Privacy Policy
Last updated:
Introduction
This Privacy Policy explains how HarnessHive ("we", "us", "our") collects, uses, and protects personal data. It applies to our website, our marketing communications (newsletter and waitlist), and the HarnessHive application — our cloud-based wiring harness design platform ("the Service"), including paid subscriptions.
For any privacy question you can reach us at info@harnesshive.com.
This policy complements our Cookie Policy, which governs cookies and similar technologies on our website.
Our two roles: controller and processor
Because HarnessHive is a business-to-business tool, we handle personal data in two distinct capacities, and your rights and our responsibilities differ depending on which applies.
We are the data controller for the personal data we decide how and why to process: your account and profile details, billing information, our communications with you, and website/product analytics. This policy governs that data.
We are a data processor for the content you create, upload, or store in the Service — your wiring harness designs, projects, and any files or data they contain. If those materials include personal data about your own employees, customers, or other third parties, you remain the controller of that data and decide how it is used. We process it only to provide the Service to you and only on your instructions, under a data processing agreement (DPA). If you need our DPA, contact us at info@harnesshive.com.
In short: we control your account, billing, and marketing data; you control the content you put into your designs.
What we collect
Account and identity data: name, email address, company/organization, team and role information, login credentials, and profile settings you provide when you register or use the Service.
Billing and subscription data: subscription plan, billing status, and transaction history. Payments are handled by our merchant of record, Polar (see Payments below) — we do not collect or store your full card number or other raw payment card details.
Customer content: the designs, projects, files, and related data you create or upload in the Service. We process this as your processor, as described above.
Usage and technical data: product analytics, feature usage, session and device information, IP address, log data, and error/diagnostic information, used to operate, secure, troubleshoot, and improve the Service.
Marketing contact data: email address, first name, last name, and company when you voluntarily subscribe to our newsletter or waitlist, plus limited email engagement metadata (delivery status, opens, clicks).
Purpose and lawful basis (GDPR)
Providing the Service: to create and manage your account, host your designs, and deliver the features you subscribe to. Lawful basis: performance of a contract (Art. 6(1)(b)).
Billing and payments: to process subscriptions, invoices, and taxes, and to prevent fraud. Lawful basis: performance of a contract, and legitimate interests / legal obligation for fraud prevention and record-keeping.
Service communications: operational and transactional messages about your account, subscription, security, or support requests. Lawful basis: performance of a contract, or legitimate interests (Art. 6(1)(f)).
Product analytics, security, and improvement: to understand how the Service is used, keep it reliable and secure, and improve it. Lawful basis: legitimate interests, balanced against your rights, and consent where required for non-essential cookies.
Newsletter and product updates: to send marketing emails about our product, features, roadmap, and company news when you ask to subscribe. Lawful basis: consent (Art. 6(1)(a)). You can withdraw consent at any time via the unsubscribe link in every email.
Payments
Subscription payments are processed by Polar (polar.sh), which acts as our merchant of record. This means Polar is the seller of record for your purchase and independently handles payment processing, card data, and applicable sales tax/VAT as a separate controller for that payment data. We receive confirmation of your subscription and limited billing metadata, but not your full payment card details. Polar's own privacy terms govern its processing of your payment information.
Service providers and subprocessors
We rely on trusted providers to run the Service. They process personal data on our behalf under data processing agreements and only as needed to deliver their function.
Storage (EU): Cloudflare R2 for file/object storage and Neon for our database, both hosting your data in Europe.
Compute (edge): application compute runs close to the user for performance and may take place outside the EU/EEA. Where that happens, transfers rely on the safeguards described under International transfers.
Email: Loops (app.loops.so) sends and measures our newsletter and transactional emails (deliveries, bounces, basic engagement).
Payments: Polar (polar.sh), as merchant of record — see Payments.
Analytics: PostHog for product analytics, to understand feature usage and improve the Service.
Planned — AI features: We are developing features that may use artificial intelligence or third-party AI/LLM providers (for example, design assistance or automation). These are not live yet. Before enabling any feature that sends your content or personal data to an AI provider, we will update this policy to name the provider, describe the processing and safeguards, and — where required — obtain your consent. We will not use your customer content to train third-party AI models without a lawful basis and appropriate notice.
Disclosures: We do not sell personal data. We share data only with the providers above (and their own subprocessors under contractual safeguards), and where required by law or to protect our rights, users, or the Service.
International transfers
Your stored data is held in Europe. However, edge compute and certain providers may process personal data outside the EEA/UK (e.g., in the U.S. or other regions). Where personal data is transferred outside the EEA/UK, we rely on recognized transfer mechanisms — such as the European Commission's Standard Contractual Clauses — and appropriate supplementary safeguards. Contact us at info@harnesshive.com for details about our transfer measures.
Retention
Account and content data: retained for as long as your account is active. After you close your account or cancel your subscription, we delete or anonymize your personal data and customer content within a reasonable period, unless a longer period is required for legal, tax, accounting, security, or dispute-resolution purposes. You can request earlier deletion (subject to the controller/processor distinction above).
Billing records: retained as required by applicable tax and accounting law.
Marketing contact data: retained until you unsubscribe or request deletion, or until it is no longer necessary.
Logs and analytics: retained for a limited period for security, troubleshooting, and performance.
Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, or data portability, and you may object to certain processing. Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
If your request concerns customer content for which we act as processor, and you are an end user rather than our direct customer, we may direct you to the relevant customer (the controller) or handle your request on their instructions.
You can unsubscribe from marketing using the link in our emails, or contact us at info@harnesshive.com. You also have the right to lodge a complaint with your local data protection supervisory authority.
How to unsubscribe or opt out
Email footer: click "Unsubscribe" in any marketing message to stop receiving marketing emails.
Direct request: email info@harnesshive.com to withdraw consent or request deletion.
Security
We implement appropriate technical and organizational measures and require our providers to do the same, including encrypted transmission, encryption at rest where applicable, access controls, and incident response procedures consistent with GDPR Art. 32. No system is perfectly secure, but we work to protect your data and will notify affected users and authorities of breaches as required by law.
Children's data
The Service is a professional tool not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will remove it.
Changes
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated on this page with a revised "last updated" date, and, where appropriate, by additional notice.
Contact
For privacy inquiries, data rights requests, our DPA, or questions about our processors, contact us at info@harnesshive.com.