makerHQ
← Back to MakerHQ

Privacy Policy

Last updated: July 22, 2026

This policy explains how MakerHQ collects, uses, stores, and discloses personal data when people visit MakerHQ, create or join a workspace, use MakerHQ tools, interact with the MakerHQ assistant, or appear in customer-managed records. It also explains the choices and privacy rights that may be available.

1. Scope of This Policy

This policy applies to several distinct categories of individual:

  • Account holders: individuals who create MakerHQ accounts or join a MakerHQ workspace and use products such as Clients, Tasks, Pricing, Products, Mockups, Orders, Machines, MakerCRM, Laser Settings, SVG tools, Academy, Partner Tools, or the MakerHQ assistant.
  • Leads: individuals whose contact information is imported into, discovered through, or managed in MakerCRM by a MakerHQ customer (an “Operator”), including people who have not created a MakerHQ account.
  • End customers: individuals who place orders or otherwise transact through a portal operated by an Operator using MakerCRM. End-customer data is treated as a distinct and more sensitive data category.
  • Site visitors: anyone who visits the MakerHQ website without creating an account.

For account administration, platform security, product operations, and MakerHQ’s own business purposes, MakerHQ generally determines why and how personal data is processed. For lead, client, order, and end-customer records a customer places in its workspace, MakerHQ generally processes that data on the customer’s instructions, and the customer remains responsible for its own notices and lawful use.

If you are a lead or end customer whose data has been processed through MakerHQ and you wish to exercise your privacy rights, please contact us at contact@makerhq.com. We will respond to verifiable requests in accordance with Applicable Law.

2. Information We Collect

From account holders:

  • Account data: name, email address, password hash or federated login, workspace name, invitations, team membership, role, assistant name, and assistant personality settings.
  • Authentication data: session and verification information, multi-factor enrollment data, and basic profile information received from an identity provider when you use federated sign-in.
  • Subscription and billing data: subscription plan, service entitlements, payment processor customer or account identifiers, and billing address. Payment card details are handled by the payment processor; we do not receive full card numbers.
  • Usage data: feature use, settings changes, errors, security events, and other interactions recorded to operate, secure, and improve the service.
  • Device data: IP address, browser type, operating system, and device identifiers, used for security, fraud prevention, and debugging.
  • Communications: support requests, feedback, screenshots or files you attach, and other content you send to us.
  • Workspace and business data: business profile details such as website, logo, brand colors, contact details, social links, products, pricing inputs, machines, settings, files, mockups, tasks, client and order records, and data imported from a website or integration.
  • AI, memory, and inference data: prompts, uploaded images or files, chat messages, generated content, tool calls and action results, assistant feedback, saved personal memories, shared workspace facts and events, learned business and customer context, summaries, recommendations, and other inferences created to personalize MakerHQ.

From MakerCRM (Lead Data):

  • Contact information about leads imported into or discovered through MakerCRM by an Operator: name, business name, postal address, phone number, email address, and any associated metadata.
  • Engagement data: whether a lead opened a portal link, replied to an outbound email, placed an order, or unsubscribed.
  • Inbound email replies routed to an Operator’s configured inbound address, including the message body and headers.
  • Lead Data sourced through third-party business directories, discovery services, or integrations an Operator chooses to use.

From MakerCRM (End-Customer Data):

  • Order data submitted by end customers through an Operator’s portal: name, contact information, order details, customizations, uploaded artwork, and proof photos.
  • Payment-related metadata where Operators integrate a payment processor (we do not store full card numbers).

From Laser Settings:

  • The material/machine combinations queried, used to surface relevant settings and to improve recommendations. Anonymous queries do not require an account.

Cross-product: when an accountholder accesses a connected MakerHQ service, we exchange the limited account and access information needed to authenticate the user and authorize that service.

