Legal
Privacy Policy
Effective: June 6, 2025 · Last updated: June 6, 2025
Summary: We collect only what we need to provide services. We do not sell your data. Passwords are hashed. MFA is available. You have rights to access, correct, and delete your data. Contact [email protected] for any privacy requests.
1. Who We Are
GildMade ("GildMade", "we", "us", "our") operates gildmade.com and related services. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you visit our website, create an account, or engage our services. By using our services, you consent to the practices described in this policy. If you are in the European Economic Area (EEA) or the United Kingdom, GildMade acts as the data controller for your personal information.
2. Information We Collect
We collect the following categories of personal information: (a) Account Information: When you register, we collect your full name, username, email address, and hashed password. If you sign in with Google, we receive your name, email, and profile image from Google. (b) Project and Communication Data: Messages, project briefs, feedback, and support ticket content you submit through our platform. (c) Payment Information: We use Stripe to process payments. We do not store your full credit card number, CVV, or bank account details. We receive and store transaction IDs, amounts, and billing addresses from Stripe. (d) Usage and Technical Data: IP addresses, browser type and version, device type, operating system, pages visited, time spent on pages, referral URLs, and clickstream data. (e) Cookies and Tracking: See Section 7 for our full cookie policy. (f) Communications: If you contact us by email or via our contact form, we store those communications. (g) Log Data: Server logs automatically record your IP address, timestamps, and pages requested.
3. Legal Basis for Processing (GDPR)
For users in the EEA and UK, we process your personal data on the following legal bases: (a) Contract: To provide services you have requested or fulfill a contract with you. (b) Legitimate Interests: To improve our services, prevent fraud, and communicate about relevant services. (c) Consent: For marketing emails (you may withdraw consent at any time). (d) Legal Obligation: Where required by applicable law.
4. How We Use Your Information
We use your information to: (a) create and manage your account; (b) deliver, administer, and improve our services; (c) process payments and send payment-related communications; (d) send project updates, invoices, and service notifications; (e) respond to your inquiries and provide customer support; (f) send marketing emails about our services (with your consent, where required); (g) detect, prevent, and address fraud, security incidents, and technical issues; (h) analyze usage patterns to improve our website and services; (i) comply with legal obligations and enforce our Terms of Service; (j) protect the rights and safety of GildMade, our users, and the public.
5. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information. We share information only in the following circumstances: (a) Service Providers: With trusted third-party vendors who process data on our behalf, including Stripe (payments), IONOS (email), Vercel / AWS (hosting and storage), Google Analytics (usage analytics), and Google (authentication). All service providers are bound by data processing agreements. (b) Legal Requirements: When required by law, court order, or governmental authority, or to protect the rights, property, or safety of GildMade, our users, or others. (c) Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets, your data may be transferred. We will notify you before your data is subject to a different privacy policy. (d) With Your Consent: For any other purpose with your explicit consent. We never share or disclose one user's personal data to other users of the platform.
6. Data Retention
We retain personal data for as long as necessary to provide our services and fulfill the purposes described in this policy, unless a longer retention period is required by law. Account data is retained for the lifetime of your account and for up to 7 years after account closure for financial and legal compliance purposes. You may request deletion of your account at any time; see Section 9 for your rights.
7. Cookies and Tracking
We use cookies and similar technologies. Types of cookies we use: (a) Strictly Necessary: Authentication session cookies required for you to log in and use our platform. These cannot be disabled without preventing platform functionality. (b) Functional: Cookies that remember your preferences (e.g., theme, language). (c) Analytics: We use analytics tools to understand how visitors use our site. This data is aggregated and anonymized where possible. (d) Third-Party Cookies: Google (if you use Google Sign-In or we embed Google services) and Stripe may set cookies for their own purposes. You can manage cookies through your browser settings. Disabling certain cookies may affect functionality. Our cookie consent banner gives you control over non-essential cookies.
8. Security
We implement industry-standard security measures including: HTTPS/TLS encryption for all data in transit; bcrypt password hashing (cost factor 12); multi-factor authentication (TOTP) available for all accounts; role-based access controls; regular security scans and audits; limited employee access on a need-to-know basis. However, no system is 100% secure. We cannot guarantee the absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials. Please notify us immediately at [email protected] if you suspect unauthorized access to your account. Where we build automation systems on your behalf, any third-party API keys or access tokens you provide are stored encrypted, used only to operate the automation you requested, scoped to least-privilege access, and never sold or shared. You may revoke this access at any time.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data: (a) Access: Request a copy of the personal data we hold about you. (b) Correction: Request correction of inaccurate or incomplete personal data. (c) Deletion ("Right to be Forgotten"): Request deletion of your personal data, subject to legal obligations requiring retention. (d) Portability: Receive your data in a structured, machine-readable format. (e) Objection: Object to processing based on legitimate interests. (f) Restriction: Request restriction of processing in certain circumstances. (g) Withdraw Consent: For processing based on consent, you may withdraw at any time (this does not affect prior lawful processing). (h) CCPA Rights (California Residents): You have the right to know what personal information we collect, the right to delete, and the right not to be discriminated against for exercising these rights. We do not sell personal information. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (EEA/UK: within 1 month). We may need to verify your identity before fulfilling requests.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn we have collected personal information from a child under 18, we will promptly delete it. If you believe we have inadvertently collected such information, please contact us at [email protected].
11. International Data Transfers
GildMade is based in the United States. If you are located outside the US, your information will be transferred to and processed in the US. For EEA and UK users, such transfers are made pursuant to appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission. By using our services, you consent to this transfer.
12. Third-Party Links
Our website may contain links to third-party websites or services. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party sites you visit. GildMade is not responsible for the privacy practices of third parties.
13. Do Not Track
Some browsers support "Do Not Track" (DNT) signals. Our website does not currently respond to DNT signals because there is no industry standard for how to do so. We continue to monitor developments in this area.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Effective" date, and by emailing your registered address for significant changes. We encourage you to review this policy periodically.
15. Contact and Data Protection Officer
For privacy-related inquiries, to exercise your rights, or to file a complaint: Email: [email protected] Website: https://gildmade.com/contact If you are in the EEA and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.