SPSPSoftProgrammer
Products ▾
Industries ▾
How We WorkResourcesAboutBlogContactSign inGet Started

Privacy Policy

Last updated: August 16, 2026

SoftProgrammer ("we", "us", "our") operates softprogrammer.com and the SoftProgrammer iOS app (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the choices and rights you have.

If you have questions or want to exercise any of the rights below, email support@softprogrammer.com.

1. Information we collect

Account data — Full name and work email you provide at signup, plus (optional) company name, the password hash generated by our auth provider, and the time of your signup.

Project data — Descriptions, requirements, budgets, timelines, attached files, and messages you submit when you request a quote, book a demo, or open a project in your dashboard.

Payment data — If you purchase a subscription or build, Stripe processes your payment details on our behalf. We do not store your full card number — we store only a token reference and limited billing metadata (card brand, last 4, country, subscription status).

Communications — Emails, chat transcripts with our AI assistant, support conversations, and any files you share during those conversations.

Usage data — IP address, user agent, pages viewed, referring URL, timestamps, approximate location derived from IP (country/region level), and device type. We collect this via server logs.

Analytics and campaign data — If, and only if, you accept optional cookies, we also collect aggregated usage measurements through Google Analytics and record which marketing campaign or referral partner brought you to the site. See section 6 for the detail, including how to decline.

Recruitment data — If you apply for a role, we collect the name, email, phone, resume, portfolio and profile links you submit, and any notes we make while assessing your application.

The Service is intended for business users aged 18 or over, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us and we will delete it.

2. Why we use it (legal bases)

  • To provide the Service — authenticating you, building what you've asked for, sending you project updates (performance of a contract).
  • To communicate with you — reply to support requests, notify you of material changes, send transactional emails (performance of a contract; legitimate interests).
  • To bill you — process payments, send invoices, handle refunds (performance of a contract).
  • To measure and improve the Service — understand which pages are useful and which campaigns work (consent, withdrawable at any time).
  • To keep the Service secure — detect abuse, prevent fraud, enforce our Terms (legitimate interests; legal obligation).
  • To assess job applications — evaluate your suitability for a role you applied to (steps prior to entering a contract; legitimate interests).
  • To comply with law — respond to lawful requests, preserve records we are required to keep (legal obligation).

We do not sell or share your personal data, and we do not use it to train third-party large language models without your explicit consent.

3. Who we share it with (sub-processors)

We share the minimum necessary data with the following sub-processors. Each is contractually required to protect your data and use it only to provide services to us.

  • Supabase — authentication, Postgres database, file storage (US).
  • Amazon Web Services — hosting (US).
  • Stripe — payment processing (US / Ireland).
  • Resend — transactional email delivery (US).
  • Google — "Sign in with Google" OAuth, and Google Analytics where you have accepted analytics cookies (US / global).
  • Cloudflare — Turnstile bot protection on our forms and sign-in pages (US / global).
  • Anthropic — powers our AI chat assistant (US).

We do not share your personal data with advertisers or data brokers. We disclose data to law enforcement only when legally compelled and, where permitted, we will tell you first. If we are involved in a merger, acquisition, or asset sale, your personal data may transfer to the successor, bound by this Privacy Policy or a materially similar one.

4. International transfers

Our infrastructure is based in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses or equivalent mechanisms with our sub-processors.

5. How long we keep it

  • Account data — while your account is active, plus 90 days after deletion.
  • Project data — while your account is active, plus up to 7 years thereafter for contractual, warranty, and tax recordkeeping, unless you ask us to delete it sooner.
  • Payment records — 7 years (tax and accounting requirements).
  • Server and security logs — 90 days, then aggregated or deleted.
  • Support tickets and AI chat transcripts — 2 years.
  • Analytics data — retained by Google Analytics for 14 months from your last visit.
  • Campaign attribution cookies — 90 days (campaign) and 60 days (referral partner) from the visit that set them.
  • Recruitment data — 12 months after a hiring decision, unless you ask us to delete it sooner or agree to be kept on file.

6. Cookies and similar technologies

Strictly necessary (always on). Session cookies that keep you signed in, CSRF protection, Cloudflare Turnstile bot protection, and a record of your own cookie choice. These are set by us, cannot be switched off, and do not require your consent.

Analytics (optional, off by default). We use Google Analytics 4 to understand which pages are read and where visitors leave. Google is a third party and sets its own cookies. No Google Analytics script is requested or loaded until you press "Accept All" on our cookie banner — if you choose "Essential Only", or simply never answer, you are not measured at all.

