Legal
Privacy Policy
Last updated Β· June 22, 2026
designs.art ("we", "us") respects your privacy. This policy explains what we collect, why, how we use it, and your choices.
01What we collect
- Account data β name, company, email, phone you provide during onboarding.
- Project content β briefs, files, references, and feedback you share with us.
- Billing data β handled by our payment processor; we store only the metadata needed for invoicing (last 4 digits, country, plan).
- Usage data β IP-derived country (used to set default currency), browser type, and pages visited, via privacy-respecting analytics.
02How we use it
- To deliver the services you ask for and communicate about them.
- To bill you and prevent fraud.
- To improve the site and services in aggregate.
- To send transactional emails (account, project, billing). We do not send marketing email without your consent.
03Who we share with
We share only with service providers that help us run the service, under contract:
- Hosting & database β our cloud platform, where account, project, and email-log data are stored.
- Email delivery β transactional emails sent via our verified
notify.designs.artsender. - Scheduling β when you book a kickoff call, that flow uses our scheduling provider.
- Payments β once enabled, a PCI-compliant payment processor handles card data; we never see or store your full card number.
04Cookies
We use a small number of cookies for essential functionality (session, currency preference) and lightweight analytics. See the cookie policy for details.
05Retention
Account and project data are retained for the duration of your relationship with us plus a reasonable period for legal, tax, and dispute purposes. Email logs are retained for 90 days. You can request earlier deletion at any time.
06Your rights
Subject to applicable law, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Email us via the contact page and we'll respond within 30 days.
07Security
We use industry-standard practices β encryption in transit, access controls, audit logging, and least-privilege access. No system is perfectly secure; we don't claim to be certified to any specific framework.
08International transfers
Your data may be processed in countries other than where you live, in line with our hosting and provider footprint. We rely on standard contractual safeguards where required by law.
09Children
The service is not directed at children under 16 and we do not knowingly collect their data.
10Changes
We'll update this page when our practices change and revise the "last updated" date above. Material changes will be announced by email.
11Contact
Reach us via the contact page for any privacy question or request.