Privacy Policy
This Privacy Policy explains how Custome (“Custome,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use our websites, applications, and related services (the “Service”).
Custome helps you turn active Stripe subscriptions into live customer logos for your marketing surfaces. If you do not agree with this Policy, do not use the Service.
1. Who we are and roles
For your account and billing relationship with us, we act as a data controller (or equivalent under applicable law).
For subscriber and customer data you sync from Stripe or manage in Custome so you can display logos, we act as a data processor / service provider on your behalf. You are the controller of that data and are responsible for having a lawful basis to share it with us and to display logos.
2. Information we collect
Account and authentication
When you sign up or sign in, we collect information such as your name, email address, password (stored hashed), profile image if provided by an identity provider, and session metadata (for example IP address and user agent). If you use Google or GitHub to sign in, we receive the profile information those providers share with us under their policies.
Workspace and product settings
We store workspace settings you configure, including product name, the public page URL where logos appear, reply-to email for permission messages, public embed keys, and sync timestamps.
Stripe connection
To sync subscriptions, you connect a Stripe secret or restricted API key. We store that credential encrypted at rest and use it only on our servers to read customers and subscriptions, keep the wall up to date, and process webhooks. We do not use your Stripe key to create charges or change your customers’ billing.
Subscriber and logo data
From Stripe (and your edits in the dashboard) we may store customer identifiers, subscription status, email, name, company name, domain, logo URLs and resolution source, visibility/hidden flags, and logo permission status (including tokens and request/response timestamps used for approve/decline links).
Communications
If you send logo-permission emails through Custome, we process the recipient address and message content needed to deliver that email and record the outcome. We may also process support or transactional messages you send us.
Technical and usage data
Like most online services, our hosts and security tooling may process IP addresses, device/browser information, request logs, and approximate location derived from IP, to operate, secure, and debug the Service.
3. How we use information
We use information to:
- Provide, maintain, and improve the Service
- Authenticate users and secure accounts
- Sync Stripe data and resolve or refresh logos
- Send permission requests you initiate, and host approve/decline pages
- Serve public embeds and APIs for approved, active logos only
- Process subscriptions, trials, and payments for Custome itself
- Communicate about the Service (transactional and, where allowed, product updates)
- Prevent abuse, debug issues, and comply with law
We do not sell your personal information. We do not use your customers’ data to market Custome to them, except to deliver permission emails you explicitly send.
4. Legal bases (where applicable)
If you are in the EEA, UK, or a similar jurisdiction, we process personal data as needed to perform our contract with you, for our legitimate interests in running a secure product (balanced against your rights), to comply with legal obligations, and—where required—based on consent (for example certain cookies or optional communications).
5. How we share information
We share information with service providers who help us run Custome, under obligations to process it only for our instructions, including:
- Hosting and infrastructure (for example Vercel) — application hosting and delivery
- Database (for example Neon) — storage of account and product data
- Authentication (better-auth; Google/GitHub if you choose those sign-in methods)
- Stripe — reading your connected account data; also used if you pay for Custome
- Logo.dev — logo image delivery and company/logo lookup
- Email delivery (for example Resend) — permission and transactional email
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required). Public embeds and the public wall API expose only logos and related display fields you have approved to show.
6. Your customers’ privacy
You are responsible for your relationship with your end customers, including notices and rights under privacy laws. Custome should only display a logo after permission is approved in-product (or marked approved by you because you already have rights). Permission emails are sent only when you trigger them.
If an end customer contacts us about data you control, we may redirect them to you as the controller.
7. Retention
We keep account and Service data for as long as your account is active and as needed to provide the Service. We may retain limited records afterward for security, dispute resolution, backups, and legal compliance. You may request deletion of your account; we will delete or anonymize personal data we control unless we must retain it by law. Encrypted Stripe credentials are removed when you disconnect Stripe or delete your account, subject to backup cycles.
8. Security
We use administrative, technical, and organizational measures appropriate to the risk, including encryption of Stripe credentials at rest, server-side use of secrets, and access controls. No method of transmission or storage is completely secure; you use the Service at your own risk and should prefer a restricted Stripe key limited to the reads Custome needs.
9. International transfers
We and our providers may process data in countries other than where you live. Where required, we rely on appropriate transfer mechanisms (such as standard contractual clauses) or provider commitments.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights for data we control, contact us using the details below. You may also lodge a complaint with your local supervisory authority.
11. Children
The Service is not directed to children under 16 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
12. Changes
We may update this Policy from time to time. We will post the revised version with an updated “Last updated” date and, when changes are material, provide additional notice as required by law.
13. Contact
For privacy questions or requests, contact us at privacy@custome.app.