Privacy Policy

Last updated: February 27, 2026

1. Information We Collect

When you create a Palette account, we collect your name, email address, password (stored in hashed form), and optionally your company name and professional role. As you use the platform, we collect project data, material orders, finish selections, and other content you create within Palette.

We automatically collect certain technical information when you visit our website, including your IP address, browser type, operating system, referring URLs, and pages viewed.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Palette platform
  • Create and manage your account
  • Process and fulfill your requests
  • Send you technical notices, updates, and administrative messages
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent or unauthorized activity

3. Cookies & Tracking

Palette uses essential cookies to maintain your authentication session and preferences. We do not use third-party advertising cookies or tracking pixels. Session cookies are automatically deleted when you close your browser or after your session expires.

4. Third-Party Services

We may share your information with the following third-party services that help us operate Palette:

  • Hosting: Railway (application hosting and database infrastructure)
  • Email: Resend (transactional emails and invitations)
  • Authentication: NextAuth.js (session management, processed server-side)

These services are contractually obligated to protect your data and may only use it to provide their services to us.

5. Data Retention

We retain your account information and project data for as long as your account is active. If you request account deletion, we will remove your personal information and project data within 30 days. Some information may be retained in backups for up to 90 days after deletion.

6. Your Rights

You have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion of your account and data
  • Export your project data
  • Opt out of non-essential communications

To exercise any of these rights, contact us at support@palette.co.

7. Data Security

We implement industry-standard security measures to protect your data, including encrypted connections (HTTPS/TLS), hashed passwords (bcrypt), and secure database access controls. However, no method of electronic transmission or storage is 100% secure.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last updated” date. Your continued use of Palette after changes constitutes acceptance of the updated policy.

9. Contact Us

If you have any questions about this Privacy Policy, please contact us at support@palette.co or visit our Contact page.