Privacy Policy
How we protect your data at ButtonMaker
1. Introduction
This Privacy Policy describes how Sold My Stuff Here LLC ("we," "us," or "our") collects, uses, and protects your information when you use the ButtonMaker service ("Service") operated by us.
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. We are committed to protecting your privacy and handling your data transparently.
2. Information We Collect
2.1 Personal Information
When you create an account or use our Service, we may collect:
- Account Information: Email address, name, password
- Profile Data: Account preferences and settings
- Authentication Data: Information from third-party login providers (Google, Facebook) such as email and basic profile information
- Payment Information: Billing details for subscriptions and AI credit purchases, processed securely through Stripe (we do not store payment card details)
2.2 Usage Information
We automatically collect information about how you use our Service:
- Button Creation Data: Templates used, button specifications, quantities, and creation history
- Usage Analytics: Pages visited, features used, time spent on the Service
- Device Information: Browser type, operating system, IP address, device identifiers
- Log Data: Access times, pages requested, and other usage statistics
- Performance Metrics: Page load times, Core Web Vitals, and other performance data collected via Vercel Analytics
2.3 AI Feature Data
- AI Prompts: Text prompts you submit for image generation are processed by our AI providers (Google Gemini, OpenAI ChatGPT, Photoroom)
- Images Sent to AI: Images uploaded for modification, enhancement, or background removal
- Generated Images: AI-generated and modified images are stored on our servers (see retention policy below)
- AI Usage Data: Credit consumption, generation timestamps, operation types (generate, enhance, remove background)
- Prompt Hashes: Cryptographic hashes of prompts are retained for abuse detection (not plain text)
- Image Library: Images you explicitly save to your library for future use
2.4 Third-Party Analytics, Advertising, and Tracking
We use third-party services to understand, improve, and monetize our Service:
- Google Analytics: To analyze website traffic and user behavior
- Google AdSense: To display targeted advertisements and generate revenue to support our free service
- Facebook Pixel: To measure advertising effectiveness and optimize ad campaigns
- Cookies and Similar Technologies: To enhance user experience, track usage patterns, and serve relevant advertisements
2.5 Advertising Data Collection
- Google AdSense: May collect device information, browsing behavior, and ad interaction data to serve personalized advertisements
- Ad Performance Data: Click-through rates, ad impressions, and engagement metrics
- Interest Categories: Inferred interests based on browsing patterns for ad targeting
- Geographic Information: General location data for region-appropriate advertisements
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: To provide, maintain, and improve our button design Service
- Account Management: To manage your account, subscriptions, and user preferences
- Payment Processing: To process subscription payments and AI credit purchases through our payment processor (Stripe)
- AI Credit Management: To track credit balances, process purchases, and enforce usage limits
- Communication: To send service updates, support responses, and account notifications
- Analytics and Improvement: To analyze usage patterns and improve Service functionality
- Advertising and Revenue: To display relevant advertisements and measure their effectiveness
- Marketing and Advertising: To show relevant ads and measure campaign effectiveness
- Legal Compliance: To comply with legal obligations and protect our rights
3.2 AI Feature Data Processing
- Prompt Processing: Your text prompts are sent to AI providers (Google Gemini, OpenAI ChatGPT) for image generation
- Image Processing: Images you upload are sent to AI providers (Photoroom, Google Gemini, OpenAI ChatGPT) for modification, enhancement, and background removal
- Safety Filtering: Prompts and images are screened for prohibited content before processing
- Image Storage: Generated and modified images are stored securely on Supabase cloud infrastructure
- Abuse Prevention: Prompt hashes (not plain text) are retained to detect patterns of misuse
- Credit Management: We track credit usage to enforce subscription limits
- Quality Improvement: Aggregated, anonymized data may be used to improve AI features
4. Information Sharing and Disclosure
4.1 Third-Party Service Providers
We share information with trusted third-party providers who help us operate our Service:
- Stripe: Payment processing and billing management (subscriptions and AI credit purchases)
- Supabase: Database and authentication services
- Vercel: Website hosting, content delivery, and performance monitoring
- Google Analytics: Website analytics and usage tracking
