Duefront

Privacy Policy

Last updated: July 3, 2026

This policy describes what data Duefront collects, why, and how it is handled. The short version: we collect what is needed to run a readiness-monitoring service for your organization, we don't sell personal data, and you can ask for your data to be deleted.

1. Data we collect

We collect the following categories of data:

  • Account data — name, email address, and authentication identifiers. If you sign in with Google, we receive your name, email, and avatar from Google.
  • Organization content — the data your team imports or creates: monitored surfaces, owner directories, readiness workspaces, notes, and evidence records.
  • Billing data — subscription status and plan. Card details are collected and processed by Stripe, our payment processor; we never store card numbers.
  • Usage and log data — standard technical logs (IP address, browser type, timestamps) used for security and debugging.

2. How we use data

We use data to:

  • operate the Service — maintain your inventory, route owners, run scheduled re-checks, and generate readiness evidence;
  • send transactional email such as digests, owner notifications, and account messages;
  • process subscription billing;
  • secure the Service and prevent abuse;
  • improve the product using aggregate, non-identifying usage patterns.

3. What we don't do

We do not sell personal data. We do not use your organization's content for advertising. We do not share your inventory or readiness data with third parties except the service providers below, acting on our instructions.

4. Service providers

Duefront runs on a small set of infrastructure providers:

  • Supabase — authentication and database hosting for account data and organization content.
  • Stripe — subscription billing and payment processing.
  • Resend — transactional email delivery.
  • Vercel — application hosting and logs.
  • Google — optional sign-in (OAuth).

5. Data retention and deletion

Account and organization data is retained while your account is active — a retained inventory is the core of the Service. If you delete your account or request deletion at founder@duefront.com, we delete personal data within a reasonable period, except records we must keep for legal or billing reasons.

6. Security

Data is encrypted in transit (TLS) and at rest by our hosting providers. Access to production data is restricted, and organization data is isolated per organization with row-level security.

7. Cookies

The Service uses cookies for authentication sessions. The marketing site does not use third-party advertising cookies.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Contact founder@duefront.com and we will respond to verified requests.

9. Changes

If we change this policy materially we will give notice by email or in-app before the change takes effect.

10. Contact

Privacy questions and requests: founder@duefront.com.