Privacy Policy
Last updated: April 25, 2026
Controller: DesignBuff LLC (“we,” “us,” “our”).
This Privacy Policy describes how DesignBuff LLC (“DesignBuff”) collects, uses, and shares personal information when you use our website at designbuff.co (and related subdomains) (“Site”) and when you purchase or use our design subscription, project, or related services (together with the Site, the “Services”).
Contact: hello@designbuff.co (general) · legal@designbuff.co (legal, privacy, and copyright notices). Registered office / agent (notices): 30 S Doughty Ave, Somerville, NJ 08876, USA.
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services. Where required by law, we provide additional information or rights below.
1. Information we collect
1.1 You provide to us. For example: name, email, company name, role, billing and payment information, project briefs, files you upload (e.g. logos, product copy), communications with us, and any information you submit through forms, email, Tally, or discovery calls.
1.2 Automatically. For example: IP address, device type, browser type, approximate location derived from IP, pages viewed, referring URL, and dates/times of access. We may use cookies and similar technologies as described in Section 6.
1.3 From third parties. For example: payment processor (e.g. transaction status, limited account identifiers), email or calendar tools if you connect them with our consent, or lead sources if you come through a partner campaign.
1.4 We do not knowingly build our Services to collect sensitive categories of data (e.g. health, biometric) as a separate, regulated product. Tally is a project tool, not a HIPAA-compliant or “secure health repository” (see Section 8 and our Terms of Service/Section 9 for Tally). Do not upload PHI, patient identifiers, or other information that must be isolated under HIPAA or similar rules to Tally unless we have expressly agreed in a separate writing to a different model.
2. How we use information
We use personal information to:
- Provide, deliver, and improve the Services, including scoping, design work, and support;
- Operate the Site and Tally (task tracking, timelines, and collaboration as described in our Terms of Service);
- Process payments, send invoices, and manage subscriptions or project billing;
- Communicate with you about the Services, including security, product, and policy updates;
- Secure our systems, prevent fraud, and enforce our terms;
- Comply with law, legal process, and reasonable requests from public authorities; and
- Analyze use of the Site in aggregate or de-identified form to improve our marketing and product (where permitted).
We do not sell your personal information for money as that term is commonly understood in U.S. state “Do Not Sell” laws.
3. Legal bases (if you are in the EEA, UK, or similar regions)
Where GDPR or similar law applies, we rely on: (a) performance of a contract; (b) legitimate interests (e.g. security, product improvement, marketing that is not intrusive); (c) legal obligation; and (d) consent where required (e.g. non-essential cookies or certain marketing), which you may withdraw as described in our cookie or consent UI when available.
4. Sharing of information
We may share information with:
- Service providers that help us run the business (e.g. hosting, email, payment processing, analytics, customer support, security), subject to appropriate contractual protections;
- Professional advisers (lawyers, accountants) when needed;
- Acquirers or investors in a merger, financing, or sale of assets, with notice as required by law; and
- Authorities when we believe in good faith that disclosure is required by law, subpoena, or to protect our rights, safety, or the rights of others.
We may also share aggregated or de-identified information that does not identify you.
5. International transfers
We are based in the United States. If you access the Services from outside the U.S., your information will be processed in the U.S. and other countries where we or our subprocessors operate. If we transfer personal data from the EEA, UK, or Switzerland, we use appropriate mechanisms (e.g. Standard Contractual Clauses) or other lawful bases as required, and you may request a copy of relevant safeguards by contacting us.
6. Cookies and similar technologies
We and our partners may use cookies, local storage, and similar technologies for necessary operation of the Site (e.g. session, load balancing, security) and, where you consent, for analytics or measurement of marketing effectiveness. You can control cookies through your browser settings. Where we use a consent management platform, you may use it to set preferences. Blocking some cookies may affect Site functionality.
