Scope and roles
This Policy applies when FocalShift determines why and how personal information is processed, including account, website, billing, support, and product-usage information. When a customer uses FocalShift to process information about its own customers, leads, members, employees, or contacts, that customer generally acts as controller or business and FocalShift acts as processor or service provider under the Data Processing Addendum.
Information we collect
We may collect account identifiers and contact details; profile and workspace information; billing and transaction records; content, files, prompts, instructions, and communications; connected-account identifiers and tokens; device, browser, IP address, log, diagnostic, and usage information; support requests; preferences; approximate location inferred from IP; and information supplied by customers, integrations, or other users.
We do not intentionally collect payment-card numbers directly when a payment processor handles them. We may receive payment status, billing address, card type, and limited card details.
How we use information
We use information to provide and personalize the Services; authenticate users; operate workspaces and integrations; process transactions; publish or transmit content at your direction; provide support; prevent fraud and abuse; secure and troubleshoot systems; analyze performance; improve features; communicate service and account information; market our Services where permitted; enforce agreements; and comply with law.
Legal bases
Where applicable law requires a legal basis, we process information to perform a contract, comply with legal obligations, protect vital interests, pursue legitimate interests that are not overridden by individual rights, and act on consent. Legitimate interests include operating and securing the platform, supporting customers, improving products, preventing misuse, and communicating about relevant services.
How information is disclosed
We may disclose information to infrastructure, hosting, security, analytics, communications, payment, customer-support, and AI service providers acting under contract; to connected services at your direction; to workspace owners and authorized members according to permissions; in a business transaction; to professional advisers; to protect rights and safety; and when required by law or valid legal process.
We do not sell personal information for money. If an activity is treated as “selling,” “sharing,” or targeted advertising under applicable law, we will provide required notices and choices.
AI features
Prompts, files, context, and outputs may be processed to provide requested AI features. Access is limited according to workspace permissions and service requirements. We describe user responsibilities and output limitations in the AI Use and Generated Content Policy. Customer Content is not used to train third-party general-purpose models unless the applicable feature or setting clearly states otherwise and the customer authorizes that use.
Retention
We retain personal information for as long as needed to provide the Services, maintain the account, satisfy legal and accounting duties, resolve disputes, enforce agreements, prevent fraud, and maintain security. Retention depends on the information’s nature, sensitivity, purpose, risk, contractual commitments, backup cycles, and legal requirements. We delete or de-identify information when it is no longer reasonably needed.
Security and international transfers
We use safeguards designed to protect information against unauthorized access, loss, alteration, and disclosure. No system is completely secure. Information may be processed in countries other than where it was collected. Where required, we use recognized transfer mechanisms and contractual safeguards.
Your choices and rights
Depending on location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information; withdraw consent; opt out of certain sharing, targeted advertising, or profiling; and appeal a denied request. You may also update account settings, unsubscribe from marketing communications, and control cookies.
We may verify a request and may retain information where an exception applies. Authorized agents must provide proof of authority.
California disclosures
California residents should also read the California Privacy Notice, which describes categories of information, purposes, retention criteria, disclosures, and available rights.
Children
The Services are intended for adults and are not directed to children under 13. Accounts are limited to people 18 or older. Additional information appears in the Age Eligibility and Children’s Privacy Notice.
Changes and contact
We may update this Policy to reflect legal, technical, or product changes. The effective date identifies the current version. Privacy questions and requests may be submitted through FocalShift Contact.
Network and public content
Public profiles, posts, badges, certifications, listings, comments, project summaries, and campaigns may be indexed, copied, cached, captured, or redistributed by others. Deleting content from FocalShift does not remove copies held by search engines, recipients, or third parties. Members can use available audience controls and report, block, and mute tools, but those controls cannot retrieve copies another person already made.
Payments, wallet, identity, and compliance data
When you use subscriptions, commerce, wallet, affiliate, or payout features, we may process plan and invoice records; payment status; limited billing details; credits; ledger entries; pending, available, reserved, withdrawn, fee, and commission amounts; payout eligibility; connected-account identifiers; tax information; identity-verification status; and risk or sanctions-screening results. Full card and bank-account numbers are handled by the payment provider rather than stored by FocalShift.
Account deletion and lawful retention
You may request account deletion through available account-security controls or by contacting privacy@focalshift.ai. A self-service request includes identity confirmation and a 30-day cool-off period during which it may be withdrawn. On completion, we delete or de-identify account information and private content except records retained for tax, accounting, payment, fraud, security, abuse prevention, legal holds, claims, and backup cycles.
Deletion does not remove content another member owns or copies already held outside FocalShift. Public and shared records may remain where retention is necessary to preserve another member’s rights, transaction history, safety records, or legal obligations.
Data export and portability
Available account-security controls provide a machine-readable export of the core account record, excluding credentials and password hashes. Certain tools provide CSV exports for their records. For a broader copy across tools, submit a request to privacy@focalshift.ai. We may verify identity before responding and will provide portability required by applicable law.
Global Privacy Control
Where applicable law treats an activity as selling or sharing personal information, we recognize browser-based Global Privacy Control signals as an opt-out request for that browser or device. Other cookie and marketing choices remain available through applicable settings and unsubscribe controls.