- Microsoft Clarity: User behavior analytics and session replay for UX improvement
- Google AdSense: Advertisement serving and revenue optimization
- Facebook: Advertising analytics and conversion tracking
- Google Gemini (AI): AI image generation and processing
- OpenAI ChatGPT (AI): AI image generation and processing
- Photoroom (AI): AI background removal and image enhancement
4.2 AI Provider Data Sharing
- Google Gemini: Text prompts and images for AI generation and modification. Google processes this data according to their Privacy Policy
- OpenAI ChatGPT: Text prompts and images for AI generation and modification. OpenAI processes this data according to their Privacy Policy
- Photoroom: Images for background removal and enhancement. Photoroom processes this data according to their Privacy Policy
- No Personal Data: We do not send your personal information (email, name, payment details) to AI providers
- Prompt Content Only: Only the text of your prompts, images, and necessary context (e.g., button size) is shared with AI providers
- No Training: Your prompts are not used to train AI models (per enterprise API terms)
4.3 Advertising Partners
- Google AdSense: May access browsing data, device information, and interaction patterns to serve relevant advertisements
- Ad Networks: Third-party advertising networks may collect data through cookies and tracking technologies
- Performance Metrics: Anonymized advertising performance data may be shared to optimize ad placements
4.4 Legal Requirements
We may disclose your information if required by law or in good faith belief that such disclosure is necessary to:
- Comply with legal processes or government requests
- Protect and defend our rights or property
- Prevent fraud or security issues
- Protect the safety of users or the public
4.5 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership.
5. Cookies and Tracking Technologies
5.1 Types of Cookies We Use
- Essential Cookies: Required for basic site functionality and user authentication
- Analytics Cookies: Google Analytics cookies to understand site usage and performance
- Advertising Cookies: Google AdSense and partner cookies to serve relevant advertisements
- Preference Cookies: Store your settings and preferences for a better user experience
5.2 Third-Party Cookies
- Google AdSense: Uses cookies to serve personalized advertisements and measure ad performance
- Google Analytics: Tracks site usage and user behavior patterns
- Social Media: Facebook and Google login cookies for authentication
5.3 Managing Cookies
You can control cookies through:
- Browser settings to block, delete, or manage cookies
- Google Ad Settings to control personalized advertising
- Industry opt-out tools like the Network Advertising Initiative opt-out page
- Browser "Do Not Track" settings (note: not all services honor this setting)
6. Data Security
We implement appropriate security measures to protect your personal information:
- Encryption: Data transmission is secured using SSL/TLS encryption
- Access Controls: Limited access to personal data on a need-to-know basis
- Secure Storage: Data is stored in secure, access-controlled environments
- Payment Security: PCI DSS compliant payment processing through Stripe
- Regular Updates: Security measures are regularly reviewed and updated
- Ad Security: Google AdSense implements security measures to prevent malicious advertisements
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7. Your Rights and Choices
7.1 Account Access and Control
You have the right to:
- Access: View and download your personal data
- Update: Modify your account information and preferences
- Delete: Request deletion of your account and associated data
- Export: Obtain a copy of your button creation history
7.2 Advertising Controls
- Google Ad Settings: Manage personalized advertising preferences at adssettings.google.com
- AdSense Opt-out: Use Google's opt-out tools to limit personalized advertising
- Interest-based Ads: Control interest categories used for ad targeting
- Ad Blocking: Use browser extensions or settings to block advertisements (may affect site functionality)
7.3 Communication Preferences
You can control communications by:
- Updating your email preferences in your account settings
- Unsubscribing from marketing emails using the links provided
- Contacting us directly to opt out of certain communications
7.4 Cookie and Tracking Controls
You can manage cookies and tracking through:
- Browser settings to block or delete cookies
- Google Analytics opt-out browser add-on
- Facebook ad preferences and opt-out controls
- Google AdSense privacy controls and opt-out mechanisms
8. Children's Privacy
Our Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and become aware that your child has provided us with personal information, please contact us immediately. If we discover that we have collected personal information from a child under 13, we will take steps to remove such information from our servers.
