This Privacy Policy ("Policy") explains how Cellpy ("we," "us," or "our") collects, uses, discloses, and protects personal information from users ("you") of our website, dashboard, VS Code Extension, CDN infrastructure, and Marketplace (collectively, the "Services").
By using our Services, you agree to the collection and use of your information as described in this Policy. This Policy is incorporated into and forms part of our Terms of Service.
If you are located in the European Union, European Economic Area, or United Kingdom, additional rights and disclosures apply to you under Section 9 (GDPR Rights).
When you register for an account, we collect:
When you use the VS Code Extension, we collect telemetry data including:
This telemetry may constitute personal data under GDPR where it can be linked to an identifiable individual (for example, via account ID or IP address). We process this data on the basis of our legitimate interests in operating, securing, and improving the Services. You can disable non-essential telemetry in the extension settings. Security-related telemetry (error and crash reports) may continue regardless of this setting.
This data does not include the HTML/CSS content of your Blocks.
Our CDN infrastructure (Cloudflare R2) generates logs of requests to serve Blocks. These logs may include:
CDN logs are used for security monitoring, abuse prevention, and performance optimization. They are retained for up to 90 days. Note that CDN requests may originate from end users of third-party websites embedding Cellpy Blocks, not from registered Cellpy users; Cellpy does not use such logs to identify or track those end users.
When you use the Cellpy dashboard, we collect standard web analytics data including page views, session duration, and feature interactions. This data is collected via cookies and analytics tools (see Section 7).
If you contact us for support or other inquiries, we retain records of those communications.
We use the information we collect to:
We do not use your personal data to train AI or machine learning models. We do not sell your personal data to third parties.
We share your information only in the following circumstances:
We share data with the following categories of subprocessors who process data on our behalf:
A current list of subprocessors is available on our website. We will notify you of material changes to our subprocessor list with at least 30 days' prior notice where practicable.
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Cellpy, our users, or the public.
If Cellpy undergoes a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our platform before your information becomes subject to a different privacy policy.
We retain your account information for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except:
De-identified and aggregated data derived from your usage may be retained indefinitely for statistical and operational purposes.
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These include encrypted data transmission (TLS), hashed password storage, and access controls limiting data access to authorized personnel.
We maintain an internal incident response procedure for data breaches. In the event of a breach involving your personal data, we will notify affected users and relevant supervisory authorities as required by applicable law (including within 72 hours for GDPR-regulated breaches where feasible).
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
The Services are not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will promptly delete it. If you believe we may have collected data from a minor, please contact us at privacy@cellpy.com.
If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and applicable UK data protection law:
To exercise any of these rights, contact us at privacy@cellpy.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.
Our legal bases for processing your personal data are:
Cellpy is based in Canada. Canada benefits from an EU adequacy decision under GDPR Article 45 for commercial organizations subject to PIPEDA, meaning transfers of personal data from the EU/EEA to Cellpy in Canada are permitted without additional safeguards.
However, some of our subprocessors (including Cloudflare, Stripe, and Vercel) may process data in the United States or other jurisdictions that do not benefit from an adequacy decision. In such cases, transfers are governed by Standard Contractual Clauses (SCCs) or other appropriate safeguards as implemented by those subprocessors. We recommend reviewing the privacy policies of these subprocessors for further detail.
Cellpy does not currently maintain a formal EU Representative under GDPR Article 27. We periodically assess whether appointment of an EU Representative is required under GDPR Article 27 and will make the appointment if and when it becomes necessary.
As a Canadian-based service, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Alberta Personal Information Protection Act (PIPA). You have the right to access and request correction of your personal information held by us. To exercise these rights, contact us at privacy@cellpy.com.
If you are an Organization using the Services to process personal data on behalf of your clients or end users, you may request our standard Data Processing Agreement by contacting legal@cellpy.com. The DPA sets out the terms on which Cellpy processes personal data as a data processor on your behalf and is designed to satisfy GDPR Article 28 requirements.
Blocks served by Cellpy's CDN may be embedded on third-party websites. Except for limited technical log information collected automatically for security and operational purposes as described in Section 2.3, Cellpy does not collect personal data from visitors to those third-party sites through CDN delivery. We are not responsible for the privacy practices of any third-party website. Developers and Buyers who embed Blocks on third-party sites are responsible for their own privacy compliance in connection with those sites.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on our website and, where appropriate, by email. Your continued use of the Services after the effective date of any changes constitutes acceptance of the updated Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at: