Legal
Privacy Policy
Last Updated: September 7, 2026
We take your privacy very seriously. Please read this privacy policy carefully as it contains important information on who we are, how and why we collect, store, use, and share your personal information. It also explains your rights in relation to your personal information and how to contact us in the event you have a complaint or concern.
We collect, use, and are responsible for certain personal information about you. When we do so, we are subject to applicable United States and California privacy laws, including the California Consumer Privacy Act (CCPA).
Key Terms
It would be helpful to start by explaining some key terms used in this policy:
- We, us, our
- Frederick Design Studio, LLC
- Personal information
- Any information relating to an identified or identifiable individual
Personal Information We Collect About You
- Your name, email address, and other contact details you submit through our public contact form (which also collects project type, budget range, and a free-form message);
- Information you provide through private discovery questionnaires and proposal response forms sent to prospective clients via one-time links;
- Files, messages, and other content you upload or submit through the client portal, which is accessible only to pre-approved clients;
- Server and Cloudflare request logs, including IP addresses, which are collected automatically for security, rate limiting, and bot protection purposes; and
- Payment and transaction information associated with invoices paid through our payment page, such as invoice identifiers, amount, date, payment status, and Stripe-generated transaction references. Payment card and bank account credentials are collected and processed by Stripe through its secure payment interface. We do not receive or store your full payment card or bank account numbers.
Some of this personal information (e.g., name and email address) is required to provide services to you. If you do not provide personal information we ask for, it may delay or prevent us from providing services to you.
How Your Personal Information is Collected
We collect most of this personal information directly from you via our website and apps. However, we may also collect information:
- Directly from you when you submit our contact form, complete a private discovery questionnaire or proposal response, or use the client portal;
- Automatically through server and Cloudflare request logs when you visit or interact with the Site; and
- Through authentication session management when you sign in using the 6-digit verification code sent to your registered email address.
One account on the Site is held by a third-party operator whose access is scoped to that operator’s own content and does not extend to other clients’ portal information.
How and Why We Use Your Personal Information
We use your personal information for the following business and commercial purposes:
- To provide and improve our services to you;
- To communicate with you about your projects, inquiries, and account;
- To protect the security of our Site, detect and prevent fraud and unauthorized access, and perform technical operations such as rate limiting and bot protection; and
- To comply with applicable laws and regulations.
We will not use your personal information for purposes that are incompatible with those described in this policy without providing you notice or obtaining your consent.
Cookies, Local Storage, and Similar Technologies
The Site uses a limited set of cookies and browser storage mechanisms, described below:
- Authentication cookies (sb-*): Set by Supabase strictly to maintain your session after you sign in. These are deleted when you sign out or your session expires.
- Preference cookie (pf_active_project): A first-party cookie set for signed-in dashboard users to remember your active project selection. This cookie does not contain personal information.
- Cloudflare security cookies: Set by Cloudflare to support DNS proxying, firewall protection, and bot mitigation. Cloudflare Turnstile loads from challenges.cloudflare.com to protect our contact and sign-in forms from automated abuse.
- Browser localStorage: Two values are stored locally in your browser to remember (a) whether the introductory animation has already played, and (b) whether you have dismissed the app installation prompt. Neither value contains personal information.
- Progressive web app (PWA) caching: The Site caches static assets and a single offline fallback page for use when your connection drops. No personal information is stored in this cache.
- Google Search Console: Our domain is connected to Google Search Console for aggregate search performance metrics only. Google Search Console does not set cookies in your browser and does not receive your form data or personal information.
We do not use analytics cookies, tracking pixels, advertising cookies, Google Fonts calls, or any other third-party profiling or behavioral tracking.
Future analytics: We plan to add a privacy-respecting, cookieless analytics tool that reports aggregate page-view metrics without creating individual profiles or tracking users across sites. When implemented, this tool will not require a consent banner or a CCPA opt-out mechanism because it will not involve the sale or sharing of personal information or cross-context behavioral advertising.
Communications
All email communications from us to you are strictly transactional. These include sign-in verification codes, form submission notifications, and account-related messages such as proposals, invoices, payment links, and payment receipts. For certain automated client communications, we keep a log of information such as the recipient, subject, send status, and related account or transaction reference as our record of the communication. We do not currently send promotional, marketing, or newsletter emails. If we introduce client-update communications in the future, we will provide clear opt-in mechanisms and an easy way to opt out in compliance with applicable law.
Who We Share Your Personal Information With
We share personal information only with the following categories of service providers as necessary to operate the Site and deliver our services:
- Supabase (United States): database, authentication, and private file storage;
- Railway: application hosting and infrastructure;
- Cloudflare: DNS, proxying, web application firewall, and bot protection (Turnstile);
- Resend: transactional email routing (e.g., sign-in verification codes and form notifications);
- Your browser or operating system’s push notification service: delivery of dashboard notifications you have turned on. We store the subscription endpoint and encryption keys issued for your browser or device, tied to your signed-in account, and remove the subscription when you turn notifications off or when the subscription is no longer valid;
- Google Workspace: business email and internal communications;
- Microsoft OneDrive: business records and backups; and
- Stripe: payment and invoice processing. Stripe securely processes supported payment methods through its payment interface on our payment page. We provide Stripe with information needed to create and process invoices, such as your name, email address, invoice information, and amount due. We receive and store transaction and payment-status information from Stripe. We do not receive or store your full payment card or bank account numbers.