Note: Google AdSense does not serve personalized ads to users under 18 in certain jurisdictions, in compliance with applicable privacy laws.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your jurisdiction. By using our Service, you consent to the transfer of your information to such countries. We take appropriate measures to ensure your data receives adequate protection in accordance with this Privacy Policy.
Google Services: Google AdSense and Analytics may transfer data internationally in accordance with Google's privacy policies and applicable data protection frameworks.
10. Data Retention
We retain your information for as long as necessary to:
- Provide you with our Service
- Comply with legal obligations
- Resolve disputes and enforce agreements
- Maintain business records for legitimate purposes
- Support advertising analytics and optimization
When you delete your account, we will delete or anonymize your personal information within a reasonable timeframe, unless we are required to retain it for legal or regulatory purposes. Some anonymized analytics and advertising data may be retained for business optimization purposes.
10.2 AI-Generated Content Retention
- Temporary Generations: AI-generated images not saved to your library are automatically deleted after 30 days
- Image Library: Images you explicitly save are retained until you delete them or close your account
- Prompt Hashes: Cryptographic hashes are retained for 90 days for abuse detection, then deleted
- Credit History: Transaction records are retained for billing and audit purposes
- Generation Metadata: Basic metadata (timestamps, operation types) may be retained for analytics
10.3 Your Deletion Rights
You can delete your AI-generated content at any time:
- Delete individual images from your library
- Request full account deletion through our Support Center
- Download your data before deletion using data export tools
11. Revenue and Advertising Model
ButtonMaker operates on a freemium model with multiple revenue streams:
- Free Service: Supported by Google AdSense advertising revenue
- Premium Subscriptions: Monthly subscription plans with reduced or no advertising and enhanced features
- AI Credit Sales: Pay-as-you-go AI credits for image generation, enhancement, and background removal
- Ad Revenue: Helps us provide free access to basic button creation tools
- Transparency: Advertisements are clearly marked and distinguishable from content
12. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:
- Posting the updated Privacy Policy on our website
- Updating the "Last Updated" date at the top of this page
- Sending you an email notification for significant changes
- Highlighting new or updated sections for transparency
Your continued use of our Service after any changes constitutes acceptance of the updated Privacy Policy.
13. Contact Information
Data Controller
Sold My Stuff Here LLC
If you have questions about this Privacy Policy, advertising practices, or wish to exercise your rights regarding your personal data, please visit our Support Center or contact us directly:
- Email: Contact Form
- Support Center: Complete help and contact options
- Privacy Requests: Data access, deletion, or privacy-related inquiries
- Advertising Concerns: Questions about advertising practices or opt-out requests
- Business Inquiries: Partnership, legal, or business-related matters
Response Time: We aim to respond to all privacy-related inquiries within 30 days.
14. Additional Information for Specific Jurisdictions
14.1 California Residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA), including:
- Right to know what personal information is collected and how it's used
- Right to request deletion of personal information
- Right to opt out of the sale of personal information (we do not sell personal information, but advertising partners may collect data)
- Right to non-discrimination for exercising CCPA rights
- Right to know about data sharing with advertising partners
14.2 European Residents (GDPR)
European residents have rights under the General Data Protection Regulation (GDPR), including:
- Right of access, rectification, and erasure
- Right to data portability and restriction of processing
- Right to object to processing and automated decision-making
- Right to lodge a complaint with a supervisory authority
- Right to opt out of personalized advertising
14.3 Advertising Compliance
- IAB Compliance: We follow Interactive Advertising Bureau (IAB) guidelines for online advertising
- Google Policies: Our advertising complies with Google AdSense policies and terms
- Regional Laws: Advertising practices comply with applicable regional advertising laws
- Consent Management: We implement appropriate consent mechanisms where required by law