Underlogounderlogo

Privacy Policy

Effective date: August 28, 2026

This Privacy Policy ("Policy") describes how Underlogo ("we," "us," or "our") collects, uses, stores, shares, and protects information when you use underlogo.com and its associated services (collectively, the "Service"). By creating an account or using the Service, you acknowledge that you have read and understood this Policy. This Policy is incorporated into and subject to our Terms of Service.

1. Information We Collect

1.1 Information you provide directly

When you register and use the Service, we collect:

  • Account information: Your email address and, optionally, your name.
  • Company information: Company name, website URL, industry, country, and optionally: description, founding year, and employee count range.
  • Logo: The company logo image you upload for display on the Billboard.

1.2 Information collected automatically

When you interact with the Service, we automatically collect:

  • IP addresses: Recorded at the time of authentication events and booking transactions.
  • Session data: A unique session identifier and its expiration timestamp, stored in a secure, HTTP-only cookie. We do not use analytics or tracking cookies.
  • Magic link metadata: The email address a magic link was sent to, the time of creation, expiration, and whether the link has been used.

1.3 Information generated by the Service

Through your use of the Service, the following records are created:

  • Booking records: Billboard slot bookings including tier, date, Credit amount, status, and timestamps.
  • Bid history: Spotlight auction bids including amounts, actions (placed, raised, outbid, won, lost), and timestamps.
  • Credit transactions: A ledger of all Credit purchases, spending, and refunds with running balances.
  • Payment records: Stripe payment identifiers and amounts (we do not store card details).

1.4 Information we do NOT collect

We do not collect: passwords (we use passwordless authentication), payment card details (handled by Stripe), biometric data, precise geolocation, browsing history outside the Service, social media identifiers, or any data from third-party data brokers.

2. How We Use Your Information

We use the information we collect for the following purposes and no others:

Purpose Data used Legal basis
Authenticate your identity Email, magic link token, session ID Contract performance
Display your company on the Billboard Company name, logo, industry, website Contract performance
Process Billboard bookings and bids Company ID, tier, date, Credit amount Contract performance
Process Credit purchases Stripe payment ID, amount Contract performance
Send service-critical emails Email address Contract performance
Enforce Terms of Service Account data, IP addresses Legitimate interest

We do not use your information for advertising, profiling, automated decision-making, or any purpose unrelated to the operation of the Service.

3. Emails We Send

We send emails exclusively for service-critical purposes. We do not send marketing emails, newsletters, or promotional content. The emails we send include:

  • Magic link authentication emails — when you request to sign in.
  • Outbid notifications — when your Spotlight bid has been surpassed by another bidder and your Credits have been refunded.
  • Booking confirmations — when a Billboard slot booking is confirmed.

All emails are sent from our domain via Amazon Simple Email Service (SES). We do not embed tracking pixels in emails.

4. Data Visibility

4.1 Publicly visible on the Billboard

When you book a Billboard slot, the following information is displayed publicly:

  • Company name
  • Company logo
  • Industry
  • Website URL
  • Company description (Spotlight tier only)

4.2 Not visible to other Users

Your email address, name, account creation date, Credit balance, booking history, bid amounts, session data, and magic link history are never exposed to other Users.

5. Data Sharing & Third Parties

5.1 We do not sell your data. We have never sold personal data and will not do so.

5.2 Service providers. We use the following third-party service providers:

  • Amazon Web Services (AWS): Infrastructure hosting and Amazon SES for transactional email delivery.
  • Stripe: Payment processing for Credit purchases. Stripe receives your payment card details directly — we never see or store them.
  • Azure: Blob storage for uploaded logo files and managed database hosting.

5.3 Legal requirements. We may disclose your information if required by law, subpoena, or court order, or to protect our rights, prevent fraud, or protect public safety.

5.4 Business transfers. If Underlogo is involved in a merger, acquisition, or asset sale, your information may be transferred. We will provide notice before your data becomes subject to a different privacy policy.

6. Data Retention

Data type Retention period Reason
Account & company data Duration of active account + 30 days after deletion request Service operation
Uploaded logos Duration of active account; deleted upon account deactivation Billboard display
Booking & bid records 3 years after the booking date Financial records; dispute resolution
Credit transactions 3 years after the transaction date Financial records; audit trail
Payment records (Stripe IDs) As required by tax and financial regulations Legal obligation
Magic link tokens Deleted after use or expiration Authentication security
Session records Deleted upon logout or expiration Authentication security

7. Data Security

We implement the following security measures:

  • No passwords: Passwordless magic link authentication eliminates password breach risks.
  • Secure sessions: Cryptographically random identifiers in secure, HTTP-only cookies.
  • Magic link expiration: Single-use and time-limited links.
  • Database security: Encrypted connections with restricted service account access.
  • Input validation: All inputs validated and sanitized to prevent injection attacks.
  • No client-side sensitive storage: We do not store personal data in browser localStorage or sessionStorage.

No system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you and any applicable regulatory authority as required by law.

8. Cookies

We use a single, strictly necessary cookie:

Cookie name Purpose Duration Type
session_id Maintains your authenticated session Until logout or server-side expiration Strictly necessary

We do not set analytics, advertising, or tracking cookies.

9. Your Rights

Depending on your jurisdiction, you may have the following rights:

9.1 Right of access. You may request a copy of the personal data we hold about you.

9.2 Right to rectification. You may request correction of inaccurate data. You can update your company information directly through the Service.

9.3 Right to erasure. You may request deletion of your personal data. We will delete or anonymize your data within 30 days, except for financial records we are legally required to retain.

9.4 Right to restriction of processing. You may request restriction of processing while a dispute is resolved.

9.5 Right to data portability. You may request your data in a portable format.

9.6 Right to object. You may object to processing based on legitimate interest.

9.7 Right to withdraw consent. Where processing is based on consent, you may withdraw at any time.

9.8 How to exercise your rights. Contact us at [email protected]. We will verify your identity and respond within 30 days.

10. International Data Transfers

The Service is operated from servers in Europe and the United States. If you access the Service from another jurisdiction, your data may be transferred to and processed in these regions.

For Users in the EEA, UK, or Switzerland: we rely on the legal bases described in Section 2 and, where applicable, Standard Contractual Clauses for international data transfers.

11. Children's Privacy

The Service is intended for individuals who are at least 18 years of age. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with personal data, contact us at [email protected].

12. Jurisdiction-Specific Provisions

12.1 European Economic Area, United Kingdom & Switzerland (GDPR / UK GDPR)

If you are located in the EEA, UK, or Switzerland:

  • Our legal bases for processing are described in Section 2.
  • You have the rights described in Section 9, including the right to lodge a complaint with your local data protection authority.
  • Contact: [email protected].

12.2 California (CCPA / CPRA)

If you are a California resident:

  • Categories collected: Identifiers (email, name, IP address), commercial information (company details, booking history).
  • Sale or sharing: We do not sell or share your personal information.
  • Right to know, delete, and non-discrimination: As described in Section 9.

12.3 Other jurisdictions

We will comply with applicable local data protection requirements. Contact us with questions.

13. Changes to This Policy

We may update this Policy from time to time. For material changes, we will notify registered Users by email at least 15 days before the changes take effect. Continued use after the effective date constitutes acceptance.

14. Contact

If you have questions about this Privacy Policy or our data practices:

  • Email: [email protected]

We will respond within 10 business days, or within the timeframe required by applicable law.