This Privacy Policy explains how Web Canaries LLC ("Company", "we","us", or "our") collects, uses, shares, and protects information about you when you use Vid Canary ("Service"). It also explains your rights and choices regarding your information.
By using our Service, you agree to the collection and use of information in accordance with this policy.
Overview#
Web Canaries LLC is the data controller for personal information collected through Vid Canary. We respect your privacy and are committed to protecting your personal data.
This policy aims to give you information on how we collect and process your personal data through your use of this Service, including any data you may provide when you:
- Create an account
- Subscribe to our service
- Upload product information
- Generate or download videos
- Contact customer support
Please read this policy carefully to understand our practices regarding your personal data.
Information We Collect#
We collect several types of information from and about users of our Service, including:
Account Data
- Full name
- Email address
- Password (stored as a secure hash)
- Company name (if provided)
- Stripe customer ID
Usage Data
- Log-in dates and times
- IP addresses
- Browser type and version
- Device information
- Pages visited
- Features used
- Video generation requests
- Downloads
Payment Data
- Payment method details (processed and stored by Stripe)
- Billing address
- Subscription history
- Transaction records
Note: We never store complete credit card numbers on our servers. All payment processing is handled by Stripe.
Content Data
- Product URLs you provide
- Product information (titles, descriptions, images)
- Generated videos
- Any custom text or media you provide for video generation
Cookies and Tracking Data
- Cookies necessary for Service functionality
- Authentication tokens
- Analytics data (via PostHog and Vercel Analytics)
- Session information
How We Use Your Information#
We use the information we collect for various purposes, including:
- Providing and maintaining the Service: Operating Vid Canary and delivering the functionality you expect
- Creating videos: Generating product videos based on the information you provide
- Account management: Setting up and managing your account, authentication, and user experience
- Processing payments: Handling subscriptions, billing, invoices, and payment records
- Customer support: Responding to your inquiries, troubleshooting issues, and providing assistance
- Communication: Sending important notifications about your account, subscriptions, or the Service
- Service improvement: Analyzing usage patterns to enhance features and functionality
- Security: Detecting, preventing, and addressing technical issues or fraudulent activities
- Legal compliance: Meeting our legal obligations and enforcing our Terms of Service
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose.
Legal Bases for Processing#
For users in the European Economic Area (EEA), we process personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):
- Contract: Processing necessary to fulfill our contractual obligations to you when you subscribe to our Service
- Legitimate Interests: Processing necessary for our legitimate interests, such as improving our Service, security measures, and fraud prevention, provided that these interests are not overridden by your own rights and interests
- Legal Obligation: Processing necessary to comply with our legal obligations
- Consent: Processing based on your explicit consent, which you can withdraw at any time
For each processing activity, we have determined and documented the appropriate legal basis.
Data Sharing and Disclosure#
We may share your information with the following categories of recipients:
- Service Providers: Third parties who perform services on our behalf, including:
- Stripe: Payment processing
- Supabase: Database and authentication services
- AWS: Cloud storage and computing services
- PostHog: Analytics services
- Vercel: Hosting and analytics services
- Business Transfers: In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as a business asset
- Legal Requirements: When required by law, legal process, litigation, or governmental authorities
- Protection of Rights: When necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, potential threats to the safety of any person, or violations of our Terms of Service
We require all third parties to respect the security of your personal data and to treat it in accordance with applicable laws. We do not allow our third-party service providers to use your personal data for their own purposes, and only permit them to process your personal data for specified purposes and in accordance with our instructions.
Data Security#
We implement appropriate technical and organizational measures to protect the security of your personal data, including:
- Encryption of sensitive data at rest and in transit
- Secure authentication mechanisms
- Regular security assessments and testing
- Access controls and permissions management
- Continuous monitoring for potential security incidents
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security but are committed to implementing reasonable and appropriate security measures.
Data Retention#
We retain your personal data only for as long as necessary to fulfill the purposes for which we collected it, including:
- Providing the Service to you
- Complying with legal, tax, accounting, or reporting requirements
- Resolving disputes
- Enforcing our agreements
Different types of data may be kept for different periods:
- Account data: Retained for the duration of your account and for a limited period after account closure
- Payment data: Retained in accordance with financial regulations, typically for 7 years
- Generated videos: Retained for the duration of your active subscription and for a limited grace period after subscription cancellation
- Usage data: Typically retained for 12-24 months
When personal data is no longer needed, we will securely delete or anonymize it.
International Data Transfers#
We operate globally and may transfer your personal data to countries or territories other than the one in which you reside. These countries may have data protection laws that differ from your country of residence.
For transfers from the EEA to countries not deemed to provide an adequate level of data protection, we implement appropriate safeguards, including:
- European Commission-approved Standard Contractual Clauses
- Binding Corporate Rules for transfers to data controllers
- Compliance with approved certification mechanisms (e.g., EU-US Data Privacy Framework)
By using our Service, you consent to the transfer of your data as described in this Privacy Policy. If you have questions about these safeguards, please contact us using the information provided at the end of this policy.
Your Rights#
Depending on your location, you may have certain rights regarding your personal data. These may include the right to:
- Access: Request copies of your personal data that we hold
- Rectification: Request correction of incomplete or inaccurate personal data
- Erasure: Request deletion of your personal data in certain circumstances
- Restriction: Request that we restrict the processing of your personal data
- Data Portability: Request the transfer of your personal data to you or a third party
- Objection: Object to processing of your personal data in certain circumstances
- Automated Decision-Making: Contest automated decisions and request human intervention
- Withdraw Consent: Withdraw consent where we rely on consent as the legal basis for processing
To exercise any of these rights, please contact us using the information provided at the end of this policy. We may need to verify your identity before fulfilling your request. We will respond to legitimate requests within one month, which may be extended by up to two additional months when necessary, taking into account the complexity and number of requests.
You will not have to pay a fee to access your personal data or exercise other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
Children's Privacy#
Our Service is not directed to children under the age of 18, and we do not knowingly collect personal data from children under 18. If we learn that we have collected personal data from a child under 18, we will take steps to delete that information as quickly as possible.
If you believe we have collected personal data from a child under 18, please contact us immediately.
Changes to this Policy#
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and, when appropriate, sending you a notification.
We will provide notice of material changes at least 30 days before they become effective. We will indicate the effective date of the changes at the top of this page.
We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the Service after we post changes to the Privacy Policy constitutes your acceptance of those changes.
Contact Information#
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@vidcanary.com