Cubeless Logo

Privacy Policy

Your privacy matters to us

Last Updated: December 1, 2025

Effective Date: December 8, 2025

1.

Introduction

Welcome to Cubeless (also referred to as "we," "us," or "our"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy describes how we collect, use, share, and protect the personal information of visitors to our website and users of our services ("you," "your," "user," "consumer").

This Policy applies to anyone whose personal data we collect — including residents of the European Union (for whom GDPR applies) and residents of California (for whom CPRA/CCPA apply).

If you are under the age of 16 and believe that we may have collected your personal information, please contact us — we do not knowingly allow collection of minors' data.

2.

Information We Collect

We may collect the following categories of personal information when you use our website or services:

Identity & Contact Data

Name, email address, phone number, username, company name, job title

Authentication Data

Credentials, tokens, metadata needed to provide SSO / MFA / login services

Usage & Technical Data

IP address, browser type, device type, operating system, log-in timestamps, usage logs of our service, performance/diagnostic data, error logs, cookies and tracking identifiers

Communication Data

Support requests, correspondence you send us (e.g. email), user feedback or survey responses

Billing / Payment Data

Billing address, payment method info, invoice data — if you use any paid services through us

Other Data You Provide

Any other data you submit intentionally (e.g. via forms, uploads, profile fields)

We collect this personal information:

  • Directly from you when you register, sign up, log in, contact support or otherwise input data.
  • Automatically through your use of our website or services (e.g., cookies, logs, analytics tools).
3.

Why We Collect & Use Data (Purposes)

We process your personal data for the following legitimate business purposes:

  • To provide and maintain our authentication, SSO, and MFA services;
  • To process registrations, account setup, login, passwordless or multi-factor authentication flows;
  • To communicate with you — e.g. respond to support requests, send important notices (service changes, security alerts, updates);
  • To monitor and improve service performance, reliability, and security;
  • To detect, prevent, investigate, and mitigate fraudulent or abusive activities;
  • To comply with legal obligations, and enforce our Terms of Service;
  • If applicable — to process payments, billing, invoices, and related financial transactions;
  • For analytics and business-development purposes (e.g., usage statistics, product improvement), while preserving user privacy.

We do not sell or rent your personal information for marketing or advertising.

4.

Data Sharing & Disclosure

We may share or disclose personal information under the following circumstances:

  • With our service providers, sub-processors, and vendors who help us provide our services (e.g. hosting providers, email services, payment processors, analytics tools). We require such third-parties to protect your data and use it only for the purposes permitted by us.
  • With affiliates or as part of a corporate transaction (e.g. merger, acquisition, sale) — in which case we'll notify you before transferring data.
  • To comply with legal obligations, court orders, or governmental authorities; to protect the rights, property, or safety of Cubeless, its users, or the public; or to enforce our terms.
  • When you consent or direct us to share your data.

We will never sell your personal data.

5.

Data Security

We implement "reasonable and appropriate" technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction — including encryption, secure access controls, firewalls, monitoring, and regular security assessments.

We limit access to personal information to employees, contractors, and service providers who need to know that information to carry out their work.

6.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described above (e.g. for providing authentication services, supporting your account, responding to requests) — unless a longer retention period is required or permitted by law.

When data is no longer needed, we will securely delete or anonymize it.

7.

Your Rights

Depending on where you live, you may have the following rights regarding your personal data:

AccessKnow what personal information we hold about you.
PortabilityRequest a copy of your data in a structured, machine-readable format.
CorrectionRequest correction of inaccurate or incomplete data.
Deletion ("Right to be Forgotten")Ask us to delete your personal information, subject to certain exceptions.
Restriction or objection to processingUnder certain circumstances (e.g. for legitimate interest processing).
Withdraw consentIf we rely on consent for processing (where applicable).
Opt-out of data sale/sharingFor California residents, if applicable.
Non-discriminationYou have the right not to be discriminated against for exercising your privacy rights.

If you wish to exercise any of these rights, contact us as described below (see Contact Information). We will respond according to applicable law, typically within 30 days.

8.

Cookies & Tracking Technologies

We, and our third-party partners, may use cookies, web beacons, tracking scripts, analytics, and similar technologies to collect usage and technical data.

You can control or disable cookies via your browser settings. Disabling cookies may affect functionality of the site (e.g. login flow, session persistence).

If we process personal data based on consent via cookies (or similar), we will provide a "cookie banner/consent mechanism" at first visit — per GDPR requirements.

9.

International Data Transfers

If you are located in the European Economic Area (EEA) and we transfer your data outside the EEA (e.g. to the U.S.), we will implement appropriate safeguards (e.g. Standard Contractual Clauses, or other lawful mechanisms) to ensure your data remains protected according to GDPR standards.

10.

Children's Privacy

Our services are intended for use by adults (18+). We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from someone under 16 without verification of parental consent, we will promptly delete such data.

11.

California-Specific Disclosures (CCPA / CPRA)

If you are a California resident, you have additional rights under the CPRA / CCPA:

  • Right to know what personal information is collected, used, disclosed, or sold;
  • Right to request deletion or access to your data;
  • Right to opt out of sale or sharing of personal information (though we do not sell personal data);
  • Right to limit use of "sensitive personal information" if applicable;
  • Right to non-discrimination for exercising your privacy rights.

If you want to exercise those rights, contact us using the methods below.

12.

How to Contact Us

If you have any questions, requests, or concerns about your personal data or this Privacy Policy, you can contact us at:

Attn:Privacy / Data Protection Officer
13.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time (for example, when we change our data practices or in response to new laws). We will notify users of material changes via email or by posting an updated version on our website with a new "Last Updated" date. We encourage you to check this page periodically.

14.

Miscellaneous

  • This Privacy Policy is not a guarantee that data breaches will never happen; we commit to reasonable security measures, but cannot guarantee absolute security.
  • Use of our services constitutes acceptance of this Privacy Policy.
  • If any part of this policy is found invalid or unenforceable, the remaining provisions will continue in effect.