PRIVACY NOTICE

Privacy for the BluePetal Studio platform.

This page describes the product’s intended data practices. It must be reviewed by qualified counsel and updated with BluePetal Studio’s legal business name, contact address, retention schedule, and production service providers before public launch.

Information used to operate an account

BluePetal Studio stores the account holder’s name, work email, password hash, website content, billing identifiers supplied by Stripe, support preferences, and the information the owner enters into the workspace. Passwords are salted and hashed; BluePetal Studio operators cannot read them. Full payment-card details remain with Stripe.

Website visitor information

Customer websites may collect quote-request details that a visitor intentionally submits, including contact information and project details. The business owner controls those leads and is responsible for its own customer notices and retention practices. BluePetal Studio’s built-in page analytics are aggregate and cookie-free.

BluePetal Studio account administration and support

Authorized BluePetal Studio operators can view limited account-health information needed to run the service, including the account name and email, plan and billing status, publishing status, aggregate traffic, and lead totals. The operator overview does not display passwords, full payment-card details, or the contents of individual lead requests.

Hands-on workspace support is off until the customer enables it from Account & Support. While enabled, an authorized operator may enter the workspace to troubleshoot or make customer-requested changes. Support sessions and important account changes are recorded. Customers may turn support access off at any time.

How information is protected and retained

Production access should be restricted to authorized people with a legitimate business need, protected by strong authentication, encrypted in transit, backed up, reviewed through audit records, and removed when no longer needed for the service or a legal obligation. BluePetal Studio should maintain written incident-response and retention procedures before launch.

Service providers

Production deployments may use a hosting provider, database provider, Stripe for payments, an email provider for account verification, and object storage for owner-uploaded images. BluePetal Studio should configure only providers with appropriate security terms and data-processing agreements.

Questions, corrections, or deletion requests

Before launch, add a monitored privacy contact address and a documented process for account access, correction, deletion, and applicable state privacy requests. This implementation draft is not final legal advice.