Privacy Policy

How TemplateHub collects, uses, shares, and protects personal information across the marketplace.

Effective
To be announced
Updated
5 August 2026
Version
0.2-content-draft

Content draft. This page reflects TemplateHub’s intended practices based on the current product stack. It is not yet final counsel-approved wording and is not binding until an official effective date is published.

1. Introduction

TemplateHub is a multi-vendor digital marketplace for templates, UI kits, design assets, and related digital products. This Privacy Policy explains how we collect, use, share, retain, and protect personal information when you visit TemplateHub, create an account, buy or sell products, subscribe to marketing emails, or otherwise interact with our services.

This policy applies to visitors, buyers, sellers, and newsletter subscribers. It is written for the current TemplateHub product stack (accounts, marketplace checkout, downloads, seller applications, and related platform operations).

Operator identity note: the legal entity name, registered address, and designated privacy contact for TemplateHub are not yet confirmed in product configuration. Those details will be stated here before this policy is treated as final or binding. Until then, this page is a content draft for professional review — not legal advice and not a final counsel-approved policy.

2. Effective Date and Updates

The Effective and Updated dates at the top of this page show the draft status of this policy. An official effective date will be published when TemplateHub adopts a final version after business confirmation and legal review.

We may revise this policy as the product, processors, or legal requirements change. Material changes will be reflected by updating the dates and version on this page. Continued use of TemplateHub after a published effective date constitutes notice of the updated policy, subject to any additional notice requirements that apply in your jurisdiction.

3. Information We Collect

We collect information you provide directly, information generated by your use of the platform, and information processed by service providers acting on our behalf. Categories below reflect data TemplateHub actually handles in the current product.

3.1 Account data

When you create or use an account, we process identifiers and profile fields such as name, email address, email verification status, profile image, optional bio and country, role (buyer, seller, or admin), two-factor authentication settings, and account activity timestamps.

Authentication may use email and password and/or OAuth providers configured for TemplateHub (for example Google, GitHub, Discord, or Microsoft). OAuth account linkage tokens and related auth records are stored so you can sign in securely. Passwords, when used, are stored in hashed form via our authentication provider integration — not as plain text.

Platform settings may restrict sign-up to allowed email domains (for example consumer mail domains configured by administrators). Domain eligibility rules are product configuration, not a separate data category.

3.2 Seller application and profile data

If you apply to sell on TemplateHub, we collect application and profile information such as full name, phone or WhatsApp contact, location, occupation or seller type, portfolio and work URLs, GitHub or other presence links, descriptions of what you intend to sell, and whether you already sell online (including site names/URLs you provide).

Approved sellers may also have marketplace profile fields, commission rate configuration, tier, application status history, and a connected payout account identifier with our payment partner (currently Stripe Connect). Identity verification documents required by the payment partner are collected and processed by that partner under its own terms, not stored as full identity document files in TemplateHub product databases.

3.3 Transaction and payment metadata

When you purchase a product, we create order records that include buyer and seller associations, product reference, amounts, platform commission, seller payout amounts, order status, download counts and limits, timestamps, and payment-provider references such as checkout session or payment intent identifiers.

Card numbers and full payment credentials are processed by the active payment processor (currently Stripe). TemplateHub does not store full primary account numbers (PAN) as product state. Refund and dispute-related order status updates may also be recorded when processed through platform admin tools and payment webhooks.

3.4 Product uploads, previews, and support content

Sellers upload product files, thumbnails, screenshots, descriptions, and related listing content. Product images are handled through our image upload provider; template ZIP packages are stored in object storage used for secure delivery after purchase.

Signed-in users may submit reviews, product questions, favourites/collections, and similar user-generated content associated with their account. Visitors without an account may view public marketplace content but cannot submit those forms of user-generated content. Support and operational communications may include the content of emails or messages you send to us about orders, accounts, or listings.

3.5 Device, IP, logs, and security signals

We process technical data needed to operate and secure the service, including IP address, user agent, session tokens, approximate activity times, download logs (who downloaded which order, when, and from which IP when recorded), rate-limiting counters, and abuse-prevention signals.

