GM Agency

Legal

Privacy Policy

Effective 22 May 2026 · v1.0

This policy explains what data GM Agency collects, why, and how you can exercise your rights over it. We act as a data controller for your account information and as a data processor for any user data that flows through builds we deliver to you.

01 · What we collect

Account
Name, email, password hash, optional billing address. Used to identify you, send transactional email, and bill projects.
Project
Scoping answers, uploaded references, generated specifications and mockups, build logs, change requests. Used to execute and deliver the project.
Payment
Held by Stripe. We see only the last four digits of the card and Stripe's customer/invoice identifiers — never the full card number or CVC.
Provider tokens
Encrypted OAuth tokens for GitHub / Vercel / Supabase / Cloudflare, used solely to provision your project and transfer it to you. Revoked or rotated after delivery on request.
Technical
IP address, user-agent, session cookies, application logs. Retained for security and debugging.

02 · How we use it

We do not sell, rent, or share your personal data with advertising networks. We do not send marketing email without a separate opt-in.

03 · Third-party processors

Your data is processed by a small list of subprocessors strictly necessary for the service:

04 · Retention

Account and project data are retained while your account is active and for up to 24 months after a project closes, for warranty and audit purposes. Build logs are retained for 12 months. Stripe payment records are retained for as long as required by tax and anti-fraud law (typically 7 years). You may request earlier deletion at any time, subject to legal retention requirements.

05 · Your rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA, and similar), you have rights to:

Email [email protected] to exercise any of these rights. We respond within 30 days.

06 · Cookies

We use a single first-party session cookie (gm_agency_session_v2) to keep you signed in, plus a CSRF-protection cookie. We do not use analytics or advertising cookies.

07 · Security

Passwords are hashed (bcrypt). Provider tokens are encrypted at rest. Traffic is served over TLS. We are a small team and aim to follow industry best practice but cannot guarantee absolute security; if a breach occurs we will notify affected users within 72 hours.

08 · Changes

Material changes are notified by email at least 14 days before taking effect.

Contact

Privacy questions or data requests: [email protected]