Privacy Policy
Last updated: March 2026
1. Introduction
360 Hextile ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our software and services.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Password (stored securely hashed)
2.2 Payment Information
Payment processing is handled by Stripe. We do not store your full credit card number. We receive:
- Last four digits of your card
- Card brand and expiration
- Billing address
2.3 License and Usage Data
To validate licenses and prevent abuse, we collect:
- Machine identifiers (hashed hardware IDs)
- Software version information
- License activation timestamps
2.4 Technical Data
- IP address
- Browser type and version
- Operating system
- Referring URLs
2.5 Gallery Data
When you use the 360 Hextile Gallery, we additionally collect:
- Images uploaded to the 360 Hextile Gallery (stored on our servers)
- Image metadata: title, description, slug, tags, and collection assignment
- Gallery profile information: username, display name, bio, links, and avatar
- Processing data: resolution variants generated server-side (8K, 4K, 2K, thumbnails)
- IP hashes used for reaction deduplication and report deduplication (SHA-256 hashed; plain IP addresses are never stored)
- View counts (anonymous; no personally identifiable information is collected)
2.6 Gallery Data Visibility
The following gallery data is public and visible to all visitors:
- Gallery profiles: username, avatar, display name, bio, links, and published images
- Uploaded images are publicly visible unless hidden by you or by an administrator
- Reaction counts on images are public; individual reaction identities are not tracked or exposed
- IP hashes used for deduplication are never exposed to other users or third parties
3. How We Use Your Information
We use collected information to:
- Process purchases and manage your license
- Provide customer support
- Send important product updates and security notices
- Prevent fraud and enforce our terms
- Improve our software and services
4. Information Sharing
We do not sell your personal information. We may share data with:
- Payment Processors: Stripe processes payments securely
- Email Service: Brevo (Sendinblue) for transactional emails
- Legal Requirements: When required by law or to protect our rights
- Analytics: Google Analytics (GA4) collects anonymized usage data to help us understand how visitors use our website. Analytics cookies are only set after you provide consent. When you make a purchase, your anonymized analytics identifier may be linked to your transaction record for attribution reporting. You can opt out at any time via the cookie consent banner or the "Manage Cookies" link in the footer.
5. Data Security
We implement industry-standard security measures including:
- HTTPS encryption for all data transmission
- Secure password hashing (bcrypt)
- Regular security audits
- Limited employee access to personal data
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Opt out of marketing communications
You also have the following rights with respect to gallery content:
- You can delete individual gallery images at any time via the gallery interface or API
- You can request complete deletion of all gallery data (images, profile, collections, and reactions) by contacting privacy@360hextile.com
- Account deletion removes all associated gallery content permanently
To exercise these rights, contact us at privacy@360hextile.com.
7. Cookies
We use essential cookies for:
- Session management (keeping you logged in)
- Security (CSRF protection)
We also use Google Analytics (GA4) cookies (_ga, _ga_*) to understand how visitors use our site. These cookies are only set after you provide explicit consent via the cookie banner. If you decline or do not interact with the banner, no analytics cookies are set on your device. Google may still collect anonymized, cookieless measurement signals (such as aggregate page view counts) for behavioral modeling, but these cannot identify you individually.
You can withdraw your consent at any time by clicking "Manage Cookies" in the site footer, which will remove the analytics cookies and re-display the consent banner.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide services. After account deletion, we may retain certain data for legal compliance for up to 7 years.
For gallery data specifically:
- Gallery images are stored until deleted by you or removed by an administrator
- When an image is deleted, all associated files (original, resolution variants, and thumbnails) are permanently removed from disk
- Images belonging to banned users are hidden from public view but are not automatically deleted; administrators may delete them at their discretion
- Moderation audit log entries are retained indefinitely for accountability and appeals purposes
9. Children's Privacy
Our services are not intended for users under 18. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via email or prominent notice on our website.