SDGSole Design Group

Privacy Policy

Last updated: August 15, 2026

Sole Design Group LLC ("SDG," "we," "us," or "our") operates the Client Workspace platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you access the Service.

By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

Account Information

When your account is created, we collect your name, email address, and any other information provided during the invitation and onboarding process. Account credentials are securely managed through our authentication provider.

Business Analytics Data

We aggregate and display marketing performance data from third-party platforms you have authorized us to access, including website analytics (Google Analytics), advertising performance (Google Ads, Meta Ads), email marketing metrics (Brevo), and website management data (Webflow). This data is collected to provide you with consolidated marketing insights.

Form Submissions & Lead Data

If your workspace includes form submission tracking, we store contact information submitted through your website forms (such as names, email addresses, and phone numbers of your website visitors). This data originates from your own website and is stored to help you manage leads.

Platform Credentials

If you choose to store login credentials for third-party platforms within the workspace, these are encrypted at rest and accessible only to authorized users on your account.

Documents & Uploaded Files

Any documents, images, or other files you upload to the workspace are stored securely and are only accessible to users with permission to your workspace.

Billing Information

If your organization pays SDG through the Service, we store your billing contact details, invoice line items, and payment history. Bank account and card details are collected and stored by our payment processor, Stripe — they are entered directly into Stripe's hosted payment fields and never reach SDG's own systems or database. We store only the reference Stripe gives us for a saved payment method and its type (bank account or card); details such as the last four digits are read back from Stripe when they are displayed.

Usage Data

We automatically collect certain information when you use the Service, including your IP address, browser type, pages visited, and timestamps. This data helps us maintain and improve the Service.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Display your marketing analytics and performance reports
  • Manage your account and provide customer support
  • Generate insights and recommendations for your marketing campaigns
  • Send service-related communications (account updates, security alerts)
  • Ensure the security and integrity of the platform

3. Data Sharing & Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • Service Providers: We use trusted third-party services to operate the platform. Each is named in Section 8 below, and each only accesses data as necessary to perform its service for us.
  • Legal Requirements: We may disclose information if required by law, regulation, or legal process.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
  • With Your Consent: We may share information with your explicit consent.

4. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication with session management and password hashing
  • Role-based access controls ensuring users only see data they are authorized to view
  • Row-level security policies on all database tables
  • Regular security reviews and monitoring

While we strive to use commercially acceptable means to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide you with the Service. If you or your organization terminates the service agreement with SDG, we will delete or anonymize your data within 90 days of termination, unless we are required to retain it for legal or compliance purposes.

Where we record a lead outcome for offline conversion measurement, the contact details attached to that record (email, phone, name, postal code, and advertising click identifiers) are cleared automatically 120 days after the conversion. The advertising platforms accept an offline conversion for at most 90 days, so past that point those details serve no measurement purpose. The conversion itself — its value and date — is kept for reporting.

Analytics data and generated reports may be retained in aggregate, anonymized form for our internal analysis.

6. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Export: Request an export of your data in a portable format
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, contact us at info@soledesigngroup.com.

7. Cookies & Tracking

The Service uses essential cookies for authentication and session management. These cookies are necessary for the Service to function and cannot be disabled. We do not use advertising or third-party tracking cookies within the workspace.

We do measure how the workspace is used. Vercel Analytics and Vercel Speed Insights record page views and performance timings for the pages you open; both are cookieless and do not follow you to other websites or build an advertising profile. The workspace also keeps its own first-party activity log — which workspace pages an account opened and when — so we can see which parts of the workspace are useful. Those activity records are deleted automatically after 90 days.

8. Third-Party Services

Marketing Platforms

The workspace integrates with third-party platforms — Google (Analytics, Ads, Search Console, Business Profile, Calendar, and Gmail), Meta (Facebook and Instagram), Brevo, Webflow, and Microsoft Clarity — to display your marketing data. Your use of these platforms is governed by their respective privacy policies. We only access the data you have authorized us to retrieve through authenticated API connections.

Attribution Tracking on Your Own Website

Separately from this workspace, SDG offers an attribution service that runs on a client's own website: a small script that sets a first-party _sdg_attr cookie (90-day lifetime) recording which ad campaign brought a visitor, so form submissions can be credited to the right campaign. That processing happens on the client's site, on the client's behalf, and is governed by the client's own privacy policy and consent tooling — see Section 5 of our Terms of Service. It does not run in this workspace and does not track your use of it.

Service Providers

We rely on the following providers to run the Service. Each processes data only as needed to perform its function for us:

  • Supabase — database, authentication, file storage, and encrypted storage of any credentials you save. Workspace data lives here.
  • Vercel — application hosting and delivery, plus the cookieless usage and performance analytics described in Section 7.
  • Stripe — payment processing. Bank account and card details are collected and held by Stripe, not by SDG.
  • OpenAI — generates the numeric embeddings that make knowledge-base content searchable. Text sent for embedding is not used to train OpenAI's models.
  • MailerSend — delivery of notification, digest, and report emails.
  • Anthropic — SDG's internal marketing agent runs on Anthropic's Claude and reads workspace data over an authenticated connection when an SDG team member works on your account.

9. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Sole Design Group LLC

info@soledesigngroup.com

www.soledesigngroup.com