⚠ Draft — not yet published
This is a starting draft based on what the codebase actually collects and does, written for you to review and edit — it is not legal advice. Fill in the bracketed placeholders (company name, contact address, hosting location, retention periods) before this goes live, and have it checked by whoever handles legal/compliance for the business if you're not confident doing that yourself.
Last updated: [date]
This policy explains what personal data [Your Company Name] ("we", "us") collects through the Gain Calculator Widget service (the embeddable tuning-gain calculator, its pricing site, customer portal, and admin dashboard — together, the "Service"), why, and what rights you have over it. It applies to two groups of people: site owners who subscribe to and embed the widget, and visitors who use an embedded widget on a site owner's website and submit an enquiry.
[Your Company Name], [company address / registration details]. Contact for any privacy question or request: [privacy contact email].
If you subscribe (site owners)
If you fill in the "Get a quote" form on an embedded widget (visitors)
The Service itself does not set any cookies. The admin dashboard and customer portal store a
session credential (an admin password or license key, respectively) in your browser's
localStorage so you don't have to log in on every visit — this stays on your device
and is never sent anywhere except back to our own server. If you go through Stripe Checkout to
subscribe, Stripe's own hosted payment page will set its own cookies under Stripe's privacy
policy, not ours.
[To be finalised.] As a starting point: account/subscription data for as long as your subscription is active, plus [X months/years] afterwards for accounting and legal purposes. Enquiry (lead) data for [X months/years] from submission, or until the site owner's account is closed, whichever is sooner. There is currently no automatic deletion job — removal today is a manual process on request (see below).
Depending on where you live, you may have the right to:
To exercise any of these, email [privacy contact email]. We'll respond within [30 days / your target]. This is currently handled manually rather than through a self-service tool.
Widget embeds are restricted to whitelisted domains, contact-form submissions are verified with a signed token rather than trusted at face value, and all user-submitted content is encoded before being displayed in the admin/portal dashboards to prevent it being used to run code in another user's browser. No online service can guarantee perfect security, but these are the concrete measures currently in place.
If this policy changes materially, we'll update the date at the top of this page. [Consider adding: and notify active subscribers by email.]
Questions about this policy or your data: [privacy contact email].