Campaign attribution (optional, off by default). Where you have accepted optional cookies, we set sp_utm (90 days) to record which marketing campaign brought you to the site, and sp_ref (60 days) to credit a referral partner if you arrived through one. Both are first-party cookies set by us. We do not share them with advertisers and we do not use them to build a profile of you across other websites.

You can withdraw or change your choice at any time by clearing your browser cookies and site data for softprogrammer.com, which will cause the banner to appear again on your next visit.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal data; to restrict or object to certain processing; and to withdraw consent where we relied on it. EU/UK residents may also lodge a complaint with their local supervisory authority.

To exercise any of these rights, email support@softprogrammer.com from the address on your account. We will respond within 30 days (or 45 days for complex requests, with notice to you). We may need to verify your identity before acting on a request; where we cannot verify you, we will tell you why.

Authorised agents

You may use an authorised agent to submit a request on your behalf. We will ask the agent for written proof of your authorisation, and we may ask you to confirm directly that you granted it.

No discrimination

We will not deny you service, charge you a different price, or provide you a different level or quality of service because you exercised any privacy right.

8. California residents

In the twelve months before the date at the top of this policy, we collected the following categories of personal information as defined by the California Consumer Privacy Act, as amended by the CPRA.

CategoryExamples we collectSourcePurpose
IdentifiersName, email, phone, IP address, account IDYou; your deviceProvide the Service, communicate, secure the account
Customer recordsCompany name, billing metadataYou; StripeBilling and recordkeeping
Commercial informationProjects commissioned, engagement model, order historyYouDeliver and invoice the work
Internet or network activityPages viewed, referring URL, timestamps, analytics eventsYour device; Google AnalyticsSecurity, and measurement where you consented
Geolocation dataApproximate country/region derived from IPYour deviceSecurity and fraud prevention
Professional informationResume, work history, portfolio links (applicants only)YouAssess your job application
InferencesWhich engagement model may suit youDerived from the aboveRecommend an engagement model

We do not collect sensitive personal information as that term is defined by the CPRA, and we do not use or disclose personal information for purposes other than those listed above.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" link. We have not sold or shared personal information in the preceding twelve months, and we do not knowingly sell or share the personal information of consumers under 16.

Global Privacy Control. Because we neither sell nor share personal information, there is no sale or sharing for an opt-out preference signal to stop. We nonetheless treat a GPC signal as a withdrawal of consent to optional analytics and campaign cookies.

California residents may exercise the access, deletion, correction, and non-discrimination rights described in section 7 by emailing support@softprogrammer.com.

9. Business clients and data processing

Where we host or operate software on your behalf and that software handles personal data belonging to your own customers or staff, you are the controller of that data and we act as your processor. We will enter into a Data Processing Addendum covering the terms required by GDPR Article 28 and the CCPA service provider provisions on request — contact us and we will provide one.

10. Security

We use industry-standard measures to protect your data: encryption in transit (HTTPS with HSTS) and at rest; role-based access controls and audit logging; salted password hashes; security headers on every response; and regular dependency updates with automated vulnerability scanning. No system is perfectly secure. If we discover a breach that affects your personal data, we will notify you without undue delay and, where legally required, within 72 hours of becoming aware of it.

11. Automated decision-making

Our AI assistant helps scope enquiries and may suggest an engagement model, and our tools may draft internal notes. These outputs are suggestions only. No decision that produces a legal or similarly significant effect on you — including whether we take on your project, what we charge, and any hiring decision — is made solely by automated means. A person reviews and decides.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top. If changes are material, we will email account holders at least 14 days before the change takes effect.

13. How to reach us

For privacy questions, data requests, or to exercise your rights: support@softprogrammer.com.

SPSoftProgrammer

Custom software for every business. Founded 2013.

Products

ERP SystemsCRM PlatformsMobile AppsAI ToolsSaaS PlatformsE-CommerceAll Products →

Industries

RetailHealthcareFinanceLogisticsHospitalityConstructionPet CareNon-ProfitView all 41 →

Company

About UsHow We WorkContact UsRequest a DemoCost CalculatorResourcesEarn with UsFAQCustom vs SaaSBlogCareersGet StartedSign InPrivacy PolicyTerms of UseAccessibility
Take us with you
Download on theApp Store
© 2026 SoftProgrammer. All rights reserved.California, USA · 48hr Response