Legal

Privacy Policy

Effective date: June 1, 2026 · Questions? privacy@cellpy.com

1.Introduction

This Privacy Policy ("Policy") explains how Cellpy ("we," "us," or "our") collects, uses, discloses, and protects personal information from users ("you") of our website, dashboard, VS Code Extension, CDN infrastructure, and Marketplace (collectively, the "Services").

By using our Services, you agree to the collection and use of your information as described in this Policy. This Policy is incorporated into and forms part of our Terms of Service.

If you are located in the European Union, European Economic Area, or United Kingdom, additional rights and disclosures apply to you under Section 9 (GDPR Rights).

2.Information We Collect

2.1 Account Information

When you register for an account, we collect:

  • Name and email address
  • Password (stored in hashed form) or SSO provider token (Google/GitHub)
  • Organization name (if applicable)
  • Billing information (processed and stored by Stripe; Cellpy does not store raw payment card data)

2.2 Usage and Telemetry Data from the VS Code Extension

When you use the VS Code Extension, we collect telemetry data including:

  • Block creation and publishing events (timestamps, block IDs, publish destinations)
  • Extension feature usage patterns
  • Error and crash reports
  • Account identifiers associated with extension actions

This telemetry may constitute personal data under GDPR where it can be linked to an identifiable individual (for example, via account ID or IP address). We process this data on the basis of our legitimate interests in operating, securing, and improving the Services. You can disable non-essential telemetry in the extension settings. Security-related telemetry (error and crash reports) may continue regardless of this setting.

This data does not include the HTML/CSS content of your Blocks.

2.3 CDN Request Logs

Our CDN infrastructure (Cloudflare R2) generates logs of requests to serve Blocks. These logs may include:

  • IP addresses of requesting clients
  • Timestamps and URLs of requested Blocks
  • HTTP headers (user agent, referrer)

CDN logs are used for security monitoring, abuse prevention, and performance optimization. They are retained for up to 90 days. Note that CDN requests may originate from end users of third-party websites embedding Cellpy Blocks, not from registered Cellpy users; Cellpy does not use such logs to identify or track those end users.

2.4 Dashboard Usage Data

When you use the Cellpy dashboard, we collect standard web analytics data including page views, session duration, and feature interactions. This data is collected via cookies and analytics tools (see Section 7).

2.5 Communications

If you contact us for support or other inquiries, we retain records of those communications.

3.How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Services
  • Process payments and manage subscriptions via Stripe
  • Authenticate users and secure accounts
  • Send transactional emails (account verification, payment receipts, block review status)
  • Send product updates and marketing communications (you may opt out at any time)
  • Monitor for abuse, fraud, and violations of our Terms of Service
  • Analyze aggregate usage patterns to improve the platform
  • Comply with legal obligations

We do not use your personal data to train AI or machine learning models. We do not sell your personal data to third parties.

4.Information Sharing and Disclosure

We share your information only in the following circumstances:

4.1 Third-Party Subprocessors

We share data with the following categories of subprocessors who process data on our behalf:

  • Cloudflare — CDN, DNS, DDoS protection, edge network infrastructure, and analytics event storage (Cloudflare Analytics Engine, used to store aggregate A/B experiment impression and click data). Cloudflare may process data in the United States and other jurisdictions; Cloudflare relies on Standard Contractual Clauses for EU data transfers.
  • Stripe — Payment processing and payouts to Designers via Stripe Connect. Stripe may process data in the United States; Stripe relies on Standard Contractual Clauses for EU data transfers.
  • Vercel — Web application hosting and serverless functions. Vercel may process data in the United States; Vercel relies on Standard Contractual Clauses for EU data transfers.
  • Google / GitHub — Single sign-on authentication (where you choose to use SSO).
  • Analytics providers — Aggregate usage analytics (see Section 7).
  • Email service providers — Transactional and marketing emails.

A current list of subprocessors is available on our website. We will notify you of material changes to our subprocessor list with at least 30 days' prior notice where practicable.

4.2 Legal Requirements

We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Cellpy, our users, or the public.

4.3 Business Transfers

If Cellpy undergoes a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our platform before your information becomes subject to a different privacy policy.

5.Data Retention

We retain your account information for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except:

  • Block assets (HTML/CSS content) are retained for as long as active Buyer CDN URLs depend on them, on the legal basis of contractual necessity to perform the Buyer's license agreement. Block assets do not typically contain personal data of the Designer; where they do (e.g., a Designer's name embedded in code comments), we will work with you to remove such personal data while preserving the operational asset.
  • Financial and transaction records are retained as required by Canadian tax and accounting law (generally 7 years).
  • CDN request logs are retained for up to 90 days.
  • A/B experiment event data (aggregate impression and click counts stored in Cloudflare Analytics Engine) is retained for up to 90 days.
  • Communications records are retained for up to 3 years.

