Privacy Policy
At fontyle, your privacy is fundamental to how we design and deliver our font services. This policy outlines exactly what data we collect, why we collect it, and how we protect it.
Your Data, Protected
Information We Collect
We collect information that you provide directly to us, information collected automatically when you use our font services, and information from third-party sources.
Identity Data
Name, email, profile photo
Payment Data
Billing address, transaction history
Technical Data
IP address, browser, device info
Usage Data
Fonts downloaded, pages visited
Communication Data
Support tickets, feedback forms
Preference Data
Settings, font favorites, language
Font-Specific Data: When you use our font rendering API or embed our fonts on your website, we collect the domain URL, font family names requested, character subsets used, and aggregate rendering performance metrics. We do not log individual text content typed by end users.
How We Use Your Data
We use the information we collect to provide, maintain, and improve our font services, process transactions, and communicate with you.
- Service Delivery — To provide access to our font library, cloud syncing, web font hosting, and license management features.
- License Management — To track your font licenses, enforce usage limits, and generate license certificates for compliance.
- Payment Processing — To process subscriptions, one-time purchases, and refund requests through our payment partners.
- Personalization — To recommend fonts based on your usage patterns, design preferences, and project history.
- Communication — To send service updates, license renewal reminders, and respond to your support inquiries.
- Analytics & Improvement — To analyze how our services are used, identify performance issues, and guide product development.
- Security & Fraud Prevention — To detect unauthorized access, prevent font piracy, and protect our platform integrity.
We process your data based on contractual necessity (to deliver our services), legitimate interest (security and improvement), consent (marketing communications), and legal obligation (tax and regulatory compliance). You can manage your consent preferences at any time from your account settings.
Data Sharing & Third Parties
We do not sell your personal data. We share data only with carefully vetted service providers who help us operate our platform.
| Category | Purpose | Data Shared | Type |
|---|---|---|---|
| Payment Processors | Process transactions securely | Name, email, billing details | Required |
| Cloud Infrastructure | Host & deliver font files globally | Usage metrics, technical data | Required |
| Analytics Services | Understand platform usage patterns | Anonymized usage data | Optional |
| Email Delivery | Send transactional & marketing emails | Email address, name | Optional |
| Font Foundry Partners | Distribute royalty reports | Aggregated license data only | Required |
All third-party vendors are bound by Data Processing Agreements (DPAs) that restrict their use of your data to the specific purposes outlined above. We conduct regular audits to ensure ongoing compliance.
Cookies & Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyze traffic, and personalize content across our font platform.
- Essential Cookies — Required for authentication, session management, and security. These cannot be disabled.
- Analytics Cookies — Help us understand how visitors interact with our font library, search features, and checkout flow.
- Preference Cookies — Remember your font filter settings, grid/list view preference, and language selection.
- Marketing Cookies — Used to deliver relevant font recommendations and track campaign effectiveness across channels.
Managing Cookies: You can control cookie preferences through our Cookie Consent Banner (displayed on first visit) or via your browser settings. Disabling certain cookies may affect the functionality of font previews, search suggestions, and personalized recommendations.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Data | Duration of account + 30 days | Service delivery |
| Transaction Records | 7 years | Legal & tax compliance |
| Support Tickets | 2 years after resolution | Quality assurance |
| Analytics Data | 26 months | Product improvement |
| Marketing Preferences | Until consent withdrawn | Consent-based processing |
When your data reaches the end of its retention period, it is securely deleted or anonymized. Font files you've downloaded under an active license are not affected by account data deletion — your license rights remain valid per the original agreement.
Your Rights
Depending on your location, you have specific rights regarding your personal data. We are committed to honoring these rights promptly.
Right to Access
Request a copy of all data we hold about you
Right to Rectify
Correct inaccurate or incomplete data
Right to Erase
Request deletion of your personal data
Right to Portability
Receive your data in a machine-readable format
Right to Object
Object to processing based on legitimate interest
Right to Restrict
Limit how we process your data
You can manage most of these rights directly from your Account Settings → Privacy Dashboard. For complex requests or data portability exports, contact our Data Protection Officer at support@fontyle.com. We respond to all requests within 30 days as required by GDPR.
Data Security
We implement industry-leading technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.
- Encryption in Transit — All data is transmitted over TLS 1.3 with forward secrecy enabled.
- Encryption at Rest — Sensitive data is encrypted using AES-256 encryption standards.
- Access Controls — Role-based access with multi-factor authentication for all internal systems.
- Regular Audits — Annual SOC 2 Type II audits and quarterly penetration testing.
- Incident Response — Dedicated security team with a 24-hour incident response protocol.
- Employee Training — Mandatory data protection training for all team members, refreshed annually.
Children's Privacy
fontyle services are not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take immediate steps to delete that information.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@fontyle.com and we will promptly remove it.
International Data Transfers
As a global font platform, your data may be transferred to and processed in countries other than your own. We ensure that appropriate safeguards are in place for all international transfers, including:
- Standard Contractual Clauses (SCCs) — EU-approved contracts for transfers outside the EEA.
- UK International Data Transfer Agreement — Approved addendum for UK data transfers.
- Data Privacy Framework — Certification for US-EU data transfers where applicable.
- Adequacy Decisions — Reliance on jurisdictions recognized as providing adequate data protection.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Post a prominent notice on our dashboard for logged-in users.
- Send an email notification for changes that significantly affect your rights.
- Maintain previous versions in our policy archive for your reference.
Your continued use of fontyle after any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us.
412 Font Avenue, Suite 800, San Francisco, CA 94105
We acknowledge all privacy-related inquiries within 48 hours and aim to provide a complete response within 30 calendar days. For urgent data breach notifications or legal requests, please mark your subject line as "URGENT — Privacy Request."