Legal · plain language
Privacy Policy
This policy explains the information DonePages processes, why we process it, and the privacy choices available to you.
Last updated: August 31, 2026
1. Scope and our role
DonePages (“DonePages,” “we,” “us,” or “our”) provides software that turns completed-job photos and details into public pages, PDFs, social assets, lead forms, and review requests. This policy applies to donepages.com, the DonePages application, the affiliate program, and related support and communications (the “Service”).
DonePages is the controller of account, website, billing, security, and affiliate-program information. When a business customer uploads its own customer or prospect data, that business decides why and how the data is used; DonePages processes it on the business's behalf as a service provider or processor. Business customers are responsible for providing required notices and obtaining required permissions.
2. Information we collect
- Account and sign-in data. Name, email address, avatar, authentication identifiers, and security events. Password authentication is handled by Supabase Auth; DonePages does not store readable passwords. If you use Google sign-in, we receive profile details Google makes available, such as your name, email, avatar, and provider identifier.
- Business and workspace data. Business name, industry, logo, contact details, website, service areas, team memberships, domains, brand settings, and onboarding or acquisition information.
- Content and customer data. Photos, notes, project details, generated or edited copy, approvals, leads, and review-request recipient details such as a name, email, phone number, message, and delivery or engagement status.
- Billing data. Plan, subscription status, invoice and Stripe customer identifiers, and limited transaction information. Stripe processes card and bank details; DonePages does not store full payment-card numbers.
- Affiliate data. Application details, country, website, promotion methods, accepted terms, referral code, Stripe payout-account status, commission and payout records, and fraud or risk review information.
- Usage and device data. Page views, clicks, downloads, referrals, support interactions, browser or device details, referrer, approximate location inferred from network data, and pseudonymous or hashed IP and visitor identifiers.
- Cookies and local storage. Authentication, workspace and signup preferences, interface state, and a first-party 60-day referral-attribution cookie after a visitor follows an affiliate link. See our Cookie Policy.
We receive this information from you, people who use forms or links you publish, your team or referring affiliate, your browser or device, and providers such as Google, Stripe, Supabase, and Resend.
3. How and why we use information
- Provide, secure, personalize, and support the Service; authenticate users; and maintain workspaces and permissions.
- Create, publish, deliver, and measure DonePages, PDFs, social assets, lead forms, approvals, and review requests.
- Process subscriptions, prevent duplicate or fraudulent transactions, administer affiliates, attribute referrals, calculate commissions, and facilitate payouts.
- Send transactional, security, billing, support, and requested marketing communications.
- Analyze performance, troubleshoot errors, improve features, enforce our terms, and protect users and the public.
- Comply with tax, accounting, sanctions, fraud-prevention, law-enforcement, and other legal obligations.
Where applicable law requires a legal basis, we rely on performance of our contract, compliance with legal obligations, consent, and our legitimate interests in operating, improving, securing, and promoting the Service. You may withdraw consent where processing depends on it; withdrawal does not affect earlier lawful processing.
4. AI processing
Project notes and relevant business details may be sent to OpenAI to draft content. OpenAI states that API inputs and outputs are not used to train its models by default. Limited data may be retained by the provider for safety and abuse monitoring under its applicable terms. Do not submit unnecessary sensitive information. AI output is a draft: you must review its accuracy, rights, and suitability before publishing or sending it.
5. Public pages and indexing
Content you publish to a public DonePage, portfolio, collection, service-area page, embed, or custom domain can be viewed, copied, shared, cached, and indexed by search engines and AI search services. Removing it from DonePages may not immediately remove copies held by third parties. Do not publish personal information, photos, reviews, or property details unless you have the right and any required consent to do so.
7. Retention
We keep account and workspace data while your account is active and for a reasonable period afterward to support restoration, security, disputes, and legal obligations. Public content remains until you unpublish or delete it, subject to backups and third-party caches. Billing, tax, affiliate, payout, fraud, audit, and transaction records may be kept longer where needed for accounting, enforcement, or law. Support records are kept as needed to resolve and improve support. We delete or de-identify information when it is no longer reasonably needed for these purposes.
8. Security
We use measures designed to protect information, including encrypted transport, access controls, row-level database security, restricted administrative access, multifactor authentication for privileged administration, signed webhooks, and audit records. No system can be guaranteed completely secure. Protect your credentials, use a unique password, and contact us promptly if you suspect unauthorized access.
9. International transfers
Our providers may process information in the United States, Europe, and other countries. Where required, transfers are supported by contractual protections or another legally recognized transfer mechanism. Local privacy laws may differ from those where you live.
10. Your privacy rights
Depending on your location, you may request access, correction, deletion, portability, or restriction; object to certain processing; withdraw consent; or opt out of sale or sharing. We do not discriminate against anyone for exercising a privacy right. California residents may also request the categories and specific pieces of personal information collected and disclosed, where the CCPA applies. EEA and UK residents may complain to their local data-protection authority.
Submit a request to [email protected]. We may verify your identity and authority before acting. If data was submitted by a DonePages business customer about you, contact that business first; we will assist it as required.
11. Children
The Service is designed for businesses and is not directed to anyone under 18. We do not knowingly collect children's personal information.
12. Changes
We may update this policy as the Service or law changes. We will update the date above and provide additional notice when a material change requires it.
13. Contact
Privacy questions and requests: [email protected]. General questions: [email protected].