Sigma Foundry

privacy policy

Privacy Policy — TEMPLATE

> ⚠️ Template, not legal advice. Fill every `[BRACKET]` and have a lawyer review before use.

> If you serve EU/UK (GDPR) or California (CCPA/CPRA) users, confirm the specifics with counsel.

[COMPANY LEGAL NAME] ("we," "us")

Effective date: [DATE]

This Privacy Policy explains what personal data we collect, why, and your rights.

1. Data we collect

provider, [Outseta/Memberstack].

directly by Stripe**; we do not store full card numbers.

operate and secure the Services.

We aim to collect the minimum necessary. We do not sell your personal data.

2. How we use data

To provide and secure the Services, process subscriptions and payments, verify active access

(the subscription check), provide support, comply with law, and communicate service and billing

notices.

3. Legal bases (GDPR, if applicable)

We process data to perform our contract with you (providing the Services), for our

legitimate interests (security, preventing abuse/redistribution), to **comply with legal

obligations (tax, accounting), and with your consent** where required (e.g., marketing email).

4. Sharing with processors

We share data only with service providers that help us run the business, under appropriate

agreements:

These providers process data on our behalf and are not permitted to use it for their own purposes.

5. Data retention

We retain personal data for as long as your account is active and as needed for legal, tax, and

accounting purposes, then delete or anonymize it.

6. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict

processing of your data, and to object or withdraw consent. To exercise these, contact

[privacy@yourbrand.com]. California residents have rights under CCPA/CPRA, including the right

to know and delete, and we do not sell personal information.

7. International transfers

If we transfer data across borders, we use appropriate safeguards (e.g., standard contractual

clauses) where required.

8. Security

We use reasonable technical and organizational measures (including HTTPS and reputable processors)

to protect your data. No method is 100% secure, but we work to protect it.

9. Cookies

We and our providers use cookies/local storage necessary to authenticate sessions and operate the

Services. [Add a cookie banner/notice if you use analytics or marketing cookies.]

10. Children

The Services are not directed to children under [13/16], and we do not knowingly collect their data.

11. Changes

We may update this Policy; material changes will be communicated, and the "effective date" updated.

12. Contact

[COMPANY LEGAL NAME], [ADDRESS] — [privacy@yourbrand.com]