Privacy Policy
Effective date: 2026-08-18
Draft — pending legal review. This document was generated as a starting point for Project Hub's privacy policy and has not been reviewed by an attorney. Do not treat it as final or legally binding until it has been reviewed and approved.
This Privacy Policy explains how ORCHEXIS LLC ("Company," "we," "us," or "our") collects, uses, and shares information in connection with Project Hub (the "Service"). It applies to visitors to our marketing site and to organizations and users of the Service ("Customer Data" and "Personal Data," respectively, as described below).
1. Information We Collect
Account information. When you sign up, we collect your name, email address, and password (stored in hashed form by our authentication provider — we never see or store your password in plain text).
Organization and project data. Data your organization enters into the Service — project names, statuses, milestones, status updates, department and phase names, and similar operational content ("Customer Data"). This may include personal data about your organization's own users and, at your discretion, third parties named in project fields (e.g. a sponsor's name).
Billing information. If you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details directly — we receive only a customer and subscription reference, never your full card number.
Usage and log data. We automatically collect information about how you use the Service, including IP address, browser type, pages visited, and timestamps, for security, debugging, and product-improvement purposes.
Cookies. We use essential cookies to keep you signed in and maintain your session. We do not currently use third-party advertising or tracking cookies.
2. How We Use Information
- To provide, maintain, and secure the Service;
- To authenticate users and enforce organization-level access controls;
- To process payments and manage subscriptions;
- To send transactional communications (e.g. password resets, invitations, billing receipts, and — where you've opted in — reminder and digest emails);
- To respond to support requests;
- To detect, investigate, and prevent fraud, abuse, and security incidents; and
- To comply with legal obligations.
We do not sell Personal Data or Customer Data, and we do not use Customer Data to train third-party models.
3. How We Share Information
We share information only as follows:
- Within your organization. Customer Data you submit is visible to other users in your organization according to the role-based permissions your organization's Admins configure.
- Service providers (subprocessors). We use third-party providers to operate the Service, including Supabase (database, authentication, and file storage) and Stripe (payment processing). These providers act on our behalf and are contractually restricted from using your data for any other purpose.
- Legal and safety. We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith it's necessary to protect the rights, property, or safety of the Company, our users, or the public.
- Business transfers. If we're involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this Policy or a materially equivalent one.
4. Data Retention
We retain Customer Data for as long as your organization maintains an account, plus a limited period afterward to allow for account recovery and to comply with legal, tax, and accounting requirements. Append-only records such as project status-update history are retained as part of your organization's audit trail for the life of the account. You can request earlier deletion as described in Section 6.
5. Data Security
We use industry-standard safeguards to protect information, including encryption in transit, database-level tenant isolation between organizations (Row-Level Security), and role-based access controls enforced both in our application and at the database layer. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted to or from the Service.
6. Your Rights and Choices
Depending on your location, you may have the right to:
- Access, correct, or export the Personal Data we hold about you;
- Request deletion of your Personal Data, subject to legal retention requirements;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on consent (e.g. optional reminder emails, which you can opt out of individually from your notification preferences); and
- Lodge a complaint with a data protection authority.
To exercise these rights, contact us at [insert privacy contact email]. Because most Customer Data is controlled by your organization's Admins, some requests about organizational data may need to be directed to your organization first.
7. International Data Transfers
Our infrastructure providers may process and store data in countries other than your own. Where we transfer Personal Data internationally, we rely on appropriate safeguards as required by applicable law.
8. Children's Privacy
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect Personal Data from children under 16.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by email or an in-product notice, before the changes take effect.
10. Contact Us
Questions about this Privacy Policy can be sent to [insert privacy contact email].
