Legal
Privacy Policy
Last updated 2025-12-02
Identity and Contact Details
This Privacy Policy is issued by Fontish. We operate remotely and do not maintain a fixed office address. Fontish is the data controller responsible for your personal data.
If you have any questions or concerns about this Privacy Policy or how we handle personal data, you can contact us at legal@fontish.com.
Information We Collect
We collect the following categories of personal data when you use Fontish:
- Account information: When you register, we collect standard account details such as your name, email address, and authentication information. Authentication is handled through our identity provider, Clerk. If you choose to sign up using a third party account, such as Google, we receive basic profile information shared by the provider with your permission.
- Onboarding information: After registration, we collect additional information to personalize your experience. This may include your user type, role, primary goal for using the platform, company name, and team size.
- Technical and usage data: We may automatically collect information when you use the platform, such as IP address, browser type, device information, access times, and basic analytics about how you use the Service, including pages visited or features used.
Most of this information is provided directly by you during registration and onboarding. Technical and usage data is collected automatically through your interaction with the platform.
Certain personal data, such as billing and payment information, is processed by third party service providers like Stripe for the purpose of payment processing.
How and Why We Use Personal Data
We use the personal data we collect for the following purposes:
- Account creation and management: To register users, create and maintain accounts, and provide access to the platform.
- Service delivery: To operate and provide the platform’s features and functionality.
- Personalization: To tailor the onboarding experience and platform based on your role, intended use, and team size.
- Communication: To send important information related to your account, including service updates, security notices, and administrative messages.
- Legal compliance and security: To comply with applicable laws, enforce our terms, and maintain the security of the platform.
We do not use personal data for automated decision making that produces legal or similarly significant effects on users.
Legal Basis for Processing
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Performance of a contract: We process personal data as necessary to provide our services, create and manage user accounts, deliver platform features, and fulfill our contractual obligations to you.
- Legitimate interests: We process personal data to maintain and improve the platform, ensure security, prevent misuse, analyze usage, and support business operations. We carefully balance these interests against your privacy rights and expectations.
- Consent: Where required by law, we rely on your consent for specific activities, such as the use of non essential cookies or sending optional communications. You may withdraw your consent at any time by contacting us.
- Legal obligations: We may process personal data to comply with applicable legal requirements, including tax, accounting, or regulatory obligations.
Where processing is based on legitimate interests, you have the right to object. Where processing is based on consent, you may withdraw it at any time. This does not affect any processing carried out before withdrawal.
Sharing and Disclosure of Data
We share personal data with trusted third parties to help us operate, provide, and improve Fontish. These third parties receive only the personal data necessary to perform their specific functions and are required to process it in accordance with applicable privacy laws and this Privacy Policy.
We may share personal data with the following categories of recipients:
- Service providers and vendors: We use third party providers for hosting, security, authentication, analytics, customer support, communications, and email delivery. Examples include Cloudflare for hosting and security, Postmark for transactional email delivery, and Stripe for payment processing.
- Payment processors: If you choose to make a purchase, we share relevant information with payment providers to process transactions securely.
- Legal or regulatory authorities: We may disclose personal data when required to comply with applicable laws, legal requests, or to protect our rights and the rights of others.
- Business transfers: If we are involved in a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that process.
All third party service providers process personal data only on our instructions. We do not sell personal information.
International Data Transfers
Your personal data may be processed in countries outside of your country of residence, including the United States, where our service providers are located.
When we transfer personal data outside the European Economic Area, the United Kingdom, or Switzerland, we use appropriate safeguards as required by applicable data protection laws.
If you would like more information about these safeguards, you can contact us at legal@fontish.com.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy. This includes providing our services, complying with legal obligations, resolving disputes, and enforcing agreements.
- We keep account information for as long as your account remains active.
- If you delete your account, we will delete or anonymize your personal data within a reasonable period, unless we are required to retain it for legal or legitimate business purposes, such as tax or accounting obligations.
- Technical and analytics data may be retained for a limited period to support security, troubleshooting, and service improvements.
Your Rights
Depending on your location, you may have certain rights regarding your personal data under applicable data protection laws, including the GDPR (EU, EEA, and United Kingdom) and the CCPA (California).
- Access: You can request a copy of the personal data we hold about you.
- Rectification: You can ask us to correct inaccurate or incomplete personal data.
- Erasure: You can request deletion of your personal data, subject to legal or legitimate exceptions, such as tax or security obligations.
- Restriction: You can ask us to limit how we process certain personal data.
- Objection: You can object to processing based on legitimate interests.
- Data portability: You can request your personal data in a structured, commonly used, and machine readable format.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
You can exercise any of these rights by contacting us at legal@fontish.com. We may request additional information to verify your identity before acting on your request. We aim to respond within 30 days or as otherwise required by applicable law.
If you are located in the European Union or the United Kingdom, you have the right to lodge a complaint with your local data protection authority if you believe that we have not complied with applicable data protection laws.
California residents: If you are a California resident, you have the right to request information about the categories of personal information we collect, the sources of that information, the purposes for which it is collected, and the categories of third parties with whom we share it. You also have the right to request deletion of your personal information, subject to legal exceptions. We do not sell personal information as defined by the CCPA, and you will not be discriminated against for exercising your rights.
Cookies and Tracking
We use only essential cookies that are necessary for the operation of Fontish. These cookies enable core functions such as account login, session management, and maintaining the security and stability of the platform.
We do not use cookies for marketing, analytics, or advertising purposes.
You can control or delete cookies through your browser settings. Most browsers allow you to block or delete cookies, though some features of the platform may not function properly if you do so.
Because we use only essential cookies, we do not display a cookie consent banner.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons.
When we make changes, we will update the Last updated date at the top of this page. If the changes are significant, we may provide additional notice, such as by sending an email or displaying a prominent message within the platform.
The most current version of this Privacy Policy will always be available on this page.
Contact Information
If you have any questions or concerns about this Privacy Policy or our data practices, you can contact us at:
Fontish