Privacy Policy
Last updated: October 02, 2026
We process payments through Waffo Pancake (PCI-DSS compliant Merchant of Record). We do not store your payment card details on our servers.
1. Data Controller
The data controller for this service is:
Company: figma2code
Registered Address: Available upon request
Privacy Contact: privacy@figma2code.tech
Data Protection Officer: Available upon request
2. Information We Collect
2.1 Information You Provide
- Account information – Email address, display name, password (hashed)
- Payment information – Transaction amount, payment status. Full card data is handled exclusively by Waffo Pancake; we never see or store your card number.
- Uploaded sketches – Images you upload for AI processing (processed securely, deleted after generation unless saved)
- API usage data – Metrics for quota management
- Support correspondence – Emails and tickets you send to our support team
2.2 Information We Collect Automatically
- Device & network – IP address, device type, operating system, browser, timezone
- Usage behavior – Pages visited, features used, session duration
- Server logs – Request timestamps, error logs, performance data
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Service provision & maintenance | Contract performance |
| Billing & payment processing | Contract performance |
| Customer support | Contract performance / Legitimate interest |
| Service notifications (billing, security, policy updates) | Legitimate interest |
| Security & fraud prevention | Legitimate interest |
| Product improvement & analytics | Legitimate interest |
| Legal compliance | Legal obligation |
| Marketing communications (with consent) | User consent |
We may anonymize or aggregate data for statistical analysis. Such data cannot identify individuals.
4. AI Model Disclosure
Our service is built on third-party AI models from established, mainstream providers. We use:
- Alibaba Cloud (Qwen) – AI vision recognition and text-to-design processing
- DeepSeek – AI code generation and design interpretation
The performance and availability of our service depend on these third-party providers. We do not guarantee specific output quality from AI models. Generated content may contain inaccuracies and should be reviewed before professional or commercial use.
5. Cookies & Tracking
| Type | Purpose | Can be disabled |
|---|---|---|
| Strictly necessary | Authentication, session management, security (CSRF protection) | No |
| Functional | Language preferences, UI personalization | Yes |
| Analytics | Anonymous usage statistics, product improvement | Yes |
| Marketing (if applicable) | Targeted advertising (we currently do not use marketing cookies) | N/A |
6. Data Sharing & Disclosure
We do not sell your personal information, as "selling" is defined under applicable data protection laws including CCPA.
We share data only in the following circumstances:
- Waffo Pancake – Payment processing and Merchant of Record. Card data never touches our servers. Privacy Policy
- AI model providers (Qwen, DeepSeek) – Sketch and text inputs are processed by these providers to deliver AI generation services
- Service providers – Email delivery, cloud infrastructure, analytics – under strict data processing agreements
- Legal authorities – When required by law, court order, or valid government request
- Business transfers – In the event of a merger, acquisition, or sale of assets, with prior notice
- With your consent – For any other purpose not listed above
7. Data Security
- Transport encryption – TLS/HTTPS on all connections
- Storage encryption – Sensitive data (passwords) is hashed, not stored in plaintext
- Access control – Least-privilege principle; employees sign confidentiality agreements
- Regular audits – Periodic security reviews and vulnerability scanning
In the event of a security breach affecting your rights, we will notify you and relevant authorities within 72 hours of discovery, as required by applicable law.
8. Data Retention
| Data Type | Retention Period | After Expiry |
|---|---|---|
| Account data | While active; deleted 90 days after account deletion | Secure deletion or anonymization |
| Transaction records | As required by law (typically 5–7 years) | Archived or deleted |
| Support correspondence | 3 years | Secure deletion |
| Security audit logs | 12 months | Secure deletion |
| Uploaded sketches | Deleted immediately after AI processing, unless you save to account | Permanent deletion |
9. Your Data Rights
To exercise any of the following rights, contact us at privacy@figma2code.tech. We respond within 30 calendar days.
| Right | Description |
|---|---|
| Right to be informed | Know what data we collect and how we use it |
| Right of access | Receive a copy of your personal data |
| Right to rectification | Correct inaccurate or incomplete data |
| Right to erasure | Request deletion of your data under certain conditions |
| Right to restrict processing | Pause processing in specific circumstances |
| Right to data portability | Receive your data in a machine-readable format |
| Right to object | Object to processing based on legitimate interests or marketing |
| Right to withdraw consent | Withdraw consent for consent-based processing at any time |
If you believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority.
10. Marketing & Communications
With your explicit consent, we may send you marketing emails about our products and services. You can unsubscribe at any time:
- Click the "Unsubscribe" link in any marketing email
- Disable marketing notifications in your account settings
- Contact us at support@figma2code.tech
Service-related notifications (billing, security alerts, policy changes) are not subject to marketing opt-out, as they are necessary for service delivery.
11. International Data Transfers
Our servers and AI processing partners may be located outside your country of residence. When data is transferred internationally, we ensure adequate protection through:
- Data Processing Agreements incorporating Standard Contractual Clauses (SCCs) where applicable
- Transfers only to jurisdictions with equivalent data protection standards
- Other mechanisms as required by applicable law (e.g., adequacy decisions, BCRs)
12. Children's Privacy
OpenSaaS is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal data, please contact us immediately at privacy@figma2code.tech and we will promptly delete such data.
13. Third-Party Links
Our service may contain links to third-party websites or services. This Policy applies only to data we directly collect. We are not responsible for the privacy practices of third parties. Please review the privacy policies of any third-party services you use.
14. Policy Changes
We may update this Policy periodically. Material changes will be communicated at least 15 days before taking effect via email or platform notice. The "Last updated" date at the top of this page reflects when changes were last made. Continued use of our service after changes constitutes acceptance of the updated Policy.
15. Contact
For privacy-related inquiries, data rights requests, or breach notifications, contact us:
Privacy: privacy@figma2code.tech
Support: support@figma2code.tech
Company: figma2code
Response time: Monday–Friday, 09:00–18:00 UTC+8