Privacy Policy
Last updated: April 28, 2026
1. Introduction
Logic Framework (“Company,” “we,” “us”) operates the LogicSite platform at logicsite.pro (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you access or use the Service.
By using the Service you consent to the practices described in this policy. If you do not agree, please discontinue use of the Service. This policy should be read alongside our Terms of Service.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily submit when you:
- Create an account (name, email address, organization details).
- Complete your profile or team settings (job title, phone number, address).
- Upload content such as floor plans, device data, project files, and messages.
- Contact us for support or provide feedback.
- Subscribe to a paid plan (billing and payment information processed by our payment provider).
2.2 Information Collected Automatically
When you interact with the Service we automatically collect certain technical and usage data, including:
- IP address, browser type and version, operating system, and device identifiers.
- Pages visited, features used, click paths, and time spent within the Service.
- Referring URL, search terms, and general geographic location derived from IP.
- Performance metrics, error logs, and diagnostic information.
2.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies to maintain session state, remember your preferences, and understand how you use the Service. You can manage cookie preferences through your browser settings; however, disabling cookies may limit certain features.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To operate, maintain, and provide the features and functionality of the Service.
- Account Management: To create and manage your account, process transactions, and send transactional communications.
- Customer Support: To respond to your inquiries, troubleshoot issues, and provide technical assistance.
- Analytics and Product Improvement: To analyze usage patterns, measure feature adoption, monitor performance, identify areas for improvement, and develop new features and capabilities. This includes tracking how you interact with the Service (pages visited, features used, workflows completed, time spent) to improve the user experience, prioritize our product roadmap, and optimize platform performance. We may use this data in both identifiable and aggregated forms for these purposes.
- Product Research and Machine Learning: To conduct research, build internal models, train and improve machine learning systems, and develop intelligent features. We may use your content and usage data in aggregated, anonymized, or de-identified form to train models that improve device placement suggestions, layout optimization, and other platform capabilities. This helps us advance the Service for all users.
- Personalization: To customize your experience, provide relevant recommendations, and surface content and features that are most useful to you based on your usage history and preferences.
- Benchmarking and Insights: To generate aggregated, non-identifying benchmarks, statistics, and insights about platform usage, industry trends, and best practices that we may share publicly or with other customers.
- Security and Compliance: To detect, prevent, and address fraud, abuse, security incidents, and technical issues.
- Communications: To send service updates, product announcements, and, where you have opted in, marketing communications.
- Legal Obligations: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
4. Aggregated and De-identified Data
We may aggregate or de-identify information so that it can no longer reasonably be used to identify you. Logic Framework may use such data for any lawful business purpose without restriction, including but not limited to:
- Analyzing industry trends, benchmarking platform usage, and generating reports on adoption patterns.
- Training, improving, and evaluating machine learning models and algorithms that power platform features.
- Developing new products, features, and services — including features that leverage artificial intelligence.
- Publishing aggregated statistics, research findings, or industry insights.
- Optimizing platform infrastructure, performance, and reliability.
- Providing aggregated analytics dashboards or benchmarks to customers or the public.
Aggregated and de-identified data is not subject to the restrictions that apply to personal information under this policy. We will not attempt to re-identify aggregated or de-identified data, and we contractually require the same of any third parties with whom we share such data.
5. How We Share Your Information
We do not sell or rent your personal information to third parties. We may share your information in the following circumstances:
- Service Providers: With trusted third-party vendors who perform services on our behalf (hosting, analytics, payment processing, customer support). These providers are contractually obligated to use your data only for the purposes we specify and in accordance with this policy.
- Legal Requirements: When required by law, subpoena, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
- With Your Consent: We may share your information for other purposes when you have given us explicit consent.
5a. Analytics and Cookies
We use the following first-party and third-party technologies to collect usage data:
- PostHog (product analytics): hosted by PostHog Inc. in the United States (us.i.posthog.com). Collects pageviews, click and interaction events, viewport size, browser/OS, referrer, and (for authenticated users) your account ID and email so we can attribute behavior to your session. IP addresses are not stored. Person profiles are created only after sign-in. Data is retained for up to 12 months.
- Strictly necessary cookies: session cookies set by Supabase for authentication, plus a regional preference cookie (`ls-region`) used to render the correct privacy banner. These cannot be disabled because the Service does not function without them.
