Legal
Legal & Compliance Foundation

Privacy Policy

Learn how uidesigner protects your personal information, respects your digital privacy rights, and safeguards Customer Content as a trusted processor.

Effective: September 24, 2026
•
Last Updated: September 24, 2026
•v2026-09-24
§ 1

Introduction & Dual Processing Roles (Controller vs. Processor)

uidesigner ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy describes how we collect, process, store, and safeguard personal information across our applications, APIs, and websites (including uidesigner.ai, review.uidesigner.ai, and audit.uidesigner.ai).

Under applicable data protection laws (including the European Union General Data Protection Regulation / UK GDPR, the California Consumer Privacy Act / CCPA as amended by CPRA, and the India Digital Personal Data Protection Act 2023 / DPDP Rules 2025), uidesigner operates in two distinct legal capacities:

1. uidesigner as Data Controller

We act as a Data Controller (or "Business" under California law) with respect to information we collect directly to manage our customer relationships and operate our platform. This includes account credentials, billing records, direct customer support communications, security audit logs, platform administration, and system-level performance telemetry.

2. uidesigner as Data Processor / Service Provider

We act as a Data Processor (or "Service Provider" under California law) with respect to Customer Content submitted to and processed within collaborative review organizations (such as annotations, review comments, uploaded UI assets, and website DOM elements). In this capacity, we process personal data strictly on behalf of the customer, according to their instructions, and as governed by our Terms of Service and applicable Data Processing Agreements.

§ 2

Categories of Personal Data We Collect

We collect information in the following categories depending on how you interact with our platform:

Account & Identity Information

When you create an account, sign in, or accept an invitation, we collect your name, email address, profile picture (if authenticated via OAuth), organization roles, and authentication timestamps.

Organization & Review Content

Information generated during organization collaboration, including canvas pins, feedback annotations, comment threads, uploaded design mockups, and screen recording video sessions stored securely in object storage.

Audit & Scanning Data

Target URLs submitted for automated analysis, accessibility audit results, DOM element references, performance metrics, and rendered web page screenshots.

Billing & Transaction Records

When you subscribe to paid tiers, payments are processed by our Merchant of Record and payment partner, Dodo Payments. uidesigner does not store raw credit card numbers. We retain customer identifiers, transaction IDs, subscription tier, and payment status.

Technical Telemetry & Security Logs

To secure the platform against abuse and denial of service, our servers and edge proxies record IP addresses (via CF-Connecting-IP / X-Real-IP), browser user-agent headers, operating system details, referring URLs, and request timestamps.

§ 4

Subprocessors & Infrastructure Providers

We work with selected third-party service providers and subprocessors who assist us in providing, securing, and operating the platform. All subprocessors are subject to strict confidentiality and data protection obligations:

Our active subprocessors include Convex (database & real-time sync), Dodo Payments (billing & payments), Cloudflare (R2 storage & edge security), and Resend (transactional email delivery). Detailed roles and data processing scopes are set forth in our Subprocessor Registry below.

Authorized Subprocessor Registry

Active service providers and infrastructure partners authorized to process data on behalf of uidesigner.

SubprocessorPurpose & CategoryData ProcessedLocation
Convex
subprocessor
Database & Backend Infrastructure

Primary database, authentication sessions, and real-time state synchronization

Account identityOrganization dataReview commentsAudit metadata
Subjects: Account users, Organization members, Invited reviewers
Global infrastructure; see provider documentation (primarily US)
Dodo Payments
subprocessor
Billing & Merchant of Record

Subscription management, payment processing, tax compliance, and customer billing portal

Billing contact detailsPayment transaction tokensSubscription status
Subjects: Organization owners, Billing administrators
United States / Global infrastructure
Cloudflare
subprocessor
Cloud Infrastructure & Media Storage

R2 object storage for review attachments, screenshots, and screen recordings; edge CDN & DDoS protection

Uploaded mockupsRecorded video sessionsCaptured screenshot assets
Subjects: Organization members, Invited reviewers
Global Edge Network
Resend
subprocessor
Transactional Communications

Dispatch of magic sign-in links, team invitations, quota alerts, and support notifications

Recipient email addressNotification payload metadata
Subjects: Account users, Invited members, Contact form submitters
United States
Google LLC
subprocessor
Web Analytics & Performance

