Amberpact

Legal

Privacy Policy

Last updated September 8, 2026. Amberpact is studio software. We collect what we need to run your workspace and take payment.

Template for a studio CRM SaaS. This is not legal advice. Have counsel review — especially GDPR, CCPA, and cookie consent — before you treat it as final.

Who we are

Amberpact is the controller for account and billing data on amberpact.com. When you store client contacts or files, you are the controller of that client data; we process it to provide the product. Support: support@amberpact.com.

What we collect

Account data (name, email, password hash), workspace settings, contacts, projects, documents, messages, files you upload, calendar events, inquiry submissions, and payment metadata (plan, Stripe customer and subscription ids — not raw card numbers). Client portal visitors act on files you send; we log those events on the project.

Payments

Amberpact subscriptions go through Stripe Checkout and the Stripe Customer Portal. Client invoice checkout uses the studio’s linked Stripe Connect or Square account. Card numbers are handled by those processors. The Golden Hour demo may use a mock checkout so testers can click through.

Cookies and analytics

We use an HTTP-only session cookie to keep you signed in. If Google Analytics 4 or Google Tag Manager IDs are configured in production, those scripts may set cookies. A consent banner is not shipped yet; we will add Consent Mode before a strict EU launch.

Processors

Hosting and database on our cloud provider (including Vercel and Postgres). Support mail is Microsoft on amberpact.com. Hostinger holds DNS and mail only — not app hosting. Stripe (and Square, if a studio connects it) process payments.

Retention and your rights

We keep workspace data while the account is open and for a reasonable period after cancel so you can export. Write support@amberpact.com to export or delete a workspace. We will not sell studio contact lists.