TemplateHub maintains blocked-IP records (address, reason, timestamps, optional expiry) for fraud, abuse, and security enforcement. Admin audit logs may record sensitive administrative actions for accountability.

3.6 Newsletter and marketing data

If you subscribe to the newsletter, we store your email address, active/inactive subscription status, and subscribe/unsubscribe timestamps. Welcome or marketing messages may be sent through our email delivery provider when a subscription is active.

3.7 Cookies and similar technologies

TemplateHub uses cookies and similar technologies for authentication sessions, security controls (including two-factor verification state), and essential site operation. We also use deployment-platform web analytics and performance measurement (currently Vercel Analytics and Vercel Speed Insights) on the site. A deeper category-by-category description lives in the Cookie Policy.

For details, cookie categories, storage inventory, and browser controls, see the Cookie Policy at /cookie-policy. This Privacy Policy summarizes cookies only at a high level.

4. How We Use Information

We use personal information to:

Provide and operate the marketplace — accounts, browsing, search, cart and checkout, order fulfillment, digital downloads, and seller tooling.

Process payments and payouts through our payment partners, including commissions, transfers, refunds, and related reconciliation.

Communicate with you about transactions, security events, seller application status, product updates you request, and (where permitted) marketing.

Prevent fraud, enforce rate limits, block abusive IPs, protect account security (including 2FA flows), and investigate misuse.

Moderate listings and user content, handle intellectual-property complaints, and operate admin review workflows.

Improve reliability and performance — for example caching, search indexing of product catalog data, background jobs, and error monitoring.

Comply with legal obligations and enforce our Terms, Refund Policy, License Terms, Seller Terms, and related policies once those documents are finalized and in force.

6. How We Share Information

We do not sell personal information. We share information only as needed to run the marketplace and meet legal duties:

Sellers — buyer name, buyer email, and order/product information needed to fulfill a purchase, handle legitimate support about a sold item, or manage refunds/chargebacks tied to that order.

Service providers (processors) — hosting, database, authentication, payments, file storage, email delivery, search, caching, background jobs, and error monitoring providers listed in the next section.

OAuth identity providers — when you choose to sign in with a third-party account, that provider shares profile/email data according to your authorization with them.

Legal and safety — when we believe disclosure is required by law, valid legal process, or necessary to protect TemplateHub, our users, or the public from fraud, security threats, or illegal activity.

Business transfers — if TemplateHub is involved in a merger, acquisition, financing, or sale of assets, personal information may transfer as part of that transaction under appropriate continuity protections.

7. Payment Processors and Subprocessors Overview

TemplateHub currently relies on specialized providers to process data on our behalf. The active stack includes, at a high level:

Payments: Stripe (Checkout, webhooks, Connect payouts for sellers). Card data is handled by Stripe; TemplateHub stores payment metadata and identifiers needed for orders and refunds.

Authentication: Better Auth-compatible account/session storage in our database, with optional OAuth through configured providers (Google, GitHub, Discord, Microsoft).

Database and app hosting: Supabase Postgres for primary application data; application hosting and image optimization on the deployment platform used for TemplateHub (currently Vercel-oriented Next.js delivery).

Web analytics and performance: Vercel Analytics and Vercel Speed Insights, loaded on the public site via the application layout.

Files: UploadThing for product image uploads; Cloudflare R2 (or compatible object storage) for template ZIP delivery objects.

Infrastructure: Upstash Redis for caching and rate limiting; Meilisearch for product search indexing; Inngest for background/event jobs; Brevo (or configured SMTP) for transactional and newsletter email; Sentry for error monitoring when enabled.

Payment-provider migration note: TemplateHub may adopt additional or replacement payment providers in the future (for example a Whop-based checkout and ledger model discussed in product planning). If that happens, this section will be updated to name the live processors without restructuring the rest of this policy.

Each provider processes data under its own terms and security controls. We configure providers for marketplace operation; we do not control every subprocess of every vendor’s global infrastructure.

8. International Transfers

TemplateHub serves a global audience. Personal information may be processed in countries other than where you live, including countries where our hosting, payment, email, or infrastructure providers operate.

