← Home

Privacy Policy

SuedeDoor Privacy Policy

Version
1.1
Effective Date
September 8, 2026
Last Updated
October 1, 2026

SuedeDoor LLC (“SuedeDoor,” “we,” “us,” or “our”) operates the SuedeDoor website, application, and related services (collectively, the “Service”). This Privacy Policy explains what personal information we collect, how we use and disclose it, how long we keep it, and the choices and rights available to you.

SuedeDoor is a U.S.-focused business service. Account registration is designed for business users with a U.S. organizational presence. Although the Service is offered for U.S. use, some infrastructure and service providers may process information in other jurisdictions as described below.

Privacy at a Glance

1. Scope

This Policy applies when you visit or use the Service, create or maintain an account, use SuedeDoor research and AI features, contact support, submit a product or correction, subscribe to communications, make a privacy request, or otherwise interact with SuedeDoor. It does not govern third-party websites or services that you access through outbound links from SuedeDoor.

2. Information We Collect

Account and business profile information

When you create and use an account, we may collect your full name, job title, business (work) email address, display name, company or organization name and website (and the domain derived from it), company email domain, company type and size, AEC role, project types, primary software, BIM platform, hosting preference, AI software budget, security requirements, organizational state, U.S.-presence attestation information, work-email verification status, registration and signup/review status, and related account timestamps. We also maintain role information and records showing acceptance of applicable Terms and Privacy Policy versions.

When you register, we send a one-time code to your work email address. Entering it confirms that you control that email address; it does not verify your identity, employment, or job title, which remain information you provide. If your work-email domain cannot be automatically matched to your organization website, the registration is reviewed before access is activated.

Authentication information

Account authentication is provided through Lovable Cloud/Supabase Auth. Authentication and session tokens are used to keep you signed in and protect authenticated functions. SuedeDoor application code does not receive your plaintext account password.

Research, workspace, and AI content

Depending on the features you use, we may collect and store research queries, AI chat messages, saved comparisons, Live Look-up URLs and results, saved research, Dynamic Workspace profile and stack information, generated reports, and private workspace notes. Private notes are treated separately from AI features and are not included in AI prompts or model payloads.

Subscription and payment metadata

We store limited subscription and usage information such as your Stripe customer and subscription identifiers, product and price identifiers, subscription status and period dates, plan information, purchase or credit information, and monthly usage counters. Card numbers, CVVs, expiration dates, bank credentials, and similar raw payment credentials are handled by Stripe and are not stored in SuedeDoor tables.

Support, vendor, correction, newsletter, and privacy-request information

When you contact support or use an intake workflow, we collect the information you choose to provide. This can include email address, message or conversation content, support category, product and vendor information, source URLs, correction details, submitter name and role, authority attestations, and privacy-request details. Vendor-submission workflows may also maintain technical verification, deduplication, and rate-limiting information needed to prevent abuse and validate submissions.

Technical and operational information

The Service and its infrastructure providers may automatically process technical information needed to deliver and secure the Service, such as IP address, browser or device information, request and session identifiers, timestamps, authentication events, service usage, error information, and server or security logs. We do not use this information to operate behavioral advertising or cross-site user profiles.

Consent and preference information

We record your cookie/storage choices and observed browser privacy signals. Functional preferences, such as theme or layout preferences, are persisted only when the applicable Functional consent has been granted, except for storage that is strictly necessary to operate authentication, security, payments, or the consent system itself.

3. Sources of Information

We collect information from:

4. How We Use Information

We use information to:

We do not use personal information for third-party advertising, and we do not sell personal information or share it for cross-context behavioral advertising.

5. AI Features and AI Processing

Some SuedeDoor features use AI to provide factual research, comparison, workspace, support, and catalog-related functions. AI requests are initiated from SuedeDoor server-side functions rather than directly from the browser.

Information that may be sent to AI services

Depending on the feature, an AI request may include your query or conversation text, relevant catalog information, tool results, product/vendor identifiers, public vendor-page content, and, for Dynamic Workspace, the business-profile context needed to perform the requested comparison or research. Support AI may include the support conversation and plan/tier context needed to answer the request. Support tickets and email escalations, including the retained conversation context, may be reviewed by authorized SuedeDoor personnel, and applicable service providers may process support data on SuedeDoor's behalf. Support data follows the retention schedule stated in this Policy.

Information excluded from AI processing

Dynamic Workspace conversation text (your messages and the assistant's replies) may be stored temporarily, for up to 7 days, to provide conversation context and operate the service. Private workspace notes are not part of that conversation history.

SuedeDoor does not include private workspace notes in AI prompts or model payloads. Our current implementation also does not send passwords, payment-card information, authentication tokens, or other credentials to AI models.

