Legal

Privacy Policy

Last updated

Logo Slide Labs lets you search a company, drop its official logo onto a 16:9 slide, build deal tombstone walls and market maps, and export the whole thing as an editable PowerPoint file. This page explains what we store while you do that, why we store it, who else ever sees it, and how to get it back or get it deleted.

It applies to logoslidelabs.com and to the signed-in app. It is written to be read, not to be survived — where the honest answer is “we have not built that yet”, it says so.

01 — The short version

A summary for orientation only. The numbered sections below are the actual policy.

  • We store your email address, your name, your company, and the projects you save. That is most of it.
  • We never see or store your card number. Stripe handles payments end to end.
  • No ads. We do not sell or share your information, and there are no advertising or analytics trackers on this site.
  • Your projects, your deal library and your profile are private to your account and enforced as private at the database level, not just in the interface. Logo artwork is the exception: fetched logos sit in a shared brand cache that any signed-in user can search, so a logo you pull in is not private to you.
  • Logos belong to the brands that own them — not to us, and not to you. See the Terms of Service for what that means in practice.
  • Ask us anything, or ask for your data back or deleted, at legal@logoslidelabs.com.

02 — Who is responsible for your data

Logo Slide Labs LLC, a New York limited liability company, is the controller of the personal information described here. For questions or requests, write to legal@logoslidelabs.com. For anything about your account or a charge, support@logoslidelabs.com is faster.

We have not appointed a data protection officer or an EU/UK representative; at our size we are not required to. Requests come to the addresses above and are handled by a person, not a queue.

03 — What we collect

  • Account details. Your email address, your name and your company (all required at signup), your phone number if you give one, and whether you opted in to product emails. Your password is handled by our authentication provider, Supabase — it is stored hashed, and we never see it.
  • The work you save. Your projects: logo slides, tombstone walls and market maps, including their titles, the company names and deal details you type, your layout settings, and the logo images themselves. Tombstone and market-map logos are stored inline in our database next to the project that uses them; logo slides reference image files held in our storage bucket. We also render and store a small picture of each project’s slide so your dashboard can show a preview — for a tombstone wall, that picture has the deal details on it.
  • What you search for. When you look up a company, the name or domain you typed is sent from our server to Brandfetch so it can return the brand’s official assets.
  • Billing identifiers. If you subscribe to a paid plan, we store the Stripe customer and subscription identifiers plus your plan and its status, so the app knows which features to unlock. Card numbers, expiry dates and security codes go directly to Stripe and never touch our servers.
  • Plan and usage records. A count of the exports you make each month, so plan limits can be applied; and, if you redeem a promo code, which code you used, the plan it granted and when it expires.
  • Ordinary server logs. Our hosting provider and Supabase keep standard technical logs — IP address, timestamp, which request was made, whether it failed — for security and debugging. We do not build profiles out of them.

We do not ask for, and have no use for, special-category data: health, biometrics, race, religion, political opinions, trade-union membership, sex life or sexual orientation, or precise geolocation. Please do not put any of it in a project.

04 — What we do not do

  • We do not sell or share your personal information, and we never have. Under California law “sharing” has a specific meaning — cross-context behavioural advertising — and we do not do that either.
  • We do not show ads, and we do not share your data with ad networks.
  • We do not run third-party analytics, session recorders, tracking pixels or cross-site trackers.
  • We do not receive, process or store payment card details.
  • We do not use your projects to train machine-learning models, ours or anyone else’s.
  • We do not read through your projects for marketing or product research. We would only open a specific project if you asked us to help with it, or if we had to investigate abuse, a security problem or a legal obligation.
  • We make no decisions about you by automated means that produce legal or similarly significant effects.

05 — Why we store it, and our legal basis

We use what we collect for these purposes and no others. The bracketed basis is the one we rely on under the GDPR, for readers in the EEA and the UK.

  • To create your account, sign you in, and keep you signed in. [performance of a contract]
  • To save your work and let you reopen, edit and export it later. [performance of a contract]
  • To fetch the logos you ask for. [performance of a contract]
  • To run billing, apply plan limits, and honour promo codes. [performance of a contract; legal obligation for tax and accounting records]
  • To keep the service working and secure, prevent abuse, and fix bugs. [legitimate interests]
  • To email you about your account — password resets, receipts, and notices that genuinely affect the service. [performance of a contract]
  • To email you about new features, only if you opted in. You can stop this at any time from your account settings or by asking us. [consent]

Where we rely on legitimate interests, we have considered your rights and interests and believe they are not overridden. You can object — see Section 11.

06 — Who else touches your data

A handful of service providers process data on our behalf so the product can exist. Each is bound by its own terms and privacy policy, and each receives only what it needs to do its job.

