Privacy Policy
Your privacy is important, and this Privacy Policy explains how information about you is collected,
used, and disclosed by the Company when you visit the websites within the domain aheadsheep.com (the "Site") and
use
the
Company's services (collectively, the "Services").
The Company collects minimal information to provide services to users. Currently, the only personal data
retained on Company servers is IP addresses and related request information in standard access and error logs, which are rotated every 90 days.
In the future, additional information may be collected if you choose to use optional features such as
newsletters or cloud storage, and any such changes will always be reflected in this policy.
IP Address: IP addresses and related request information may be collected for security, fraud detection, or
performance monitoring purposes. These may be stored temporarily in access logs for the following
purposes:
- Security monitoring: Ensuring the website is protected from unauthorized access
or malicious activity.
- Operational performance: Monitoring traffic to maintain the availability and
proper functioning of the website.
IP addresses and related request information are not used for profiling, tracking, or analytics by the Company. If you choose to use optional
features in the future (such as newsletters or cloud storage), additional information you provide will only be
collected as necessary to deliver those services.
Local Storage: The Site also may use local browser storage technologies, such as IndexedDB
(IDB), to save settings, preferences, and project data directly on your device. This information is never
transmitted to the Company's servers and remains entirely under your control.
Where optional tracking or data collection is available, the Company provides controls for managing consent
preferences. No non-essential tracking is performed without the required consent.
For more details, please refer to the Cookie Policy.
Security Measures: The Company uses encryption and other security measures to protect sensitive
personal data where appropriate.
To Provide and Improve Services:
- Deliver, maintain, and improve the Site and its functionality.
- Use IP addresses and related request information in access logs for security monitoring, fraud detection, and
operational performance.
Legal Compliance:
- Comply with applicable laws, regulations, and legal processes.
- Enforce the Company's policies and protect the Company's rights.
No Routine Sharing: The Company does not sell or share personal data with third parties for
marketing or advertising purposes. No data is used for profiling or advertising.
For Legal Compliance: Information may be disclosed if required to comply with applicable laws,
regulations, legal processes, or government requests.
For Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of
the Company's assets, user information may be transferred to the new owner as part of that transaction.
With Your Consent: The Company may share information with third parties for optional services
when you have provided the required consent.
Cookie Policy
Current Use of Storage: The Site may use local browser storage technologies, including IndexedDB
(IDB), to save settings, preferences, and project data directly on your device. This information is not
transmitted to the Company's servers and remains under your control. You can clear this stored data at any time
through your browser's settings.
Cookies: The Site makes minimal use of traditional cookies. Essential cookies may be set to
support basic functionality (such as remembering consent choices). These cookies do not track users across
websites or build behavioral profiles.
Consent Management: Where applicable, the Site provides users with control over non-essential
cookies and tracking technologies. By default, no non-essential cookies or tracking technologies are used unless
you provide consent.
Future Use: If the Company introduces optional features in the future that rely on cookies or
third-party services (such as analytics or advertising), those services may place cookies or similar
technologies. Any such changes will be disclosed in this policy and subject to your consent.
Data Security
The Company takes the security of user information seriously. At present, the only personal data collected by
the Site consists of IP addresses and related request information in temporary server logs, which are automatically deleted after 90 days. All
project data created in the Site's tools is stored locally in your browser (e.g., IndexedDB) and never sent to
the Company's servers.
To protect the limited data the Company does handle, the following measures are in place:
Technical Safeguards
- Encryption to protect data in transit (SSL/TLS) when transmitted over the internet.
- Regular security updates and monitoring to protect against vulnerabilities.
- Firewalls and intrusion detection systems to monitor for unauthorized access.
Administrative Safeguards
- Access controls to ensure only authorized personnel can view server logs.
- Data minimization practices, ensuring only necessary information is collected and retained.
While these measures reduce risk, no security system is impenetrable. Users remain in control of locally stored
data (IndexedDB) and may clear it at any time through their browser settings.
Retention of Data
Retention period: The Company retains personal data only for as long as necessary to provide
services and comply with legal obligations. At present, the only personal data collected is IP addresses and
related request information in server access logs, which are securely stored for 90 days and then permanently
deleted. After deletion, the data is not retained in backups.
Legal Obligations: If required by law (for example, in response to a valid request from law
enforcement), the Company may retain access logs beyond the standard retention period. In such cases, retention
will be extended only for the duration necessary to comply with those obligations.
