Privacy Policy

Last updated: 11/17/2025

Quick Summary: We collect minimal data to provide our service, never sell your information, and give you full control over your data. We use industry-standard security practices to protect your information.

1. Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Name (optional)
  • Profile picture (optional)
  • Authentication data (managed by Clerk)

Service Data

When you use StaticBox, we store:

  • Form submissions and responses
  • Data store entries you create
  • Project configurations and settings
  • File uploads and assets
  • Localization content and translations
  • API usage statistics

Technical Information

We automatically collect:

  • IP addresses (for security and analytics)
  • Browser and device information
  • Usage patterns and feature interactions
  • Error logs and performance data

2. How We Use Your Information

Service Delivery

  • Process and store your forms, data, and files
  • Send email notifications and responses
  • Provide customer support
  • Manage your account and subscriptions

Service Improvement

  • Analyze usage patterns to improve features
  • Monitor service performance and reliability
  • Develop new features and capabilities
  • Prevent abuse and ensure security

Communication

  • Send important service updates
  • Respond to your questions and requests
  • Send optional product updates (you can opt out)

3. Information Sharing

We never sell your data. We only share information in the limited circumstances described below.

Service Providers

We share data with trusted third parties who help us provide our service:

  • Clerk: User authentication and account management
  • Stripe: Payment processing and subscription management
  • Vercel/AWS: Hosting and infrastructure
  • Email providers: Sending notifications and responses

Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal processes
  • Protect our rights and property
  • Ensure user safety and security
  • Investigate potential violations of our terms

4. Data Security

We implement industry-standard security measures:

  • Encryption: Data encrypted in transit and at rest
  • Access control: Strict employee access policies
  • Infrastructure: Secure, monitored hosting environment
  • Regular audits: Security reviews and vulnerability assessments
  • API security: Rate limiting, authentication, and authorization

Note: No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

5. Your Rights and Choices

Data Access and Portability

You have the right to:

  • Access your personal data
  • Export your data in a portable format
  • Receive a copy of information we have about you

Data Correction and Deletion

You can:

  • Update your account information at any time
  • Delete your data through your dashboard
  • Request account deletion (we'll delete all your data within 30 days)
  • Opt out of marketing communications

Data Processing

You have the right to:

  • Object to processing of your personal data
  • Request restriction of processing
  • Withdraw consent (where processing is based on consent)

6. Data Retention

We retain your data only as long as necessary:

  • Active accounts: While your account is active
  • Deleted accounts: Up to 30 days for recovery purposes
  • Usage logs: Up to 12 months for security and analytics
  • Legal obligations: As required by applicable law

7. International Data Transfers

StaticBox operates globally. Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for international transfers, including:

  • Adequacy decisions by the European Commission
  • Standard Contractual Clauses (SCCs)
  • Certification schemes and codes of conduct

8. Children's Privacy

StaticBox is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.

9. Cookies and Tracking

We use cookies and similar technologies to provide and improve our service. For detailed information about our use of cookies, please see our Cookie Policy.

10. Changes to This Policy

We may update this privacy policy from time to time. When we do, we will:

  • Post the updated policy on this page
  • Update the "Last updated" date
  • Notify you of significant changes via email or service notification
  • Give you time to review changes before they take effect

11. Contact Us

If you have questions about this privacy policy or want to exercise your rights, please contact us:

Have questions about our privacy policy?

We typically respond within 48 hours

For EU residents: If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.