Lovable AI Gateway and model providers

SuedeDoor uses Lovable AI Gateway for application AI calls. Lovable has stated to SuedeDoor that data submitted by end users of apps built on Lovable is not used to train Lovable's AI models. Lovable has also stated that its agreements with the downstream model providers it uses restrict those providers' use of submitted content to what is needed to provide the service, including a restriction on training AI models on that content.

Lovable has informed us that the AI Gateway entry point is hosted in the European Union and that inference on standard plans may be brokered to provider endpoints hosted in the United States. The AI path therefore is not necessarily confined to one region. Lovable does not provide SuedeDoor with a verified fixed retention period for raw prompts and responses at every gateway or downstream-provider layer, so this Policy does not promise a specific third-party raw-prompt retention period.

For the production SuedeDoor project, Lovable's optional “AI app context” setting is disabled. This means SuedeDoor has not opted into Lovable's optional use of application AI-call context for debugging and improvement.

6. Cookies, Browser Storage, and Tracking

Necessary storage

SuedeDoor uses a first-party consent cookie (currently named sd_consent) for approximately 180 days to remember your versioned privacy choices and relevant browser privacy signals. Authentication/session information is maintained through Lovable Cloud/Supabase Auth using browser storage necessary to keep you signed in and secure the account.

Functional storage

Optional functional preferences are persisted only after Functional consent is granted. If Functional consent is not granted, the Service may use temporary in-session state where needed without persisting a non-essential preference.

Payments

Stripe payment interfaces and fraud-prevention systems may use cookies or other technical identifiers that Stripe considers necessary to provide secure checkout and billing functions. Those technologies are controlled by Stripe.

No behavioral analytics or advertising tracking

The production Service does not include Google Analytics, Google Tag Manager, Meta Pixel, advertising pixels, behavioral analytics platforms, session replay, heatmaps, browser-fingerprinting libraries, or cross-site tracking. Lovable Visitor analytics is disabled for the production project. SuedeDoor does not use externally hosted Google Fonts; the application font is served locally.

Global Privacy Control and Do Not Track

Our consent system observes Global Privacy Control (GPC) and Do Not Track (DNT) signals. GPC prevents marketing consent from being enabled, and DNT prevents analytics and marketing consent from being enabled. Because SuedeDoor does not currently sell or share personal information for targeted advertising and does not operate behavioral analytics, these controls reinforce the Service's existing privacy-minimizing configuration.

7. How We Disclose Information

We disclose information only as needed to operate, secure, support, and administer the Service, or as required by law.

Current service and infrastructure providers include:

Current service and infrastructure providers and the purpose of each
Provider / ServiceLovable / Lovable Cloud (including Supabase-based database and authentication infrastructure)PurposeHosting, database, authentication, server functions, application infrastructure, and operational/security logging.
Provider / ServiceLovable AI Gateway and downstream model providersPurposeAI inference for SuedeDoor AI-assisted features.
Provider / ServiceLovable Connector Gateway and StripePurposeSubscription checkout, billing portal, payment processing, and subscription status. Card data is entered directly into Stripe-controlled interfaces.
Provider / ServiceMailgunPurposeOutbound verification, vendor, support, and Weekly Change Report email functions, and inbound support-email handling when those functions are enabled.
Provider / ServiceFirecrawlPurposeRetrieval of public vendor/product web pages for Live Look-ups and research. SuedeDoor does not intentionally send end-user account identifiers with these retrieval requests.
Provider / ServicePerplexityPurposeCatalog and industry research using product/vendor research prompts. SuedeDoor does not intentionally send end-user account identifiers for these research operations.
Provider / ServiceDataForSEOPurposeSearch and market-discovery data using product/vendor search queries. SuedeDoor does not intentionally send end-user account identifiers for these research operations.

We may also disclose information to professional advisers, auditors, insurers, regulators, courts, law-enforcement authorities, or other parties when reasonably necessary to comply with law, protect rights or security, investigate misuse, resolve disputes, or carry out a corporate transaction. If ownership or control of SuedeDoor changes, information may be transferred as part of that transaction subject to applicable law.

No sale or targeted-advertising sharing. SuedeDoor does not sell personal information and does not share personal information for cross-context behavioral advertising or targeted advertising.

