Privacy Policy

Spec In A Sec, LLC

Effective Date: February 17, 2025

Website: https://specinasec.com

1. Introduction

Spec In A Sec, LLC ("we," "us," or "our") operates a fabric pattern design platform and SaaS application accessible through specinasec.com and a network of associated websites, branded domains, subdomains, and services (collectively, the "Ecosystem"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website and services.

This Privacy Policy applies to all users, vendors, and licensees who access any property within the Ecosystem, regardless of whether access is through the primary specinasec.com website, a vendor-branded domain, a licensee-branded domain, a custom domain, a subdomain, or any other entry point. This includes current services as well as future services the Company develops or operates, including but not limited to a 3D model specification tool.

By using our services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

User Accounts:

  • Name
  • Email address
  • Phone number
  • Shipping address
  • Company name

Vendor Accounts:

  • Company name and contact information
  • Business details for directory listings
  • Patterns, fabrics, images, and product descriptions
  • Pricing and availability information
  • Social media links and marketing materials
  • Domain and branding configuration data

Licensee (Organization) Accounts:

  • Organization name and contact information
  • Business details and branding assets
  • Logos, color schemes, and other customization preferences
  • Domain and branding configuration data

Platform Activity Data:

  • Project specifications and design selections
  • Sample requests and fulfillment records
  • Specsheet content and generation history
  • Pattern and fabric selections and preferences
  • Communications between users and vendors facilitated through the Platform
  • E-commerce transactions and order information

2.2 Information Collected Automatically

When you access our website or any property within the Ecosystem, we automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Login attempt data
  • Pages visited and features used
  • Referral source and entry point (including which Branded Domain or White-Label instance you accessed)

This information is used to prevent spam, detect unauthorized access attempts, understand which platforms our users engage with, optimize their experience, and improve our services across the Ecosystem.

3. How We Use Your Information

3.1 Service Operations

We use the information we collect to:

  • Facilitate communication between users and vendors
  • Process and fulfill project requests and orders
  • Create and maintain vendor directory listings
  • Send transactional emails related to your account and orders
  • Send marketing and promotional communications (with your consent)
  • Monitor and prevent fraudulent or unauthorized activity
  • Analyze platform usage to improve our services
  • Ensure compatibility across devices and browsers
  • Comply with legal obligations

3.2 Ecosystem-Wide Data Usage

As described in our Terms and Conditions, the Spec In A Sec Ecosystem operates as an interconnected network of services. We use your information across the entire Ecosystem to:

  • Provide and maintain your account across all properties within the Ecosystem
  • Display and share content, including patterns, fabrics, specifications, and project data, across Ecosystem properties as needed to operate the Platform
  • Make vendor and licensee information available on current and future services, including but not limited to the 3D model specification tool
  • Enable cross-platform features and functionality
  • Improve existing services and develop new tools and features
  • Generate aggregated, anonymized, or de-identified analytics for business intelligence, product improvement, and marketing
  • Train, improve, and develop features and tools within the Ecosystem

3.3 User Accounts Across Entry Points

Regardless of which website, domain, or entry point you use to register or access the Platform, your account is a Spec In A Sec, LLC account. You are a subscriber of Spec In A Sec, LLC. This means your account data, activity, and preferences may be used across all properties within the Ecosystem to provide, personalize, and improve the Service.

3.4 Vendor and Licensee Content

Patterns, fabrics, product information, and other content provided by Vendors and Licensees is used across the Ecosystem in accordance with the Vendor Services Agreement and Licensee Services Agreement, respectively. This includes making such content available on specinasec.com, any subdomain, the 3D model specification tool, and any future services the Company operates. Vendor access control settings (manual approval vs. automatic approval) are honored as described in the applicable service agreement.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

We may share your information in the following circumstances:

Within the Ecosystem:

Your information may be shared across all properties within the Spec In A Sec Ecosystem as necessary to operate the Platform and provide services. This includes sharing user account information, project data, vendor content, and licensee content across specinasec.com, branded domains, subdomains, and future services such as the 3D model specification tool. Vendors and Licensees participating in the Ecosystem are automatically made available on future Ecosystem properties.

With Vendors:

User-provided information is shared with vendors to fulfill project requests, sample orders, and other interactions initiated by the user or facilitated by the Platform.

With Licensees:

Information relevant to the operation of a Licensee's Organization may be shared with the Licensee in accordance with the Licensee Services Agreement.

Service Providers:

We may engage third-party service providers to assist with email delivery (such as Brevo), payment processing, domain registration, hosting, analytics, or other operational functions. These providers are contractually obligated to protect your information and use it only for the services they provide to us.

Legal Requirements:

We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers:

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

5. Cookies and Tracking Technologies

We use only essential cookies necessary for the operation of our website and the Ecosystem. These cookies:

  • Maintain your session while logged in
  • Store temporary data while creating projects
  • Enable core website functionality
  • Maintain session continuity across Branded Domains within the Ecosystem

We do not currently use analytics or advertising cookies. If this changes in the future, we will update this policy and provide appropriate notice and consent mechanisms.

6. Data Retention

6.1 Active Accounts

We retain your personal information for as long as your account is active or as needed to provide you services and to fulfill the purposes described in this Privacy Policy.

