Privacy Policy

Last updated: July 14, 2026

1. Introduction

VOIDCRAFT STUDIOS LLC ("we," "our," or "us") operates FrameOnce (frameonce.io). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

By using FrameOnce, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

2.1 Personal Information

When you sign up for our waitlist or create an account, we collect:

  • Email address (required)
  • Name (optional)
  • Business type/use case (optional)

If you request a full Shop Critique report, we collect your email address and the shop details you submitted (shop URL, platform, and your critique results) in order to generate and deliver the report. Requesting a full report also adds you to our waitlist audience, tagged with its source; you can unsubscribe at any time.

2.2 Image Data

Free demo: the product image you submit (or link to) on the free try-it page is processed to generate your standardized result. Where a step uses an AI or GPU provider (see Section 5), the image is sent to that provider solely to produce your result.

Free Shop Critique: we fetch publicly available catalog data (product listings and images) from the shop URL you submit, analyze a sample of those images via our AI analysis providers, and store the resulting report so your report link works. We do not create accounts for, or build profiles of, the shops analyzed.

Catalog workflow: we process the product images you upload or import, your processed output images, and your Style Preset configurations.

Image Retention Policy

We retain uploaded and processed working copies for 7 days to provide customer support, after which they are automatically deleted. Separately, each processed photo has a verification record (the registered original and output images, content fingerprints, processing metadata, shop name, and dates) that is retained for as long as the record exists, because the record is the service: it is what lets you prove how your photo was made. Records are private by default; you control whether a record's detail is published, and you can request deletion of your records (deleting a record means it can no longer back you up in a dispute). We do not use your images to train AI models; images sent to our service providers are used solely to deliver your results.

2.3 Analytics Data

We use Google Analytics and Microsoft Clarity for analytics, which collect:

  • Pages visited and time spent
  • Click and scroll behavior
  • Device type and browser information
  • Approximate geographic location (country/region level)
  • Traffic sources and referral data
  • Session recordings (mouse movements, clicks) via Clarity

These analytics tools do not collect personal information like your name or email. They respect standard privacy controls in your browser settings. Analytics are only loaded after you explicitly accept cookies.

2.4 Payment Information

We never store your credit card information. For plans purchased on our site, payment processing is handled by Stripe, which may act as the merchant of record for your purchase; Stripe's privacy policy applies to payment data:https://stripe.com/privacy. For plans purchased through the Shopify App Store, billing is handled entirely by Shopify and the charge appears on your Shopify invoice; we receive only your plan selection and its status, never your payment details.

2.5 Connected Shopify Stores

When you install the FrameOnce app on a Shopify store, or connect a store from your FrameOnce account, we collect and store:

  • Your store's domain, display name, and store contact email
  • An API access token authorizing product read/write access, encrypted at rest
  • Product catalog data (titles, images, and related metadata) that we read in order to standardize your images
  • The standardized images we publish back to products, only when you ask us to

Our Shopify access is limited to product data. We never request or receive your customers' (shoppers') personal data, orders, or checkout information. Uninstalling the app immediately invalidates and deletes the stored access token, and we honor Shopify's data-deletion requests: after Shopify notifies us of an uninstall-triggered erasure request, we delete the stored connection and store details, and for accounts that were created by an App Store install we delete the entire provisioned account and everything it contains. If you connected a store to a FrameOnce account you created yourself, that account and the work in it remain yours (see Your Rights below for account deletion). We respond to Shopify's privacy webhooks (data requests and redaction) within the timelines Shopify requires.

2.6 Technical Data

When you use our website and tools, we process your IP address and basic request metadata to enforce rate limits and usage caps on the free tools, to prevent fraud and abuse, and to keep the service secure. The free demo also uses Cloudflare Turnstile to verify you are human; Turnstile processes technical signals from your browser for that purpose only. This data is used only for those purposes and is kept transiently.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Generate the analysis results you request from our free tools
  • Process your images according to your Style Presets
  • Read your connected store's product catalog and, when you request it, publish standardized images back to it
  • Maintain verification records for photos processed by the paid workflow
  • Send you service-related communications (account updates, launch notifications)
  • Respond to your inquiries and provide customer support
  • Analyze usage patterns to improve user experience
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. Email Communications

We use Loops.so to manage our email list. When you join our waitlist, you will receive:

  • Welcome email confirming your signup
  • Launch announcement when FrameOnce goes live
  • Occasional product updates (no more than 2-3 per month)

You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email. Transactional emails (account-related) cannot be unsubscribed.

5. Data Sharing and Disclosure

We do not sell your personal information. We share data only with the service providers we use to operate FrameOnce, and as required by law:

  • AI analysis providers: images analyzed for Shop Critique and images processed by our editing and enhancement engine are sent to AI model and GPU providers solely to produce your results. We currently use OpenRouter (which routes requests to vision models operated by providers such as Google, Alibaba, and NVIDIA) and fal.ai (image segmentation and AI backgrounds).
  • Commerce platforms: Shopify, when you connect or install our app on your store: we read your product catalog and publish standardized images back through Shopify's APIs, and Shopify handles billing for plans purchased through its App Store
  • Infrastructure: Vercel (website hosting), Hetzner (processing backend hosting, EU data centers), Supabase (database for waitlist signups and critique reports), Upstash (rate limiting and job queues)
  • Email: Loops.so (waitlist and report delivery emails)
  • Payments: Stripe (plans purchased on our site; Stripe may act as merchant of record)
  • Abuse prevention: Cloudflare Turnstile (human verification on the free demo)
  • Analytics: Google Analytics and Microsoft Clarity (only after cookie consent)
  • Legal Requirements: when required by law, subpoena, or government request
  • Business Transfers: in connection with a merger, acquisition, or sale of assets

6. Data Security

We implement industry-standard security measures to protect your data:

  • HTTPS encryption for all data in transit
  • Encrypted storage for sensitive data at rest
  • Regular security audits and updates
  • Limited employee access to personal data

While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

7. Your Rights (GDPR & CCPA)

Depending on your location, you may have the following rights:

Legal Bases (GDPR)

Where the GDPR applies, we process personal data on the following bases: performance of a contract (providing the services and tools you request, including free-tool results and report delivery), legitimate interests (rate limiting, fraud and abuse prevention, service security and improvement), consent (marketing emails and analytics cookies, each withdrawable at any time), and legal obligation (where we must retain or disclose data by law).

For EU/EEA Residents (GDPR)

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing of your data
  • Restriction: Request limited processing of your data

For California Residents (CCPA)

  • Know: What personal information we collect and how it's used
  • Delete: Request deletion of your personal information
  • Opt-Out: Opt out of sale of personal information (we do not sell data)
  • Non-Discrimination: Equal service regardless of exercising rights

To exercise any of these rights, contact us at hello@frameonce.io. We will respond within 30 days. If you are in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority.

8. Cookies and Tracking

We use essential cookies for site functionality and analytics cookies via Google Analytics and Microsoft Clarity. We do not use advertising cookies or third-party tracking cookies. Analytics cookies are only loaded after you explicitly consent.

You can disable cookies in your browser settings, but some features may not work properly.

9. Children's Privacy

FrameOnce is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

10. International Data Transfers

Our image processing backend runs in EU data centers (Hetzner). Other service providers, including our website hosting, database, email, analytics, and AI analysis providers, may process data in the United States and other countries. Where personal data is transferred internationally, we rely on appropriate safeguards such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses, in compliance with applicable laws.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of our services after changes constitutes acceptance.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us:

VOIDCRAFT STUDIOS LLC

Email: hello@frameonce.io

Website: frameonce.io