De-identified and aggregated data derived from your usage may be retained indefinitely for statistical and operational purposes.

6.Data Security

We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These include encrypted data transmission (TLS), hashed password storage, and access controls limiting data access to authorized personnel.

We maintain an internal incident response procedure for data breaches. In the event of a breach involving your personal data, we will notify affected users and relevant supervisory authorities as required by applicable law (including within 72 hours for GDPR-regulated breaches where feasible).

No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7.Cookies and Tracking

We use the following categories of cookies and tracking technologies on the Cellpy dashboard. You will be presented with a cookie consent manager when you first access the dashboard, allowing you to accept, reject, or configure your preferences for non-essential cookies.

Essential Cookies
Required for the Services to function. These include session authentication cookies and security tokens. They cannot be disabled without impairing functionality and do not require consent.
Analytics Cookies
Used to understand how users interact with the platform (e.g., page views, feature usage). This data is used to improve the Services. These cookies require your consent. You may withdraw consent at any time via the cookie settings on our website.
Marketing and Advertising Cookies
Used to deliver relevant advertising and to measure the effectiveness of our marketing campaigns. These cookies may be set by third-party advertising partners. They require your explicit consent. You may withdraw consent at any time via the cookie settings on our website. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.

8.Children's Privacy

The Services are not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will promptly delete it. If you believe we may have collected data from a minor, please contact us at privacy@cellpy.com.

9.GDPR Rights (EU/EEA/UK Users)

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and applicable UK data protection law:

Right of Accessrequest a copy of the personal data we hold about you
Right to Rectificationrequest correction of inaccurate or incomplete data
Right to Erasurerequest deletion of your personal data, subject to certain exceptions (including our retention obligations for active Buyer CDN URLs and legal recordkeeping requirements)
Right to Restrictionrequest that we restrict processing of your data in certain circumstances
Right to Data Portabilityreceive your data in a structured, machine-readable format
Right to Objectobject to processing based on legitimate interests or for direct marketing
Right to Withdraw Consentwhere processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at privacy@cellpy.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.

Legal Bases for Processing

Our legal bases for processing your personal data are:

Performance of a contractto provide the Services you have subscribed to
Legitimate interestsplatform security, fraud prevention, product improvement, and operational telemetry (where not overridden by your interests or rights)
Consentanalytics and marketing cookies, marketing email communications, and non-essential VS Code Extension telemetry
Legal obligationfinancial recordkeeping and regulatory compliance

International Data Transfers

Cellpy is based in Canada. Canada benefits from an EU adequacy decision under GDPR Article 45 for commercial organizations subject to PIPEDA, meaning transfers of personal data from the EU/EEA to Cellpy in Canada are permitted without additional safeguards.

However, some of our subprocessors (including Cloudflare, Stripe, and Vercel) may process data in the United States or other jurisdictions that do not benefit from an adequacy decision. In such cases, transfers are governed by Standard Contractual Clauses (SCCs) or other appropriate safeguards as implemented by those subprocessors. We recommend reviewing the privacy policies of these subprocessors for further detail.

EU Representative

Cellpy does not currently maintain a formal EU Representative under GDPR Article 27. We periodically assess whether appointment of an EU Representative is required under GDPR Article 27 and will make the appointment if and when it becomes necessary.

10.Canadian Privacy Law

As a Canadian-based service, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Alberta Personal Information Protection Act (PIPA). You have the right to access and request correction of your personal information held by us. To exercise these rights, contact us at privacy@cellpy.com.

11.Data Processing Agreement (DPA)

If you are an Organization using the Services to process personal data on behalf of your clients or end users, you may request our standard Data Processing Agreement by contacting legal@cellpy.com. The DPA sets out the terms on which Cellpy processes personal data as a data processor on your behalf and is designed to satisfy GDPR Article 28 requirements.

12.Third-Party Sites and Embedding

Blocks served by Cellpy's CDN may be embedded on third-party websites. Except for limited technical log information collected automatically for security and operational purposes as described in Section 2.3, Cellpy does not collect personal data from visitors to those third-party sites through CDN delivery. We are not responsible for the privacy practices of any third-party website. Developers and Buyers who embed Blocks on third-party sites are responsible for their own privacy compliance in connection with those sites.

13.Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on our website and, where appropriate, by email. Your continued use of the Services after the effective date of any changes constitutes acceptance of the updated Policy.

14.Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:

Websitecellpy.com
AddressCalgary, Alberta, Canada