6.2 Account Termination and Data Retention

When you terminate your account:

(a) Your login credentials will be deactivated and your direct access to the Platform will be revoked;

(b) Personally identifiable information associated with your account profile (such as your name, email address, phone number, and shipping address) will be handled in accordance with applicable data protection laws. You may request deletion of this information as described in Section 7;

(c) Content and data that has been incorporated into the Ecosystem during the term of your account may be retained and continued to be used by the Company in accordance with the Platform Data License granted in the Terms and Conditions. This includes but is not limited to project specifications, sample requests, design selections, specsheets, vendor interactions, and any other content that has been integrated into projects, samples, or derivative works created by you, other Users, Vendors, or the Platform;

(d) Aggregated, anonymized, or de-identified data derived from your use of the Platform may be retained indefinitely for analytics, product improvement, and business development purposes;

(e) Records necessary for legal compliance, dispute resolution, and enforcement of our agreements may be retained for the period required by applicable law or our internal policies.

6.3 Vendor and Licensee Data Retention

Upon termination of a Vendor Services Agreement or Licensee Services Agreement, the Company may retain and continue to use Vendor Content or Licensee Content that has been incorporated into the Ecosystem in accordance with the applicable agreement. Patterns, fabrics, specifications, and other content that has been used in projects, samples, or other derivative works may continue to be available across the Ecosystem.

7. Your Rights and Choices

7.1 All Users

You have the right to:

  • Access and update your account information at any time
  • Request deletion of personally identifiable information associated with your account, subject to the data retention provisions described in Section 6
  • Opt out of marketing communications
  • Request information about the data we hold about you

Please note that due to the interconnected nature of the Ecosystem and the Platform Data License granted in the Terms and Conditions, certain content and data that has been incorporated into the Ecosystem may not be eligible for deletion. This includes content that has been integrated into other users' projects, specifications, or other derivative works, as well as data necessary for the continued operation of the Platform.

7.2 European Economic Area (EEA) Residents — GDPR

If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure: Request deletion of your personal data, subject to the data retention provisions described in Section 6 and applicable legal exceptions.
  • Right to Restrict Processing: Request that we limit how we use your data.
  • Right to Data Portability: Request transfer of your data to another service.
  • Right to Object: Object to processing of your personal data for certain purposes.
  • Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process your data.

To exercise these rights, contact us at the information provided below. We will respond to requests in accordance with applicable law and may need to verify your identity before processing your request.

7.3 California Residents — CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: Request deletion of your personal information, subject to the data retention provisions described in Section 6 and applicable legal exceptions.
  • Right to Opt-Out: We do not sell personal information, so this right does not apply.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise these rights, contact us at the information provided below.

7.4 Canadian Residents — PIPEDA

If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):

  • Access your personal information held by us
  • Challenge the accuracy and completeness of your information
  • Withdraw consent to the collection, use, or disclosure of your information

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Secure encrypted connections (HTTPS) across all Ecosystem properties
  • Login attempt monitoring and spam prevention
  • Access controls limiting data access to authorized personnel
  • Secure session management across Branded Domains

While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

9. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age. Access to our platform requires vendor authorization or account registration, which inherently limits access to business professionals and authorized individuals.

If we become aware that we have collected personal information from someone under 18, we will take steps to delete that information immediately.

10. International Data Transfers

Our services are operated from the United States, hosted on DigitalOcean infrastructure. If you are accessing our website or any Ecosystem property from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States.

10.1 EEA and UK Transfers

For transfers of personal data from the European Economic Area (EEA) or the United Kingdom to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs), Module Two (Controller to Processor), as the legal mechanism to ensure adequate protection of your data. These clauses are incorporated into our Data Processing Agreement, which is available to Licensees and Vendors upon request or at specinasec.com/legal/data-processing-agreement.

10.2 UK International Data Transfer Addendum

For transfers of personal data from the United Kingdom, we apply the UK International Data Transfer Addendum to the EU SCCs, as issued by the UK Information Commissioner's Office (ICO), in addition to the SCCs referenced above.

10.3 Swiss Transfers

For transfers of personal data from Switzerland, the SCCs are applied with the necessary modifications to comply with the Swiss Federal Act on Data Protection (FADP).

10.4 Supplementary Measures

In addition to the contractual safeguards above, we implement supplementary technical measures including encryption of data in transit (TLS 1.2+) and at rest (AES-256), access controls limiting data access to authorized personnel, and regular security assessments.

11. Third-Party Links

Our website and Ecosystem properties may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

Branded Domains and White-Label instances within the Ecosystem are not third-party sites; they are part of the Spec In A Sec Ecosystem and are subject to this Privacy Policy.

12. Relationship to Other Agreements

This Privacy Policy works in conjunction with our Terms and Conditions, and where applicable, the Vendor Services Agreement, Licensee Services Agreement, White-Label Service Addendum, and Data Processing Agreement. The Platform Data License described in the Terms and Conditions governs the Company's rights to use data across the Ecosystem. This Privacy Policy describes how we collect, use, and protect that data.

For Licensees and Vendors subject to the General Data Protection Regulation (GDPR) or UK GDPR, the Data Processing Agreement governs the specific terms under which we process personal data on your behalf, including sub-processor disclosures, security measures, and breach notification obligations.

In the event of any conflict between this Privacy Policy and the Terms and Conditions regarding data usage rights, the Terms and Conditions shall control. In the event of any conflict between this Privacy Policy and the Data Processing Agreement regarding the processing of personal data, the Data Processing Agreement shall control.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Effective Date" at the top of this policy.

For significant changes, we will provide notice through our website or by email. Your continued use of our services after any changes indicates your acceptance of the updated policy.

15. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or have concerns about how we handle your personal information, please contact us:

Spec In A Sec, LLC

Email: info@specinasec.com

This Privacy Policy was last updated on March 23, 2026.