3. How We Use Your Data

  • To provide, maintain, personalize, secure, and improve MakerHQ and its tools.
  • To process payments and manage subscriptions and entitlements.
  • To authenticate you, manage sessions, apply workspace roles, and keep personal settings separate from shared workspace information.
  • To send transactional communications (account verification, password resets, billing receipts, security notifications) and, with your consent, product updates and marketing communications.
  • To prevent fraud, abuse, and unauthorized access.
  • To comply with legal obligations and respond to lawful requests.

4. Data Sharing and Service Providers

We do not sell your personal information. We do not share personal information for cross-context behavioral advertising as defined under the California Privacy Rights Act (CPRA), and we do not engage in the “sharing” of personal information as defined under CPRA. We disclose data in the following limited circumstances:

  • Service providers We use vetted providers to support hosting and data storage, account authentication, payment processing, communications, analytics and security, customer support, website retrieval, business-data discovery, and AI-enabled features. They may process personal data only as needed to provide those services, subject to contractual and legal obligations.
  • Workspace members within the active workspace so authorized seats can collaborate. Workspace-wide business profiles, clients, products, orders, machines, settings, shared AI facts, and similar business records may be visible to other workspace members according to their role. Personal assistant identity, personal memories, and user-scoped chats remain scoped to the individual unless the user intentionally shares their content or an action creates a workspace record.
  • Law enforcement or regulatory authorities when required by Applicable Law or valid legal process.
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.

5. Data Retention and Deletion

We retain different categories of data for different periods, balancing service functionality, legal obligations, and individual privacy:

  • Account data: kept while the account is active and afterward only as reasonably needed for account administration, security, dispute resolution, legal compliance, or an applicable deletion workflow.
  • Subscription and billing records: kept as reasonably necessary to administer subscriptions and meet tax, accounting, chargeback, and legal obligations.
  • Lead Data (MakerCRM): retained while the Operator’s workspace is active, subject to deletion on Operator instruction or on a verified request from the lead. Data obtained through third-party discovery sources may be subject to shorter retention required by those sources or Applicable Law.
  • End-Customer Data (MakerCRM): kept according to the Operator’s instructions and as reasonably needed for order fulfillment, returns, warranties, accounting, disputes, and legal obligations, then deleted or de-identified.
  • Inbound email messages (MakerCRM): kept while needed for the Operator’s communication history and service delivery, then deleted or de-identified under the applicable workspace or deletion workflow.
  • AI chats, outputs, memories, and inferences: MakerHQ may save chat threads, messages, generated content, tool results, personal memories, workspace facts and events, and learned business or customer context so the assistant can resume prior work and become more useful over time. Personal assistant identity, personal memories, and user-scoped chats are scoped to the individual; broader business facts and records may be shared across authorized workspace seats. Service providers that support AI-enabled features process relevant data under applicable contractual, privacy, and security obligations.
  • Shared workspace records: shared business information remains with the workspace for as long as needed to provide the service or until an authorized workspace administrator removes it, subject to legal, security, backup, and dispute-related retention. Removing one seat does not automatically erase shared workspace records.
  • Service usage records: kept for periods reasonably necessary to operate, secure, troubleshoot, and improve the service, then deleted or aggregated when practical.
  • Security and diagnostic records: kept for periods reasonably necessary for fraud prevention, debugging, security, abuse response, and legal compliance.

You may request earlier deletion of your data at any time by following the procedure on the Data Deletion page or by contacting us at contact@makerhq.com. We will respond within the timeframes required by applicable law. Some data may be retained where required by law or reasonably necessary for security, fraud prevention, disputes, legal claims, or shared-workspace continuity.

6. Cookies and Consent

MakerHQ uses cookies and browser storage to operate the service and remember choices. Browser storage may include cookies, local storage, and session storage.

  • Essential cookies: required for the platform to function, including session management, authentication, and security. These are set without separate consent because they are strictly necessary.
  • Preferences and local drafts: MakerHQ may use browser storage to remember interface preferences, settings, and unfinished drafts. MakerHQ does not currently use third-party advertising cookies. If optional analytics or other non-essential tracking is introduced, MakerHQ will provide any notice and consent controls required before activating it.

