Legal

Privacy Policy

Last updated April 17, 2026

This Privacy Policy describes how Frontal Web (“we”, “us”, or “our”) collects, uses, and safeguards information when you access or use the Frontal Web client portal (the “Service”). By using the Service you agree to the practices described here.

Information we collect

We collect only the information necessary to operate the Service:

  • Account information — name, email address, and the password hash (passwords themselves are never stored).
  • Organization data — the client, agency, or partner records you create, including billing contact details, invoice data, files, tasks, and messages.
  • Technical data — IP address, browser user-agent, and timestamps attached to critical actions (sign-in, e-signature, password reset) for security and audit.
  • Payment data — processed by Stripe under their own privacy policy. We store only non-sensitive references (customer id, payment intent id) and the amount paid.

How we use information

  • Provide, secure, and support the Service.
  • Send transactional emails (invitations, invoices, password resets).
  • Detect abuse, prevent fraud, and meet legal obligations.

We do not sell personal data, and we do not use it for advertising or profiling outside the Service.

Data sharing

We share data only with processors that help us run the Service:

  • Stripe — payment processing
  • Resend — transactional email delivery
  • Backblaze B2 — encrypted file storage
  • Sentry — error telemetry (redacted)

Each processor is bound by contract to handle data only on our instructions and in line with applicable law.

Retention

We retain account, invoice, and audit data for as long as the Service is in use, plus a reasonable period afterwards to meet accounting and legal obligations. Backups are purged on a rolling schedule.

Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise these rights, contact us at the address below. We’ll respond within a reasonable time.

Security

We use encryption in transit (TLS) and at rest for stored files. Passwords are hashed using bcrypt. Access to production systems is logged and restricted to personnel who need it.

Contact

Questions about this policy? Email hello@frontalweb.net.