Design With Friends Ltd., a company incorporated under the laws of the State of Israel, with its registered office at He-Kharish St 7, Emek Hefer Industrial Park, Israel 3877701 (the "Company", "we", "us" or "our"), respects your privacy. This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, and the choices and rights you have.
This Policy applies to www.designwithfriends.com and any of our subdomains and related webpages (the “Site”), to the Design With Friends mobile applications for iOS and Android (the “App”, and together with the Site, the “Platform”), and to the services we provide through them (the “Services”). It is incorporated into, and forms part of, our Terms of Use. Capitalised terms not defined here have the meaning given in the Terms of Use.
The Platform is intended only for individuals aged eighteen (18) or over. See “Children” below.
1. Summary
In short, and without replacing the detail below:
- We collect the information you give us when you create an Account and use the Services, the designs you create, and technical information about how you use the Platform.
- We use it to run the Services, process payments, provide our AI-powered rendering features, support you, keep the Platform secure, and market our product.
- Your nickname, profile picture, badges, rendered designs, likes, ratings and comments are public. Anyone can see them, including people without an Account, and search engines may index them. Rendering a design with “Make it Real” publishes it automatically.
- We use advertising and analytics partners, including Meta and Pinterest. Under California law this counts as “selling” and “sharing” your personal information for cross-context behavioral advertising, and you can opt out at any time.
- We do not sell the designs you create, or the photographs you submit, in any form that identifies you. We may use designs and renderings in de-identified form to train and improve our own models; we do not train on anything that identifies you, or on your photographs, without your consent.
- You can access, correct, delete or export your information, and opt out of targeted advertising, using the contacts and controls described in “Your rights and choices”.
2. Information we collect
2.1 Information you give us
- Account information: your name, e-mail address, password (stored in hashed form), and any profile details you choose to add. If you register using Facebook, Google or Sign in with Apple, we receive your name, e-mail address and, where you allow it, your profile picture and country from that provider.
- Payment information: purchases on the Site are processed by Stripe, and purchases inside the App are processed by Apple or Google. We do not receive or store your full payment card number. We receive a payment token, the last four digits, the card type, the billing country, and the outcome of the transaction.
- Designs and Results: the rooms and spaces you design using the items in our editor, and the Results you generate from them. Designs are composed from our own catalogue of visual assets; the Platform does not allow you to upload photographs of your home.
- Public profile information: the display name (nickname or handle) and the profile picture or avatar you choose when you register. If you sign up with Google, Facebook or Apple, these fields are pre-filled from that account — for Google, your Google name and Google profile picture — and you are asked to confirm or change them, and told that they will be publicly viewable, before you continue.
- Furniture photographs [forthcoming]: if you use the forthcoming feature that turns a photograph of a single furniture item into a 3D model, the photograph you submit. These photographs are used only to generate that model for you. They are not published to the public feed, are not shown to other Users, and do not appear on your profile. A 3D model generated from a photograph may appear in designs you create and publish.
- Item requests: if you have a Premium subscription and ask us to add an item to our catalogue, the product page link you submit. We use it to create a 3D model of that item for the catalogue and to tell you whether the item was added. The link is not published and is not shown to other Users. An item added to the catalogue becomes available to everyone and is not attributed to you.
- Community activity: the comments you post, the likes, ratings and votes you give, the challenges you enter, and any badges or achievements you earn.
- Communications: messages you send us by e-mail or through support channels.
- Marketing preferences: your subscription and consent choices.
- Instagram handle: if you message us on Instagram to claim a reward for following us, we see and record your Instagram handle so that we can check that you follow us and credit the reward. This is entirely optional and the Services work without it.
2.2 Information we collect automatically
- Device and connection data: IP address, device type and model, operating system and version, browser type, language, mobile device identifiers, and (in the App) app version.
- Usage data: pages and screens viewed, features used, designs created, buttons and menus interacted with, session length, timestamps, and referring page.
- Approximate location: an approximate location (typically city or region level) inferred from your IP address. We do not collect precise GPS location.
