Draft. These documents are not final. Text in [brackets] is filled in once the business details are set, and a lawyer should review everything before paid plans launch.

Privacy Policy

Last updated September 24, 2026

This policy explains how [Company legal name] (“we”, “us”) collects, uses, and shares personal information when you visit this website or use Templatize (the “Service”), and the choices you have.

1. Who is responsible for your information

We decide how account information is used, so for it we are the “business” (or “controller”). The content a company puts into its workspace, such as templates, belongs to that company. For that content we act as its “service provider” (or “processor”) under our Data Processing Addendum, and the company's own privacy policy applies. If your employer invited you, questions about how your employer uses the workspace go to your employer.

2. What we collect

  • Account information: your name, work email, workspace name, and role. Your password is stored only as a one-way bcrypt hash, so we can't read it.
  • Preferences: your time zone, which your browser reports so greetings and dates are right, and the mail app you prefer.
  • Workspace content: templates, categories, tags, version history, and favorites.
  • Activity: when you copy or open a template, which template it was, and when you were last active. We record that a copy happened, not what you pasted or who you emailed.
  • Security data: the IP address of sign-in, signup, and waitlist attempts, used to block password-guessing and spam, and records of your signed-in sessions.
  • Consent records: when you agreed to our Terms, and which version.
  • Waitlist and sales requests: the email, name, company, team size, plan, and message you send us.
  • Billing, once checkout opens: your plan, billing period, and subscription status. Our payment processor, Stripe, collects your card and billing address directly. We never receive full card numbers.
  • Server logs: our hosting provider records basic request details, such as IP address, browser type, and the page requested, for a short time to keep the Service running and secure.

We do not collect precise location, and we do not buy personal information from data brokers. The values you type into a template's fill-in fields, such as a client's name, stay in your browser and are not sent to us.

3. Cookies

We use one cookie, templatize_session, which keeps you signed in. It is strictly necessary, can't be read by scripts, and expires after 30 days or when you sign out. We use no analytics, advertising, or third-party cookies, no tracking pixels, and no third-party scripts. Fonts are served from our own servers. Because the only cookie is required for the Service to work, there is no cookie banner.

4. How we use information

  • To provide the Service: accounts, workspaces, templates, and sign-in.
  • To keep it secure: rate limits, abuse prevention, and investigating problems.
  • To give workspace admins usage analytics about their own workspace.
  • To provide support and send service messages, such as security, billing, and policy notices.
  • To send the one email you asked for when checkout opens, or to answer your sales request.
  • To meet legal obligations, such as tax and automatic-renewal record-keeping.

We do not use personal information for advertising, do not sell it, and do not use workspace content to train machine-learning models. We don't send newsletters; if we ever do, they will have an unsubscribe link.

5. How we share information

  • Inside your workspace. Admins can see members' names, emails, roles, last active times, and which templates they use. Everyone in the workspace can see who last edited a template.
  • With service providers that host and run the Service for us, under contracts that limit their use of the data. They are listed on our Subprocessors page.
  • With your mail provider, when you choose. “Open in” Gmail, Outlook, or Yahoo opens that provider's compose page with the subject and body in the web address, so the provider receives them under its own privacy policy. “Your mail app” hands the email to the app on your device.
  • For legal reasons, when required by law or needed to protect people's safety or our rights.
  • In a business transfer, such as a merger or acquisition, with notice to you.

We have not sold or shared personal information, as those terms are defined in the California Consumer Privacy Act, in the past 12 months, and we do not do so.

6. How long we keep it

  • Account and workspace data: while the account or workspace exists.
  • Deleted accounts and workspaces: removed from our live database immediately, and from backups within 30 days.
  • Security records of sign-in, signup, and waitlist attempts: up to two days.
  • Sessions: until they expire after 30 days or you sign out.
  • Waitlist and sales requests: until we have answered you, and no longer than 24 months.
  • Billing and consent records: as long as the law requires, which is up to seven years for tax records and at least three years for automatic-renewal consent.

7. Security

Data is encrypted in transit and at rest, passwords are hashed, and access is limited to what each role needs. See our Security page for details. No system is perfectly secure, so if we learn of a breach affecting your information, we will notify you as the law requires.

8. Your choices and rights

  • Access and download: Settings, then Your data, then Download my data. Admins can also export the whole workspace.
  • Correct: edit your name and preferences in Settings. Ask a workspace admin to change your email.
  • Delete: Settings, then Your data, then Delete my account. Admins can delete the whole workspace.
  • Anything else: email [support email]. We respond within 45 days, and will tell you if we need up to 45 more.

To protect you, we verify requests by confirming control of the account's email address. You may use an authorized agent, who must show your written permission. We will not treat you differently for using your rights. If your employer's workspace holds your information, we may refer your request to your employer, who controls that workspace.

9. California privacy rights

Whether or not the California Consumer Privacy Act applies to us, we extend its rights to everyone. California residents may ask to know, access, correct, and delete their personal information, to opt out of its sale or sharing, and to limit the use of sensitive personal information. We don't sell or share personal information and we use sensitive personal information only to let you sign in, so there is nothing to opt out of or limit.

In the past 12 months we collected these categories, from you, your workspace admin, and your browser:

CategoryExamplesUsed for
IdentifiersName, email address, IP address, account IDAccounts, sign-in, security, support
Customer recordsName, email, company name, and, once checkout opens, billing details held by StripeAccounts, billing, support
Commercial informationPlan, billing period, subscription status, purchase historyBilling, plan limits
Internet or other electronic network activityWhich templates you copy and when, last active time, sign-in attemptsWorkspace analytics for admins, security
Professional informationCompany name, your role in the workspaceRunning the workspace
Sensitive personal informationYour email and password, used together to sign in (the password is stored only as a one-way hash)Sign-in only

We disclose these categories for business purposes only to the service providers listed on our Subprocessors page. We do not knowingly sell or share the information of anyone under 16.

Global Privacy Control and Do Not Track. We honor Global Privacy Control signals as a request to opt out of sale and sharing, which we already don't do. We don't track you across other websites, so the Service works the same whether or not your browser sends a Do Not Track signal.

Shine the Light. We do not disclose personal information to third parties for their own direct marketing (California Civil Code Section 1798.83).

10. Visitors outside the United States

The Service is hosted in the United States, and your information is stored and processed there. Where the law requires, we rely on the European Commission's Standard Contractual Clauses, or the UK and Swiss equivalents, for transfers. If you are in the European Economic Area, the United Kingdom, or Switzerland, you may also object to or restrict processing, ask for a portable copy, withdraw consent, and complain to your local data protection authority. We process your information to perform our contract with you, for our legitimate interests in running and securing the Service, to meet legal obligations, and, for the waitlist, with your consent.

11. Children

The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

12. Changes to this policy

We will post any update here and change the date at the top. If a change is material, we will email account holders or show a notice in the Service before it takes effect.

13. Contact

[Company legal name]
[Business mailing address]
[support email]