Privacy Policy
Last updated: September 8, 2026 · Applies to firmitas.studio and the client portal
This Privacy Policy explains how Firmitas ("Firmitas", "we", "us") collects, uses, and protects personal data when you visit firmitas.studio, use the client portal, or engage us for services. For questions or data requests, contact hello@firmitas.studio.
1. Data we collect
- Portal accounts. When you create a portal account, we collect your name, email address, business or project details, and any address or project brief you provide.
- Communications. When you contact us by email, we process your email address and message content to respond and to maintain a record of the project.
- Payments. Payments are processed by Whop, Inc. We do not receive or store payment card details. We retain the payment reference data Whop returns (amount, status, transaction identifier) to administer the project.
- Technical data. Our hosting provider (Cloudflare) processes standard request logs (IP address, requested pages, timestamps, user agent) for security and abuse prevention.
- Sign-in. If you use "Continue with Google", we receive your email address and profile name from Google to authenticate your account.
2. Purposes and legal bases
We process personal data to perform our contracts with clients (account management, project delivery, payment administration), based on our legitimate interests in operating and securing the site and portal (request logs, abuse prevention), and with your consent where required (third-party sign-in). We do not use personal data for advertising, and we do not sell or share personal information for cross-context behavioral advertising as defined by the CCPA.
3. Cookies and similar technologies
- fm_sess — strictly necessary. Set when you sign in to the portal; authenticates your session; expires after 14 days or on logout. The portal does not function without it.
- Whop badge script — a third-party script from our payment processor loads on these pages to measure page visits for our internal dashboard. It may set its own cookies under Whop's privacy policy. It is not used for advertising.
- Cloudflare Web Analytics — Cloudflare injects a privacy-first, cookie-free analytics script on our pages (beacon.min.js) that measures aggregate page visits. It sets no cookies and does not track you across sites.
No advertising cookies are set by us, and the only analytics we run (Cloudflare Web Analytics) is cookie-free. Most browsers allow you to block or delete cookies; blocking fm_sess will prevent portal sign-in.
4. Service providers and sharing
We share personal data only with the providers required to operate:
- Cloudflare, Inc. — hosting, DNS, and database. Data is stored in Cloudflare's network (primarily the United States).
- Whop, Inc. — payment processing, if you pay through the portal.
- Google — authentication, if you choose "Continue with Google".
We do not sell, rent, or trade personal data. We disclose personal data only where required by law, and we notify affected clients of legal demands where permitted.
5. International transfers
Our operations are based in the United States, and the providers listed above process data in the United States and other countries. Where required for transfers of personal data from the European Economic Area or the United Kingdom, we rely on the transfer mechanisms our providers offer (such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework, as applicable to each provider).
6. Retention
We retain account and project records for as long as your project is active and for up to 24 months after handover, to provide support and to meet legal obligations. Payment reference records are retained as required by tax and accounting rules. Technical logs are retained by our providers per their standard periods. When data is no longer required, it is deleted or anonymized on request.
7. Your rights
Subject to applicable law, you may request access to the personal data we hold about you, correction of inaccurate data, deletion of data we no longer require, and a copy of your data in a portable format. California residents have the rights described in the CCPA, including the right to know, delete, and correct, and the right not to receive discriminatory treatment for exercising them; we do not sell or share personal information as defined by the CCPA. EU/UK residents have equivalent rights under the GDPR, including the right to object to processing based on legitimate interests and to lodge a complaint with a supervisory authority. To exercise any right, email hello@firmitas.studio; we respond within 30 days.
8. Children
Our services are directed to businesses and are not intended for children under 16. We do not knowingly collect personal data from children.
9. Security
We apply technical and organizational measures appropriate to the data we hold, including HTTPS on all connections, least-privilege administrative access, and security monitoring. If a breach affects your personal data, we will notify you and the relevant authorities as required by law.
10. Changes to this policy
We may update this policy from time to time. The current version is published on this page with its effective date. If a change materially affects portal clients, we will also announce it in the portal.
11. Contact
Privacy questions, data requests, or complaints: hello@firmitas.studio.