- Cookies and similar technologies: including software development kits (SDKs) in the App. See “Cookies and similar technologies” below.
- Diagnostic data: crash reports and error logs.
- Session recordings: we record your session on the Platform — the pages and screens you view, your clicks, scrolling and navigation, the content displayed on screen, and the design canvas you are working in — so that we can understand how the Platform is used and diagnose problems. Text you type into form fields is masked and is not recorded. Where the law requires your consent, we ask before we start recording; elsewhere recording is on by default and you can turn it off at any time in Privacy choices.
2.3 Information from third parties
- Social login providers (Facebook, Google, Apple), as described above. The way those providers use your information is governed by their own policies, not this one.
- App stores: Apple and Google provide us with purchase and subscription status, and aggregated download and performance statistics. They do not give us your payment card details.
- Advertising and analytics partners, who may provide us with measurement and campaign-performance information.
2.4 Your public profile and community activity
The Platform includes a public feed in which designs rendered by Users are shown alongside the publishing User's display name and profile picture, and in which Users can like, rate and comment on one another's designs.
When you render a design using “Make it Real”, the rendered design — whether an image or a video — is published to the public feed automatically. There is no separate publishing step. Designs you build in the editor but do not render are not published.
The following are public. They can be seen by anyone, including people who do not have an Account, and may be indexed by search engines: your display name; your profile picture or avatar; any badges, ratings or similar non-identifying information shown on your profile; any design you render using Make it Real, whether as an image or a video, or enter into a challenge; your likes and ratings; and your comments, together with the date they were posted.
The following are not public: your e-mail address; your password; your payment and subscription details; designs you build in the editor but do not render; any photograph you submit to the forthcoming 3D-model feature; and your Account settings.
We tell you at the point of registration that your nickname and avatar will be publicly viewable and that profiles, likes and comments are public. Please choose a display name and picture accordingly. If you would rather not be identifiable, choose a nickname that is not your real name and an avatar that is not a photograph of you.
You can change your display name or profile picture at any time in your Account settings. To remove a rendered design from the public feed, delete the design; there is no separate unpublish control. You can also delete individual comments and likes, and delete your Account. When you do, we remove the content from the Platform, but we cannot recall copies that other people have already made or control how long search engines keep cached copies. See “How long we keep information” below.
3. What we collect, why, and whether it is shared for advertising
The following table sets out, for each category of personal information in the California Consumer Privacy Act, what we collect, the purposes for which we use it, and whether we “sell” or “share” it for cross-context behavioral advertising as those terms are defined under California law.
| Category | Examples | Why we use it | Sold / shared for ads? |
|---|---|---|---|
| Identifiers | Name, e-mail address, account ID, display name, profile picture, IP address, device identifiers, cookie IDs, and your Instagram handle where you provide it | Create and administer your Account, authenticate you, communicate with you, security and fraud prevention, marketing | Yes – online identifiers, and your e-mail address and Account ID in hashed form, are shared with advertising partners |
| Commercial information | Subscriptions, purchases, credit balance, transaction history, and the product page links you submit when you request an item for the catalogue | Process payments, provide paid features, add requested items to the catalogue, prevent fraud, meet accounting obligations | Limited – conversion events only |
| Internet or network activity | Pages and screens viewed, features used, clicks, session data, referring page, likes, ratings and comments, and session recordings | Operate and improve the Services, analytics, troubleshooting, personalization, advertising measurement | Yes |
| Geolocation data | Approximate city or region inferred from IP address | Security, fraud prevention, localisation, analytics | Yes – as part of online identifiers |
| Visual information — designs and Results | Rooms and spaces you design using our editor, and the Results you generate, including rendered images and videos | Provide the design and AI rendering features, display your Results to you and, once rendered, to other Users and to the public; promote the Services, including by featuring designs in our own advertising; and, in de-identified form, develop and improve our own models | No — not shared with advertising partners for targeting. Designs may appear in our own advertising |
| Visual information — furniture photographs [forthcoming] | Photographs of individual furniture items you submit for 3D modeling | Generate a 3D model of that item for you. The photograph is not published and is not shown to other Users. A 3D model generated from it may appear in designs you render, which are published to the public feed | No |
| Audio, biometric, employment, education, or precise location data | Not collected | — | No |
| Sensitive personal information | Not collected. We do not collect government identifiers, precise geolocation, racial or ethnic origin, health, religious beliefs, union membership, genetic or biometric data, or the contents of your mail, e-mail or messages | — | No |
| Inferences | Design style preferences, likely interests, engagement level | Personalize the Services and our marketing | No |
Because we do not collect sensitive personal information, we do not offer a “Limit the Use of My Sensitive Personal Information” control — there is nothing to limit.
