Workbench Privacy Notice
- Effective date
- 2026-09-01
- Version
- workbench-public-privacy-owner-approved-2026-09-01-r7
This Privacy Notice explains how HardwareHub handles personal information in Workbench. It supplements the privacy notice for the public Hardware Hub website. If the notices conflict for Workbench activity, this Workbench notice controls.
1. Scope and roles
This notice applies to Workbench accounts, projects, files, support, billing, and security activity. HardwareHub generally decides how account, billing, support, and security information is used. For personal information that you place in project content, you decide what to submit and are responsible for having an appropriate basis to do so; HardwareHub processes it to provide the Service.
The initial self-service offering is available only to adult account holders whose primary residence is in the United States. An organization bound by the account holder must be organized in or have its principal place of business in the United States. Each Individual workspace is intended for one account holder and does not provide team-member or external-collaborator access. Workbench is not directed to children.
2. Information we handle
Account and identity information
Name or display name, email address, authentication identifier, optional Google identity subject, verification status, MFA/session state, workspace membership and role, account status, and records of legal acceptance.
Project and business information
Project titles, briefs, deliverables, revisions, decisions, risks, schedules, bills of materials, parts, materials, costs, suppliers, business contacts, quotes, documents, reviews, handoffs, directory searches, displayed vendor matches, fit inputs and scores, saved or dismissed vendor suggestions, audit history, and notifications.
Files and file metadata
Uploaded file bytes plus file name, type, size, checksum, version, project association, upload status, and private storage metadata.
Communications
Support requests, feedback, issue reports, and screenshots you choose to provide.
Sensitive data excluded from launch
Workbench does not request or authorize identifiable consumer health data or other sensitive personal data prohibited by the Terms in User Content, and HardwareHub does not intentionally infer a person's health status or other sensitive characteristics from project content. Ordinary business contact information, product or medical-device designs and specifications, and deidentified technical or test data not linked or reasonably linkable to a natural person remain within the launch scope.
If HardwareHub learns that prohibited sensitive data was submitted, it may restrict access and process only the minimum necessary to secure, investigate, return, quarantine, or delete it; notify relevant processors; comply with law; and document the response. Continued processing for another purpose requires a separate legal, privacy, security, and product review.
Billing information
Billing contact name, email, address, and tax information where provided; plan, price, currency, subscription status, billing period, Stripe customer/subscription identifiers, invoice and payment-event status, and acceptance records. Stripe processes full payment-card information; HardwareHub does not store full card numbers or card security codes.
Technical and security information
IP address, hosting-derived country code, request and response metadata, timestamps, browser/device information made available through ordinary HTTP activity, authentication cookies, security and audit events, rate-limit events, and error logs. Browser local or session storage may hold preferences, navigation state, draft text, request identifiers, or selected project identifiers. We use the country code for fraud prevention and to enforce the U.S.-only restriction on new public signup and new paid checkout; we do not use it to block an existing customer merely because they travel.
3. Sources
We receive information from you; automatically from your browser and use of the Service; from authentication, hosting, storage, email, CAPTCHA, and payment providers; and from HardwareHub support or security personnel.
4. Why we use information
We use information to:
- create and secure accounts;
- provide projects, uploads, downloads, exports, billing, support, and other requested features;
- search and organize the vendor directory, calculate and display project-fit information, and record vendors you choose to add, dismiss, or track;
- verify permissions, plan limits, and user-directed sharing;
- process subscriptions and reconcile payment status;
- respond to support, privacy, security, and legal requests;
- detect abuse, prevent fraud, investigate incidents, and maintain audit records;
- measure reliability, capacity, and cost;
- enforce the U.S.-only launch scope and applicable tax, sanctions, and fraud controls;
- improve the Service using feedback and aggregated or deidentified service-usage and reliability information; and
- comply with law and enforce agreements.
We do not use User Content for targeted advertising. We do not use the substance of User Content to improve the Service except at your direction or with separate consent.
5. Providers and disclosures
We use providers only for the functions described below. A current vendor register will identify the providers enabled in production.
- Supabase: authentication, Postgres database, and object storage.
- Vercel: application hosting, functions, delivery, and runtime/security logs.
- Google: Sign in with Google if that option is enabled and you choose it.
