: legal@acme.com