Skip to the content
Vectorizer← Back to Vectorizer
Legal

Privacy Policy

Effective September 7, 2026Last updated September 7, 2026

This Privacy Policy explains what information Vectorizer (the “Service”) collects, how it is used, and the choices you have. It covers the website, the tracing tool, and any related APIs.

This document is a plain-language template with placeholders in [brackets] for company and vendor details. Fill those in and have a lawyer review it before you rely on it in production.

On this page

  1. Overview
  2. Who we are
  3. Information we collect
  4. How we use information
  5. Legal bases (EEA / UK)
  6. How your images are handled
  7. Service providers and subprocessors
  8. Other sharing and disclosure
  9. Data retention
  10. Security
  11. International data transfers
  12. Your privacy rights
  13. California privacy rights
  14. Cookies and analytics
  15. Do Not Track and Global Privacy Control
  16. Children's privacy
  17. Third-party links
  18. Changes to this policy
  19. Contact and complaints

Overview

The Service is designed to collect only what it needs to convert your image and keep the site running:

  • the image you upload and your tracing settings, used to produce your result;
  • standard server logs recording technical details of requests, for security and reliability;
  • any message you send us if you contact support.

The sections below give the detail.

Who we are

The Service is operated by [COMPANY LEGAL NAME] (“[Company],” “we,” “us”), [street address, city, region, postal code, country]. For the purposes of the EU and UK General Data Protection Regulation, [Company] is the data controller for the limited personal data described here.

Our representative in the EEA / UK, where one is required, is [EU / UK representative name and address, if required]. You can reach us about privacy at privacy@vectorizer.example.

Information we collect

Images and project content you provide

When you trace an image, you provide the image file and your tracing settings (color count, palette edits, export options). The image is transmitted to our systems so it can be converted, and the vector result is returned to you. We do not ask for, and the tool does not need, any information about who you are.

Images may themselves contain personal data — for example a photo of a person, or metadata embedded in the file. We process that content only to perform the trace you asked for.

Technical and log data

Like almost all websites, our servers and our hosting provider automatically record request metadata: IP address, browser type and version (user agent), referring page, requested URL, timestamps, and response status. We use this for security, abuse prevention, debugging, rate limiting, and understanding aggregate load.

Cookies

The Service may use strictly necessary cookies to support security and basic site function, and, where you consent, analytics cookies. See Cookies and analytics.

Communications

If you email us (for support, a rights request, or feedback), we receive your email address, your message, and anything you choose to include, and we keep that correspondence so we can respond and keep a record.

How we use information

We use the limited information described above to:

  • provide the tracing tool and return your vector result;
  • operate, maintain, secure, and improve the Service, including diagnosing errors and preventing abuse, fraud, and denial-of-service;
  • enforce our Terms & Conditions and other policies;
  • respond to your messages and rights requests;
  • comply with legal obligations and respond to lawful requests from authorities.

We do not use your uploaded images to train machine-learning models, to build datasets, or for advertising, and we do not sell personal data.

Legal bases (EEA / UK)

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR:

  • Performance of a contract — processing your image and settings to deliver the trace you requested.
  • Legitimate interests — keeping the Service secure and reliable, preventing abuse, and understanding aggregate usage. These interests are balanced against your rights.
  • Legal obligation — retaining certain records and responding to lawful requests.
  • Consent — where we ask for it, for example any non-essential analytics or cookies. You can withdraw consent at any time.

How your images are handled

We process your image and settings to produce the vector result you asked for, and to return it to you. We may use the images to improve our vectorization service, but only in an aggregated and anonymized manner that does not identify you. However, we handle all data in accordance with our privacy policy and do not share your images or results with third parties without your consent.

Where a service provider is involved in processing (see Service providers and subprocessors), our contract limits their use of the content to providing that service to us.

Service providers and subprocessors

We share data only with vendors that help us run the Service, under contracts that require them to protect it and use it only on our instructions. Current categories:

  • Hosting and content delivery — [hosting / CDN provider]. Processes request metadata and server logs; hosts the application.
  • Cloud infrastructure and processing — [cloud infrastructure / processing provider(s)]. Supports image conversion and delivery of the Service.
  • Analytics — [analytics provider, or “none — we run no analytics”].
  • Email — [transactional email provider, if any]. Used only if we send transactional email or you contact us.

