Privacy Policy
How Frontal Labs, Inc. collects, uses, discloses, and protects personal information.
Last updated 2026년 6월 11일
Frontal Labs, Inc. ("Frontal," "Company," "we," "us," or "our") is committed to protecting the privacy and security of personal information. This Privacy Policy describes how we collect, use, disclose, and protect information about you when you access our website at https://frontal.dev (the "Site"), use our platform, APIs, infrastructure services, AI services, and related offerings (collectively, the "Services"), or otherwise interact with us.
1. SCOPE
This Privacy Policy applies to information we collect:
- when you visit our Site;
- when you create an Account and use our Services;
- when you communicate with us, including for support, sales, or other inquiries;
- through your interactions with our marketing and promotional activities; and
- from third parties, as described in this Privacy Policy.
This Privacy Policy does not apply to Customer Data (as defined in our Terms of Service) that we process on behalf of a Customer in our capacity as a data processor or service provider. Our processing of such data is governed by the applicable Data Processing Agreement and the Customer's instructions.
2. DEFINITIONS
2.1 "Personal Data" means any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
2.2 "Non-Personal Information" means information that does not and cannot be used to identify an individual natural person, including aggregated, de-identified, and anonymized data.
2.3 "Customer" means the legal entity or individual that has entered into our Terms of Service to use the Services.
2.4 "Account Data" means information provided when creating or managing an Account, including name, email address, company name, billing information, and account settings.
2.5 "Usage Data" means information about how you interact with the Services, including features used, pages visited, session duration, IP address, browser type, device information, referring URLs, and technical logs.
2.6 "Customer Data" has the meaning given in our Terms of Service.
3. INFORMATION WE COLLECT
3.1 Information You Provide Directly
We collect information you voluntarily provide when interacting with us and our Services:
- Account Information. When you register for an Account, we collect your name, email address, username, password, company or organization name, and any additional profile information you choose to provide.
- Billing and Payment Information. When you purchase paid Services, we collect payment information, including credit card details (processed by our payment processor), billing address, and tax identification numbers where required. Payment card numbers are tokenized by our payment processor and are not stored by Frontal.
- Communications. When you contact us for support, sales, or other inquiries, we collect the content of your communications, including emails, chat transcripts, support tickets, and phone call recordings (with notice and consent where required).
- Marketing Preferences. Your subscription preferences for marketing communications, newsletters, event invitations, and surveys.
3.2 Information Collected Automatically
When you access or use the Services, we automatically collect:
- Usage Data. Information about your interactions with the Services, including pages visited, features used, APIs called, sessions, and clicks on links and buttons. We do not record mouse movements, keystrokes, or session replays on our website.
- Device and Browser Data. IP address, browser type and version, operating system, device type and identifiers, screen resolution, language preferences, referring and exit URLs, and mobile carrier.
- Performance and Diagnostic Data. Service response times, latency, error rates, crash reports, memory usage, and system-level diagnostic information.
- Authentication and Security Data. Login timestamps, IP addresses used for access, authentication method, session identifiers, and security events.
3.3 Cookies and Similar Technologies
We use cookies, web beacons, local storage, and similar tracking technologies to collect information about your use of our Site and Services. Detailed information about our use of these technologies is set forth in our Cookie Policy.
3.4 Information from Third Parties
We may receive information about you from third parties:
- Identity and Authentication Providers. If you sign in using single sign-on (SSO) through Google, GitHub, or another provider, we receive authentication tokens and profile information authorized by you through that provider.
- Payment Processors. Confirmation of payment status and transaction metadata.
- Marketing and Lead Generation Platforms. Business contact information where you have consented to sharing.
- Partners. Contact and Account information from our Solutions Partners, Technology Partners, and Ecosystem Partners.
3.5 Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect Personal Data from anyone under 18. If we learn that we have collected Personal Data from an individual under 18 without verified parental consent, we will delete that data as quickly as possible. If you believe we have collected data from an individual under 18, contact us at privacy@frontal.dev.
4. HOW WE USE INFORMATION
We use the information we collect for the following purposes:
4.1 Service Provision
- To create and manage your Account.
- To provide, operate, and maintain the Services.
- To process transactions and send related communications, including billing confirmations and invoices.
- To authenticate your identity and manage access to the Services.
- To provide customer support, technical assistance, and respond to inquiries.
4.2 Service Improvement and Development
- To monitor, analyze, and improve the performance, security, reliability, and functionality of the Services.
- To detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms of Service and Acceptable Use Policy.
- To debug, identify, and repair errors or issues in the Services.
- To develop new products, features, and services that do not involve training machine learning models on Customer Data.
4.3 Communications
- To send administrative and service-related communications, including security alerts, account notifications, policy updates, and changes to our terms.
- To send marketing and promotional communications where you have consented or where permitted by applicable law.
- To send surveys, feedback requests, and research communications where you have consented.
- To personalize your experience and deliver content and feature recommendations.