- Cloudflare Turnstile: CAPTCHA and abuse prevention when public authentication is enabled.
- Resend: transactional authentication email when custom SMTP is enabled.
- Stripe: checkout, payment processing, invoices, subscription management, and customer portal when paid purchasing is enabled.
We may also disclose information to personnel and contractors who need it to operate or support Workbench; to professional advisers under appropriate duties; in a business transaction subject to continued protections; to comply with lawful process; or when reasonably necessary to protect users, HardwareHub, or the public.
HardwareHub personnel do not review the substance of project content for ordinary administration, development, analytics, or convenience. Support starts with metadata and sanitized information you choose to provide. Human content access ordinarily requires your verified, explicit authorization for the exact case and scope. A narrowly necessary security or legal emergency may use logged, time-limited break-glass access without advance approval; HardwareHub will review that access and notify you promptly unless law prohibits notice.
We do not sell personal information or project content. We do not share personal information for cross-context behavioral advertising. We do not use advertising pixels or session-replay software in Workbench at launch.
Vendor-directory entries may include public business and contact information, information a vendor provides, and HardwareHub's curated directory records. Searching the directory or adding a listing to a project does not contact that vendor and does not send it User Content. If you open a vendor's external website or contact link, that third party receives the ordinary information associated with your visit under its own privacy notice. HardwareHub shares User Content with a vendor only when you deliberately use an available sharing feature or separately direct the disclosure.
6. Limits on new processing
HardwareHub does not sell User Content, use it for advertising, or use it to train or fine-tune an AI or automated model. The current Individual Service has no AI-generated or AI-assisted feature, AI chat, or general question-answering interface, and it does not send User Content to an AI or automated-model provider. Before a material new purpose, processor, feature, or transfer involving User Content begins, HardwareHub must update this notice and obtain any user choice required by law. Existing acknowledgment does not authorize processing that is not described here.
7. Cookies and browser storage
Workbench uses essential cookies for authentication, security, continuity, selected-workspace state, and timezone preferences. It may use browser local or session storage for interface preferences, unsent drafts, selected project state, and opaque request or session identifiers. Workbench does not intentionally retain complete project files or complete project records in browser storage after signout or an account change. First-party continuity cookies last up to 15 minutes, selected-workspace cookies up to 30 days, and timezone-preference cookies up to one year. Authentication cookies follow the authenticated session lifetime. Session storage ordinarily lasts until the browser tab or session ends; local storage lasts until replaced or cleared. Third-party authentication, CAPTCHA, and payment pages may set their own necessary cookies under their notices. The separate Cookie Notice identifies these categories and controls.
Authentication, CAPTCHA, and payment providers may collect device and interaction information under their own notices, including information they receive across services. HardwareHub does not authorize them to use User Content for advertising.
Workbench does not use advertising, cross-site tracking, analytics, or session-replay cookies at launch. Because there is no targeted advertising or sale/sharing workflow, there is presently no separate sale/sharing opt-out or nonessential-cookie banner. We treat a recognized Global Privacy Control signal as an opt-out from sale, sharing for cross-context behavioral advertising, and targeted advertising; the current no-sale/no-targeting posture already satisfies that choice. We do not change the essential-only behavior based solely on the older Do Not Track signal.
8. Retention and deletion
We keep information only as long as needed for the purposes described here. The following are ordinary maximum schedules, not promises to retain information for the full period. A shorter period applies when law requires deletion sooner, and a longer period applies only when a legal minimum, documented legal hold, dispute, or security investigation requires it:
- Active account and project content is retained while the account remains active and as needed to provide the Service.
- Archiving a project does not delete it.
- Canceling a paid plan does not delete the account or existing project content. Over-limit content is handled through the notice, download, and cure process in the Terms rather than automatic deletion.
- The available Individual project JSON export contains structured project records and file metadata; it excludes file bytes. Files must be downloaded separately.
- Universal workspace export and self-service hard deletion are not currently available.
- After a verified account-closure or deletion request, eligible User Content will be removed from active systems within the time required by applicable law and ordinarily within 45 days. If applicable law permits and circumstances reasonably require an extension, HardwareHub will notify the requester within the initial period and complete the request within the permitted extended period. Retention remains permitted for security, billing, disputes, legal obligations, or a legal hold, and account or service-usage records may instead be deidentified where lawful.
