Privacy Policy
Last updated on activation. This is placeholder legal copy. Replace it with your own reviewed terms before launch.
Effective date: [Add your launch date]. Data controller: [Your legal entity name], [registered address], contact hello@beacon.example. [Name a Data Protection Officer or EU/UK representative if you are required to.]
This sample policy explains what Beacon collects, why, and the controls you have. Replace it with a policy that reflects your actual data practices, checked against GDPR, UK GDPR, and CCPA/CPRA where they apply to you.
1. What we collect
From the marketing site, if you use the contact form, we collect the name, email, company, team size, and message you submit. From the app, we collect account details (name, email, role) and the organization content you create (clients, projects, tasks, estimates, time entries, payouts). Automatically, we collect basic server logs and security events.
2. Cookies and analytics
The marketing site does not set advertising or tracking cookies and does not run third-party analytics by default. WordPress may set strictly necessary cookies for core functionality. If you add analytics or any non-essential cookies, update this section and add a consent banner before those scripts load, as required by GDPR and the ePrivacy Directive.
3. Why we process it, and the legal basis
We process contact-form data to respond to your enquiry, on the basis of your consent. We process account and organization data to provide the service, on the basis of our contract with you. We process security logs on the basis of our legitimate interest in keeping the platform safe.
4. Who we share it with (sub-processors)
We use service providers to run the platform, and we share only what each needs. [Placeholder, list your actual providers, for example: a payment processor for subscriptions, a hosting provider, an email delivery provider, and object storage for files.] We do not sell your personal data.
5. International transfers
[Placeholder] If data is transferred outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses. [State where your data is hosted.]
6. How long we keep it
[Placeholder] We keep contact-form messages for [period], account data for the life of the account, and logs for [period]. An organization Admin can export or delete organization data at any time.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. California residents have rights under CCPA/CPRA, including the right to know and to delete. To exercise any of these, email hello@beacon.example. You may also lodge a complaint with your local data protection authority.
8. Security
Passwords are hashed with bcrypt. Access uses JWT auth with an active-user check on every request. Tenants are isolated at the data layer, input is validated, requests are rate-limited, and responses ship with hardened HTTP headers.
9. Children
The service is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.
10. Changes
We may update this policy and will post the new effective date here. Material changes will be communicated to account holders.
11. Contact
Questions about this policy? Email hello@beacon.example.