FrameGloss Back to the edit

Privacy
notice.

Who is responsible

BeaconWorks, LLC operates FrameGloss and is the controller of the personal information described here. Our business mailing address is 8 The Green, Ste 15772, Dover, Delaware 19901, USA. Contact [email protected] for privacy questions or to exercise your rights.

Information we collect

You provide your name, email address and sign-in details when you create an account. We store a protected password hash for email sign-in, verification and account dates, and session and security-token records. If you choose Google sign-in, Google provides your verified email, name, Google account identifier and, if available, profile image. We store the prompt identifiers and dates for your favorites and recently opened looks.

A free-pack request provides your email address. We record the pack request, delivery status, access-token records, and any separate marketing consent, including its source, version, date and withdrawal. If you contact us, we receive the information in your message. Service requests also involve technical information such as your IP address, browser and requested URL, which our infrastructure may process to deliver and protect the service.

Stripe processes your checkout and payment information. We store Stripe customer and subscription identifiers, the plan, subscription status and billing periods to manage access. We do not store your full card number. Stripe may receive your account name, email and identifier together with the billing details you provide to it.

For a subscription purchase, we record your agreement to recurring billing, including the terms version, date, plan, price and billing interval. If you submit a withdrawal notice, we store your name, confirmation email, contract reference, statement and receipt time, with a proof identifier and relevant contract details. Confirmation and reminder delivery records include the recipient, message, status and delivery attempts.

Photos and prompt edits

FrameGloss has no reference-photo upload. You provide photographs directly to your chosen image tool, under that tool’s privacy terms. Text you edit in our prompt editor stays in that browser page’s memory and is not saved to your FrameGloss account. Copying a prompt writes the text to your device’s clipboard.

Why we use information

Where EU or UK data protection law applies, we use the following legal bases:

  • To provide the account, saved looks, requested free pack, billing and subscription access: performance of our contract with you, or steps you request before entering one.
  • To secure accounts, prevent abuse, troubleshoot the service and respond to support requests: our legitimate interests in operating a safe, reliable service, balanced against your rights.
  • To send optional marketing emails: your separate consent. Receiving a free pack or creating an account does not require this consent.
  • To keep records required by tax, accounting or other applicable law: compliance with legal obligations. We process contract-withdrawal notices and related confirmations to meet applicable consumer-law duties. Keeping consent and dispute evidence where not legally required relies on our legitimate interest in protecting legal rights.

An email address and sign-in information are needed for an account; payment information is needed for a paid subscription. Without these, we cannot provide those features. Marketing consent is optional. You can withdraw it at any time through the unsubscribe link or by emailing us; withdrawal does not affect the lawfulness of earlier processing. Requested service messages, such as password resets, are separate from marketing.

Who receives information

We use infrastructure providers to host the service and its database, Stripe for payments, and Google when you choose Google sign-in. When email delivery is enabled, OneSignal receives your email address and message content to deliver requested packs, account messages, subscription confirmations and reminders, and withdrawal receipts. Account and legal messages may instead use an SMTP email provider when configured. If marketing email delivery is enabled and you opt in, OneSignal also receives the contact and consent information needed for that delivery. Email delivery and marketing are currently disabled pending activation.

These providers process information for their services; some, such as Stripe and Google, also process information under their own privacy notices. See Stripe’s privacy policy, Google’s privacy policy and OneSignal’s privacy policy. Authorized people supporting FrameGloss may access information as needed. We may disclose it when legally required or reasonably necessary to protect legal rights or address security incidents.

Cookies and measurement

Necessary cookies keep you signed in and secure a Google sign-in attempt. FrameGloss currently uses no advertising trackers or third-party analytics. Recently opened looks are an account feature. See our cookie notice and preferences for cookie names, purposes and lifetimes.

How long we keep information

Account information, saved looks and subscription records remain stored while needed to provide your account. We consider account activity, unresolved support or payment issues, applicable recordkeeping duties and the need to establish or defend legal claims when assessing deletion. Marketing consent and opt-out records may be kept to show your choices and avoid sending unwanted marketing. Recurring-billing agreements and contract-withdrawal records may be retained where needed to document transactions, fulfill legal duties or resolve disputes.

Sign-in cookies expire after 30 days, Google sign-in state after 10 minutes, verification links after 24 hours, password-reset links after one hour and pack access links after seven days. Expiry of a link or cookie does not itself delete the associated database record. We do not currently run automatic deletion of inactive accounts or free-pack request records. Deletion requests are reviewed manually, including whether a record must be retained for a legal obligation or claim.

International processing and security

BeaconWorks is a US company. Our service providers may process information in the United States or other countries outside your country, including outside the EEA or UK. Data protection rules differ between countries. Contact us for details about the locations and safeguards that apply to your information and how to obtain a copy of applicable transfer safeguards.

We use access controls, protected password hashes and secure session cookies to help protect accounts. Changing or resetting your password revokes other account sessions. No service can guarantee absolute security.

Your controls and rights

In your account settings, you can change your name or password, sign out and manage subscription renewal. Removing a favorite deletes that saved association. Account deletion and data export are handled by request, rather than an account button: email [email protected] from your account address where possible.

Depending on applicable law, including the GDPR and UK GDPR, you may request access, correction, deletion, restriction or a portable copy of your information. You may object to processing based on legitimate interests and to direct marketing. These rights have legal conditions and exceptions. We may ask for information reasonably needed to verify your identity. We respond without undue delay, generally within one month where EU or UK law applies, and explain any permitted extension.

You may complain to your local data protection authority, including an authority in the EU country where you live or work, or the UK Information Commissioner’s Office. You can contact us about a concern without giving up that right.

Changes to this notice

We will update this notice when our practices change and show the revision date above. If a new use requires your consent, we will ask for it before starting that use.