You can clear cookies and stored site data through your browser. Blocking strictly necessary storage may prevent sign-in, security features, or saved preferences from working.

7. Your Privacy Rights

Depending on your state or jurisdiction of residence, you may have the following rights regarding your personal data:

  • Right to know/access: request disclosure of the categories and specific pieces of personal data we have collected about you.
  • Right to deletion: request deletion of personal data we have collected, subject to legal exceptions.
  • Right to correction: request correction of inaccurate personal data.
  • Right to opt out of sale or sharing: we do not sell or share personal data as defined under CCPA/CPRA. If this practice changes, we will update this policy and provide an opt-out mechanism.
  • Right to limit use of sensitive data: to the extent we process sensitive personal data as defined under applicable law, you may have the right to limit its use.
  • Right to non-discrimination: we will not discriminate against you for exercising any of these rights.

These rights may apply under U.S. state comprehensive privacy laws and other applicable laws. To exercise a right, contact us at contact@makerhq.com. We will verify and respond within the time required by the law that applies.

Where applicable, an authorized agent may submit a request with proof of authority. If we deny a request, we will explain the basis and provide instructions for appealing the decision when the applicable law requires an appeal process. We will not discriminate against you for exercising a privacy right. Because MakerHQ does not sell personal data or use it for cross-context behavioral advertising, Global Privacy Control signals do not change the current processing described in this policy.

8. International Users and GDPR

MakerHQ is operated from and primarily directed to the United States. For account, security, and product operations, MakerHQ generally acts as the controller or business. For lead, client, order, and end-customer data that an Operator places in a workspace, MakerHQ generally acts as a processor or service provider on that Operator’s instructions. The Operator remains responsible for its own lawful basis, notices, and responses to people whose data it controls.

Lawful basis under GDPR. Where the General Data Protection Regulation applies, we rely on the following lawful bases under Article 6(1):

  • Performance of a contract: to provide the Subscription Services to accountholders.
  • Legitimate interests: to operate, secure, and improve the Subscription Services.
  • Consent: for optional marketing communications and other processing for which consent is required.
  • Legal obligation: to comply with Applicable Law.

Your GDPR rights. If GDPR applies to you, you have the right to access, rectify, erase, restrict processing of, port, and object to processing of your personal data. You may exercise these rights at contact@makerhq.com. You also have the right to lodge a complaint with your local supervisory authority.

International transfers. Personal data may be transferred to and processed in the United States and other countries where service providers operate. Where required, transfers are supported by an applicable adequacy decision, Standard Contractual Clauses, the UK addendum, or another lawful transfer mechanism used by MakerHQ or its provider.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed for the nature of the data and the service, including:

  • access controls and role-based permissions designed to limit data access;
  • encryption and secure transmission practices appropriate to the data and service;
  • monitoring, testing, and abuse-prevention processes;
  • restricted access by personnel and service providers based on business need;
  • procedures for identifying, assessing, and addressing security issues;
  • regular review of safeguards as the service evolves; and
  • incident assessment and legally required notification procedures.

No system can be guaranteed perfectly secure. If you become aware of a security issue, please report it to contact@makerhq.com.

10. Third-Party Services and Embedded Content

MakerHQ may link to or, after your interaction, load third-party sites, videos, partner tools, integrations, payment pages, or other embedded content. Those providers may receive technical information such as your IP address, browser details, referrer, or activity once their service loads, and their own policies govern their processing. MakerHQ is not responsible for a third party’s independent privacy practices.

11. Children’s Privacy

MakerHQ accounts are intended only for people who are at least 18 years old, and signup requires an age confirmation. MakerHQ is not directed or offered to minors. If we learn that a minor provided personal data in violation of this requirement, we will take appropriate steps to remove it.

12. Changes to This Policy

We may update this policy as MakerHQ changes. We will post the revised policy with a new “Last updated” date and, when required by applicable law or appropriate for a material change, provide an additional in-product notice or request renewed acceptance.

13. Contact

For privacy-related questions or to submit a rights request, contact us at contact@makerhq.com. See also our Terms of Service.