Privacy.

What we hold, what the hosting can see, and how to make us delete it.

Draft. Not reviewed yet. Ramon has to read and approve this page before the service takes its first real payment. It is an accurate description of what the software does today. It is not legal advice, and nobody qualified to give any has looked at it.

What we hold

Everything you put into the builder, which is:

  • your name, your title, your company and your email address
  • your website, the label you want it shown under, and your LinkedIn address
  • the brand colour you picked and the template you chose
  • the photograph you uploaded and the logo file, if you sent one

Alongside that we hold the identifiers Stripe gives us for your customer record, your subscription and the checkout that started it, and whether the subscription is currently active. We never see and never hold your card number.

A draft is saved while you are still building, before you pay and whether or not you ever do. It holds the same fields and the same uploads. That is what lets you close the tab, come back to the same address and find your card where you left it.

Your photograph

The face is found and cropped on our own server, by ordinary computer vision code running in the same process that draws your card. The photo is not sent to another company, and it is not used to train anything. The original is kept because rebuilding your card needs it.

Reading your website

If you press Import on the Brand panel, our server opens the address you typed and reads that one page, its stylesheets and one icon, to find your colours and your mark. It happens because you pressed the button, it reads only what a visitor to that page would see, and your web host sees our server arrive the way it sees any other visitor. We keep the mark only if you accept it, redrawn by us rather than stored as it arrived, and we keep the address so the field opens on it next time. Nothing else from the page is kept.

What the hosting can see

Your signature is made of images served from our server, so when somebody opens an email carrying it, their mail client asks us for those files. Our web server records that request the way any web server does: a time, an address and a browser string. We use it to serve the file and to see whether the service is up.

We do not turn that into read receipts. We do not tell you, or anyone else, who opened your mail or when. There is no tracking pixel in your signature: every image in it is a visible part of the card. And most mail clients fetch images through their own proxy, so what usually reaches us is the proxy rather than your recipient.

What we count

When an image in your signature is loaded, when a link in it is followed, and what somebody does with your card: opening it, pressing a button, saving your details. We never keep the address, the browser string, the name or the email of whoever did it. Each record holds the time, the day, which link or button, the family of mail client it looks like, and a scrambled code for "the same browser, today", made with a key thrown away at midnight. It holds a country only where we run behind hosting we trust to add one.

Your dashboard says views, never opens or reads. A view is an image being fetched: providers prefetch and cache, so it is a trend and not a headcount. It says when your signature was last fetched, never who fetched it. Your own visits are filtered out.

Connecting your Gmail

If you press Connect Gmail, Google gives us one permission — gmail.settings.basic, which can write the signature in your Gmail settings — and your address, so the screen can say which mailbox is connected. We cannot read your mail with it, and we do not ask for a permission that could. What we store is that address and the two tokens Google issues, encrypted on our disk with a key that is not kept in the database. We write your signature into the send-as address you pick and nothing else. Press Disconnect, on your signature or on Settings, and we delete the tokens from your account and cancel the permission with Google, retrying until Google confirms; the signature already in your Gmail stays there until you change it.

SelfMark's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Payments

Stripe takes the payment. Card details go from your browser to Stripe and never touch our server. What we keep is the set of ids Stripe hands back, which is what lets Manage billing open your own billing page. Stripe holds its own record of the payment under its own privacy notice.

Cookies and tracking

One cookie, and only if you sign in: it keeps you signed in and holds nothing else. Pressing Connect Gmail sets a second one for ten minutes, carrying only the secret that proves the trip through Google came back to the browser it left. Nobody who receives your mail or opens your card is ever given one. No analytics script, no tag manager, no advertising pixel. Your draft lives on our server against the address in your browser bar, which is why that address is worth keeping.

How long we keep it

The records above keep that detail for 400 days. Every hour a job sums each finished day into a plain count and deletes detail older than 400 days; the scrambled code and the country go with it. Your order and its files stay while your subscription runs, because they are what your signature is made of. An unpaid draft goes after two days. For the rest, the next part is the fix.

Getting it deleted

Write to support@selfmark.io from the address on your card and ask. We delete the order, the uploads and the rendered images. Your signature stops working at that point, in the same way it does when a subscription ends, except that this one does not come back.

Who else gets it

Nobody. We do not sell it and we do not share it. Stripe handles the payment and holds what it needs for that. Chat runs on our own support inbox (Chatwoot, run on our servers). When you are signed in, your email and account id are handed to it so the team knows who is writing. Support is a small team helped by an assistant. A person reads every conversation. The service itself runs on rented hosting, so the company we rent from holds the disk everything sits on, which is true of every website you have ever used and is worth saying rather than leaving out.

Talking to a person

One address, read by a person: support@selfmark.io.

See also Terms, which covers what the subscription pays for and what happens when it ends.