7. Data retention
We retain information for as long as needed to provide the Services, meet legal, tax, and accounting requirements, and resolve disputes. Project files and account data may be retained for [describe retention period, e.g. the length of the relationship + X years]; backup copies may persist for a period after deletion. We may de-identify or aggregate data and retain it without time limit.
8. Tally (our project management software); no “secure” or regulated repository
8.1 What Tally is. Tally is DesignBuff’s project management and task-tracking application used to coordinate subscriptions and projects (for example requests, status, timelines, comments, and related workflow). It is not marketed or operated as a secure vault, a compliance enclave, or a long-term archival system for highly sensitive or regulated data.
8.2 What may appear in Tally. Tally may store and show what you, people on your team, and our team add in the ordinary course of work. For example briefs, uploaded media, design files, task titles and descriptions, comments, and conversations about projects and deliverables. That content is for practical collaboration; we do not treat Tally as a segregated, audit-only, or compliance- certified system.
8.3 No warranty of security, secrecy, or “confidentiality” under law (including HIPAA). We do not warrant that information in Tally (or in emails or notices from Tally) remains confidential, or that it is safe from leak, hacking, phishing, scams, social engineering, user error, or third-party incidents, or that it meets the standards of any governing body (such as HIPAA, other health-privacy rules, or industry-specific frameworks). Tally and the standard Services are not “HIPAA-compliant” and are not a BAA-covered product by default. The practices in this Policy and in our Terms of Service (especially Section 9 on Tally) are written so that we do not create false assumptions: project tracking is not the same as a compliant medical or other regulated record system.
8.4 Liability; your assumption of risk. To the maximum extent permitted by applicable law, DesignBuff is not liable for unauthorized access to, loss of, or misuse of information in or leaving Tally, or for reliance on Tally for data or use cases that Tally and the agreed Services are not designed for. The Terms of Service (including limitation of liability and indemnity) govern Tally-related incidents; you agree to read those provisions carefully (with your advisers if needed).
9. Security
We use reasonable administrative, technical, and physical safeguards to protect personal information. Reasonable does not mean warranting a particular outcome for Tally-hosted data; see Section 8. No system is 100% secure; you use the Services at your own risk as to transmission over the public internet. Please use strong passwords and protect your account credentials.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict certain processing of your personal data, and to object to some processing, including direct marketing (which you can opt out of by unsubscribing or emailing us). You may have the right to lodge a complaint with a supervisory authority.
To exercise these rights, contact hello@designbuff.co. We will respond within the time required by law (often 30 to 45 days) and may need to verify your identity. You may also designate an authorized agent in line with applicable law.
We do not discriminate for exercising your privacy rights, where that obligation applies.
11. California residents (if applicable)
If the California Consumer Privacy Act (CCPA/CPRA) or similar state law applies, you may have additional rights (e.g. to know, delete, correct, opt out of certain sharing, and to limit use of sensitive data). We describe categories of information collected, purposes, and sharing at a high level in this Policy. We do not “sell” or “share” personal information for cross-context behavioral advertising in a way that requires an opt-out link unless and until we do so, in which case we will add a “Do Not Sell or Share” or similar mechanism as required. Financial incentives (if any) will be described separately.
12. Children
The Services are not directed to children under 13 (or the age in your region). We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it promptly.
13. Third-party sites and services
The Site may link to third-party sites or embedded tools. Their privacy practices are their own. For example, our payment processor’s privacy policy applies to payment data they collect directly.
14. Changes to this policy
We may update this Privacy Policy. We will post the new version on this page, update the “Last updated” date, and, where the law requires, notify you (e.g. by email or a notice in the product). Continued use of the Services after the effective date may constitute acceptance of the update, to the extent permitted by law. If you do not agree, you should stop using the Services and contact us to close your account, subject to our Terms of Service and your subscription or SOW.
This policy is a starting point for your business and should be reviewed by qualified counsel, especially for international clients, B2B vs consumer use, and your actual data flows, subprocessors, and analytics stack.