Legal
Privacy Policy
Last updated · June 2026
In short
We collect the minimum personal data needed to run the studio, keep it secure, never sell it, and let you delete it whenever you want.
1. Who we are
Maison Founder ("we", "us", "our") provides a founder studio at maisonfounder.com. We are the data controller for the personal data described in this policy. You can contact us at hello@maisonfounder.com.
2. What we collect
- Account information - your name, email address, and password hash when you sign up.
- Studio content - the brand details, business plans, numbers, pitches and notes you create inside the studio.
- Billing information - handled by Stripe, our payment processor. We never see or store your full card details.
- Usage data - basic technical information (device, browser, pages visited) used to keep the service working and improve it.
3. How we use it
- To provide the studio, save your work and let you sign in.
- To process payments and manage your membership.
- To send essential service emails (receipts, password resets).
- To improve Maison Founder - diagnose bugs, measure performance, understand which rooms are useful.
- To comply with our legal obligations.
4. Legal bases (UK & EU)
We process your data on the basis of contract (to give you the service you signed up for), legitimate interests (to keep the service secure and improve it), consent (for optional cookies and marketing emails) and legal obligation (e.g. tax records).
5. Sharing your data
We share data only with trusted processors who help us run the service: Supabase (database & authentication), Stripe (payments), and email delivery providers. We never sell your data. We may disclose data if required by law.
6. AI features
Some rooms use large language models to help you draft and refine work. Prompts you submit may be sent to model providers (e.g. Google, OpenAI) to generate a response. We do not use your studio content to train third-party models.
7. How long we keep it
We keep your account and studio content for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we must retain it for legal reasons (e.g. invoicing records).
8. Your rights
You can access, correct, export or delete your data at any time. You also have the right to object to processing and to lodge a complaint with your local data protection authority (the ICO in the UK). To exercise any of these rights, email hello@maisonfounder.com.
9. Security
Data is encrypted in transit (HTTPS) and at rest. Access to production systems is restricted and audited. No system is perfectly secure, but we take reasonable steps to protect your information.
10. International transfers
Some of our processors are based outside the UK / EEA. Where this happens we rely on appropriate safeguards (e.g. Standard Contractual Clauses) to protect your data.
11. Changes to this policy
If we make material changes we'll let you know by email or via a notice in the studio. The latest version will always be available on this page.
See also · Cookie Policy · Terms & Conditions