Future Features: If the Company introduces optional services in the future (such as accounts,
newsletters, or cloud storage), any personal data you provide will be retained only as long as needed to deliver
those services and comply with legal obligations. If you delete an account, associated data will be retained for
30 days to allow reactivation, then permanently deleted from active systems. Secure backups may retain data for
a limited period solely for compliance and recovery purposes, after which it will also be permanently deleted.
User Rights
Opt-Out: If the Company ever introduces personalized ads, users will have the right to opt out.
Access and Correction: Users have the right to access the personal data held by the Company. At
present, this is limited to IP addresses and related request information in server logs, which are automatically deleted after 90 days. If you
provide additional data in the future (such as an email address for newsletters), you may also request
corrections to that information. Project data created in the Site's tools is stored locally in your browser
(e.g., IndexedDB) and cannot be accessed by the Company.
Data Portability: Users may request a copy of personal data actually held by the Company (e.g.,
email addresses if collected in the future) in a structured, commonly used, machine-readable format. Locally
stored data in your browser is under your control and can be exported or cleared through your browser's
settings.
Deletion: Users may request deletion of any personal data provided to the Company,
subject to legal obligations. Server access logs are already deleted automatically after 90 days. Data stored
locally in your browser (IndexedDB) remains under your control and can be cleared at any time through browser
settings or by removing site data.
Objection: Users may object to the processing of their personal data for direct marketing
purposes.
Restriction of Processing: Users may request restriction of processing in certain
circumstances.
Cookie Consent: Where applicable, users can update or withdraw consent at any time through the consent management
tool on the Site.
International Data Transfers
Current Practice: The Company does not transfer personal data internationally. At present, the
only personal data collected consists of IP addresses and related request information in access logs, which are stored securely on servers
located in the United States and remain under the Company's control.
Future Services: If optional features are introduced in the future (such as newsletters or
cloud storage) that require international data transfers, the Company will ensure that appropriate safeguards
are in place in accordance with applicable data protection laws, including the GDPR.
Data Transfer Mechanisms: Any future transfers of personal data outside the EU/EEA will be
carried out in compliance with applicable law, using mechanisms such as Standard Contractual Clauses (SCCs) or
other legal tools approved by the European Commission.
California Consumer Privacy Act (CCPA) Compliance
California Residents' Rights: In addition to the rights described above, California residents
have the right to:
- Request the categories of personal data collected, the sources of that data, and how it is used. At present,
the only personal data collected consists of IP addresses and related request information in temporary server logs.
- Request deletion of personal data, subject to exceptions (e.g., legal obligations). Access logs
are already automatically deleted after 90 days.
- Opt out of the sale of personal information. The Company does not sell or share personal information for
marketing or advertising purposes, but this right is provided under the law.
To exercise these rights, contact information for legal correspondence is provided below.
Data Breach Notification
The Company takes data security seriously and implements measures to prevent unauthorized access. Because the
Site collects only limited personal data (such as IP addresses and related request information in temporary server logs), the risk of exposure
is minimal.
In the unlikely event of a data breach that may compromise personal information, the Company will notify
affected users within a reasonable timeframe and in accordance with applicable law. If optional features are
introduced in the future (such as accounts or newsletters), those services will include appropriate safeguards
and notification procedures.
Third-Party Links
External links for your convenience: The Site may contain links to third-party websites,
products, or services. These links are provided solely for convenience and do not constitute an endorsement or
recommendation by the Company.
No control over third-party content: The Company does not control, and is not responsible for,
the content, privacy policies, or practices of third-party websites. When you follow a link, any information you
provide is governed by the policies of that third-party, not by this Privacy Policy. Users are encouraged to
review the privacy policies and terms of service of any third-party websites they visit.
Children's Privacy
The Company does not knowingly collect personal information from children under the age of 13. At present, the
Site only records limited technical information (such as IP addresses and related request information in server logs) for security and
operational purposes. These logs are automatically deleted after 90 days, are not linked to individual users,
and are never used for profiling or marketing.
If optional features are introduced in the future (such as accounts or newsletters), they will be available only
to users aged 13 and over. The Company will implement safeguards to comply with applicable child data protection
laws (such as COPPA in the United States and GDPR-K in the EU) to prevent collection of personal information
from children under 13. If any personal information from a child under 13 is inadvertently collected, it will be
promptly and permanently deleted.
Changes to the Privacy Policy
The Company may update or modify this Privacy Policy from time to time. Any changes will be effective
immediately upon posting the revised Privacy Policy on the Site. A summary of material changes will also be
noted in the Change Log included with this policy.
Users are responsible for reviewing this Privacy Policy and the Change Log periodically.