Legal

Privacy Policy

Effective August 25, 2026

Prodular is a product design studio. This policy covers two different things: the small amount of data this website collects from anyone who visits it, and the data we handle when a company hires us for a Sprint or a Partner engagement. We have tried to write it in plain language rather than legal padding, and to describe what actually happens rather than everything the law would allow us to do.

1.

Who Is Responsible for Your Data

a.Data Controller

Prodular, a product design studio, decides why and how the personal data described here is processed. For anything in this policy, write to jacob@prodular.co.

b.Client Data

During a paid engagement, the data inside your product belongs to you and we handle it on your instructions, as a processor rather than a controller. Your own agreement with us, or a data processing agreement if we sign one, governs that relationship.

2.

What We Collect

a.What You Send Us

Your name, email address, company, and whatever you choose to write when you book a call, buy a Sprint, or email us. Calls are booked through Cal.com, which collects the details you enter into its form and your chosen time.

b.Payment Details

Payments run through Stripe on Stripe's own checkout page. Card numbers are never entered on this site and we never see or store them. From Stripe we receive the buyer's name, email address, billing country, and the last four digits of the card.

c.Analytics

We use Mixpanel to understand how the site is used: which pages get read, which buttons get clicked, how much of the film on the homepage gets watched, and rough device, browser, and country information derived from your IP address. It stores its identifier in your browser's local storage rather than in a cookie, and it honours the Do Not Track setting if your browser sends one.

d.Materials Shared During Work

To design something we usually need access to it. That can mean a demo account, screen recordings, research, analytics exports, or documents your team shares with us. We ask for the least access that lets us do the work.

e.What We Do Not Collect

No advertising cookies, no tracking pixels from ad networks, no cross-site behavioural profiles, no purchased contact lists.

3.

Why We Use It, and On What Basis

a.To Deliver the Work

Booking calls, scoping and running engagements, sending files, and handling payment. The legal basis is the contract between us, or the steps taken before entering one.

b.To Run and Improve the Site

Analytics tells us which parts of the site are working and which are not. The legal basis is our legitimate interest in a site that explains our work properly. We look at it in aggregate and have no interest in identifying individual visitors.

c.To Stay in Touch

Replying to enquiries and following up on a conversation you started. The legal basis is legitimate interest, or your consent where one is required.

d.To Meet Legal Obligations

Invoices and accounting records are kept because tax law requires it.

4.

Who Else Sees It

a.Service Providers

A short list, each doing one job: Vercel hosts the site, Stripe processes payments, Mixpanel handles analytics, Cal.com handles bookings, and Google Workspace handles our email and files. They may only use the data to provide their service to us.

b.AI Tools

We use AI tools daily and say so openly on the homepage, so it would be strange to hide it here. Confidential client material only goes into business or enterprise tiers where the provider does not train on our inputs. It does not go into consumer chat products. If a client tells us in writing not to use AI tools on their material at all, we do not.

c.Legal Requests

We disclose data if the law requires it, or to establish or defend a legal claim.

d.No Selling

We do not sell personal data, rent it, or trade it for advertising.

5.

How Long We Keep It

a.Enquiries

Emails and booking records are kept for up to two years after our last exchange, which is long enough to remember a conversation that restarts.

b.Client Work

Project files and access credentials are kept for the length of the engagement and up to twelve months afterwards, so that a client coming back does not start from nothing. We delete sooner on request.

c.Invoices

Retained for five years from the end of the tax year, as tax law requires. This period overrides a deletion request for those specific records.

d.Analytics

Retained in Mixpanel for up to twenty four months.

6.

Your Rights

a.What You Can Ask For

You can ask for a copy of the data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable format, and object to processing we base on legitimate interest. Where we rely on consent you can withdraw it at any time, and that does not affect anything done beforehand.

b.How to Ask

Email jacob@prodular.co. We reply within thirty days and there is no charge.

7.

Turning Analytics Off

a.Do Not Track

Our analytics respects the Do Not Track signal, so enabling it in your browser stops collection on this site.

b.Browser Controls

Blocking local storage for this site, or using a content blocker, also prevents it. Nothing on the site breaks if you do.

8.

Security

a.How We Protect It

The site is served over HTTPS, accounts holding client material use two factor authentication, and access to client systems is limited to the people doing the work and revoked when an engagement ends. No system is perfectly secure, and we would rather say that than imply otherwise.

b.If Something Goes Wrong

If a breach affects your personal data and creates a real risk to you, we tell you directly and without delay, along with what happened and what to do about it.

9.

Changes

a.Updates

We update this policy when what we do changes. The effective date at the top always reflects the current version. Material changes affecting existing clients are sent by email rather than quietly posted.

10.

Contact

a.Questions

Anything about this policy or your data goes to jacob@prodular.co. Our terms of service are here.