You can manage analytics at any time on the Your Privacy Choices page. We honor the Global Privacy Control browser signal and treat it as a valid opt-out request under CCPA / CPRA.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. We may also retain and use your information to comply with legal obligations, resolve disputes, enforce our agreements, and for legitimate business purposes such as backup and disaster recovery.
Usage data and automatically collected technical data is generally retained for a shorter period unless it is needed for security, performance analysis, or legal compliance.
When data is no longer required, we will delete or anonymize it in accordance with our internal retention schedules.
7. Data Security
We implement administrative, technical, and physical safeguards designed to protect your information against unauthorized access, alteration, disclosure, or destruction. Specific technical measures include:
- Encryption at rest: AES-256-GCM with keys derived via PBKDF2-SHA-256 (100,000 iterations, 32-byte salt).
- Encryption in transit: TLS 1.2 or higher enforced on all connections; HSTS with preload enabled (max-age 1 year).
- Password storage: bcrypt hashing with a work factor of 12 rounds. Passwords are never stored in plaintext.
- Authentication: JWT-based sessions with automatic refresh, idle timeout (15 min), absolute timeout (12 hr), and concurrent session limits. Cloudflare Turnstile bot protection on login, registration, and password reset.
- Rate limiting: Sliding-window rate limits on all API endpoints via Upstash Redis (auth: 5/min, API: 60/min, uploads: 10/min).
- Input validation: All user input validated with Zod schemas. Explicit detection of SQL injection, XSS, path traversal, and command injection patterns before data reaches storage.
- Access control: Role-based access control (RBAC) with 52 granular permissions across 8 project roles and 4 organization roles. Every database query scoped to the authenticated tenant.
- Security headers: Content Security Policy, X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, and Permissions-Policy restricting geolocation, microphone, and camera access.
- File integrity: Uploaded files integrity-checked with SHA-256 hashing and deduplicated at the storage layer.
No method of electronic transmission or storage is completely secure. While we employ these measures to protect your information, we cannot guarantee absolute security.
8. International Data Transfers
Your information may be transferred to and processed in the United States or other jurisdictions where our service providers operate. These jurisdictions may have data protection laws that differ from those in your country of residence. By using the Service, you consent to such transfers. We take reasonable steps to ensure that your data receives an adequate level of protection wherever it is processed.
9. Your Rights and Choices
9.1 General Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your personal information, subject to legal retention requirements.
- Object to or restrict certain types of processing.
- Receive your data in a portable, structured format.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at support [at] logicsite [dot] pro. We will respond within the timeframe required by applicable law.
9.2 European Economic Area (GDPR)
If you are located in the EEA, we process your personal data under one or more of the following legal bases: performance of a contract, legitimate interest, compliance with a legal obligation, or your consent. You have the rights described in Section 9.1 above, and you may also lodge a complaint with your local supervisory authority.
9.3 California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what categories and specific pieces of personal information we collect, use, disclose, or share.
- Delete personal information we have collected, subject to certain legal exceptions.
- Correct inaccurate personal information.
- Opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising. We do not sell personal information for monetary value, but our use of analytics may constitute “sharing” under the broad CPRA definition.
- Limit the use of sensitive personal information.
- Non-discrimination for exercising any of these rights.
To opt out of analytics in this browser, visit Your Privacy Choices. We honor the Global Privacy Control browser signal as a valid opt-out request. To exercise other rights (access, deletion, correction), email [email protected]. We will respond within 45 days as required by CCPA / CPRA.
9.4 Communication Preferences
You may opt out of non-essential marketing communications at any time by using the unsubscribe link in our emails or by contacting us. Transactional and service-related messages are not subject to opt-out.
10. Do Not Track
Some browsers transmit “Do Not Track” (DNT) signals. We honor DNT signals and do not track, plant cookies, or use advertising when a DNT browser mechanism is enabled.
11. Third-Party Analytics
We may use third-party analytics services to help us understand how the Service is used. These services may collect information sent by your browser or device, including pages visited and other usage data. The information collected is used to evaluate aggregate usage patterns and is subject to the respective provider’s privacy policy.
12. Payment Processing
We do not store your payment card details directly. All payment information is processed by our third-party payment processor, which adheres to PCI-DSS standards. We only receive limited transaction data (such as the last four digits of your card and billing address) necessary to manage your subscription.
13. Children’s Privacy
The Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will take steps to delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email or through a notice within the Service. We encourage you to review this policy periodically.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: support [at] logicsite [dot] pro
- Location: Los Angeles, CA