Publishing information on your public profile is not a “sale” or “share” of personal information under California law. It is a disclosure that follows from your choice to render and post content, and the “Sold / shared for ads?” column above refers only to disclosures to our advertising partners.
“Sold” and “shared” are used here as California law defines them. We do not receive money in exchange for personal information — those terms cover disclosures to advertising partners made in return for advertising and analytics services.
4. How we use your information
We use personal information to: provide, operate and maintain the Platform and the Services; create and administer your Account; generate, store and display your designs and Results; process payments and manage subscriptions and credit balances; provide customer support and respond to your enquiries; personalize your experience; operate community, gallery and challenge features; send you service messages (such as security alerts, transaction confirmations and, where required, subscription renewal reminders); send you marketing communications where you have not opted out; measure and improve our advertising; promote the Services, including by featuring designs created on the Platform in our advertising; display advertising in the App; understand how the Platform is used and improve it; develop, train, evaluate and improve our own models, technology and features using de-identified designs and renderings; detect, investigate and prevent fraud, abuse and security incidents; and comply with our legal obligations and establish, exercise or defend legal claims.
5. AI-powered features
The Platform includes AI-powered features that turn the 3D designs you build in our editor into more realistic images or renderings. We want to be specific about what leaves our systems:
- When you request a realistic rendering, the 3D design you have composed in our editor is sent to one of our AI providers — currently OpenAI and xAI (Grok) — which returns the rendered image. Where you generate a video of a design, the video is rendered on our serverless compute provider, Modal, and returned to you. Your free-text prompts and any photograph you submit to the 3D-model feature are not sent to those providers for this feature.
- [FORTHCOMING] We will shortly offer a feature that lets you photograph a piece of furniture in your home and turn it into a 3D model. If you use that feature, the photograph you submit will be sent to our 3D modeling provider, Meshy, for that purpose. This feature is optional and only processes images you specifically submit to it. Photographs submitted to it are not published to the public feed and are not shown to other Users.
- We keep server-side logs of activity on the Platform, including AI rendering requests, so that we can operate, support and secure the Services and investigate misuse. How long we keep them is set out in “How long we keep information” below.
- We may use designs and Results in de-identified form — stripped of your name, display name, Account identifier and anything else that identifies you — to develop, train, evaluate and improve our own models and features, such as better rendering and design assistance. We do not use your prompts, the photographs you submit, or anything that identifies you to train our own or any third party's foundation models unless you have given us your prior consent, which you may withdraw at any time in your Account settings or by contacting us.
AI-generated output can be inaccurate or unrealistic, and should be independently reviewed. Our AI providers process information as our service providers, under contractual restrictions that prohibit them from using it for their own purposes.
6. Cookies and similar technologies
We and our partners use cookies, pixels, tags, local storage and mobile SDKs to operate the Platform, remember your preferences, understand usage, and measure and deliver advertising. We use three broad categories:
- Strictly necessary — required to run the Platform, sign you in, keep your session, protect security, and remember your preferences and settings. These cannot be switched off.
- Analytics — help us understand how the Platform is used, so we can improve it. This category also covers session recording. These are set by PostHog and by Google Analytics.