We also use GitHub for source code management. GitHub does not receive or process any personal information about our clients or website visitors.
The Company intends to introduce AI-assisted features to support client portal functionality. When that system is activated, certain content you submit through the client portal may be processed by a third-party AI service provider acting as our service provider. The identity of that provider and a description of the processing will be added to this list before the system is enabled. The AI service provider will process your information only on our instructions, for the limited purpose of delivering the feature to you, and will be subject to data protection obligations consistent with this policy. We will update this policy and notify active portal users before enabling any AI processing of their data.
We only share personal information with service providers that have agreed to handle it in a manner consistent with this policy. We do not share personal information with marketing agencies, advertising networks, or social media platforms for their own purposes.
We may also disclose personal information to law enforcement agencies or regulatory bodies where required by law, or to a successor entity in connection with a sale or restructuring of our business, subject to confidentiality obligations.
We Do Not Sell or Disclose Personal Information.
We do NOT sell any personal information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. This includes:
- Identifiers (e.g., a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers);
- Information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, his or her name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information;
- Characteristics of protected classifications under California or federal law;
- Commercial information (e.g., records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies);
- Biometric information;
- Internet or other electronic network activity information (e.g., browsing history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement);
- Geolocation data;
- Audio, electronic, visual, thermal, olfactory, or similar information;
- Professional or employment-related information;
- Education information, defined as information that is not publicly available personally identifiable information as defined in the Family Educational Rights and Privacy Act (FERPA); and
- Inferences drawn from any of the information identified above to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Where Your Personal Information is Held
Information may be held at our offices and those of our service providers, representatives, and agents as described above (see above: “Who We Share Your Personal Information With”).
How Long Your Personal Information Will Be Kept
We will keep your personal information while you have an account with us or we are providing services to you. Thereafter, we will keep your personal information:
- To respond to any questions, complaints or claims made by you or on your behalf;
- To show that we treated you fairly;
- To keep records required by law.
We will not retain your personal information for longer than necessary for the purposes set out in this policy. As a general guide, we retain contact and account information for as long as you have an active relationship with us and for up to three (3) years thereafter, billing and transaction records for up to seven (7) years to satisfy applicable legal and tax obligations, and any information we are required to retain by law for the period required by such law.
California Users: Your Rights Under the CCPA.
- Disclosure of Personal Information We Collect About You
You have the right to know:
- The categories of personal information we have collected about you;
- The categories of sources from which the personal information is collected;
- Our business or commercial purpose for collecting or selling personal information;
- The categories of third parties with whom we share personal information, if any; and
- The specific pieces of personal information we have collected about you.
Please note that we are not required to:
- Retain any personal information about you that was collected for a single one-time transaction if, in the ordinary course of business, that information about you is not retained;
- Reidentify or otherwise link any data that, in the ordinary course of business, is not maintained in a manner that would be considered personal information; or
- Provide the personal information to you more than twice in a 12-month period.
- No Personal Information Sold or Used for a Business Purpose
California residents have the right under the California Consumer Privacy Act of 2018 (CCPA) and certain other privacy and data protection laws, as applicable, to opt-out of the sale or disclosure of your personal information. Importantly, we will never sell or disclose your information, so you will never need to opt-out.
- Right to Deletion
Subject to certain exceptions set out below, on receipt of a verifiable request from you, we will:
- Delete your personal information from our records; and
- Direct any service providers to delete your personal information from their records.
Please note that we may not delete your personal information if it is necessary to:
- Complete the transaction for which the personal information was collected or otherwise perform a contract between you and us;
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity;
- Debug to identify and repair errors that impair existing intended functionality;
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;
- Comply with the California Electronic Communications Privacy Act;
- Comply with an existing legal obligation; or
- Otherwise use your personal information, internally, in a lawful manner that is reasonable and compatible with the context in which you provided the information.
- Protection Against Discrimination
You have the right to not be discriminated against by us because you exercised any of your rights under the CCPA. This means we cannot, among other things, discriminate via:
- Denying services to you;
- Charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
- Providing a different level or quality of services to you; or
- Suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
Do Not Track
Your browser settings may allow you to automatically transmit a “Do Not Track” signal to websites and online services you visit. We do not currently respond to “Do Not Track” signals, and our data collection and use practices remain the same whether or not a “Do Not Track” signal is received. We do not authorize third parties to collect personal information about your online activities over time and across different websites when you use our site. To find out more about “Do Not Track,” you may visit www.allaboutdnt.com.
Keeping Your Personal Information Secure
We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorized way. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorized manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
Links to Third Party Websites
We do offer links to other websites. When you click on links to other websites, we encourage you to read their privacy policies. Their standards may differ from ours.
This policy applies solely to frederickdesign.studio. Other websites that may use the same underlying technical infrastructure are governed by their own separate privacy policies.
How to Complain
Please contact us at the contact information below if you have a complaint. We hope that we can resolve any query or concern you raise about our use of your information.
Changes to This Privacy Notice
We may change this privacy notice from time to time. When we do, we will inform you by updating the date at the top of this page. We encourage you to review this policy periodically.
How to Contact Us
Please contact us at [email protected] if you have any questions about this privacy policy or the information we hold about you.