1. Introduction
Welcome to AssetSnag (“AssetSnag”, “we”, “us”, or “our”). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy describes how we collect, use, store, share, and protect information when you use our dashboard web application (https://assetsnag.app) and interact with our client portal and credential collection services.
2. Roles & Scope (Controller vs. Processor)
AssetSnag as a Data Controller: When you create an account, purchase a subscription, or log in to the dashboard, we act as a Data Controller for your account, login, and billing data.
AssetSnag as a Data Processor: When you (the “Agency” or “Customer”) use our platform to collect files, assets, or credentials from your clients (“End-Users” / “Client Contributors”), you are the Data Controller of that data, and AssetSnag processes and stores it strictly on your behalf as a Data Processor under our Data Processing Agreement (DPA).
3. Information We Collect
A. Information You Provide to Us
- Account Data: Name, agency/business name, email address, session tokens, and workspace preferences when you register.
- Billing Information: Payment card details, billing address, and tax identification numbers. (Note: Payment transactions and invoices are handled directly by our Merchant of Record, Paddle, and raw payment card numbers never touch or reside on our servers).
- Workspace & Project Data: Project titles, client names, onboarding checklists, custom branding configurations, and project metadata.
B. Client Assets and Credential Vault Data
- Uploaded Files & Assets: Documents, images, brand assets, and deliverables uploaded to your portal workspaces.
- Encrypted Vault Credentials: Passwords, API keys, and sensitive access tokens submitted via the Credential Vault. These secrets are protected with application-level AES-256-GCM encryption at rest and TLS 1.3 in transit.
C. Usage & Technical Data
- Usage & Device Data: IP address, browser type, operating system, access timestamps, and error diagnostics.
- In-App Product Analytics: Within the authenticated dashboard, we use PostHog to understand feature usage and platform performance. This data is not used for advertising and is not sold to third parties.
- Marketing Site Analytics: On our public marketing pages, Google Analytics 4 (GA4) may be utilized to analyze aggregate website traffic, subject to user consent where applicable.
4. How We Use Your Information & GDPR Legal Basis
Under the General Data Protection Regulation (GDPR) and similar data protection laws, we must establish a valid legal basis for each processing activity:
| Processing Purpose | Data Categories | GDPR Legal Basis |
|---|---|---|
| Account Creation & Service Delivery | Name, email, agency name, workspace settings | Performance of a Contract (Art. 6(1)(b)) |
| Payment Processing & Invoicing | Billing address, subscription tier, tax ID (via Paddle) | Performance of a Contract & Legal Obligation (Art. 6(1)(b)/(c)) |
| Platform Security & Fraud Prevention | IP address, session tokens, audit logs | Legitimate Interests (Art. 6(1)(f)) |
| In-App Product Analytics (PostHog) | Dashboard UI interactions, feature adoption | Legitimate Interests (Art. 6(1)(f)) |
| Marketing Site Analytics (GA4) & Optional Updates | Aggregated page views, opt-in product newsletter | Consent (Art. 6(1)(a)) |
| Client Asset & Credential Intake | Files, assets, encrypted vault credentials | Data Processor acting under Customer's instructions (Art. 28) |
5. Cookies and Tracking Technologies
Essential Cookies: Required for core platform functionality, user authentication, session persistence, and security tokens. These cannot be disabled as they are strictly necessary for the Service to function.
In-App Product Analytics (PostHog): Once logged into the AssetSnag dashboard, we use PostHog to evaluate feature usage and improve user workflow. This is processed on the legal basis of our legitimate interest in platform optimization. PostHog does not serve ads and is not shared with ad networks.
Marketing Website Analytics (Google Analytics 4): On public-facing marketing pages (outside the authenticated dashboard), GA4 is used to assess aggregate traffic patterns and acquisition channels, subject to cookie consent requirements in applicable jurisdictions.
No Third-Party Ad Trackers: We do not sell your personal data or deploy cross-site third-party data broker advertising trackers.
6. Sub-processors & Third-Party Sharing
We do not sell, rent, or trade your personal data. We only disclose data to trusted service providers (sub-processors) under strict confidentiality and data protection agreements:
| Service Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Serverless edge compute (Workers), edge database (D1), key-value storage (KV), object storage (R2), CDN, SSL, and DDoS mitigation | Global / EU / US |
| Paddle.com | Merchant of Record, payment processing, fraud screening, and global tax compliance | UK / EU / US |
| Transactional Email (Resend) | System transactional emails, magic login links, client asset request notifications | US / EU |
| PostHog | In-app product analytics (dashboard post-login only) | EU / US Cloud |
| Google Analytics 4 (GA4) | Public marketing site traffic and conversion analytics (landing pages only) | Global / US |
When adding a new sub-processor, Agency accounts will be notified at least 15 days in advance via email or in-app announcement.
7. Data Security & Storage Controls
- Cloud Infrastructure: All application compute, databases, and asset storage reside on Cloudflare's hardened global edge infrastructure.
- Encryption Standards: Data in transit is secured using modern TLS 1.3/HTTPS. Data at rest is encrypted across our cloud infrastructure providers and application-level authenticated encryption controls (AES-256-GCM) where applicable for sensitive vault secrets.
- Credential Vault Protection: Vault secrets are encrypted with dedicated keys and strict access authorization policies, ensuring secrets are only accessible by authorized workspace administrators.
8. Data Retention, Backup Lifecycle & Breach Notification
- Active Accounts: Data is retained for as long as your account remains active.
- Account Cancellation & Grace Period: Upon account cancellation or deletion, account data and uploaded client files are retained for a 30-day grace period to allow data export, after which they are permanently deleted from active production databases and object storage.
- Disaster Recovery Backups: Routine automated encrypted backup snapshots are overwritten and purged within standard retention cycles (typically up to 90 days), except where longer retention is strictly required by statutory, tax, or legal compliance obligations.
8b. Data Breach Notification
In the event of a confirmed personal data breach affecting your account or client data, we will notify affected Agency accounts without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in line with our obligations under GDPR and our Data Processing Agreement.
9. Your Rights (GDPR, UK GDPR & CCPA/CPRA)
Depending on your jurisdiction, you may have the following rights:
- The right to access, update, or erase the personal information we hold about you.
- The right to data portability (exporting your data in a standard structured format).
- The right to restrict or object to certain processing activities.
- The right to withdraw consent at any time without affecting the lawfulness of prior processing.
California residents may also exercise their rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under CCPA/CPRA.
To submit a request or exercise any rights, please contact us at privacy@assetsnag.app.
10. Children's Privacy
AssetSnag is designed exclusively for business and professional use. We do not knowingly collect personal information from children under the age of 16.
11. Security Contact & Responsible Disclosure
For security inquiries or to report potential security vulnerabilities responsibly, please email security@assetsnag.app.
12. Changes to This Policy
We may update this Privacy Policy periodically. If we make material changes, we will notify you by updating the “Last Updated” date, sending an email notification, or displaying a notice within the dashboard.
13. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy, please contact our team:
Privacy & Data Protection: privacy@assetsnag.app
Security Team: security@assetsnag.app
Legal Inquiries: legal@assetsnag.app