We will update this list when our subprocessors change. Ask us at privacy@vectorizer.example for the current details.

Other sharing and disclosure

We may disclose information outside the vendors above when we believe it is reasonably necessary to:

  • comply with a law, regulation, legal process, or enforceable governmental request;
  • enforce our Terms, including investigating potential violations;
  • detect, prevent, or address fraud, security, or technical issues;
  • protect the rights, property, or safety of [Company], our users, or the public.

If [Company] is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction; we will require the recipient to honor this policy or give you notice and choice where required by law.

Data retention

  • Uploaded images and results — retained only as long as needed to produce and return your result and handle errors, then deleted. Not archived long-term.
  • Server and access logs — retained for a limited period (target: [e.g. 30–90 days]) for security and diagnostics, then deleted or aggregated.
  • Email correspondence — retained as long as needed to handle your request and for a reasonable period afterward as a record.

Security

We use technical and organizational measures appropriate to the limited data we handle, including encryption in transit (HTTPS), access controls, authentication between our systems and our service providers, and minimizing what we store. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

International data transfers

We and our service providers may process information in countries other than yours, including [country / state whose data-protection law applies] and the countries where our service providers operate. Where personal data is transferred out of the EEA or the UK, we rely on an adequacy decision or on Standard Contractual Clauses (with the UK Addendum where applicable), together with supplementary safeguards as needed. Contact us for a copy of the relevant safeguards.

Your privacy rights

Depending on where you live, you may have some or all of these rights regarding personal data we hold about you:

  • access to it and information about how we process it;
  • correction of inaccurate or incomplete data;
  • deletion (“right to be forgotten”);
  • restriction of, or objection to, processing;
  • data portability;
  • withdrawal of consent, where processing is based on consent.

To exercise a right, email privacy@vectorizer.example. We will respond within the time required by applicable law (generally within one month under the GDPR, extendable for complex requests). We may hold little or no data that identifies you; if we cannot verify your identity or locate data about you, we will tell you.

California privacy rights

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use and disclose it, the right to request access and deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising these rights.

In the past 12 months we have collected the categories described in Information we collect (chiefly internet / network activity such as IP address and log data, plus any content you upload or send us). We disclose these categories to the service providers listed above for the business purposes described in this policy. We do not sell or “share” personal information as those terms are defined under the CPRA, and we do not use sensitive personal information for purposes that would trigger a right to limit its use. Submit requests to privacy@vectorizer.example; you may use an authorized agent.

Cookies and analytics

Strictly necessary cookies. If set, they support security and basic site function and cannot be switched off through the Service.

Analytics. [analytics provider, or “none — we run no analytics”]. If we use analytics, we will configure it to minimize data (for example IP truncation) and, where required, ask for your consent first and provide an opt-out. If we run no analytics, there is nothing to opt out of.

You can block or delete cookies and clear site data in your browser’s settings. Doing so may reset your preferences and your consent choices.

Do Not Track and Global Privacy Control

There is no common standard for responding to browser “Do Not Track” signals, so the Service does not respond to them. Where required by law, we treat a Global Privacy Control (GPC) signal as a valid request to opt out of any “sale” or “sharing” of personal information — though, as noted above, we do not sell or share it.

Children’s privacy

The Service is not directed to children under 13 (or the age of digital consent in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact privacy@vectorizer.example and we will delete it.

Third-party links

The Service may link to sites we do not operate. We are not responsible for their content or privacy practices. Review the privacy policy of any site you visit.

Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date above, and for material changes that reduce your rights we will give more prominent notice (for example a banner on the site) before they take effect. Your continued use of the Service after an update means you accept the revised policy.

Contact and complaints

Questions, concerns, or requests about privacy: [COMPANY LEGAL NAME], [street address, city, region, postal code, country], privacy@vectorizer.example.

If you are in the EEA or the UK and believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority. We would appreciate the chance to address your concern first.

Vectorizer
HomeTermsPrivacy
Image tracing that keeps the file in your hands.