8. Data Retention

We use defined retention rules intended to keep information only as long as needed for the purposes described in this Policy, subject to legal holds, security needs, dispute resolution, and other legal obligations. Our current production retention rules include the following:

Current production retention rules by record type
Data / RecordUnreferenced Live Look-upsCurrent Retention RuleDeleted after 30 days when not saved and not referenced by a workspace.
Data / RecordMonthly usage countersCurrent Retention RuleDeleted after the current period plus 13 months of historical periods.
Data / RecordFully used top-up/credit recordsCurrent Retention RuleDeleted 13 months after purchase once no credits remain.
Data / RecordResolved support ticketsCurrent Retention RuleDeleted 12 months after resolution or last interaction, subject to any retention hold.
Data / RecordDormant support conversationsCurrent Retention RuleDeleted after 12 months when no unresolved support ticket remains.
Data / RecordInbound support emailCurrent Retention RuleDeleted after 12 months unless linked to an unresolved matter or otherwise held.
Data / RecordVendor-submission representative informationCurrent Retention RuleName/email are de-identified 12 months after final disposition; governance/product history is retained.
Data / RecordCatalog-correction reporter informationCurrent Retention RuleReporter email/role are de-identified 12 months after the correction is applied or rejected.
Data / RecordCompleted or denied privacy requestsCurrent Retention RuleDeleted 24 months after completion or denial.
Data / RecordPolicy-acceptance evidenceCurrent Retention RuleRetained after account closure for 4 years, then deleted.
Data / RecordVendor-submission rate-limit recordsCurrent Retention RuleDeleted after 90 days.
Data / RecordVendor-verification recordsCurrent Retention RuleDeleted 7 days after expiration.
Data / RecordSaved research, workspaces, comparisons, reports, and private notesCurrent Retention RuleRetained while the user chooses to keep them and the account remains active; removed through applicable user deletion or account-deletion processes.
Data / RecordCatalog Assistant chat threads and messagesCurrent Retention RuleRetained with the account. The current product does not provide a separate user-facing delete control for individual chat threads; chat threads and messages are deleted when the user account is deleted.
Data / RecordDynamic Workspace conversation historyCurrent Retention RuleRetained for up to 7 days; deleted sooner if the account is deleted.
Data / RecordWeekly Change Report unsubscribe recordsCurrent Retention RuleThe email address may be retained as a suppression record so we continue to honor the opt-out; the unsubscribe token is removed after 30 days.

Account deletion is currently fulfilled through the privacy-request process rather than through a one-click in-product account-deletion control. When account deletion is completed, account-linked data is deleted or de-identified as applicable, subject to the retention exceptions described above and any legal requirement to preserve particular records.

9. Security

We use administrative and technical safeguards designed to protect information, including authenticated access controls, database row-level access controls, server-side authorization, restricted service-role functions for sensitive maintenance operations, protected payment interfaces, and scheduled retention/deletion processes. No method of transmission, storage, or security is completely risk-free, and we cannot guarantee absolute security.

10. Your Privacy Choices and Rights

Privacy Request Center

Authenticated users can use the SuedeDoor Privacy Request Center at /privacy-requests to submit access, correction, or deletion requests. SuedeDoor also provides an immediate self-service JSON export of account-related data. A signed-in session is used to verify the requester's account identity. We may request additional information when reasonably necessary to verify a request, protect another person's privacy, or comply with law.

State privacy rights

Depending on where you live and which privacy laws apply to SuedeDoor, you may have rights to request access to or confirmation of personal information we process, obtain a copy, correct inaccurate information, request deletion, and obtain information about how information is used or disclosed. Applicable law may also provide rights concerning targeted advertising, sale or sharing of personal information, sensitive personal information, portability, non-discrimination, and appeal of certain request decisions.

SuedeDoor does not sell personal information or share it for cross-context behavioral advertising. If applicable law gives you a right to appeal a privacy-request decision, you may appeal by contacting us at support@suededoor.com and identifying the request you want reviewed. We will not discriminate against you for exercising applicable privacy rights.

Global Privacy Control

Where a Global Privacy Control signal is received, our consent system treats the signal as a privacy preference that prevents marketing consent from being enabled. SuedeDoor does not currently engage in sale or targeted-advertising sharing that would require a separate opt-out transaction.

How to submit a request

You may use the Privacy Request Center while signed in or contact us at support@suededoor.com. If you cannot access your account, contact us by email and provide enough information for us to identify the relevant account and verify the request. You may also write to the mailing address in Section 15.

11. Email Communications

We may send transactional or service emails necessary to operate your account or fulfill a request, including email confirmation, support, verification, vendor-submission, privacy-request, or billing-related communications. If you subscribe to optional email updates, you may unsubscribe using the available unsubscribe mechanism. We may retain an unsubscribed address as a suppression record so we do not re-subscribe that address contrary to your choice.

12. Third-Party Websites and Public Sources

SuedeDoor contains links to vendor websites and may retrieve publicly available vendor/product pages as part of research functions. When you leave SuedeDoor or interact directly with a third-party website, that third party's privacy practices apply. SuedeDoor is not responsible for the privacy practices of websites or services we do not control.

13. Children

SuedeDoor is a business-oriented service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, contact us so we can review and address the matter.

