Legal

Privacy Policy

How PreFlight.art, LLC collects, uses, discloses, retains, and protects information when you use our services.

Contents
  1. Scope and Role
  2. Information We Collect
  3. How We Use Information
  4. AI Processing and Service Improvement
  5. How We Disclose Information
  6. Marketing Communications
  7. Cookies, Analytics, and Similar Technologies
  8. Data Retention
  9. Security
  10. Your Choices and Privacy Rights
  11. California Privacy Notice
  12. International Users
  13. Children’s Privacy
  14. Third-Party Sites and Services
  15. Changes to This Policy
  16. Contact Us

Effective date: AUGUST 1, 2026

PreFlight.art, LLC(“Company,” “we,” “us,” or “our”) respects privacy and is committed to explaining how we collect, use, disclose, retain, and protect information when you access https://preflight.art/, create an account, upload artwork or other files, purchase or use our AI-assisted preflight and related services, communicate with us, or otherwise interact with us (collectively, the “Services”).

This Privacy Policy applies to information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual or household (“Personal Information”). It does not apply to information that is lawfully made public, deidentified, or aggregated so that it cannot reasonably be associated with an individual.


01

Scope and Role

In most direct interactions with account holders and website visitors, we determine why and how Personal Information is processed. When a business customer submits information concerning another person, including information contained in artwork or files belonging to that customer’s own client, we may process that information on the customer’s instructions. The customer remains responsible for providing required notices and for obtaining the rights, permissions, and authorizations necessary for us to receive and process that information, including under any confidentiality obligation the customer owes a third party. Our Data Processing & Confidentiality Addendum may govern that processing.

The Services are designed primarily for businesses and their authorized personnel. They are not directed to consumers acting for personal, family, or household purposes, although applicable privacy rights may still apply.


02

Information We Collect

2.1 Information You Provide

Account and contact information. We collect names, business email addresses, account credentials, company affiliation, occupation or role, and information you provide when creating, verifying, or administering an account.

Transaction and billing information. Stripe processes payment-card and ACH details. We may receive billing contacts, transaction identifiers, subscription status, payment status, refund and dispute information, and limited payment metadata. We do not ordinarily receive complete payment-card numbers. QuickBooks or another accounting provider may process accounting records.

Customer Content. We collect artwork, label files, dielines, brand assets, specifications, feedback, and other files or information submitted for a preflight review. Customer Content may contain intellectual property or information belonging to the customer or its client, and may contain business contact details, addresses, ingredient or formulation information, and regulatory statements appearing on the label itself. Account history generally contains reports and related metadata; previously uploaded source files may not be accessible through the customer-facing history interface.

Communications and support. We collect information in support requests, emails, survey responses, product feedback, and communications sent through the Services.

2.2 Information Collected Automatically

When you use the Services, we may automatically collect IP address, browser and device characteristics, operating system, referring URLs, pages or functions used, timestamps, session events, crash and diagnostic data, approximate location derived from IP address, and interactions with emails. We may use cookies, software development kits, pixels, local storage, and similar technologies. See Section 7.

2.3 Information From Other Sources

We may receive information from payment processors, authentication and email providers, analytics providers, business customers that authorize an account, and publicly available business sources. We combine that information with other information described in this Policy when permitted by law.


03

How We Use Information


04

AI Processing and Service Improvement

The Services use automated and AI-assisted systems to analyze Customer Content and generate preflight reports. Authorized personnel and contracted service providers may access Customer Content when reasonably necessary to provide support, rerun or troubleshoot a preflight, conduct quality assurance, prevent abuse, evaluate missed issues, and improve, develop, test, and maintain the Services.

We may use Customer Content, report results, corrections, metadata, usage patterns, and feedback to improve the Services and their models. Where reasonably practical for the purpose, we use aggregated, pseudonymized, or deidentified information. We do not sell Customer Content, license it as a standalone asset, use it to create competing artwork, or intentionally disclose one customer’s identifiable Customer Content to another customer.

Third-party model training. We do not use Customer Content to train foundation models operated by third parties. Our agreements with the AI providers that process Customer Content on our behalf prohibit those providers from using it to train their own models. Improvements derived from our own quality assurance and development work exist as changes to our rules, models, and reference data, and are not designed to reproduce or expose Customer Content.

Content that should not be submitted. The Services are not designed for, and are not offered as compliant with, the handling requirements for certain regulated categories of data. Customers should not upload protected health information subject to HIPAA, payment-card data subject to PCI DSS, Social Security numbers or other government identifiers, biometric data, export-controlled or classified technical data, or similarly regulated or highly sensitive information, unless expressly authorized in writing and subject to appropriate additional terms. This restriction does not apply to ordinary business contact information and label copy that appear in artwork submitted for preflight review in the normal course.


05

How We Disclose Information

Service providers. We disclose information to vendors that perform services for us under contracts restricting them to that purpose:

This list may change as the Services evolve. Each provider maintains its own list of subprocessors. Providers may use subprocessors and may process information outside the state where it was collected, subject to applicable contractual safeguards.

Business customers and account administrators. If an account is provided or managed by an organization, its authorized administrators may access account status, users, reports, usage, and information associated with the organization.

Legal and safety disclosures. We may disclose information when we reasonably believe disclosure is required by law or lawful process; necessary to protect rights, safety, security, or property; or appropriate to investigate fraud, abuse, or violations.

