Legal
Privacy Policy
What we collect when you use templify.digital, why we collect it, who else touches it, and how you take control of it.
1Who is responsible for your data
2BROS GROUP LIMITED, 483 Green Lanes, London N13 4FG, England, is the controller of the personal data described in this policy. That means we decide why and how it is used, and we are answerable for it.
For any privacy question, or to exercise a right described below, write to contact@2brosgroup.com. Please put “Privacy” in the subject line so it reaches the right person quickly.
2What this policy covers
This policy covers templify.digital and the services we deliver through it: browsing the library, creating an account, buying a plan, downloading files and contacting support.
It does not cover third-party sites we link to, or what you do with an asset once you have downloaded it and published a project of your own.
3What we collect
We collect only what the service actually needs. In practice it falls into a few groups.
- Account data — your email address, a securely hashed password (never the password itself), your name if you give one, and, if you sign in with Google, the email address, name and profile picture Google returns.
- Purchase data — which plan you bought, when, the amount, the currency, the status of your subscription, and a Stripe customer and payment reference. Your full card number never reaches us.
- Usage data — which assets you download or export, and when. This is what makes fair-use limits and your download history work.
- Technical data — IP address, browser and device type, and request logs kept by our hosting and security layers, including the counters behind our rate limiting.
- Support data — the content of emails and contact-form messages you send us, and our replies.
- Preferences — your language and theme choice, and the templates you mark as favourites, which stay in your browser.
4Why we use it, and on what legal basis
Under the UK and EU GDPR every use of personal data needs a legal basis. Ours are these.
- To give you the service you bought — account, access, downloads, invoices, service email. Basis: performance of our contract with you.
- To take payment and to prevent fraud and chargebacks. Basis: performance of our contract, and our legitimate interest in not being defrauded.
- To keep the service secure and enforce fair use — rate limits, abuse detection, logs. Basis: our legitimate interest in a working, non-abused service.
- To answer your support messages. Basis: performance of our contract, or our legitimate interest in helping people who write to us.
- To keep accounting and tax records. Basis: a legal obligation we are under.
- To send occasional product or marketing email. Basis: your consent, which you can withdraw at any time from the unsubscribe link.
- To remember your language and theme. Basis: your consent, or our legitimate interest in the site working the way you left it.
5Payments
Payments are processed by Stripe Payments Europe, Ltd. and its group companies. At checkout you are handed to Stripe’s own hosted flow: your card details go to Stripe, not to us.
Stripe returns to us a customer identifier, the outcome of the payment, the brand and last four digits of the card, and the subscription status. That is enough to give you access, show your billing history and issue a refund, and no more.
Stripe is an independent controller for the payment data it holds and processes it under its own privacy policy, published on stripe.com.
6Who else processes your data
We use a small number of providers to run the service. Each is bound by a contract that allows it to use your data only on our instructions.
- Stripe — payments, subscriptions and the billing portal.
- Vercel — hosting, delivery and request logs for the site.
- Neon — the managed PostgreSQL database holding accounts, sessions, entitlements and download records.
- Sanity — the content platform holding the catalogue and its descriptions.
- An S3-compatible object storage provider — the asset files themselves and the signed links that deliver them to you.
- Our transactional email provider — account, password-reset, receipt and support email.
- Google — only if you choose to sign in with a Google account, and only for that sign-in.
7International transfers
Some of our providers operate outside the United Kingdom and the European Economic Area, including in the United States.
Where data is transferred outside the UK or the EEA, it is protected by an approved transfer mechanism — in practice the European Commission’s Standard Contractual Clauses together with the UK Addendum, alongside the technical measures described below.
You can ask us for details of the safeguards applying to a particular transfer by writing to contact@2brosgroup.com.
8How long we keep it
Account data is kept while your account exists, and for up to twelve months after you close it so that we can deal with a late dispute or a duplicate signup.
Purchase and invoice records are kept for as long as tax and accounting law requires — in practice up to seven years — even after an account is closed.
Download and usage records are kept for up to twenty-four months, which is what we need to enforce fair use and to answer “where is my file” questions.
Technical logs are kept for a short period, typically no more than ninety days. Support email is kept for up to three years. Session records are deleted when the session expires or when you sign out.
9Your rights
If the UK or EU GDPR applies to you, you have the rights below. They are free to exercise, and we answer within one month.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of data that is wrong or incomplete.
- Erasure — deletion of your data, where we have no overriding reason or legal duty to keep it.
- Restriction — a pause on our use of your data while a dispute about it is resolved.
- Portability — the data you gave us, in a structured, machine-readable format.
- Objection — to processing based on our legitimate interests, and at any time to direct marketing.
- Withdrawal of consent — at any time, without affecting what we did lawfully before you withdrew it.
- Complaint — to a supervisory authority: the Information Commissioner’s Office in the UK, or the data protection authority of the country you live in within the EU.
11Children
Templify is not intended for children. You must be at least 16 years old, or the age of digital consent where you live if that is higher, to create an account.
If you believe a child has given us personal data, write to contact@2brosgroup.com and we will delete it.
12How we protect it
Traffic to the site is encrypted in transit. Passwords are stored only as salted hashes, never in a readable form. Session tokens are stored as digests, so a leaked database row cannot be replayed as a login.
Asset files are served through short-lived signed links rather than from a public bucket, and sensitive actions are rate limited.
Access to production data inside our team is limited to the people who need it. No system is perfectly secure, but if a breach ever put your rights at risk we will notify you and the relevant authority as the law requires.
13Changes to this policy
We update this policy when the service or the law changes. The version on this page is always the current one, dated at the top.
If a change materially affects how we use your data, we will tell you by email before it takes effect.
14Contact
Privacy questions and rights requests go to contact@2brosgroup.com, or by post to 2BROS GROUP LIMITED, 483 Green Lanes, London N13 4FG, England.
Site operator
2BROS GROUP LIMITED483 Green LanesLondon N13 4FGEnglandcontact@2brosgroup.comWrite to us at the address above with any question about this document. Every message is answered by a real person, usually within two working days.