Privacy Policy for FrameVerk
Last Updated: August 8, 2026
FrameVerk ("we", "our", "us") operates frameverk.com, the FrameVerk web application, project workspace, and related services (collectively, the "Service").
This Privacy Policy explains what information we collect, why we collect it, how we use it, when we share it, how long we keep it, and what rights may be available to you.
By using the Service, you acknowledge that your information will be handled as described in this Privacy Policy.
1. Scope
This policy applies to personal data and project-related data processed through FrameVerk. It does not apply to third-party websites, services, platforms, payment processors, analytics providers, hosting providers, or integrations that have their own privacy policies.
If you use FrameVerk on behalf of a company, client, construction project, or other organization, you are responsible for ensuring that you have authority to provide any personal data or project data you upload.
2. Information We Collect
2.1 Information You Provide
- Account data: name, email address, password credentials, authentication data, profile details, account role, preferences, and settings.
- Project data: project names, descriptions, 2D/3D models, walls, roofs, posts, plates, sheathing, layouts, measurements, notes, images, checklists, quantities, cut-list data, and related design information.
- Billing data: plan selection, billing status, transaction identifiers, and payment-related metadata when paid plans are available. Full payment card details are processed by third-party payment providers and are not stored by FrameVerk unless expressly stated.
- Communications: emails, support requests, feedback, bug reports, survey responses, waitlist submissions, and other messages you send to us.
2.2 Information Collected Automatically
- Technical data: IP address, device identifiers, browser type, operating system, language, timezone, referring URL, pages visited, and approximate location derived from IP address.
- Usage data: feature usage, clicks, navigation paths, session activity, project actions, app interactions, errors, crash logs, performance metrics, and diagnostic events.
- Security data: login attempts, authentication events, rate-limit events, abuse signals, audit logs, and security-related metadata.
2.3 Cookies and Similar Technologies
We may use cookies, local storage, pixels, analytics tags, and similar technologies to:
- keep you signed in and operate secure sessions;
- remember preferences and language settings;
- measure traffic, performance, and feature usage;
- detect abuse, fraud, bots, or security issues;
- improve the product and user experience.
Cloudflare Web Analytics is used across eligible FrameVerk routes and client-side navigations for aggregate visit and page measurement, independently of the Google Analytics choice. Administrative /manager and development /dev routes are excluded. It does not use cookies or local storage, does not log query strings, and capability-token share URLs are measured only as the generic /share route. Google Analytics analytics storage starts enabled by default for session, user, and campaign measurement. Choosing Only necessary changes analytics storage to denied, clears Google Analytics cookies and bounded attribution, and is remembered for later visits. Advertising storage remains denied. You may block cookies in your browser, but some functional parts of the Service may stop working.
3. How We Use Information
We use information for the following purposes:
- creating, authenticating, securing, and managing accounts;
- saving, loading, syncing, rendering, backing up, and operating project workspaces;
- providing app features, support, billing, notices, and service communications;
- debugging errors, improving performance, testing features, and developing new functionality;
- detecting, preventing, and investigating abuse, fraud, spam, security incidents, and Terms violations;
- complying with legal obligations, responding to lawful requests, enforcing agreements, and protecting rights, safety, and property;
- analyzing aggregated or de-identified usage trends.
4. Legal Bases for Processing
For users in the EU/EEA, UK, or other regions with similar laws, our legal bases may include:
- Contract: processing needed to provide the Service you requested.
- Legitimate interests: product improvement, security, fraud prevention, analytics, support, and business operations, where not overridden by your rights.
- Consent: where required for certain cookies, marketing, or optional processing.
- Legal obligation: where processing is required by applicable law.
- Legal claims: where needed to establish, exercise, or defend legal rights.
5. How We Share Information
We do not sell personal data. We may share information as described below:
- Service providers: hosting, database, authentication, storage, analytics, email, monitoring, security, payment, and support providers that help operate FrameVerk.
- Project collaborators: users you invite, share with, or authorize through project-sharing, view-only, collaboration, or team features.
- Legal and safety: authorities, courts, advisors, insurers, or other parties where required by law or where necessary to protect rights, safety, security, users, or the Service.
- Business transfers: parties involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction.
- Aggregated or de-identified data: information that does not reasonably identify you.
Service providers and subprocessors may change as the Service evolves. Where required by law or contract, we will use reasonable measures such as data-processing terms, access controls, and confidentiality obligations with providers that process personal data for us.
6. Third-Party Services
FrameVerk may rely on third-party providers, including but not limited to:
- Supabase for database, authentication, storage, and related backend services;
- Vercel for hosting and deployment;
- Cloudflare for DNS and privacy-first, cookie-free aggregate Web Analytics across eligible non-administrative FrameVerk routes and client-side navigations;
- Resend or similar email providers for transactional emails;
- Google Analytics for default session, user, and campaign measurement with a persistent Only necessary opt-out;
- Stripe or similar payment processors if paid plans are implemented.
These providers process information under their own terms and privacy policies. We are not responsible for the privacy practices of third-party services outside our control.
7. Project Data and Sensitive Information
Project data may reveal business plans, construction plans, client information, locations, designs, technical assumptions, material quantities, and other sensitive or commercially valuable information.
- Do not upload information you are not authorized to process or share.
- Do not upload highly sensitive data unless necessary for your use of the Service.
- You are responsible for removing confidential, regulated, or third-party data from projects before sharing them with others.
- People you share projects with may view, copy, export, screenshot, or further disclose project information depending on the permissions and features available.
8. Retention
We retain information for as long as reasonably necessary to provide the Service, maintain your account, operate projects, comply with legal obligations, resolve disputes, enforce agreements, maintain backups, and protect security.
- Account and project data may remain until you delete it or request deletion, subject to backup and legal retention limits.
- Free, trial, beta, inactive, cancelled, or unpaid accounts and related project data may be limited, archived, or deleted after notice where reasonably practical.
- Logs, analytics, and security records may be retained for shorter or longer periods depending on operational, legal, and security needs.
- Deleted data may persist temporarily in backups, caches, logs, or archived systems before permanent deletion.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, such as encrypted connections, authentication controls, access restrictions, password hashing, role-based access controls, logging, and infrastructure security features.
No online service, database, storage system, transmission, or security measure is 100% secure. To the maximum extent permitted by law, FrameVerk is not responsible for unauthorized access, disclosure, loss, corruption, or misuse of data resulting from factors outside our reasonable control or from your account, device, sharing, or credential practices.
10. International Transfers
We and our service providers may process or store information in countries other than where you live. These countries may have different data-protection laws.
Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, data-processing agreements, provider compliance programs, or other lawful transfer mechanisms.
11. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data, and to withdraw consent where processing is based on consent.
You may also be able to update account information in the Service, disable certain cookies in your browser, unsubscribe from non-essential emails, or contact us to request assistance.
To exercise rights, contact support@frameverk.com. We may need to verify your identity and may deny or limit requests where permitted by law.
12. Children's Privacy
FrameVerk is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps.
13. Marketing Communications
If you sign up for a waitlist, account, newsletter, product update, or launch access, we may send service-related or marketing communications. You can unsubscribe from marketing emails, but we may still send important account, security, billing, or service notices.
14. Legal Requests and Protection of Rights
We may access, preserve, use, or disclose information if we believe it is reasonably necessary to comply with law, respond to lawful requests, enforce our Terms, investigate abuse or security issues, protect users or the public, or defend legal claims.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we may notify you by email, in-app notice, or website notice. Continued use of the Service after an updated policy becomes effective means you acknowledge the updated policy.
16. Contact
Privacy questions, requests, or concerns may be sent to: