Cabinet Run

Privacy Policy

Last updated: 11 September 2026

DRAFT — have a lawyer review before launch, and replace [Legal Entity] with the operating entity.

The short version

We collect your email so you can sign in, your cabinet designs so the Service can work, and enough billing information to take payment. We use no analytics, no tracking pixels and no advertising. We never see your card number. We don’t sell anything to anyone, and you can ask for a copy of your data or its deletion at any time.

Who we are

[Legal Entity] operates Cabinet Run and is the controller of the personal information described here. Contact us at support@cabinetrun.com.

What we collect

Account details. Sign-in is handled by Clerk. They hold your email address, your name if you give one, your password or social-login connection, and sign-in timestamps. Our own database stores only your Clerk user ID — we do not keep a copy of your password, ever.

Your designs. Projects, rooms, walls, cabinets, appliances, countertops, materials, hardware profiles and tool settings. This is the content you create, and it is the reason the Service exists.

Billing. If you subscribe, we store your Stripe customer and subscription IDs, subscription status, renewal date, and a copy of each invoice (number, amounts, dates, tax). We also record when your trial started, whether you have used your free export, and any complimentary access an administrator has granted. Card numbers never reach our servers— the payment form is Stripe’s, running in their own frame.

Support.If you contact us or use “Report a problem”, we store your message, your name and email, and — for in-app reports — the page you were on and your browser’s user-agent string, because that is usually what makes a problem reproducible.

Operational records. Ordinary server logs kept by our hosting provider, a record of payment events received from Stripe, and a log of administrative actions taken on accounts (for example granting free access or issuing a refund), which exists so such actions are accountable.

What we don’t collect

  • No analytics, product telemetry or session recording.
  • No advertising, no third-party trackers, no cross-site pixels.
  • No card numbers, CVCs or bank details.
  • No location tracking, and no access to files on your computer beyond what you type in.

Cookies

We use only what sign-in requires: session cookies set by Clerk to keep you logged in, and cookies Stripe sets on its own payment form for fraud prevention. There are no advertising or analytics cookies, which is why you are not asked to dismiss a consent banner.

Why we’re allowed to use it

For anyone in the UK, EU or a comparable regime, our lawful bases are: performance of a contract for account, design and billing data — we cannot run the Service without it; legal obligation for invoices and tax records; legitimate interests for security, fraud prevention, support and keeping the Service working. We do not rely on consent, because we do not do the things consent is usually needed for.

Who processes it for us

We keep this list short on purpose. Each of these is bound by a data-processing agreement and may use your data only to provide their service to us.

  • Clerk — authentication and account records (United States).
  • Stripe — payments, invoicing and fraud prevention. Stripe is a controller in its own right for payment data; see their privacy policy.
  • Neon — the database holding your designs, billing records and support tickets.
  • Vercel — application hosting and server logs.
  • Resend — transactional email such as support replies, where enabled.

We do not sell personal information, and we do not share it for advertising. We will disclose data if the law genuinely requires it.

Where it goes

We are based in British Columbia, Canada, and our providers operate in Canada, the United States and the European Union. Where data leaves your region, transfers rely on the safeguards those providers put in place, such as standard contractual clauses.

How long we keep it

  • Designs and account data: while your account is open.
  • Inactive accounts: deleted after twelve months without activity, with email warning first and a chance to export.
  • Deleted accounts: designs, settings and support messages are removed; invoices and the administrative log are retained where law requires.
  • Invoices and tax records: as long as tax law requires, typically six to seven years.
  • Server logs: short-term, as kept by our hosting provider.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or send it somewhere else in a portable format. You can object to processing we base on legitimate interests. Write to support@cabinetrun.com and we will respond within 30 days. We will not charge you or treat you differently for asking.

You can also complain to a regulator: in Canada the Office of the Privacy Commissioner, in the UK the Information Commissioner’s Office, or your national data-protection authority in the EU. We would rather you told us first.

Security

Connections are encrypted in transit, data is encrypted at rest by our database provider, passwords are handled entirely by Clerk and never reach us, and card details never touch our servers. No system is perfectly secure; if a breach affects you we will tell you and the relevant regulator as the law requires.

Children

The Service is not for children. We do not knowingly collect information from anyone under 18, and will delete it if we discover we have.

Changes

If we change this policy we will update the date above, and give notice by email or in the Service for anything material. Adding analytics or a new processor would count as material.

Contact

Privacy questions and requests: support@cabinetrun.com.