Google Analytics telemetry for monitoring website visitor traffic, page latency, and user journeys

Anonymized IP addressBrowser/device metadataPage URLs visitedReferral sources
Subjects: Website visitors, Account users
United States / Global infrastructure
PostHog Inc.
subprocessor
Product Telemetry & UX Analytics

Product analytics, feature flag evaluation, and session diagnostics to identify usability bottlenecks

Pseudonymous distinct IDOrganization navigation eventsFeature interactions
Subjects: Account users, Invited reviewers
United States / EU (Cloud)
Meta Platforms, Inc.
subprocessor
Marketing & Conversion Attribution

Facebook Pixel conversion measurement and attribution of sign-ups to digital advertising campaigns

Browser identifiersReferral campaign metadataConversion event timestamps
Subjects: Website visitors, Landing page users
United States / Global infrastructure
§ 5

International Data Transfers

uidesigner and its infrastructure providers utilize globally distributed cloud architecture, primarily located in the United States and global edge points of presence.

If you access our Services from the European Economic Area (EEA), the United Kingdom, Switzerland, or other jurisdictions with data transfer restrictions, personal data may be transferred to and processed in countries that may not provide the same level of data protection as your home country.

Where required by applicable law, we ensure appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent competent authorities.

§ 6

Data Retention & Account Deletion

Retention Practices

We retain personal data for as long as your organization account remains active or as needed to provide you with the Services, fulfill legitimate business purposes, maintain security, and comply with statutory retention requirements (such as financial or tax regulations).

Account Deletion & Data Purge

When you delete your account or organization through the platform or by contacting support, your personal data and Customer Content are permanently purged or anonymized from production databases in accordance with our system lifecycle procedures. Residual copies stored in encrypted operational backups will be securely overwritten in accordance with standard backup rotation cycles.

§ 7

Your Data Rights & Grievance Contact

Depending on your jurisdiction (e.g. GDPR, UK GDPR, India DPDP Act 2023, California CCPA/CPRA), you may have the following legal rights regarding your personal information:

  • Right to Access: Request confirmation of whether we process your data and receive a copy.
  • Right to Rectification: Correct inaccurate or incomplete personal records.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data, subject to legal retention obligations.
  • Right to Restriction & Objection: Object to or restrict certain processing based on legitimate interests.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.

California Privacy Rights (CCPA / CPRA Notice)

California residents have specific rights regarding personal information under the CCPA/CPRA. uidesigner does NOT sell personal information. uidesigner does NOT share personal information with third parties for cross-context behavioral advertising.

Privacy & DPDP Grievance Contact

To exercise any data rights, submit questions, or lodge a formal grievance under the India DPDP Act 2023 / Rules 2025 or international privacy regulations, please contact our designated Privacy Contact:

Designated Privacy & Grievance Contact: [email protected]. We will acknowledge and respond to verified requests within the statutory timelines required by applicable law.
§ 8

Security Measures & Incident Management

We implement rigorous administrative, technical, and physical safeguards designed to protect personal data from unauthorized access, alteration, disclosure, or destruction. These measures include TLS 1.3 encryption in transit, AES-256 encryption at rest in Cloudflare R2, strict least-privilege IAM controls, and edge WAF DDoS defense.

Security Incident Notification

If uidesigner becomes aware of a security incident that compromises the confidentiality, integrity, or availability of personal data, we will promptly investigate, take all necessary remediation steps, and notify affected customers and competent supervisory authorities in accordance with applicable statutory notification requirements.

§ 9

Children's Privacy

uidesigner provides business-to-business and professional web collaboration tools. Our Services are not designed for or directed to children under 16 years of age. We do not knowingly collect personal data directly from children. If you become aware that a child has provided us with personal information without parental consent, please contact us at [email protected] so we can promptly delete the data.

§ 10

Updates to this Policy & Contact Information

We may update this Privacy Policy from time to time to reflect changes in our legal obligations, technology stack, or operational practices. The "Last Updated" date at the top of this page indicates when the latest modifications were made.

For any inquiries, requests, or privacy concerns, please contact us:

Questions regarding these legal terms?

Contact our legal, privacy, and compliance team for inquiries, data rights requests, or enterprise agreements.