Corporate transactions. Information may be disclosed or transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or related diligence, subject to confidentiality protections where appropriate.

At your direction. We disclose information when you direct us to do so or provide consent.

We do not sell Personal Information for money. We do not permit service providers to use Customer Content for their independent marketing. Certain analytics or advertising technologies, if enabled, may constitute a “sale,” “sharing,” or targeted advertising under some state laws even when no money changes hands. We will provide any legally required notice and choice mechanism before or when enabling such practices.


06

Marketing Communications

We may send newsletters, product updates, and promotional messages through Loops.so or another provider after an account is created or verified, as permitted by law. You may unsubscribe through the link in a marketing email. We may continue sending non-promotional messages concerning transactions, security, accounts, and material service changes.


07

Cookies, Analytics, and Similar Technologies

We use or may implement technologies necessary for authentication, security, preferences, performance, analytics, and advertising. These may include Google Analytics, Meta Pixel, email-measurement tools, and similar services. The technologies actually used may change as the Services evolve. Where required, we will request consent or provide a mechanism to manage nonessential technologies.

Browser settings may allow you to block or delete cookies, but doing so may impair account access or functionality. If applicable law requires us to honor a recognized opt-out preference signal, such as Global Privacy Control, we will treat a valid signal as a request for the browser or device from which it is sent.


08

Data Retention

We retain information for no longer than reasonably necessary for the purposes described in this Policy, including to provide the Services, satisfy customer instructions, maintain security and continuity, comply with law, resolve disputes, and enforce agreements. Our retention schedule is:

We may retain information beyond these periods where an earlier deletion is not legally permitted, a different period is agreed with a customer in writing, or preservation is necessary for security, an investigation, a legal claim, or compliance with law.

Deletion from active systems is followed by deletion or overwrite from backups according to our backup cycle, ordinarily within 90 days. We do not restore deleted data from backups except in a disaster recovery event. Deidentified information may be retained without time limit to the extent permitted by law and is not reidentified.


09

Security

We use reasonable administrative, technical, and physical safeguards designed to protect information. These include access controls limiting internal access to personnel who require it, authentication requirements for user accounts, use of reputable infrastructure providers that maintain recognized security certifications, and monitoring for errors and anomalous activity.

Information transmitted between your browser or device and the Services is encrypted in transit using industry-standard TLS, and information stored in our production databases and file storage is encrypted at rest.

No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Customers are responsible for safeguarding credentials, limiting account access, and promptly reporting suspected compromise to hello@preflight.art.


10

Your Choices and Privacy Rights

Depending on where you reside and subject to exceptions, you may have the right to request access to or a copy of Personal Information; correction; deletion; information about collection, use, and disclosure; portability; restriction or objection; withdrawal of consent; or an appeal of a decision. You may also have rights to opt out of sale, sharing, targeted advertising, or certain profiling. We do not discriminate against a person for exercising a legally protected right.

Submit a request to hello@preflight.art. We may verify your identity and authority, request information reasonably necessary to locate records, and deny or limit a request where permitted by law. Authorized agents may be required to provide signed authorization and the individual may be required to verify identity directly. We aim to acknowledge routine inquiries within two business days; statutory response periods govern completion.

Where a request would require deletion of information necessary to maintain an active account, we may need to close the account in order to fulfill it.


11

California Privacy Notice

If the California Consumer Privacy Act, as amended (CCPA), applies to us or to particular processing, California residents may exercise the rights described in Section 10. During the preceding 12 months, we may have collected the following statutory categories: identifiers; customer records; commercial information; internet or other electronic network activity; approximate geolocation; professional or employment-related information; and inferences derived from activity or feedback. Sources, purposes, and recipients are described in Sections 2, 3, and 5.

We do not knowingly sell Personal Information for money. If our use of advertising or analytics technologies constitutes sale or sharing under the CCPA, we will provide an appropriate “Do Not Sell or Share My Personal Information” method and honor applicable opt-out preference signals. We do not knowingly sell or share the Personal Information of consumers under 16.


12

International Users

The Services are operated from the United States and currently use United States-based infrastructure. If you access the Services from another country, information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. Before intentionally offering the Services in the European Economic Area, United Kingdom, or other jurisdictions requiring additional transfer mechanisms or notices, we may adopt supplemental terms. Canadian users may contact us regarding access, correction, or withdrawal of consent, subject to applicable exceptions.


13

Children’s Privacy

The Services are intended for business use by individuals who are at least 18 years of age, consistent with our Terms & Conditions, and are not directed to children. We do not knowingly collect Personal Information from anyone under 18. If you believe a person under 18 has provided Personal Information, contact us so we can review and take appropriate action.


14

Third-Party Sites and Services

The Services may link to or integrate with third-party services. Their privacy practices are governed by their own notices. We are not responsible for third-party practices except as required by law or contract.


15

Changes to This Policy

We may update this Policy to reflect changes in law, technology, or our Services. We will post the revised Policy and update the effective date. If a change materially affects how we use previously collected information, we will provide additional notice or obtain consent when required.


16

Contact Us

Questions or requests may be sent to hello@preflight.art.

PreFlight.art, LLC
Website: https://preflight.art/
Contact: hello@preflight.art