Privacy Policy
Learn how uidesigner protects your personal information, respects your digital privacy rights, and safeguards Customer Content as a trusted processor.
Introduction & Dual Processing Roles (Controller vs. Processor)
uidesigner ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy describes how we collect, process, store, and safeguard personal information across our applications, APIs, and websites (including uidesigner.ai, review.uidesigner.ai, and audit.uidesigner.ai).
Under applicable data protection laws (including the European Union General Data Protection Regulation / UK GDPR, the California Consumer Privacy Act / CCPA as amended by CPRA, and the India Digital Personal Data Protection Act 2023 / DPDP Rules 2025), uidesigner operates in two distinct legal capacities:
1. uidesigner as Data Controller
We act as a Data Controller (or "Business" under California law) with respect to information we collect directly to manage our customer relationships and operate our platform. This includes account credentials, billing records, direct customer support communications, security audit logs, platform administration, and system-level performance telemetry.
2. uidesigner as Data Processor / Service Provider
We act as a Data Processor (or "Service Provider" under California law) with respect to Customer Content submitted to and processed within collaborative review organizations (such as annotations, review comments, uploaded UI assets, and website DOM elements). In this capacity, we process personal data strictly on behalf of the customer, according to their instructions, and as governed by our Terms of Service and applicable Data Processing Agreements.
Categories of Personal Data We Collect
We collect information in the following categories depending on how you interact with our platform:
Account & Identity Information
When you create an account, sign in, or accept an invitation, we collect your name, email address, profile picture (if authenticated via OAuth), organization roles, and authentication timestamps.
Organization & Review Content
Information generated during organization collaboration, including canvas pins, feedback annotations, comment threads, uploaded design mockups, and screen recording video sessions stored securely in object storage.
Audit & Scanning Data
Target URLs submitted for automated analysis, accessibility audit results, DOM element references, performance metrics, and rendered web page screenshots.
Billing & Transaction Records
When you subscribe to paid tiers, payments are processed by our Merchant of Record and payment partner, Dodo Payments. uidesigner does not store raw credit card numbers. We retain customer identifiers, transaction IDs, subscription tier, and payment status.
Technical Telemetry & Security Logs
To secure the platform against abuse and denial of service, our servers and edge proxies record IP addresses (via CF-Connecting-IP / X-Real-IP), browser user-agent headers, operating system details, referring URLs, and request timestamps.
Purposes & Legal Bases for Processing
We process your personal data under the following recognized legal bases:
- Contractual Necessity: To provide, maintain, and deliver the Services you request, manage your account, authenticate your sessions, and process payments.
- Legitimate Interests: To detect and prevent security threats, combat spam, maintain edge rate limiting, debug software defects, and measure platform reliability.
- Legal & Regulatory Compliance: To fulfill statutory tax obligations, maintain financial records, respond to lawful law enforcement requests, and enforce our legal terms.
- Consent: Where required by law (such as when subscribing to marketing newsletters or contacting our support team with optional information).
Subprocessors & Infrastructure Providers
We work with selected third-party service providers and subprocessors who assist us in providing, securing, and operating the platform. All subprocessors are subject to strict confidentiality and data protection obligations:
Authorized Subprocessor Registry
Active service providers and infrastructure partners authorized to process data on behalf of uidesigner.
