Privacy policy
Last updated 2026-08-20
Las páginas legales se ofrecen en inglés.
1. Who we are
This website, framemode.com (the "Site"), is operated by Framemode LLC ("Framemode", "we", "us"), a limited liability company organized in the United States. For the purposes of the EU and UK General Data Protection Regulation (GDPR), Framemode LLC is the data controller for personal data collected through the Site. You can reach us about anything in this policy at think@framemode.com.
2. Scope
This policy covers personal data processed when you visit the Site or contact us through it. Separate Framemode applications may have their own privacy notices; data submitted inside those applications is governed by the agreement covering that application.
3. What we collect
Contact form: the name you enter, your email address, your message, the page and language you contacted us from, the referring hostname and any UTM campaign labels in the link, and, if you arrived from a waitlist link, the product you are interested in. We attach this limited source context to the inquiry so we can understand which pages lead to relevant conversations; we do not collect the full referring URL. Correspondence: emails you send us, and our replies. Technical data: our hosting provider (Cloudflare) processes IP address, user agent, and request metadata in transient logs to serve, secure, and rate-limit the Site. Analytics: we use privacy-preserving, aggregate web analytics that do not use cookies, do not fingerprint devices, and do not build visitor profiles, we see aggregate counts (page views, referrers, countries, performance), not individuals.
4. What we do not do
The Site has no user accounts and sets no advertising or tracking cookies. We do not sell personal data, we do not "share" personal data for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act), we do not run third-party ad networks, and we do not buy visitor data. Because the Site does not use tracking that would require it, honoring Do Not Track / Global Privacy Control signals never becomes necessary, there is nothing to opt out of.
5. Purposes and legal bases
We process contact-form and correspondence data to respond to you, discuss potential engagements, and keep a record of what was agreed, on the legal bases of taking steps prior to entering a contract (GDPR Art. 6(1)(b)) and our legitimate interest in operating a business (Art. 6(1)(f)). We process technical log data to run and secure the Site (Art. 6(1)(f), legitimate interest in security and availability). Aggregate analytics involve no identifiable personal data.
6. Cookies and local storage
The Site sets no tracking cookies and no advertising cookies. Any storage used is strictly necessary for delivering the Site (for example, Cloudflare security challenges may set a technical cookie to distinguish humans from bots). Because we use no non-essential cookies, no cookie consent banner is required.
7. Who receives your data
We use a small number of service providers acting as processors: Cloudflare, Inc. (San Francisco, USA), hosting, content delivery, security, and the serverless functions that deliver contact-form submissions; and Namecheap, Inc. / PrivateEmail (USA), the mailbox (think@framemode.com) where your messages are delivered and stored. We do not disclose personal data to anyone else except where required by law, to protect our rights, or as part of a business transfer (in which case this policy continues to apply).
8. International transfers
We are a US company and our processors operate globally, so data you send us is processed in the United States and may transit other countries via Cloudflare’s network. Where GDPR applies, transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework where the recipient is certified, or on Standard Contractual Clauses incorporated in our processors’ data processing terms.
9. Retention
Contact-form messages and correspondence are kept in our mailbox for as long as needed to handle your inquiry and maintain a record of business communications, after which they are deleted. Transient technical logs are retained by Cloudflare for short periods per its published practices. Aggregate analytics contain no personal data and are retained indefinitely.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to processing, to withdraw consent, and to lodge a complaint with your local supervisory authority (in the EU/UK, your data protection authority; in California, the California Privacy Protection Agency). California residents additionally have the rights to know, delete, and correct, and, since we do not sell or share personal data, there is nothing to opt out of; we will never discriminate against you for exercising any right. To exercise a right, email think@framemode.com; we will verify the request using the email address associated with the data and respond within the timeframe required by applicable law (30 days under GDPR, 45 days under the CCPA, extendable where the law allows).
11. Children
The Site is a business site and is not directed at children under 16. We do not knowingly collect personal data from children; if you believe a child has sent us personal data, contact us and we will delete it.
12. Security
All traffic to the Site is encrypted in transit (TLS). We collect the minimum data needed, restrict access to the mailbox where submissions land, protect the contact endpoint against abuse (rate limiting, origin checks, input validation), and keep credentials in a secrets store rather than in code. No method of transmission or storage is 100% secure, but we treat the small amount of data you give us with care.
13. Changes to this policy
When we change this policy we will update the date at the top of this page. Material changes will be flagged prominently on the Site. Continued use of the Site after a change means the updated policy applies.