Skip to main content

Privacy Policy

[PLACEHOLDER] This Privacy Policy explains how Dufftur ("Dufftur", "we", "us", or "our") collects, uses, shares, and protects personal information when you use our website, workspace, public profiles, and client portals. Effective date: [PLACEHOLDER]

1. Who we are

Dufftur is operated by [PLACEHOLDER]. For privacy-related questions, contact us at [PLACEHOLDER: privacy@example.com].

2. Scope

This Privacy Policy applies to:

  • The Dufftur website and authenticated workspace.
  • Public user profiles and profile links.
  • Public client trackers and related shared content.
  • Registration, onboarding, settings, and support interactions.

This policy does not apply to third-party websites or services that you access through links inside Dufftur, including websites listed in your profile links or client records.

3. Information we collect

The information we collect depends on how you use Dufftur. We collect information you provide directly, information generated through your use of the service, and limited technical information needed to operate and secure the platform.

3a. Account and identity information

When you register and maintain an account, we may collect:

  • First and last name
  • Email address
  • Date of birth
  • Username
  • Account role and plan
  • Password, which is handled through our authentication provider and not stored by us in plain text

3b. Profile and business information

Through onboarding and account settings, you may provide:

  • Secondary email address and primary contact phone number
  • Avatar image URL
  • Preferred currency and whether you are accepting work
  • Business name, website, business contact details, and address
  • Tax and registration details such as GSTIN, PAN, Udyam number, or similar identifiers
  • Bank account details used in invoicing workflows
  • Appearance preferences such as theme and accent color
  • Social profile URLs

3c. Workspace data

When you use Dufftur to manage your work, we store the information you enter into workspace features, including:

  • Client records, contacts, addresses, notes, and compliance-related fields
  • Gigs, deliverables, tasks, sub-tasks, and reminders
  • Invoices, invoice line items, and related billing details
  • Contracts, contract parties, and section values
  • Expenses, categories, and payment methods
  • Tracker configuration, activity logs, and visibility settings
  • Notifications generated by your workspace activity

3d. Data you make public

If you enable public features, certain information may be visible to visitors without requiring a Dufftur account. This may include:

  • Your public profile details and social links
  • Profile links and destinations you publish
  • Your public inquiry form and related settings
  • Tracker content you choose to expose through visibility settings

You control whether these features are enabled and what information is shared. If you enable passcode protection on a tracker, visitors must provide the passcode you set before accessing protected content.

3e. Data others provide about you

Visitors may submit inquiries or other information to you through public forms on your profile. We store the information they provide so you can review it. We may also store limited technical metadata, such as network and browser information, to help detect abuse and protect the service.

3f. Automatic and technical information

We automatically collect certain technical information, including:

  • Cookies and similar technologies described in our Cookie Policy
  • Error and performance data through monitoring tools such as Sentry
  • Optional session replay data if you consent to analytics cookies
  • Profile link click metadata, including hashed network identifiers, browser information, and referrer data

3g. Browser-local storage

Some convenience features store information locally in your browser, such as draft invoices, draft inquiry responses, saved form input, bookmarks or collections, and offline task sync data. This information remains on your device unless you clear browser storage or we provide a server-side equivalent.

Data categories summary

The table below summarizes major categories of information, why we process them, and how long we generally keep them.

Category Examples Purpose Typical retention
Account and identity Name, email, date of birth, username, role, plan Create and manage your account and authentication While your account is active; deleted after account removal
Profile and business Secondary email, phone, avatar, business details, tax identifiers, bank accounts, appearance settings, social links Personalize your profile and support business workflows While your account is active; deleted after account removal
Workspace data Clients, gigs, deliverables, tasks, invoices, contracts, expenses, notifications, trackers Provide core workspace features you use While your account is active; deleted after account removal
Public profile data Public name, username, avatar, accepting-work status, profile links, social links Display your public profile and link-in-bio pages While published; removed when you disable features or delete your account
Client portal data Tracker content you choose to share, optional passcode settings Share selected project information with clients While enabled; removed when you disable portals or delete your account
Inquiry submissions Submitter name, company, email, phone, project details; technical metadata for abuse prevention Deliver inquiries to the profile owner and prevent abuse Typically up to one year unless deleted earlier by the recipient
Profile link analytics Hashed IP, user-agent, referrer, device/browser signals Provide click analytics for profile links you manage While your account is active or as needed for analytics history
Cookies and technical logs Session cookies, preference cookies, error monitoring data Operate the service, remember preferences, improve reliability Varies by cookie or log type; see our Cookie Policy
Browser-local drafts Invoice drafts, inquiry drafts, bookmarks, offline task data Improve convenience and reduce data loss while you work Stored locally in your browser until you clear it

