Privacy Policy

Last updated: June 25, 2026

1. Introduction & overview

This Privacy Policy explains how Ammario collects, uses, shares, and protects personal data when you use the Ammario platform — the admin application, the end-user feedback portal, the public roadmap and changelog, and related services. We are committed to compliance with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). By using Ammario, you agree to the practices described here.

2. Information we collect

Personal data

For admin accounts, we collect your email, username or display name, profile details, and authentication tokens. Authentication is handled by Clerk; we never see or store your password in plain text — credentials are managed by Clerk.

Usage data

We collect workspace configuration, board / post / vote / comment activity, product analytics, IP address, device, browser and operating system, and which pages and features are used.

Payment data

Billing information is processed by Paddle, our Merchant of Record. We retain transaction history, subscription details, and invoices. Card data is never stored on our servers — all payment-card processing is performed by Paddle, which is PCI DSS compliant.

End-user data

Visitors to a customer’s feedback portal may submit posts, votes, and comments, and may optionally provide an email address if they choose to identify themselves. This content belongs to the workspace owner, for whom we act as a processor.

3. How we collect information

  • Directly — when you sign up, configure a workspace, subscribe, or contact support.
  • Automatically — through server logs, product analytics, and error tracking.
  • From third parties — Clerk (authentication) and Paddle (payments).
  • Cookies — for session, security, and analytics (see section 9).

4. How we use information

We use personal data to provide and operate the Service, improve and develop features, maintain security and prevent fraud, and communicate with you about your account and the Service. Marketing communications are optional and you may opt out at any time.

5. Legal bases (GDPR)

Where the GDPR applies, we process personal data on these bases:

  • Performance of a contract — to deliver the Service you signed up for.
  • Legitimate interests — to secure, analyze, and improve the Service.
  • Legal obligation — to meet tax, accounting, and compliance duties.
  • Consent — for optional marketing and non-essential cookies.

6. Data sharing & sub-processors

We never sell your personal data. We share data only with the sub-processors needed to run the Service:

  • Paddle — payment processing and billing as Merchant of Record (see paddle.com/privacy).
  • Clerk — authentication and identity management.
  • Cloud hosting providers — to host and store workspace data.
  • Email providers — to deliver transactional and notification email.
  • Analytics — anonymized and aggregated only.

We may also disclose data where required by law or in connection with a business transfer such as a merger or acquisition, subject to this Policy.

7. Data retention

We retain active account data until you delete your workspace. Usage logs are kept for roughly 12 months. Payment records are retained for approximately 7 years to meet legal and tax obligations. Marketing preferences are kept until you opt out. Workspace data is exportable at any time and is deleted after the cancellation grace window described in our Terms.

8. Your privacy rights

GDPR (EU/EEA)

You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and not to be subject to solely automated decision-making. Data portability is also built into the product: one-click CSV/JSON export means your data is always yours to take with you.

CCPA (California)

You have the right to know what personal information we collect, to request deletion, to opt out of the sale of personal information (we do not sell it), and to non-discrimination for exercising your rights.

To exercise any right, email privacy@ammario.com. We respond to verified requests within 30 days. You may also delete your account from your workspace settings. We honor recognized Do-Not-Track and opt-out signals where required.

9. Cookies & tracking

  • Essential — authentication, session, and security; always on.
  • Analytics — product usage measurement; you can opt out.
  • Third-party — set by Paddle during checkout.

You can manage or block cookies through your browser settings; blocking essential cookies may break parts of the Service.

10. Data security

We protect data in transit with HTTPS/TLS and store it on secure, access-controlled infrastructure (including S3-compatible object storage). Passwords and credentials are managed by Clerk, payment-card security and PCI compliance are handled by Paddle, and we perform ongoing security reviews. No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard safeguards.

11. Children’s privacy

The Service is not intended for anyone under 16. We do not knowingly collect personal data from children, and we will delete such data if we discover it has been collected.

12. International data transfers

Your data may be processed in countries other than your own. Where we transfer personal data out of the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses. Our place of establishment and the specifics of these transfers remain to be confirmed.

[Ammario — legal entity, registered address & governing law to be confirmed]

13. Changes to this policy

We may update this Policy from time to time. For material changes we will notify you by email or via the website at least 30 days in advance. Continued use of the Service after the changes take effect constitutes acceptance.

14. Contact

For privacy questions or to exercise your rights, contact privacy@ammario.com or contact@ammario.com.

[Ammario — legal entity, registered address & governing law to be confirmed]

15. Regulatory authorities

If you are in the EU/EEA, you have the right to lodge a complaint with your local data protection authority or the EDPB; in the UK, with the ICO; and in California, with the California Attorney General. We ask that you contact us first so we can try to resolve your concern directly.