Legal Document

Privacy Policy

At fontyle, your privacy is fundamental to how we design and deliver our font services. This policy outlines exactly what data we collect, why we collect it, and how we protect it.

Last Updated: May 8, 2026
Version 3.2
8 min read

Your Data, Protected

256-bit SSL Encrypted
GDPR Compliant
01

Information We Collect

We collect information that you provide directly to us, information collected automatically when you use our font services, and information from third-party sources.

Identity Data

Name, email, profile photo

Payment Data

Billing address, transaction history

Technical Data

IP address, browser, device info

Usage Data

Fonts downloaded, pages visited

Communication Data

Support tickets, feedback forms

Preference Data

Settings, font favorites, language

Font-Specific Data: When you use our font rendering API or embed our fonts on your website, we collect the domain URL, font family names requested, character subsets used, and aggregate rendering performance metrics. We do not log individual text content typed by end users.

02

How We Use Your Data

We use the information we collect to provide, maintain, and improve our font services, process transactions, and communicate with you.

  1. Service Delivery — To provide access to our font library, cloud syncing, web font hosting, and license management features.
  2. License Management — To track your font licenses, enforce usage limits, and generate license certificates for compliance.
  3. Payment Processing — To process subscriptions, one-time purchases, and refund requests through our payment partners.
  4. Personalization — To recommend fonts based on your usage patterns, design preferences, and project history.
  5. Communication — To send service updates, license renewal reminders, and respond to your support inquiries.
  6. Analytics & Improvement — To analyze how our services are used, identify performance issues, and guide product development.
  7. Security & Fraud Prevention — To detect unauthorized access, prevent font piracy, and protect our platform integrity.
Legal Basis

We process your data based on contractual necessity (to deliver our services), legitimate interest (security and improvement), consent (marketing communications), and legal obligation (tax and regulatory compliance). You can manage your consent preferences at any time from your account settings.

03

Data Sharing & Third Parties

We do not sell your personal data. We share data only with carefully vetted service providers who help us operate our platform.

Category Purpose Data Shared Type
Payment Processors Process transactions securely Name, email, billing details Required
Cloud Infrastructure Host & deliver font files globally Usage metrics, technical data Required
Analytics Services Understand platform usage patterns Anonymized usage data Optional
Email Delivery Send transactional & marketing emails Email address, name Optional
Font Foundry Partners Distribute royalty reports Aggregated license data only Required

All third-party vendors are bound by Data Processing Agreements (DPAs) that restrict their use of your data to the specific purposes outlined above. We conduct regular audits to ensure ongoing compliance.

04

Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze traffic, and personalize content across our font platform.

  • Essential Cookies — Required for authentication, session management, and security. These cannot be disabled.
  • Analytics Cookies — Help us understand how visitors interact with our font library, search features, and checkout flow.
  • Preference Cookies — Remember your font filter settings, grid/list view preference, and language selection.
  • Marketing Cookies — Used to deliver relevant font recommendations and track campaign effectiveness across channels.

Managing Cookies: You can control cookie preferences through our Cookie Consent Banner (displayed on first visit) or via your browser settings. Disabling certain cookies may affect the functionality of font previews, search suggestions, and personalized recommendations.

05

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy.

Data Type Retention Period Reason
Account Data Duration of account + 30 days Service delivery
Transaction Records 7 years Legal & tax compliance
Support Tickets 2 years after resolution Quality assurance
Analytics Data 26 months Product improvement
Marketing Preferences Until consent withdrawn Consent-based processing

When your data reaches the end of its retention period, it is securely deleted or anonymized. Font files you've downloaded under an active license are not affected by account data deletion — your license rights remain valid per the original agreement.

06

Your Rights

Depending on your location, you have specific rights regarding your personal data. We are committed to honoring these rights promptly.

Right to Access

Request a copy of all data we hold about you

Right to Rectify

Correct inaccurate or incomplete data

Right to Erase

Request deletion of your personal data

Right to Portability

Receive your data in a machine-readable format

Right to Object

Object to processing based on legitimate interest

Right to Restrict

Limit how we process your data

How to Exercise Your Rights

You can manage most of these rights directly from your Account Settings → Privacy Dashboard. For complex requests or data portability exports, contact our Data Protection Officer at support@fontyle.com. We respond to all requests within 30 days as required by GDPR.

07

Data Security

We implement industry-leading technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

  • Encryption in Transit — All data is transmitted over TLS 1.3 with forward secrecy enabled.
  • Encryption at Rest — Sensitive data is encrypted using AES-256 encryption standards.
  • Access Controls — Role-based access with multi-factor authentication for all internal systems.
  • Regular Audits — Annual SOC 2 Type II audits and quarterly penetration testing.
  • Incident Response — Dedicated security team with a 24-hour incident response protocol.
  • Employee Training — Mandatory data protection training for all team members, refreshed annually.
08

Children's Privacy

fontyle services are not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take immediate steps to delete that information.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@fontyle.com and we will promptly remove it.

09

International Data Transfers

As a global font platform, your data may be transferred to and processed in countries other than your own. We ensure that appropriate safeguards are in place for all international transfers, including:

  1. Standard Contractual Clauses (SCCs) — EU-approved contracts for transfers outside the EEA.
  2. UK International Data Transfer Agreement — Approved addendum for UK data transfers.
  3. Data Privacy Framework — Certification for US-EU data transfers where applicable.
  4. Adequacy Decisions — Reliance on jurisdictions recognized as providing adequate data protection.
10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Post a prominent notice on our dashboard for logged-in users.
  • Send an email notification for changes that significantly affect your rights.
  • Maintain previous versions in our policy archive for your reference.

Your continued use of fontyle after any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.

11

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us.

Address

412 Font Avenue, Suite 800, San Francisco, CA 94105

Response Time

We acknowledge all privacy-related inquiries within 48 hours and aim to provide a complete response within 30 calendar days. For urgent data breach notifications or legal requests, please mark your subject line as "URGENT — Privacy Request."