Legal

Privacy Policy

Last updated: April 1, 2026

1. Introduction

PCB Cupid (“we”, “our”, or “us”) operates pcbcupid.com, shop.pcbcupid.com, app.pcbcupid.com, and related services (collectively, the “Services”). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

By using our Services you agree to the practices described in this policy. If you do not agree, please discontinue use.

2. Information We Collect

Account information. When you register, we collect your name, email address, and a hashed password. If you sign in via a third-party provider (Google, GitHub), we receive the profile information that provider shares.

Usage data. We log interactions with Circuit Spell — prompts submitted, designs generated, exports triggered — solely to improve the AI model and debug errors. Prompt text is never sold or shared with third-party advertisers.

Order and payment data. For shop purchases, billing name, shipping address, and order history are stored. Payment card details are processed directly by Razorpay and are never stored on our servers.

Technical data. IP address, browser type, device identifiers, and page-view events are collected automatically for security monitoring and performance analysis.

3. How We Use Your Information

  • Provide, operate, and improve the Services.
  • Process orders and send order confirmations.
  • Send product updates, security notices, and support replies.
  • Detect and prevent fraud, abuse, and security incidents.
  • Train and fine-tune AI models used in Circuit Spell (using anonymised, aggregated data only).
  • Comply with legal obligations.

We do not sell your personal data. We do not use your design files or prompt history for targeted advertising.

4. Third-Party Services

We use the following sub-processors who may receive your data as necessary to operate the Services:

  • Razorpay — payment processing (PCI-DSS compliant).
  • PostHog — product analytics (self-hosted; EU-resident data stays in the EU).
  • Supabase — database and authentication infrastructure.
  • Cloudflare — CDN, DDoS protection, and edge compute.
  • ZeptoMail — transactional email delivery.

Each sub-processor is bound by a Data Processing Agreement consistent with GDPR requirements where applicable.

5. Cookies & Analytics

We use strictly necessary cookies for authentication sessions and CSRF protection. We also set first-party analytics cookies (via PostHog) to understand how features are used. We do not place third-party advertising cookies.

You may disable non-essential cookies in your browser settings. Doing so will not affect core functionality.

6. Data Retention

Account data is retained for the lifetime of your account plus 90 days after deletion to allow recovery from accidental deletions. Order records are retained for seven years to comply with tax and accounting regulations. Anonymised, aggregated analytics data may be retained indefinitely.

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, or to object to or restrict its processing. To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be announced via email or an in-app notice at least 14 days before they take effect. Continued use of the Services after the effective date constitutes acceptance of the revised policy.

9. Contact Us

PCB Cupid — privacy queries: [email protected]