- Advertising — used by Meta, Pinterest, Google, OpenAI and AppLovin to measure our campaigns and show you relevant advertising on other services.
Where required, we ask for your consent before setting non-essential cookies, and you can change your choices at any time through the cookie preferences link on the Site. In the App, you can limit advertising identifiers through your device settings (on iOS, Settings › Privacy & Security › Tracking; on Android, Settings › Privacy › Ads).
Changing your choices. You can accept or reject analytics and marketing cookies in the banner shown on your first visit, from the "Cookie settings" link in the footer, from Preferences on your account page, or right here:.
7. Advertising, and your opt-out rights
Advertising we buy. We promote the Services through advertising partners — currently Meta (the Meta Pixel and Facebook Login), Pinterest (the Pinterest Tag), Google (Google Ads conversion tracking), OpenAI (its advertising pixel) and AppLovin (whose tag also runs on the Site). These partners set cookies or receive identifiers that allow them to recognize your browser or device across services, to measure the performance of our advertising, and to attribute app installs.
Server-side conversion measurement. As well as the tags that run in your browser, our servers send conversion events directly to Meta and Pinterest when you register or complete a purchase on the Site. These events identify you to those partners using your e-mail address and, for Pinterest, your Account identifier, each converted into an irreversible cryptographic hash before it is sent, together with your IP address, your browser's user-agent string, and any advertising click identifier already stored in your browser. We do not send these events from the App. Hashing stops those partners reading your e-mail address, but it still lets them match you to an account you already hold with them, so we treat this as personal information.
Matching in your browser. The OpenAI advertising pixel does something similar without involving our servers. It runs in your browser and can automatically detect customer information present on the page — for example an e-mail address you have entered into a form — convert it into an irreversible cryptographic hash, and send that hash with the conversion event. Raw customer information is not sent to OpenAI. Like every advertising tag on the Site, the pixel loads only where you have consented to advertising cookies.
Advertising we show. The App displays advertising supplied through AppLovin's mediation platform, which runs an auction across a number of advertising networks and their demand partners. Those partners may receive your device identifiers, IP address and information about how you interact with an advertisement, and may use it to select advertising for you. AppLovin's privacy policy, which describes how it handles this information, is available at legal.applovin.com/privacy. We may also serve advertising on the Site through Google.
Opting out does not remove advertising. If you have not consented to personalized advertising, or you opt out, you will still see advertisements in the App, but they will be selected without using your personal information to profile you.
Under California law, this activity constitutes “selling” and “sharing” personal information for cross-context behavioral advertising. We do not sell personal information for money, and we do not knowingly sell or share the personal information of anyone under 18. The Platform is intended only for adults — see “Children” below.
You can opt out at any time:
- Use the “Do Not Sell or Share My Personal Information” link in the footer of the Site.
- Adjust your choices in the cookie preferences center.
- Send us a request at privacy@designwithfriends.com.
We honour opt-out preference signals, including the Global Privacy Control (GPC). If your browser transmits a GPC signal, we will treat it as a valid request to opt out of the sale and sharing of personal information associated with that browser. Because an opt-out is stored against a browser or device, you will need to opt out separately on each browser and device you use, and again if you clear your cookies.
8. Who we share information with
We do not sell the designs you create, the Results, or the photographs you submit, in any form that identifies you. Apart from the advertising activity described above, we do not sell your personal information. We share personal information only as described below.
