This Privacy Policy describes how SecondLight (“we”, “us”, or “our”) collects, uses, stores, and protects your personal information when you use our AI-powered virtual staging platform (“Service”). By using the Service, you consent to the practices described in this policy.
Information We Collect
Information You Provide
- Account information: When you create an account, we collect your name, email address, and profile image through our authentication provider (Clerk).
- Uploaded content: Photographs of rooms and properties that you upload for virtual staging.
- Contact submissions: If you contact us through our contact form, we collect your name, email address, subject, and message.
- Payment information: Billing details are collected and processed by our payment provider (Polar). We do not directly store your credit card numbers or full payment details.
Information Collected Automatically
- Usage data: Pages visited, features used, generation history, and interaction patterns within the Service.
- Device information: Browser type, operating system, screen resolution, and device identifiers.
- Log data: IP addresses, access times, referring URLs, and error logs.
- Cookies and analytics: We use cookies and analytics tools to understand how the Service is used and to improve the user experience.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service, including processing your uploaded photos through our AI staging system.
- Process transactions, manage your photo balance, and handle billing through our payment provider.
- Communicate with you, including responding to contact form submissions, sending service updates, and providing customer support.
- Analyse usage patterns to improve the Service, fix bugs, and develop new features.
- Detect, prevent, and address fraud, abuse, and security issues.
- Comply with legal obligations.
How We Process Your Photos
When you upload a photo to the Service, it is processed by our AI staging system to generate a virtually staged version. Your photos are:
- Stored securely on our cloud infrastructure for as long as your account is active.
- Sent to third-party AI providers solely for the purpose of generating staged images. These providers process your images in accordance with their own privacy and data processing policies.
- Not used to train AI models unless you provide explicit consent.
- Not shared publicly or with other users of the Service.
Data Sharing and Third-Party Services
We share your information only with the following categories of third parties, and only to the extent necessary to provide the Service:
- Authentication: Clerk — manages user accounts, sign-in, and session management.
- Payments: Polar — processes subscriptions, one-time purchases, and manages billing.
- Analytics: PostHog — collects anonymised usage data to help us improve the Service.
- Cloud infrastructure: Convex — hosts our backend database and server-side logic.
- AI processing: Third-party AI providers — generate staged images from your uploaded photos.
Each third-party service operates under its own privacy policy. We encourage you to review their policies. We do not sell your personal information to any third party.
Data Retention
- Account data: Retained for as long as your account is active. When you delete your account, your personal data is removed in accordance with this policy.
- Uploaded photos and generated images: Retained while your account is active. You may delete individual photos and projects at any time through the Service.
- Contact submissions: Retained for the purpose of responding to your inquiry and for record-keeping.
- Transaction records: Retained as required for accounting, legal, and tax purposes.
- Analytics data: Retained in anonymised form for the purpose of improving the Service.
Data Security
We implement industry-standard security measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS).
- Secure cloud infrastructure with access controls.
- Authentication via a trusted third-party provider (Clerk).
- Regular security reviews of our systems and dependencies.
However, no method of electronic storage or transmission is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, including your account and uploaded content.
- Portability: Request a machine-readable copy of your data.
- Objection: Object to certain processing of your data, such as for marketing purposes.
- Withdrawal of consent: Where processing is based on consent, you may withdraw consent at any time.
To exercise any of these rights, please contact us via our contact page. We will respond to your request within 30 days.
Cookies
We use cookies and similar technologies for authentication, session management, and analytics. You can control cookie preferences through your browser settings. Disabling cookies may affect the functionality of the Service.
Children’s Privacy
The Service is not intended for children under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.
International Data Transfers
Your data may be processed and stored in countries other than your own. By using the Service, you consent to the transfer of your information to these countries, which may have different data protection laws than your jurisdiction.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting a notice on the Service or sending an email to the address associated with your account. The “Last updated” date at the top of this page reflects the most recent revision.
Contact
If you have any questions about this Privacy Policy or how we handle your data, please reach out via our contact page.