4.4 Research and Analytics
- To generate aggregated, de-identified, or anonymized datasets for analytics, benchmarking, and research purposes.
- To analyze usage trends and patterns to inform business and product strategy.
4.5 Legal and Compliance
- To comply with applicable laws, regulations, legal processes, and governmental requests.
- To enforce our Terms of Service and other agreements.
- To protect the rights, property, and safety of Frontal, our users, and the public.
- To establish, exercise, or defend against legal claims.
5. HOW WE DISCLOSE INFORMATION
We disclose information in the following circumstances:
5.1 Service Providers and Subprocessors
We share information with third-party service providers and subprocessors who perform services on our behalf, including cloud infrastructure hosting, payment processing, customer support, email delivery, analytics, error monitoring, identity verification, and security monitoring. These providers are contractually obligated to process data only in accordance with our instructions and to implement appropriate security measures. A current list of subprocessors is maintained in our Subprocessors List.
5.2 Business Transfers
If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of a product or service to another provider, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
5.3 Legal Requirements
We may disclose information if we have a good-faith belief that access, use, preservation, or disclosure is reasonably necessary to:
- comply with applicable law, regulation, legal process, or enforceable governmental request;
- enforce our Terms of Service, including investigation of potential violations;
- detect, prevent, or address fraud, security, or technical issues; or
- protect against harm to the rights, property, or safety of Frontal, our users, or the public, as required or permitted by law.
5.4 With Your Consent
We may disclose information with your consent or at your direction, including when you authorize third-party integrations or applications to access your Account.
5.5 Affiliates
We may share information with our corporate affiliates, parents, and subsidiaries for purposes consistent with this Privacy Policy.
5.6 Aggregated and De-Identified Information
We may share aggregated, de-identified, or anonymized information that cannot reasonably be used to identify you for any purpose, including research, marketing, and analytics.
6. DATA TRANSFERS
6.1 International Transfers
Frontal is incorporated in the United States (Delaware) and is a fully remote company. We use service providers located in various jurisdictions. Personal Data we collect may be transferred to, stored in, and processed in the United States or other countries where we or our subprocessors operate. These jurisdictions may have data protection laws that differ from those of your home jurisdiction.
6.2 Transfer Mechanisms
When we transfer Personal Data across borders, we implement appropriate safeguards in accordance with applicable data protection laws, including:
- EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). Frontal is pursuing certification under these frameworks. For current transfer mechanisms, see our European Data Protection Notice. If there is any conflict between this Privacy Policy and the DPF Principles, the Principles govern. To learn more, visit https://www.dataprivacyframework.gov/.
- Standard Contractual Clauses (SCCs). We enter into the European Commission-approved Standard Contractual Clauses and the UK International Data Transfer Agreement with subprocessors and Customers as appropriate.
- Adequacy Decisions. Where the European Commission or UK Government has determined a country provides an adequate level of data protection, we may rely on that determination.
6.3 Data Privacy Framework Dispute Resolution
In compliance with the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF, Frontal commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the DPF should first contact Frontal at privacy@frontal.dev.
In compliance with the DPF, Frontal commits to refer unresolved complaints concerning our handling of personal data received in reliance on the DPF to JAMS, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://www.jamsadr.com/dpf-dispute-resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.
Under certain conditions, more fully described on the DPF website at https://www.dataprivacyframework.gov/, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
Frontal is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC). Frontal remains liable for the onward transfer of personal data to third parties acting as agents unless we can demonstrate we are not responsible for the event giving rise to the damage.
7. DATA SECURITY
We implement and maintain administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of Personal Data. These measures are described in our Data Protection Policy and Data Encryption Policy. However, no security measures are impenetrable, and we cannot guarantee the security of your data.
8. DATA RETENTION
We retain Personal Data for as long as necessary to provide the Services and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Our retention practices are detailed in our Data Retention Policy. When Personal Data is no longer needed, we securely delete or anonymize it in accordance with our Data Disposal Policy.
9. YOUR RIGHTS AND CHOICES
9.1 Access
You may request access to and obtain a copy of your Personal Data held by us. We will provide information about the categories of Personal Data processed, the purposes of processing, and the recipients or categories of recipients to whom the Personal Data has been disclosed.
9.2 Correction
You may request correction of inaccurate or incomplete Personal Data. You can also update certain information directly through your Account settings.
9.3 Deletion
You may request deletion of your Personal Data, subject to exceptions where retention is required by law, necessary for the performance of a contract, or necessary to establish, exercise, or defend legal claims.
9.4 Restriction
You may request restriction of processing of your Personal Data in certain circumstances, including while we verify the accuracy of contested data or assess a request to object to processing.
9.5 Objection
You may object to processing of your Personal Data based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, or where processing is necessary for legal claims.
9.6 Data Portability
You may request to receive your Personal Data in a structured, commonly used, machine-readable format, and to have that data transmitted directly to another controller, where technically feasible and where the processing is based on consent or contract and carried out by automated means.
