Privacy Policy
Last updated August 2026
This policy explains what personal data Stylehub handles, why, on what legal basis, how long we keep it, and what you can do about it. It covers stylehub.cloud, the app behind it, and the brand hubs our customers publish on subdomains and custom domains.
1. Who is responsible
Stylehub is operated from Switzerland. For questions about this policy, or to exercise any of the rights in section 9, write to privacy@stylehub.cloud. If you need our full company details and postal address for a formal request, ask at that address and we will provide them.
Controller and processor
The distinction matters, because it decides who you should contact:
- For account data we are the controller. Your name, email, password hash, plan and login history exist because you have an account with us, and we decide how they are handled.
- For workspace content we are a processor. The brand manuals, uploaded files, team lists and anything a customer puts into Stylehub belong to that customer. They decide what goes in and what it is used for; we only host and display it on their instruction. If you appear in a workspace that is not yours, contact the company that runs it. We will pass a request on if you are not sure who that is.
2. What we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account data | Email address, optional display name, a bcrypt password hash, optional avatar image, timezone and date format preferences, and whether the account is a platform administrator. | You, when you register or edit your account. |
| Workspace and team data | Workspace name and slug, memberships, roles and custom roles, invitations you send including the invited email address. | You and your colleagues. |
| Workspace content | Brand manual sections and blocks, colors, typography, text, uploaded logos, images, fonts and documents, comments, and version snapshots. | The workspace members. |
| Activity records | Who changed what and when, including the name shown next to the change, so a team can see its own history. | Generated as you work. |
| Billing data | Plan, subscription status, and identifiers from our payment provider. Card numbers never reach us. | Stripe, when you subscribe. |
| Published hub statistics | Daily view counts per workspace, plus coarse device type (mobile or desktop) and the referring domain. No individual visitor profile is built, no visitor identifier is stored, and the counts are aggregates only. | Visitors to a published brand hub. |
| Technical logs | Server and infrastructure logs needed to run and secure the service, which can include IP addresses for a short period. | Automatically, as with any web service. |
3. Why we use it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Giving you the service: accounts, editing, publishing, storage, team management. | Performance of a contract (Art. 6(1)(b) GDPR). |
| Taking payment and managing subscriptions. | Performance of a contract, and legal obligation for accounting records. |
| Keeping the platform available and secure, preventing abuse, and fixing faults. | Legitimate interests (Art. 6(1)(f)): running a service that works and is not abused. |
| Aggregate, cookieless measurement of published hubs so customers can see how their brand hub is used. | Legitimate interests, on data that does not identify individual visitors. |
| Answering support requests. | Performance of a contract, or legitimate interests where you are not the account holder. |
| Optional product emails, if we ever send them. | Consent (Art. 6(1)(a)), withdrawable at any time. |
We do not sell personal data. We do not use customer content to train machine learning models, and we do not share it with anyone who would.
4. Processors we rely on
These providers process data on our behalf under data processing agreements. We keep the list short on purpose.
| Provider | What for | Where |
|---|---|---|
| Hostinger | Application and database hosting | Europe |
| DigitalOcean Spaces | Object storage for uploaded files, images and fonts | Europe |
| Cloudflare | DNS, TLS certificates and network protection | Global network, EU traffic served from Europe |
| Stripe | Payments and subscription management. Card data is handled entirely by Stripe and never touches our servers. | EU and US, under Standard Contractual Clauses |
| Logiwolf | Cookieless, aggregate analytics for our own marketing pages. No cookies, no cross site tracking, no individual profiles. | Europe |
If we add or replace a processor, we update this list. Customers on a paid plan can ask for notice of changes at privacy@stylehub.cloud.
5. Cookies
Stylehub sets no advertising cookies and no cross site tracking cookies, which is why you are not asked to dismiss a banner. These are the only cookies we set, and all of them are strictly necessary:
| Cookie | Purpose | Lifetime |
|---|---|---|
sh_session | Keeps you signed in. Signed, and readable only by the server. | 30 days, or until the browser closes if you do not tick Keep me logged in |
sh_org | Remembers which workspace you were last working in. | Session |
sh_pw_... | Records that a visitor entered the correct password for one password protected brand hub. Bound to that page and to the current password. | 7 days |
sh_team_... | Records that a signed in team member may view one private brand hub on its public address. | 2 hours |
6. How long we keep things
| Data | Kept for |
|---|---|
| Account and workspace content | As long as the account exists. Deleting a workspace removes its manuals, sections, memberships and uploaded files, from object storage as well. |
| Activity log and version snapshots | 370 days, then deleted automatically. Your plan decides how far back you can look, but the retention period is the same for everyone. |
| Login sessions | Up to 30 days, and immediately on logout or account deletion. |
| Published hub statistics | Aggregate daily counters with no visitor identifier, kept for trend reporting. |
| Billing records | As long as commercial and tax law requires, typically ten years, independently of the account. |
| Backups | Deleted data can persist in encrypted backups for a short rolling window before those are overwritten. |
7. International transfers
Our application, database and file storage are in Europe. Where a processor handles data outside the EEA or Switzerland, notably Stripe, the transfer relies on the European Commission Standard Contractual Clauses together with the Swiss addendum, plus the provider's own supplementary measures.
8. Security
- Passwords are stored only as bcrypt hashes, never in readable form.
- Session tokens are signed and stored in cookies the browser cannot read from JavaScript.
- Every workspace is isolated, and every read and write is checked against the role of the person making it.
- Traffic is served over TLS, with certificates renewed automatically.
- Rich text authored in the editor is sanitized before it is published, so a manual cannot be used to run scripts against its readers.
No system is perfect. If we become aware of a breach that is likely to put your rights at risk, we notify the competent supervisory authority within 72 hours where required, and we tell affected customers without undue delay.
9. Your rights
Under the GDPR and the Swiss FADP you can ask us to give you a copy of your data, correct it, delete it, limit what we do with it, object to processing based on legitimate interests, or hand it to another provider. You can withdraw consent at any time without affecting what happened before.
What you can do yourself, right now
- Get a copy: Account, then Download my data. You get a JSON file with your profile, memberships, uploads, comments and activity.
- Correct it: Account, for your name and preferences.
- Delete it: Account, then Delete my account. This removes the account and any workspace nobody else is in, files included, and strips your name from shared histories and comments. A workspace you share with others has to be handed over first, so the people you work with do not lose it.
- Export the brand kit: Dashboard, then Export, for the full workspace content as a ZIP.
Deleting a workspace under Settings removes that workspace only. It does not delete your account.
For anything the app cannot do, write to privacy@stylehub.cloud. We answer within one month. You can also complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner, or in the EU the authority where you live or work.
10. Automated decisions
We do not make decisions about you by automated means that produce legal effects or similarly significant effects. Plan limits are applied mechanically, but they follow the plan you chose.
11. Children
Stylehub is a tool for businesses and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us data, write to us and we will remove it.
12. Changes
We update this policy as the service changes. The date at the top always reflects the current version, and we tell customers in the app about changes that matter.
13. Contact
privacy@stylehub.cloud for privacy matters, hello@stylehub.cloud for everything else. Our Terms of Service cover the commercial side of the relationship.