Service providers and processors. We use the following providers. Most process personal information only on our instructions and under contract. Our payment processors also act as controllers in their own right, for fraud prevention and to meet their own legal obligations, and our advertising partners act as independent controllers for their own advertising purposes. In each case that processing is governed by their own privacy policies:
| Provider | What it does for us | Information involved | Location |
|---|---|---|---|
| Amazon Web Services | Hosting and storage of designs, renderings, assets and catalogue data | Account data, designs, uploaded images, Results | United States |
| Google (Firebase) | Authentication and push notifications | Account identifiers, e-mail address, device push tokens | United States |
| Expo | Delivering push notifications to your device | Device push token and the content of the notification | United States |
| Cloudinary | Image upload, transformation and delivery | Uploaded images and designs | United States |
| Stripe | Payment processing for purchases on the Site | Name, e-mail, billing country, payment token, transaction data | United States |
| Apple / Google | In-app purchases and subscriptions | Purchase and subscription status | United States |
| OpenAI (AI rendering) | AI rendering of 3D designs into realistic images | The 3D design submitted for rendering, and the resulting image | United States |
| xAI (Grok) | AI rendering of 3D designs into realistic images | The 3D design submitted for rendering, and the resulting image | United States |
| Meshy [forthcoming] | Generating 3D models from photographs of furniture | Photographs you submit to that feature | United States |
| Modal | Serverless compute on which we run our AI video rendering | The 3D design submitted for rendering, and the resulting video | United States |
| PostHog | Product analytics, session replay, and AI-assisted analysis of that data | Usage and device data, account identifier, and session recordings | United States |
| Google (Analytics) | Website analytics — understanding how the Site is used | Usage and device data, online identifiers, IP address | United States |
| Sentry | Error and crash monitoring | Diagnostic data, device data, IP address | United States |
| LaunchDarkly | Feature flags and staged rollouts | Account identifier, device data | United States |
| Meta | Advertising, conversion measurement, Facebook Login | Online identifiers, your hashed e-mail address, activity and conversion events | United States |
| Advertising and conversion measurement | Online identifiers, your hashed e-mail address and hashed Account identifier, activity and conversion events | United States | |
| Google (Ads) | Conversion measurement for advertising we buy on Google | Online identifiers, activity and conversion events | United States |
| OpenAI (advertising) | Conversion measurement for advertising we buy on OpenAI services | Online identifiers, your hashed e-mail address, activity and conversion events | United States |
| AppLovin | Conversion measurement on the Site for advertising we buy; advertising and install attribution for the App, and serving advertising in the App through its mediation platform, which runs an auction across other advertising networks and their demand partners | Device identifiers, IP address, app events and advertising interactions | United States |
AI features of our analytics provider. PostHog, our product analytics provider, offers AI features that help us query and summarize the usage information described above, and those features are enabled on our account. When we use them, the analytics information concerned, which can include session recordings, is processed by PostHog's own AI providers — currently OpenAI, Google, Anthropic, Microsoft and Cloudflare — in the United States. PostHog is contractually required to prevent those providers from using that information to train or develop their own AI models. This is separate from the rendering of your designs described in the “AI features” section above: your designs, Results and uploaded photographs are not sent to PostHog or to its AI providers for this purpose.
Other Users and the public. When you render a design, enter a challenge, or make a Result available through the feed, community, gallery or marketplace features, that content is public: it is displayed together with your display name and profile picture, and can be viewed by other Users and by anyone else, including people who do not have an Account. Your likes, ratings and comments are public in the same way. Public pages may be indexed by search engines and may appear in search results.
Because this content is public, other people may copy, screenshot, download, re-post or index it. If you delete public content or your Account, we remove it from the Platform, but we have no ability to retrieve copies that others have already made, and search engines may continue to show cached copies until they next re-crawl the page. You can usually ask a search engine directly to remove a cached page.
Legal and safety. We may disclose personal information where we believe in good faith that it is necessary to comply with a law, regulation, legal process or enforceable governmental request; to enforce our Terms of Use; to detect, prevent or address fraud, security or technical issues; or to protect the rights, property or safety of the Company, our Users or the public.
Corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your personal information becomes subject to a materially different privacy policy.
Aggregated and de-identified information. We may create and use aggregated or de-identified information that cannot reasonably be used to identify you, for any lawful purpose. Where we hold information in de-identified form, we will maintain it in that form and will not attempt to re-identify it, except to test the effectiveness of our de-identification.