14. Changes to This Privacy Policy

We may update this Policy as the Service, our providers, or legal requirements change. We will post the revised Policy with an updated effective or last-updated date and provide any additional notice or consent required by applicable law. Material changes will apply prospectively unless law permits otherwise.

15. Contact Us

Questions or privacy requests can be sent to:

SuedeDoor LLC
2108 N St
#17419
Sacramento, CA 95816
support@suededoor.com

16. Notice at Collection

This section describes the categories of personal information SuedeDoor collects at or in connection with creating and maintaining an account, why we collect each category, whether we sell or share it for cross-context behavioral advertising, and how long we keep it. It summarizes the same practices described elsewhere in this Policy, including Section 2 (Information We Collect), Section 4 (How We Use Information), Section 6 (Cookies, Browser Storage, and Tracking), and Section 8 (Data Retention).

SuedeDoor does not sell or share personal information for cross-context behavioral advertising.

Categories of personal information collected at or in connection with account creation, with purposes, sale/share status, and retention periods or criteria
CategoryAccount identifiers and contact informationExamplesFull name, business (work) email address, account identifier, display name, and account timestamps.PurposeCreate and authenticate your account, operate the Service, provide support, and send service and account emails.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaRetained while the account remains active and deleted with the account, subject to security, fraud-prevention, and legal retention obligations.
CategoryProfessional and business informationExamplesJob title, company or organization name, organization website and the domain derived from it, company email domain, company type and size, AEC role, project types, primary software, BIM platform, hosting preference, AI software budget, and security requirements.PurposeConfirm business use, tailor research and workspace features to your firm, and administer your account.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaRetained while the account remains active and deleted with the account.
CategoryEligibility informationExamplesOrganization U.S. state, U.S.-presence attestation and its attestation version, work-email verification status and time, registration and signup/review status, and the result of an automatic comparison of your work-email domain with your organization website. Verification codes are stored only in hashed form and expire after 10 minutes.PurposeVerify control of your work email address, determine and record eligibility to use the Service (which is offered only to U.S.-based organizations using business email addresses), review signups that need an eligibility review, and prevent fraud and misuse. Email verification confirms control of the email address only; SuedeDoor does not verify your identity, employment, or job title.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaRetained while the account remains active and deleted with the account.
CategoryAuthentication informationExamplesAuthentication and session tokens and authentication event records held by our authentication infrastructure. SuedeDoor application code does not receive your plaintext password.PurposeKeep you signed in, protect authenticated functions, and secure the Service.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaSession tokens last only as long as the session or its stored lifetime; authentication records are kept with the account and by our infrastructure provider for security-log purposes.
CategorySubscription and account-administration informationExamplesStripe customer and subscription identifiers, product and price identifiers, subscription status and period dates, plan information, purchase or credit records, and monthly usage counters. Card numbers and similar raw payment credentials are handled by Stripe and are not stored in SuedeDoor tables.PurposeProvide and administer paid plans, apply entitlements and usage limits, process purchases, and keep required financial records.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaMonthly usage counters are deleted after the current period plus 13 months of historical periods; fully used top-up/credit records are deleted 13 months after purchase once no credits remain; other subscription records are retained with the account.
CategoryPolicy-acceptance evidenceExamplesThe Terms version and Privacy Policy version you accepted, the acceptance context, the server-generated acceptance timestamp, and a snapshot of the account identifier and email at the time of acceptance.PurposeMaintain evidence that you agreed to the Terms and acknowledged the Privacy Policy, and to resolve disputes about the applicable policy version.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaRetained for the lifetime of the account and, after account closure, for 4 years, then deleted.
CategoryConsent and preference informationExamplesYour cookie/storage choices, observed browser privacy signals such as Global Privacy Control or Do Not Track, and functional interface preferences.PurposeHonor your storage and privacy choices and remember interface preferences where the applicable consent has been granted.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaThe consent record is stored in your browser for 180 days from your choice; preference values are removed when you withdraw Functional consent.
CategoryTechnical and security informationExamplesIP address, browser or device information, request and session identifiers, timestamps, error information, and server or security logs processed by the Service and its infrastructure providers.PurposeDeliver, secure, monitor, and troubleshoot the Service and prevent abuse. This information is not used for behavioral advertising or cross-site profiles.Sold or shared for cross-context behavioral advertising?No.Retention period or criteriaKept only as long as needed for operations, security, and abuse prevention under our infrastructure providers’ log retention practices.

Where a retention statement above depends on account or service state rather than a fixed period, that criterion is the applicable rule. Some information may be kept longer where necessary to comply with legal obligations, resolve disputes, prevent abuse, or enforce our agreements. To exercise a privacy choice, use the Privacy Request Center or contact support@suededoor.com.