  • Supabase. Our database, authentication and file storage. Holds your account details and your saved projects. United States.
  • Brandfetch. Our logo source. Receives the company name or domain you searched. The request is made from our server, so your browser and IP address are not exposed to it.
  • Stripe. Payments and subscriptions. Receives your payment details directly through Stripe’s own hosted checkout, plus your email address so it can issue receipts.
  • Google Fonts. Serves the typeface the site is set in, and therefore receives the IP address and browser details of everyone who loads a page, before signup. We intend to serve the font from our own domain instead, which will remove this entirely.
  • Our hosting provider (currently Vercel). Serves the site and keeps request logs.

Beyond those, the only times we would hand over data are: where the law requires it or a valid legal process compels it; where it is necessary to establish, exercise or defend a legal claim; where it is needed to prevent harm or investigate abuse; or if the business were ever sold or merged — in which case your data would move with it under this same policy, and we would tell you first.

07 — Cookies and local storage

  • A session token from Supabase keeps you signed in between visits. Without it, you would have to log in on every page. This is strictly necessary, so it is not something we ask consent for.
  • Your browser’s local storage remembers small conveniences, like the last tombstone wall or market map you had open, so the app reopens where you left off. If you type a promo code at signup it is held in your tab’s session storage just long enough to apply it, then removed. That data stays on your device.
  • No advertising cookies and no tracking pixels.
  • Our typeface is served by Google Fonts, so loading any page on this site sends your IP address and browser details to Google before you sign in.

08 — How long we keep it

  • Your account and projects. For as long as your account is open.
  • After you ask us to delete. There is no self-service delete button yet — write to legal@logoslidelabs.com and we will delete your account, your profile and the projects attached to it within 30 days.
  • Two things need a separate request today. The stored preview pictures of your slides, and any logo artwork that reached our shared brand cache. Neither is removed automatically — say so in your request and we will remove them too.
  • Backups. Copies may survive briefly in routine encrypted backups before those age out.
  • Billing records. Stripe keeps its own payment records for as long as its legal and accounting obligations require, which is outside our control. We keep enough of a record to meet our own tax obligations.
  • Server logs. Retained on our providers’ standard schedules, which are short — weeks, not years.

09 — Security

  • Everything travels over HTTPS.
  • Passwords are hashed by Supabase. We never store or see the plain text.
  • Every table holding your work — projects, deals and your profile — is protected by row-level security, so one account’s queries cannot reach another account’s projects even if the interface were bypassed. The shared brand-logo cache is the deliberate exception: it is readable by any signed-in user.
  • Billing fields on your profile, and any promo grant, can only be written by our server, never by a browser — so an account cannot promote its own plan.
  • Privileged API keys live only in server-side Edge Functions and are never shipped to your browser.

No system is perfect, and we are a very small operation. If we discover a breach affecting your personal data we will tell you and the relevant regulator without undue delay — and within 72 hours of becoming aware where the law requires it — describing what happened, what it affects, and what to do about it.

10 — Where your data lives

Our database, hosting and payment providers operate in the United States. If you use Logo Slide Labs from elsewhere, your information is transferred to and stored in the US.

For transfers out of the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) as incorporated into our providers’ data processing terms, together with the technical measures in Section 9.

11 — Your choices and rights

  • View and change your name, company and phone in your account settings. The email address you sign in with is your login identity, so to change it, ask us.
  • Take your work with you at any time — the PowerPoint export is your data, in a format nothing here can lock up.
  • Ask us to correct anything we hold that is wrong.
  • Ask us to delete your account and everything in it.
  • Ask for a copy of what we hold, in a portable format, or ask us to restrict or object to a particular use.
  • Withdraw consent to product emails at any time, without affecting anything we did before you withdrew it.

If you are in the EEA or the UK, you have rights of access, rectification, erasure, portability, restriction and objection under the GDPR, and the right to complain to your local supervisory authority — though we would rather you gave us the chance to fix it first.

If you are in California, you may request the categories and specific pieces of personal information we have collected, the sources, the purpose, and the categories of third parties we disclose to; request deletion; and request correction. We do not sell or share personal information and we do not use or disclose special-category information for inferring characteristics, so there is nothing to opt out of. We will not discriminate against you for exercising any right.

How to exercise any of it: email legal@logoslidelabs.com from the address on your account. We answer within 30 days, and will tell you if we need longer. If we cannot verify that the request comes from you, we may ask for more information rather than hand your data to someone else. An authorised agent may act for you with written permission.

12 — Do Not Track and Global Privacy Control

We do not track you across other websites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour those signals by default, in the sense that the behaviour they disable is behaviour we never had.

13 — Children

This is a professional tool for people doing deal work. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, tell us at legal@logoslidelabs.com and we will remove it.

14 — Changes to this policy

If we change what we collect, why we collect it, or who we share it with, we will update the date at the top of this page. For anything material we will also email account holders or show a notice in the app rather than quietly editing the text. Where a change requires your consent, we will ask for it before it takes effect.

15 — Contact

Logo Slide Labs LLC
Privacy requests, data deletion and legal notices: legal@logoslidelabs.com
Accounts, billing and refunds: support@logoslidelabs.com

See also the Terms of Service.