9. Your rights and choices
9.1 Everyone
Whatever your location, you can: access and update most Account information directly in your Account settings; delete individual designs and uploaded images; request deletion of your Account; unsubscribe from marketing e-mail using the link in any message; and turn off push notifications in your device settings. You can also change your display name and profile picture, delete individual comments and likes, and delete a rendered design, which removes it from the public feed. Deleting public content removes it from the Platform but does not remove copies already made by other people or cached by search engines.
9.2 California residents
If you are a California resident, the CCPA as amended by the CPRA gives you the right to: know what personal information we have collected, the sources, the purposes, and the categories of recipients; access a copy of that information in a portable form; correct inaccurate personal information; delete your personal information; opt out of the sale or sharing of your personal information for cross-context behavioral advertising; and not be discriminated against for exercising any of these rights. We do not offer financial incentives in exchange for personal information.
The table in section 3 describes the categories we collect, our purposes, and what is sold or shared. Except for any category identified in that table as forthcoming, which we do not yet collect, we have collected each of those categories in the preceding twelve (12) months, from the sources described in section 2, and disclosed them to the categories of recipients described in section 8.
9.3 Residents of other US states
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you have broadly equivalent rights to access, correct, delete and obtain a copy of your personal information, and to opt out of targeted advertising and the sale of personal information. You also have the right to appeal a refusal of your request: write to privacy@designwithfriends.com with “Privacy Appeal” in the subject line, and we will respond within the period required by your state's law and tell you how to contact your state Attorney General if you remain dissatisfied.
9.4 How to make a request
Send your request to privacy@designwithfriends.com, or use the controls in your Account settings. We will acknowledge your request and respond within forty-five (45) days, and will tell you if we need a further forty-five (45) days. To protect your information, we will verify your identity, usually by asking you to respond from the e-mail address registered to your Account, and we may ask for additional information if the request concerns sensitive or high-risk data. An authorized agent may submit a request on your behalf with written permission signed by you, and we may still contact you to confirm. Making a request is free unless it is manifestly unfounded or excessive.
10. How long we keep information
We keep personal information only for as long as we need it for the purposes described in this Policy, and then delete it or de-identify it. Our current retention periods are:
| Information | Retention period | Why |
|---|---|---|
| Account data | For the life of your Account, then deleted within 30 days of your deletion request | To provide the Services to you |
| Designs, Results and uploaded images | For the life of your Account, then deleted within 30 days of your deletion request | To provide the Services to you |
| Public profile, rendered designs, likes and comments | For the life of your Account. Deleting a design, comment or like deletes it; deleting your Account deletes your public profile, your designs and your comments, including comments you left on other Users' designs | To operate the community features |
| Backups | Up to 90 days after deletion from live systems | Disaster recovery |
| Server-side activity logs | 30 days | Operating and securing the Services, and investigating misuse |
| Session recordings | 90 days | Understanding usage and diagnosing problems |
| Product analytics | 7 years | Understanding and improving the Services |
| Error and diagnostic logs | 90 days | Debugging and security |
| Payment and transaction records | 7 years | Tax, accounting and audit obligations |
| Marketing preferences and suppression lists | Until you opt out, and then indefinitely in a suppression list | To honour your opt-out |
We may retain information for longer where we are required to do so by law, or where it is necessary to establish, exercise or defend legal claims.
Some of the providers listed above keep their own records under their own legal obligations. In particular, our payment processors — Stripe for purchases on the Site, and Apple and Google for in-app purchases — retain transaction records for the periods required by financial, tax and anti-fraud law. Those records are outside our control and are governed by their own privacy policies.
Once information has been de-identified so that it no longer identifies you and we cannot reasonably re-identify you, it is no longer personal information. We may keep and use it after that point, including in training data sets for our own models, and the periods in the table above no longer apply to it. We will not attempt to re-identify it.
11. Security
We use administrative, physical and technical measures designed to protect personal information from unauthorized access, use, alteration and loss. These include encryption in transit using TLS, encryption at rest for stored files, hashing of passwords, access controls limiting employee access to what is needed for their role, and monitoring and logging.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your Account password confidential. If we become aware of a breach of security affecting your personal information, we will notify you and the relevant authorities where required by law and without undue delay.
