adminigloo — legal
Privacy
What we hold about you, why we hold it, who else sees it, and what you can ask us to do with it.
In effect from September 21, 2026
1.Who we are
AdminIgloo LLC, trading as adminigloo, of the State of Utah, USA (full registered address available on request), is the controller of the personal data described below.
Write to dallinhumphrey@gmail.com about anything on this page, including a request to see, correct or delete what we hold.
2.What we hold
Only what the service needs in order to work. This list is generated from the parts this service is actually built out of, so it does not describe features we do not have.
- Your account
- Your name and email address, held so you can sign in and so other people in your company can see who you are.
- Your company
- Which company you belong to, what you may do inside it, and any invitation sent to you or by you.
- An audit trail
- A record of administrative actions — who changed what, and when. It is kept deliberately, because the alternative is being unable to answer that question after a security incident.
- Errors
- When something goes wrong, the failure is recorded with enough context to reproduce it, which can include your account id and the page you were on.
- Feedback you send
- When you submit feedback through the widget: your description, an optional screenshot of what you were looking at (with sensitive form fields blanked before capture), your recent clicks on the page, and any browser errors from your session.
- Orders
- What you bought, when, for how much, and the reference Stripe gave the payment. Card details are not held here.
- What your plan includes
- Your subscription, its status, and the allowances it grants you — including how much of each you have used.
3.Why we hold it
To give you the service you asked for, to keep it secure and working, and to meet obligations we cannot contract out of — tax records on a purchase, for instance.
Have a lawyer write this clause. Which lawful basis applies to which category is the question a regulator asks first, and it depends on where you and your customers are, not on how the software is built.
4.Who else sees it
These are the companies that process data on our behalf. The list is generated from the services this deployment is built on, so it is complete for the software — add anything you have connected since, such as analytics or a support desk.
| Who | What for | What reaches them |
|---|---|---|
| Clerk | Sign-in and identity | Your email address, your name, and the method you sign in with. Passwords and Google sign-in are handled by Clerk directly and never reach this service. |
| Neon | The database | Everything this service stores about you. It is held in Postgres, in the region the database was created in. |
| Vercel | Hosting, delivery, and file storage | Every request to this site, including your IP address and browser, in server logs. Screenshots submitted with feedback are stored in Vercel's blob storage. |
| Stripe | Payments and subscriptions | Your name, email address, billing address and card details. Card numbers are entered directly into Stripe and never reach this service. |
| Sentryoptional | Error reporting | Stack traces and the request context attached to an error, which can include the id of the signed-in account. |
| Upstashoptional | Rate limiting | A counter keyed to your IP address or account id. No message contents and no personal details. |
The rows marked optional are services this deployment can use and only does once they are switched on: Sentry, Upstash. Check which are configured here, and delete the rest of these rows from src/legal.ts.
5.Where it is held
Say where, and be specific. Each company above operates in particular regions and several let you choose. Name the regions you have actually selected, and say what covers a transfer out of them if there is one.
6.How long we keep it
Set real periods here.“As long as necessary” is not a retention policy and does not survive scrutiny. Two things in this service outlive an account on purpose and should be named: the audit trail, which exists to answer questions after an incident, and any record kept for tax or accounting.
7.What you can ask for
Depending on where you live you can ask for a copy of what we hold, ask us to correct it, ask us to delete it, or object to some of what we do with it. Write to dallinhumphrey@gmail.com and we will answer.
Check this against your jurisdiction. The rights, the deadline you have to answer in, and the regulator a complaint goes to all differ, and this paragraph names none of them.
8.Changes to this policy
When this changes we update the date at the top. If a change matters to you — a new company in the table above, a new purpose — we will tell you rather than relying on you re-reading this page.
The companion document is our terms of service.