4. How we use information

We use personal information to:

  • Provide, operate, and maintain Dufftur
  • Create and authenticate accounts and enforce eligibility requirements
  • Enable workspace features you choose to use
  • Display public profiles, profile links, and client trackers according to your settings
  • Deliver inquiries and notifications
  • Provide profile link analytics to account holders
  • Protect the service, investigate abuse, and enforce our terms
  • Monitor reliability, diagnose errors, and improve the product
  • Communicate with you about service-related matters
  • Comply with legal obligations and respond to lawful requests

[PLACEHOLDER: contract, legitimate interests, consent — for GDPR and similar laws]

Where required by law, we rely on appropriate legal bases such as performance of a contract, legitimate interests, compliance with legal obligations, and consent for optional cookies or similar technologies.

6. How we share information

We may share personal information in the following circumstances:

  • Service providers: With vendors that help us operate Dufftur, such as hosting, authentication, database, storage, and error monitoring providers.
  • At your direction: When you publish a public profile, enable profile links, share a tracker, or otherwise make information available to visitors or clients.
  • Other users and visitors: When you use social features such as public search or follow relationships, limited profile information may be visible to others as described in the product.
  • Legal and safety reasons: When we believe disclosure is required by law or necessary to protect rights, safety, and security.
  • Business transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.

We do not sell your personal information.

[PLACEHOLDER: process for responding to lawful requests from authorities]

7. International data transfers

[PLACEHOLDER: Supabase region, standard contractual clauses, and transfer safeguards]

If you access Dufftur from outside the country where our service providers process data, your information may be transferred to and processed in other countries with different data protection laws.

8. Data retention

We retain personal information for as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements.

  • Active accounts: We retain account, profile, and workspace data while your account remains active and as needed to support features you use.
  • Account deletion: If you schedule account deletion, we begin a grace period before permanent removal. During that period, you may cancel the deletion request.
  • Inquiries: Inquiry submissions are generally retained for a limited period so recipients can manage their inbox, typically up to one year unless deleted earlier.
  • Technical logs and analytics: Retained according to our operational needs and the policies of relevant service providers.
  • Browser-local data: Remains on your device until you clear it.

9. Security

We use administrative, technical, and organizational measures designed to protect personal information. These measures may include encrypted connections, access controls, and service-provider safeguards.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect information against unauthorized access, loss, misuse, or alteration.

You are responsible for maintaining the security of your account credentials and reviewing what you choose to make public or share through client-facing features.

10. Your rights and choices

Depending on where you live, you may have rights to:

  • Access personal information we hold about you
  • Correct inaccurate information
  • Delete information or request account deletion
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Receive a copy of certain information in a portable format
  • Lodge a complaint with a supervisory authority

You can update much of your account information directly in Settings. You can schedule account deletion from your account settings. You can manage non-essential cookies through our cookie banner or the Cookie Policy page.

To exercise privacy rights or ask questions, contact us at [PLACEHOLDER: privacy@example.com]. We may need to verify your request before responding.

11. Children's privacy

Dufftur is not intended for individuals under 18 years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take appropriate steps to delete it.

Dufftur may contain links to third-party websites, social platforms, or services that we do not operate. Your use of those services is governed by their own privacy policies. We encourage you to review the policies of any third-party service you use.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and may provide additional notice as described here: [PLACEHOLDER: how users will be notified of material changes].

Your continued use of Dufftur after an updated policy becomes effective may constitute acceptance of the revised policy, except where applicable law requires otherwise.

14. Contact us

For privacy questions, requests, or complaints, contact us at [PLACEHOLDER: privacy@example.com].

This Privacy Policy should be read together with our Terms of Service and Cookie Policy.