12. Where your information is held
We are based in Israel. The Platform is available worldwide, including in the European Economic Area and the United Kingdom, and we market primarily to users in the United States. Personal information we collect is stored and processed primarily in the United States, on Amazon Web Services and with the providers listed in section 8.
If you access the Platform from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States and other countries where our providers operate, which may have data protection laws that differ from those in your country.
13. If you are in the European Economic Area or the United Kingdom
The Platform is available in the EEA and the UK, although we market primarily to users in the United States. Where the EU GDPR or the UK GDPR applies to our processing of your personal information, this section applies to you.
Controller. Design With Friends Ltd. is the controller of your personal information. You may contact us at privacy@designwithfriends.com.
Representatives. We have appointed representatives under Article 27 of the EU GDPR and Article 27 of the UK GDPR. You, or a supervisory authority, may contact them on all issues relating to our processing of personal data:
- EU representative: Euverify Ltd (Ireland), Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland — gdpr@euverify.com
- UK representative: Euverify Ltd (UK), 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom — gdpr@euverify.com
Contacting a representative does not affect your right to contact us directly at privacy@designwithfriends.com, or to complain to your supervisory authority.
Legal bases. We rely on: performance of a contract with you, to provide the Services and process your purchases; our legitimate interests, in securing and improving the Platform, preventing fraud, and marketing our own products and services to existing Users, who can opt out at any time; your consent, for non-essential cookies, advertising, and any use of your content for model training; and compliance with a legal obligation, where the law requires us to retain or disclose information. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
Your rights. You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, including objection to direct marketing at any time. You also have the right to lodge a complaint with your local supervisory authority.
Transfers. Personal information is transferred to the United States. Where required, we rely on the European Commission's Standard Contractual Clauses, and the UK Addendum, together with supplementary measures, as the transfer mechanism.
14. Children
The Platform is intended only for individuals aged eighteen (18) or over. We do not knowingly collect personal information from anyone under eighteen (18). If we learn that we have collected personal information from a person under eighteen (18), we will delete it and terminate the Account. If you believe a minor has provided us with personal information, please contact us at privacy@designwithfriends.com.
15. Additional information for App users
- Device permissions. The App asks for permission to use your camera and photo library, so that you can photograph or select an image of an individual furniture item for the forthcoming 3D-model feature. We access only the images you actively capture or select; we do not scan or index your photo library. You can withdraw these permissions at any time in your device settings, and the App will continue to work without them, though the related features will be unavailable.
- Push notifications. If you allow them, we send notifications about activity in your Account, challenge results and, where required, subscription renewal reminders. We send marketing notifications only with your consent. You can turn notifications off at any time in your device settings or in your Account settings.
- Mobile identifiers. The App may use advertising identifiers provided by your device operating system. On iOS we will ask for your permission through the App Tracking Transparency prompt before tracking you across apps and websites owned by other companies.
- Deleting the App. Deleting the App from your device does not delete your Account, your data, or any subscription. To delete your Account, use your Account settings or contact us; to cancel a subscription bought through an app store, cancel it through that app store.
16. Third-party links and services
The Platform contains links to third-party websites and services, including product pages of retailers and our own pages on Instagram, Facebook and Pinterest. We are not responsible for their content or their privacy practices, and this Policy does not apply to them. We encourage you to read the privacy policy of any third-party service before providing information to it.
17. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will post a clear notice on the Platform and, where we hold your e-mail address, notify you by e-mail, in each case before the change takes effect. The date at the top of this Policy shows when it was last updated. Your continued use of the Platform after a change takes effect means you accept the updated Policy.
18. Contact us
If you have any questions, requests or complaints about this Policy or about how we handle your personal information, contact us at privacy@designwithfriends.com, or write to Design With Friends Ltd., He-Kharish St 7, Emek Hefer Industrial Park, Israel 3877701.