| Subprocessor | Purpose & Category | Data Processed | Location |
|---|---|---|---|
Convex subprocessor | Database & Backend Infrastructure Primary database, authentication sessions, and real-time state synchronization | Account identityOrganization dataReview commentsAudit metadata Subjects: Account users, Organization members, Invited reviewers | Global infrastructure; see provider documentation (primarily US) |
Dodo Payments subprocessor | Billing & Merchant of Record Subscription management, payment processing, tax compliance, and customer billing portal | Billing contact detailsPayment transaction tokensSubscription status Subjects: Organization owners, Billing administrators | United States / Global infrastructure |
Cloudflare subprocessor | Cloud Infrastructure & Media Storage R2 object storage for review attachments, screenshots, and screen recordings; edge CDN & DDoS protection | Uploaded mockupsRecorded video sessionsCaptured screenshot assets Subjects: Organization members, Invited reviewers | Global Edge Network |
Resend subprocessor | Transactional Communications Dispatch of magic sign-in links, team invitations, quota alerts, and support notifications | Recipient email addressNotification payload metadata Subjects: Account users, Invited members, Contact form submitters | United States |
Google LLC subprocessor | Web Analytics & Performance Google Analytics telemetry for monitoring website visitor traffic, page latency, and user journeys | Anonymized IP addressBrowser/device metadataPage URLs visitedReferral sources Subjects: Website visitors, Account users | United States / Global infrastructure |
PostHog Inc. subprocessor | Product Telemetry & UX Analytics Product analytics, feature flag evaluation, and session diagnostics to identify usability bottlenecks | Pseudonymous distinct IDOrganization navigation eventsFeature interactions Subjects: Account users, Invited reviewers | United States / EU (Cloud) |
Meta Platforms, Inc. subprocessor | Marketing & Conversion Attribution Facebook Pixel conversion measurement and attribution of sign-ups to digital advertising campaigns | Browser identifiersReferral campaign metadataConversion event timestamps Subjects: Website visitors, Landing page users | United States / Global infrastructure |
International Data Transfers
uidesigner and its infrastructure providers utilize globally distributed cloud architecture, primarily located in the United States and global edge points of presence.
If you access our Services from the European Economic Area (EEA), the United Kingdom, Switzerland, or other jurisdictions with data transfer restrictions, personal data may be transferred to and processed in countries that may not provide the same level of data protection as your home country.
Where required by applicable law, we ensure appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent competent authorities.
Data Retention & Account Deletion
Retention Practices
We retain personal data for as long as your organization account remains active or as needed to provide you with the Services, fulfill legitimate business purposes, maintain security, and comply with statutory retention requirements (such as financial or tax regulations).
Account Deletion & Data Purge
When you delete your account or organization through the platform or by contacting support, your personal data and Customer Content are permanently purged or anonymized from production databases in accordance with our system lifecycle procedures. Residual copies stored in encrypted operational backups will be securely overwritten in accordance with standard backup rotation cycles.
Your Data Rights & Grievance Contact
Depending on your jurisdiction (e.g. GDPR, UK GDPR, India DPDP Act 2023, California CCPA/CPRA), you may have the following legal rights regarding your personal information:
- Right to Access: Request confirmation of whether we process your data and receive a copy.
- Right to Rectification: Correct inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data, subject to legal retention obligations.
- Right to Restriction & Objection: Object to or restrict certain processing based on legitimate interests.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
California Privacy Rights (CCPA / CPRA Notice)
California residents have specific rights regarding personal information under the CCPA/CPRA. uidesigner does NOT sell personal information. uidesigner does NOT share personal information with third parties for cross-context behavioral advertising.
Privacy & DPDP Grievance Contact
To exercise any data rights, submit questions, or lodge a formal grievance under the India DPDP Act 2023 / Rules 2025 or international privacy regulations, please contact our designated Privacy Contact:
Security Measures & Incident Management
We implement rigorous administrative, technical, and physical safeguards designed to protect personal data from unauthorized access, alteration, disclosure, or destruction. These measures include TLS 1.3 encryption in transit, AES-256 encryption at rest in Cloudflare R2, strict least-privilege IAM controls, and edge WAF DDoS defense.
Security Incident Notification
If uidesigner becomes aware of a security incident that compromises the confidentiality, integrity, or availability of personal data, we will promptly investigate, take all necessary remediation steps, and notify affected customers and competent supervisory authorities in accordance with applicable statutory notification requirements.
Children's Privacy
uidesigner provides business-to-business and professional web collaboration tools. Our Services are not designed for or directed to children under 16 years of age. We do not knowingly collect personal data directly from children. If you become aware that a child has provided us with personal information without parental consent, please contact us at [email protected] so we can promptly delete the data.
Updates to this Policy & Contact Information
We may update this Privacy Policy from time to time to reflect changes in our legal obligations, technology stack, or operational practices. The "Last Updated" date at the top of this page indicates when the latest modifications were made.
For any inquiries, requests, or privacy concerns, please contact us:
- Privacy & Data Protection Contact: [email protected]
- Customer Support: [email protected]
- Legal Counsel: [email protected]
Questions regarding these legal terms?
Contact our legal, privacy, and compliance team for inquiries, data rights requests, or enterprise agreements.