9.7 Marketing Communications
You may opt out of marketing and promotional communications at any time by clicking the "unsubscribe" link in any marketing email or by updating your communication preferences in your Account settings. Service-related and administrative communications are not subject to opt-out.
9.8 Withdrawal of Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
9.9 Automated Decision-Making
We do not use Personal Data to make decisions that produce legal or similarly significant effects on individuals based solely on automated processing, except where necessary to perform a contract, authorized by applicable law, or based on your explicit consent.
9.10 California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information. This section describes those rights.
Categories of Personal Information Collected. We have collected the following categories of personal information in the preceding 12 months:
- Identifiers (name, email, IP address, Account identifiers).
- Commercial information (billing records, subscription details).
- Internet or other electronic network activity (usage data, interactions with Services).
- Geolocation data (derived from IP address).
- Professional or employment-related information (company name, title, where provided).
- Inferences drawn from other personal information (preferences, usage patterns).
Sources. We collect this information from sources described in Section 3 of this Privacy Policy.
Business or Commercial Purposes. We collect and disclose this information for purposes described in Sections 4 and 5 of this Privacy Policy.
Disclosure and Sale. We disclose personal information to the categories of third parties described in Section 5. We do not sell personal information as defined under the CCPA, and we have not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of individuals under 18 years of age.
Sensitive Personal Information. We only use and disclose sensitive personal information (such as Account login credentials) for purposes permitted under the CCPA, and we do not process sensitive personal information for purposes of inferring characteristics about individuals.
Your CCPA Rights. As a California resident, you have the right to:
- Know what personal information we have collected, used, disclosed, and sold or shared about you.
- Request deletion of your personal information, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (we do not sell personal information).
- Limit use and disclosure of sensitive personal information (we already limit such use).
- Not receive discriminatory treatment for exercising your CCPA rights.
Exercising Your Rights. To exercise your California privacy rights, contact us at privacy@frontal.dev or submit a request through your Account settings. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf; we may require the agent to provide proof of authorization.
Data Retention. We retain each category of personal information as described in our Data Retention Policy.
No Financial Incentive. We do not offer financial incentives for the collection or sale of personal information.
California Shine the Light. California residents may request information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, contact us at privacy@frontal.dev.
9.11 EEA, UK, and Switzerland Privacy Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following applies:
Legal Bases. Our legal bases for processing Personal Data include:
- Performance of a contract (our Terms of Service).
- Our legitimate interests, as balanced against your rights and freedoms.
- Your consent.
- Compliance with legal obligations.
Rights under GDPR/UK GDPR. You have the rights under Articles 15-21 of the GDPR, including access, rectification, erasure, restriction, portability, and objection, as described in this Section 9.
Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority in the EEA, UK, or Switzerland. Contact details for our EU Representative are provided in our EU Representative Notice.
9.12 Exercising Your Rights
To exercise any of the rights described in this Section, contact us at:
Email: privacy@frontal.dev Mail: Frontal Labs, Inc., Attn: Privacy Team, 131 Continental Drive, STE 305, Newark, DE 19713, United States of America
We will respond to requests within one month of receipt (extendable by two further months for complex or numerous requests, in which case we will inform you of the extension within the first month). Where we cannot verify your identity, we may deny the request. We will not discriminate against you for exercising your rights.
If you are a data subject whose Personal Data is processed by Frontal on behalf of a Customer (as a data processor), you should direct your request to the relevant Customer. We will assist Customers in responding to data subject requests as required by our Data Processing Agreement.
10. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to third-party websites, services, and integrations. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party services you access.
11. CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this Privacy Policy at any time. For material changes, we will notify you by:
- Sending an email to the primary email address associated with your Account.
- Posting a prominent notice on the Site.
- Displaying a notice within the Services interface.
Material changes take effect 30 days after notification. Non-material changes take effect upon posting. Your continued use of the Services after a change constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you may terminate your Account in accordance with our Cancellation Policy.
12. CONTACT US
General Privacy Inquiries: Frontal Labs, Inc. Attn: Privacy Team 131 Continental Drive, STE 305 Newark, DE 19713 United States of America Email: privacy@frontal.dev
Data Protection Officer: Email: dpo@frontal.dev
Lead Supervisory Authority (EU): Comissao Nacional de Proteccao de Dados (CNPD), Portugal Av. Dom Carlos I, 134, 1200-651 Lisboa, Portugal Frontal's operational team is located in Portugal, which constitutes an establishment under Article 3(1) GDPR. The CNPD is the lead supervisory authority for cross-border processing.
A Portuguese-language version of this Privacy Policy is available at https://frontal.dev/pt/legal/privacy-policy. Versao em Portugues disponivel em https://frontal.dev/pt/legal/privacy-policy.
EU Establishment and Lead Supervisory Authority: Frontal has an establishment in Portugal. The lead supervisory authority is the CNPD. See our European Data Protection Notice.