- Expired or abandoned upload objects are removed only after the Service verifies that they are not attached to a completed file version, ordinarily within seven days after they become eligible for cleanup.
- Routine security, audit, and service logs may be kept for up to 24 months; records tied to an incident may be kept for the duration of the investigation and resulting legal limitation period.
- Support and privacy-request records may be kept for up to three years after resolution.
- Billing, tax, subscription, and legal-acceptance records ordinarily may be kept for up to seven years after the relevant transaction or account closure. Verification of recurring-subscription consent is kept for at least three years or one year after the subscription ends, whichever is longer, even if that legal minimum extends beyond the ordinary seven-year schedule.
- Deleted or isolated information may remain in restricted backups for up to 90 additional days, and longer under a legal hold.
Users may contact privacy@hardwarehub.io to request account closure or deletion. This verified email procedure is the supported launch path; self-service hard deletion is not offered. HardwareHub will verify the request, offer the available export and separate file download, explain any information that must be retained, and respond within the time applicable law requires. Deletion from backups and provider logs follows the applicable rotation schedule, subject to legal holds and security needs.
9. Choices and privacy requests
You may request access, correction, deletion, or a portable copy of personal information, or appeal a denied request. HardwareHub uses this as its U.S. operational baseline even when a particular state-law threshold does not apply. You may also opt out of any future sale, sharing for cross-context behavioral advertising, targeted advertising, or qualifying automated profiling; HardwareHub does none of those at launch. We may verify identity and authority before acting. Some information may be retained where permitted for security, billing, legal obligations, fraud prevention, dispute handling, or documentation of the request.
The self-service project export and separate file-download tools are the ordinary portability paths. If those tools are insufficient for a verified portability request, HardwareHub will use a secure method to provide the applicable personal information, including eligible file bytes when required by applicable law, subject to identity verification, the rights of others, and lawful exceptions. This assisted legal-response path is not a universal workspace-export feature.
Send requests to privacy@hardwarehub.io from the email used for the account and include enough detail to identify the request. Do not send passwords, authentication secrets, or sensitive project files by email. We will not discriminate against a user for exercising an applicable privacy right. If we deny a request, our response will explain the reason and any available appeal right. To appeal, reply to that response or email the same address with the subject Privacy Appeal.
10. Security
HardwareHub uses safeguards appropriate to the Service's current configuration, such as encrypted transport, provider-managed encryption at rest, authentication, authorization checks, server-side validation, and restricted privileged operations. Where file uploads are enabled, uploaded objects are stored in private, access-controlled storage and download access is authorized for a limited time. Workbench is not end-to-end encrypted or zero-knowledge, and it does not currently use customer-managed encryption keys. Authorized systems, service providers, and the narrowly permitted personnel described above can process content as needed to provide, secure, support, or legally administer the Service. No security method is perfect, and we cannot guarantee that every transmission, storage system, or third-party provider will be secure against every threat.
Report a suspected security or cross-account data issue promptly to security@hardwarehub.io. HardwareHub will investigate, preserve an incident record, and provide any notification required by applicable law within the applicable deadline and without unreasonable delay after discovery of the incident, while continuing to determine its scope and affected individuals, subject only to delay permitted by applicable law.
11. International processing
HardwareHub and its providers may process information in the United States and other countries where they operate. We do not promise a particular data-residency location unless agreed in writing. Only account holders whose primary residence is in the United States, and qualifying U.S. organizations they bind, are eligible for the initial self-service offering.
12. Children
Workbench is intended for adults and is not directed to children under 18. Do not submit children's personal information. If you believe a child has provided information, contact privacy@hardwarehub.io.
13. Changes and contact
We will post changes with a revised effective date. We will provide advance notice of a material change that affects how previously collected information is used and obtain consent where required. We will not silently convert previously collected project content into advertising or model-training data.
Privacy contact: privacy@hardwarehub.io Accessibility assistance and feedback: support@hardwarehub.io Mail: Hardware Hub Consulting, LLC, 2256 Northlake Parkway, Ste 110 PMB1033, Tucker, GA 30084, United States