Where required by law, we will use appropriate transfer mechanisms (such as standard contractual clauses or provider-supplied safeguards) for restricted international transfers. The specific mechanism set will be confirmed with counsel for the jurisdictions where TemplateHub formally offers services.

9. Retention

We retain personal information only as long as needed for the purposes described in this policy, including:

Account data — for the life of the account and a reasonable period afterward for security, dispute, and fraud prevention.

Inactive buyer accounts — buyer accounts with no purchase history may receive a warning after prolonged inactivity and may then be deleted automatically (currently about 83 days inactive for warning and about 90 days inactive for deletion). Sellers, admins, and buyers with at least one purchase are not auto-deleted under this rule.

Orders, download logs, and payment metadata — for as long as needed for delivery, re-download rules, refunds, accounting, chargebacks, and legal recordkeeping.

Seller application and profile data — while an application or seller relationship is active, and afterward as needed for audit, payout reconciliation, and abuse prevention.

Newsletter data — until you unsubscribe or your subscription is deactivated; residual suppression records may be kept to honor opt-outs.

Security data (rate limits, blocked IPs, audit logs) — for as long as useful for protection and investigation, subject to expiry fields where implemented (for example temporary IP blocks).

Exact retention schedules (in days/months/years per category) will be finalized with business and counsel. When you request deletion, we will delete or anonymize personal data unless we must retain it for legal, security, or legitimate business obligations (for example completed payment records).

10. Security Measures

We implement technical and organizational measures appropriate to a digital marketplace, including encrypted transport (HTTPS), authenticated sessions, password hashing via the auth stack, optional two-factor authentication flows, administrative access controls, rate limiting, IP blocking for abuse, and least-privilege patterns in server procedures.

Payment card data is handled by PCI-oriented payment providers rather than stored as full card numbers in TemplateHub databases.

No method of transmission or storage is completely secure. We work to protect personal information but cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for using available security features such as 2FA where offered.

11. Your Rights and Requests

Depending on where you live, you may have rights to access, correct, delete, or export personal information; to object to or restrict certain processing; to withdraw consent where processing is consent-based; and to lodge a complaint with a supervisory authority.

To exercise privacy rights, contact us using the privacy contact method in Section 14 once it is published. We may need to verify your identity before fulfilling a request. Some requests may be limited where we must retain data for orders, security, fraud prevention, or legal compliance.

Account self-service: where the product allows, you can update certain profile fields directly in your account settings. Newsletter unsubscribe will be honored for marketing emails associated with that subscription record.

12. Children’s Privacy

TemplateHub is directed to adults and businesses capable of entering marketplace transactions. It is not intended for children under 13 (or under 16 where a higher digital-consent age applies).

We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take reasonable steps to delete it. Final age thresholds and parental-consent rules will be aligned with the Terms of Service and counsel guidance before final publication.

14. Contact for Privacy Requests

Privacy requests (access, deletion, correction, and related inquiries) should be sent to TemplateHub’s designated privacy contact.

Business input still required before final publication: a dedicated privacy email address, legal entity name, and mailing address (if applicable) are not yet confirmed as canonical product configuration in this repository. Until those details are published here, treat this contact section as incomplete for formal legal notices.

Operational path while details are finalized: use the Contact surface on TemplateHub when it becomes available, or the support/email channel TemplateHub publishes in site chrome or transactional email footers. Do not send payment card data over email.

15. Changes to This Policy

We may update this Privacy Policy to reflect product changes, new processors, or legal requirements. The version and Updated date at the top of the page will change when revisions are posted.

For draft versions, changes may be frequent as TemplateHub completes the legal documentation roadmap (Terms, Refund, License, Seller Terms, Cookie Policy, and DMCA). When a final version is adopted, we will set a clear Effective date and keep prior material changes discoverable through version notes or archives if required.

Related policies: Terms of Service (/terms), Cookie Policy (/cookie-policy), Refund Policy (/refund-policy), License Terms (/license), Seller Terms (/seller-terms), and DMCA / Copyright (/dmca).