Legal
Privacy Policy
This notice describes the data RenderBoard handles, why it is needed, which configured processors may receive it, and the current manual process for privacy and deletion requests.
- Operator
- RenderBoard operator (preview configuration)
- Effective date
- Not configured for this preview build
Who is responsible
RenderBoard operator (preview configuration), at Operator address not configured, operates this RenderBoard deployment and is responsible for the processing described here. Privacy questions and rights requests go to privacy@example.invalid.
Data we handle
- Account and organisation: email address, display name, password verifier, organisation name, roles, sessions, and multi-factor authentication state.
- Project content: floor plans, room geometry, briefs, layouts, materials, prompts, masks, generated images, boards, exports, and related metadata.
- Billing records: credit balances and ledger entries, selected products, transaction status, and references returned by a configured payment processor. Full payment-card entry occurs on the processor’s hosted checkout, when enabled.
- Security and operations: IP and request metadata, authentication events, error and job status, and service logs needed to protect and operate the deployment.
- Support: messages, attachments, and account or project references you choose to send.
Why we use it
We use this data to create and secure accounts; provide project, rendering, board, export, and billing functions; answer support requests; prevent abuse; diagnose failures; maintain service integrity; and comply with legal obligations.
Where applicable law requires a legal basis, core account and project processing is used to provide the service you request; security and reliability processing supports the operator’s legitimate interests where permitted; legal records are handled to meet legal obligations; and consent is used where the law requires it. RenderBoard does not currently enable nonessential browser tracking by default.
Configured processors and transfers
Project content can be sent to AI, storage, payment, or observability providers only when those integrations are configured for this deployment and the relevant feature is used. The current declarations are listed on the Subprocessors page.
A configured provider may process data in another country. The operator must confirm the provider’s processing location and any required transfer mechanism before release; this policy does not claim a transfer safeguard that has not been documented.
Retention and deletion
Account and project records do not currently have an automatic expiry. Some in-product delete actions use a soft-deletion marker, so the underlying record can remain until operator cleanup or a verified privacy request is completed. Records may also be retained where needed for security, disputes, billing, or law. This is a material limitation: there is no self-service account deletion control.
Operational logs are configured for not configured for this preview build. Backup copies are configured to age out after not configured for this preview build through the deployment’s normal backup lifecycle. Deleting an active record does not instantly rewrite an existing backup.
To request access, correction, export, restriction, or deletion, email privacy@example.invalid from your account email and include your organisation name and the request scope. The operator will verify identity and authority before acting. Do not send a password or authentication code. Applicable legal exceptions may require limited records to be retained.
Security, choices, and complaints
RenderBoard includes access controls, session protections, tenant checks, and production-oriented transport security headers, but no system can guarantee absolute security. Report a suspected account or data incident through the Support page.
You may have rights to access, correct, delete, restrict, object to processing, receive a portable copy, withdraw consent where consent is used, or complain to a regulator. The available rights and regulator depend on where you live and which law applies.
Changes and contact
Material changes will be reflected by a new effective date on this page. The privacy contact is privacy@example.invalid; the governing jurisdiction configured for this deployment is Governing jurisdiction not configured.