Privacy Policy
At Vector Witch, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site.
1. Information We Collect
1.1 Personal Information You Provide
We collect information you provide directly to us, including:
- Account Information: Email address, name, password, and profile picture
- Payment Information: Billing address, payment method details (processed by Stripe)
- Generated Content: Text prompts, uploaded images, and generated SVG files
- Communications: Messages sent through our contact form or support system
- Preferences: Language, theme settings, and notification preferences
1.2 Information Collected Automatically
When you visit our service, we automatically collect certain information about your device:
- Log Information: IP address, browser type, operating system, referring URLs
- Device Information: Hardware model, operating system version, unique device identifiers
- Usage Data: Pages visited, time spent, features used, generation history
- Cookies and Similar Technologies: Session cookies, authentication tokens, preferences
- Analytics Data: Performance metrics, error reports, usage patterns
1.3 Information from Third Parties
We may receive information about you from third parties:
- OAuth Providers: Profile information from Google when you use social login
- Payment Processors: Transaction confirmations from Stripe
- Analytics Services: Aggregated demographic data from Google Analytics
2. How We Use Your Information
We use the collected information for various purposes:
- Service Provision: To provide, maintain, and improve our SVG generation service
- Account Management: To create and manage your account, authenticate users
- Transaction Processing: To process payments, send confirmations, manage subscriptions
- Communication: To send service updates, security alerts, support messages
- Personalization: To remember your preferences, provide customized features
- Analytics: To understand usage patterns, improve performance, fix bugs
- Security: To detect fraud, prevent abuse, ensure platform security
- Legal Compliance: To comply with legal obligations, respond to legal requests
- Marketing: With your consent, to send promotional materials about new features
3. Data Sharing and Disclosure
3.1 Public Content
Important: Content you choose to make public in the Explore gallery will be visible to all users and visitors. This includes your username, generated SVGs, and creation dates.
3.2 Service Providers
We share information with third-party service providers that help us operate our service:
- Supabase: Database and authentication services
- Stripe: Payment processing and subscription management
- Cloudflare R2: Content delivery and storage
- Google Analytics: Usage analytics and performance monitoring
- SendGrid: Email delivery services
3.3 Legal Requirements
We may disclose your information if required by law or in response to:
- Court orders, subpoenas, or legal processes
- Government requests or regulatory requirements
- Protection of our rights, property, or safety
- Investigation of potential violations of our Terms
3.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of such changes.
4. Data Storage and Security
4.1 Storage Location
Your data is stored on secure servers in multiple locations including the European Union and United States. By using our service, you consent to the transfer and processing of your information in accordance with applicable data protection laws.
4.2 Security Measures
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit (TLS/SSL) and at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication requirements
- Regular backups and disaster recovery procedures
- Employee training on data protection practices
4.3 Data Breach Notification
In the event of a data breach that may affect your personal information, we will notify you within 72 hours via email and provide information about the incident and recommended actions.
5. Cookies and Tracking Technologies
5.1 Essential Cookies
Required for the operation of our service:
- Authentication: To keep you logged in securely
- Security: To prevent fraud and protect your account
- Load Balancing: To ensure optimal performance
5.2 Functional Cookies
Enhance your experience:
- Preferences: Remember your settings (theme, language)
- Recent Activity: Track your generation history
5.3 Analytics Cookies
Help us understand usage:
- Google Analytics: Track page views, user journeys, demographics
- Performance Monitoring: Identify slow pages, errors
5.4 Managing Cookies
You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of our service.
6. Your Rights and Choices
6.1 Access and Portability
You have the right to access your personal information and receive a copy of your data in a structured, machine-readable format.
6.2 Correction and Update
You can update your account information at any time through your profile settings or by contacting our support team.
6.3 Deletion
You can request deletion of your account and personal information. Note that some information may be retained for legal or legitimate business purposes.
6.4 Opt-Out
You can opt-out of:
- Marketing communications via unsubscribe links or account settings
- Analytics tracking by using browser privacy tools
- Cookies through browser settings
6.5 Do Not Track
We currently do not respond to Do Not Track signals. However, you can control tracking through cookie settings and privacy tools.
7. International Data Transfers
We operate globally and may transfer your information to countries outside your country of residence. We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses approved by the European Commission
- Privacy Shield framework compliance (where applicable)
- Adequate security measures as required by GDPR
8. Children's Privacy
Our service is not directed to individuals under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete such information.
9. California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt-out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
10. European Privacy Rights (GDPR)
If you are in the European Economic Area, you have additional rights:
- Legal Basis: We process data based on consent, contract, or legitimate interests
- Data Protection Officer: Contact our DPO at privacy@vectorwitch.com
- Supervisory Authority: You may lodge complaints with your local data protection authority
- Withdrawal of Consent: You may withdraw consent at any time where processing is based on consent
11. Data Retention
We retain your information for different periods depending on the type:
- Account Information: Until account deletion plus 30 days
- Generated Content: According to your subscription plan limits
- Payment Records: 7 years for tax and accounting purposes
- Analytics Data: 26 months (Google Analytics default)
- Security Logs: 90 days for security monitoring
12. Third-Party Links
Our service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Material changes will be notified via email or prominent notice on our service.
14. Contact Information
If you have questions or concerns about this Privacy Policy, please contact us:
- Email: privacy@vectorwitch.com
- Data Protection Officer: dpo@vectorwitch.com
- Address: VectorX Ltd., 128 City Road, London EC1V 2NX, United Kingdom
- Company Registration Number: 16739534
Last updated: September 2025