BOXFSH PRIVACY POLICY Last updated: December 2025 1. OVERVIEW This policy describes how BoxFsh collects, uses, stores, and protects information for Clients and Pros. 2. DATA WE COLLECT - Account: name, email, password/passkey data, roles, profile details, preferences. - Usage: device info, browser type, approximate location (city/region), timestamps, basic analytics. - Content: messages, files, project data, uploads, comments, and actions taken in Canvas. - Legal/consent: acceptance logs for confidentiality and contracts (user ID, job ID, timestamps, IP/user agent when provided), contract snapshots (text/PDF), scope versions. - Payments: handled by payment providers; we store limited metadata (amount, status, timestamps). 3. WHY WE COLLECT IT - Operate and secure the platform (sessions, rate limiting, fraud prevention). - Enable collaboration (messages, files, milestones, shipping, notifications). - Enforce agreements and resolve disputes (audit trails, acceptance records, scope freeze markers). - Improve reliability (performance metrics, error logs, anonymized analytics). 4. COOKIES & LOCAL STORAGE - Essential: session tokens, security flags, profile state, legal/consent records. - Optional: anonymized analytics to improve reliability (no ads or cross-site tracking). - You can choose "Essential only" in the cookie prompt; this may limit analytics. 5. SHARING - Service providers: hosting, storage, email, analytics, and payment processors under contract. - Legal: to comply with law, enforce policies, resolve disputes, or protect safety/rights. - We do not sell data or share it for advertising. 6. RETENTION - Account and project records are kept while your account is active and as needed for legal, audit, and safety purposes. Deleted accounts may retain minimal logs (e.g., acceptance records, dispute notes) for fraud and compliance. 7. SECURITY - Encryption in transit, restricted access, and monitoring. No system is perfect; report issues to security@boxfsh.io. 8. YOUR CHOICES - Update profile and settings in-app. Request data access or deletion at privacy@boxfsh.io (subject to legal and fraud-prevention requirements). - Control cookies via the consent prompt and your browser. 9. INTERNATIONAL TRANSFERS - Data may be processed in regions where our providers operate. We apply contractual and technical safeguards. 10. CHILDREN - BoxFsh is not for children under 18. 11. CHANGES - We may update this policy. Material changes will be announced in-product or by email. Continued use after updates means you accept the revised policy. 12. CONTACT - Email: privacy@boxfsh.io - Mail: BoxFsh Privacy, Surf Coast, VIC, Australia