Privacy & Security

Privacy Policy

Last updated: January 15, 2025

This Privacy Policy describes how Renderiq collects, uses, and protects your personal information when you use our AI architectural visualization platform. We are committed to protecting your privacy and complying with GDPR, CCPA, and other applicable data protection laws.

1. Introduction and Scope

Renderiq ('we', 'us', 'our') is committed to protecting your privacy. This Privacy Policy ('Policy') explains how we collect, use, disclose, and safeguard your information when you use our AI-powered architectural visualization platform ('Service') accessible at renderiq.io.

This Policy applies to all users of our Service, including visitors, registered users, subscribers, and enterprise customers. By using our Service, you consent to the data practices described in this Policy.

This Policy complies with applicable data protection laws including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant privacy legislation.

Last Updated: January 15, 2025. We may update this Policy periodically. Material changes will be notified via email or prominent notice on our platform.

2. Information We Collect

2.1 Personal Information

We collect personal information that you provide directly to us, including: (a) Account Information: name, email address, password (hashed), phone number (optional), billing address; (b) Profile Information: avatar, bio, website, location; (c) Payment Information: processed securely through Razorpay - we do not store full credit card details; (d) Communication Data: messages sent through our platform, support tickets, feedback.

2.2 Content and Project Data

We collect and store: (a) Architectural designs, drawings, sketches, and project files you upload; (b) AI-generated renders, visualizations, and videos; (c) Project metadata including names, descriptions, tags, and settings; (d) Chat conversations and prompts used for AI generation; (e) Canvas graphs and node-based editor data.

2.3 Usage and Technical Data

We automatically collect: (a) Usage Data: render history, feature usage, session duration, pages visited, actions taken; (b) Technical Data: IP address, browser type and version, device information, operating system, time zone, language preferences; (c) Performance Data: rendering times, queue positions, error logs, system performance metrics; (d) Location Data: approximate location derived from IP address (country/city level).

2.4 Cookies and Tracking Technologies

We use cookies, web beacons, and similar technologies. See our Cookie Policy for detailed information. Essential cookies are required for Service functionality. Analytics cookies help us improve our Service. Marketing cookies require your consent.

3. How We Use Your Information

3.1 Service Provision

We use your information to: (a) Create and manage your account; (b) Process payments and manage subscriptions; (c) Provide AI-powered rendering and visualization services; (d) Store and organize your projects and renders; (e) Enable collaboration features; (f) Send service-related communications (order confirmations, receipts, invoices).

3.2 Service Improvement

We analyze usage data to: (a) Improve AI model accuracy and rendering quality; (b) Enhance platform features and user experience; (c) Optimize performance and reduce processing times; (d) Develop new features based on user needs; (e) Conduct research and development (using anonymized data).

3.3 Communication

We use your contact information to: (a) Send transactional emails (receipts, invoices, payment confirmations); (b) Respond to support requests and inquiries; (c) Send important service updates and security notifications; (d) With your consent, send marketing communications (you can opt-out anytime); (e) Send subscription renewal reminders and billing notifications.

3.4 Security and Compliance

We use information to: (a) Detect and prevent fraud, abuse, and unauthorized access; (b) Verify user identity and authenticate accounts; (c) Enforce our Terms of Service and legal agreements; (d) Comply with legal obligations and respond to legal requests; (e) Protect rights, property, and safety of users and third parties.

4. Data Security and Protection

4.1 Security Measures

We implement industry-standard security measures: (a) Encryption: All data encrypted in transit using TLS 1.3/SSL and at rest using AES-256 encryption; (b) Access Controls: Role-based access control, multi-factor authentication for administrative access, regular access reviews; (c) Infrastructure Security: Enterprise-grade cloud hosting (Supabase), regular security audits, vulnerability assessments, penetration testing; (d) Data Backup: Regular automated backups with point-in-time recovery capabilities.

4.2 Payment Security

Payment processing is handled by Razorpay, a PCI DSS Level 1 compliant payment processor. We do not store full credit card numbers. Payment data is encrypted and transmitted securely.

4.3 Data Breach Procedures

In the event of a data breach affecting your personal information, we will: (a) Notify affected users within 72 hours of discovery; (b) Report to relevant data protection authorities as required by law; (c) Provide details of the breach and steps taken to mitigate risks; (d) Offer credit monitoring or identity protection services if appropriate.

4.4 Data Retention

We retain your data: (a) Account Data: Until account deletion request or 3 years of inactivity; (b) Project Data: Until you delete projects or account closure; (c) Payment Records: 7 years for tax and legal compliance; (d) Usage Data: Aggregated and anonymized data may be retained indefinitely for analytics; (e) Legal Requirements: Some data may be retained longer if required by law.

5. Your Rights and Choices

5.1 Access and Portability

You have the right to: (a) Access all personal data we hold about you; (b) Download your data in machine-readable format (JSON, CSV); (c) Export your projects, renders, and account information; (d) Request a copy of your data by contacting privacy@renderiq.io.

5.2 Correction and Update

You can: (a) Update account information through your account settings; (b) Correct inaccurate data by editing your profile; (c) Request correction of data we control by contacting us.

5.3 Deletion and Right to be Forgotten

You can: (a) Delete individual projects and renders through the platform; (b) Request account deletion which will delete associated personal data; (c) Request deletion of specific data categories; (d) Note: Some data may be retained for legal compliance (payment records, legal disputes).

5.4 Objection and Restriction

You have the right to: (a) Object to processing of your personal data for marketing purposes (opt-out available in account settings); (b) Object to processing based on legitimate interests; (c) Request restriction of processing in certain circumstances; (d) Withdraw consent where processing is based on consent.

5.5 California Privacy Rights (CCPA)

California residents have additional rights: (a) Right to know what personal information is collected; (b) Right to know if personal information is sold or disclosed; (c) Right to opt-out of sale of personal information (we do not sell personal information); (d) Right to non-discrimination for exercising privacy rights.

6. Data Sharing and Third Parties

6.1 We Do Not Sell Your Data

We never sell your personal information, architectural designs, or project data to third parties. Your content remains your intellectual property.

6.2 Service Providers

We share data with trusted service providers under strict contracts: (a) Cloud Hosting: Supabase (data storage and hosting); (b) Payment Processing: Razorpay (payment transactions); (c) AI Services: Google Cloud Vertex AI (AI model processing); (d) Analytics: Anonymous usage analytics (no personal data); (e) Email Services: Transactional and marketing emails (with opt-out). All providers are bound by confidentiality agreements and data processing agreements.

6.3 Legal Disclosures

We may disclose information: (a) When required by law, court order, or legal process; (b) To comply with government requests or regulatory requirements; (c) To protect our rights, property, or safety; (d) To prevent fraud or investigate potential violations; (e) In connection with legal proceedings or disputes.

6.4 Business Transfers

In the event of merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity. Users will be notified of such transfers, and this Privacy Policy will continue to apply.

6.5 Public Content

If you make projects or renders public through our gallery feature, that content becomes publicly accessible. You can make content private at any time.

7. International Data Transfers

7.1 Cross-Border Transfers

Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place: (a) Standard Contractual Clauses (SCCs) for EU data transfers; (b) Adequacy decisions where applicable; (c) Binding Corporate Rules for intra-group transfers.

7.2 Data Processing Locations

Primary data processing occurs in: (a) United States (Supabase hosting); (b) European Union (where applicable); (c) India (Razorpay payment processing). All transfers comply with applicable data protection laws.

8. Children's Privacy

Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@renderiq.io and we will delete such information.

9. Contact Us and Data Protection Officer

General Inquiries

For questions about this Privacy Policy or our data practices:

Email: privacy@renderiq.io

Support: support@renderiq.io

Data Protection Officer (DPO)

For GDPR-related inquiries and data subject requests:

Email: dpo@renderiq.io

Response Time: We respond to all requests within 30 days as required by law.

Data Subject Requests

To exercise your rights (access, deletion, portability, etc.), please email us with:

  • Your full name and email address associated with your account
  • Description of the request (e.g., "Request access to my personal data")
  • Verification of your identity (we may request additional verification)

Regulatory Complaints

If you are located in the EU, you have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • We will update the "Last updated" date at the top of this Policy
  • For material changes, we will notify you via email or prominent notice on our platform
  • We will provide at least 30 days' notice for material changes
  • Your continued use of the Service after changes constitutes acceptance of the updated Policy
11. Legal Basis for Processing (GDPR)

Under GDPR, we process your personal data based on the following legal bases:

  • Contract Performance: To provide our Service and fulfill our contractual obligations
  • Legitimate Interests: To improve our Service, prevent fraud, and ensure security
  • Consent: For marketing communications and non-essential cookies
  • Legal Obligation: To comply with tax, accounting, and other legal requirements
  • Vital Interests: To protect safety and security of users

Acknowledgment

By using Renderiq's platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this Policy, please discontinue use of our Service immediately and contact us to delete your account.