Overview
This privacy policy explains how Freewave.dev, a service operated by Carrot & Flower LLC, doing business as Freewave.Online ("Freewave," "we," "us"), collects, uses, and protects your personal information when you use our website and services. We keep things straightforward — no legalese walls.
Information We Collect
We collect the following information when you sign up or contact us:
- Name and email address — to create your account and communicate with you
- Phone number — if you provide one, for optional contact
- Website and project details — to understand your needs and deliver the service
- IP address and browser information — for security and fraud prevention
- Payment information — processed securely by Stripe (we never see or store your card details)
How We Use Your Information
We use your information to:
- Provide the service — build, manage, and maintain your website
- Communicate with you — account updates, login codes, service notifications, and occasional follow-up emails if you've expressed interest in our services. You can unsubscribe from promotional emails at any time using the link in those emails.
- Process payments — manage your subscription through Stripe
- Improve our service — understand how customers use Freewave so we can make it better
- Prevent fraud and abuse — protect our platform and your account
Third-Party Services
We use a small number of trusted third-party services to operate Freewave:
- Stripe — payments. We bill our own subscriptions through Stripe, and a business that uses Payments can connect its own Stripe account to get paid by its customers. Stripe handles all card and bank details under their own privacy policy.
- Square — payments. A business that uses Payments can connect its own Square account instead of Stripe to get paid by its customers. Square handles all card and bank details under their own privacy notice.
- Cloudflare Turnstile — spam prevention on forms. Cloudflare may collect limited data as described in their privacy policy.
- Resend — email delivery. Login codes, account notifications, form submissions, and the payment requests businesses send their customers are sent through Resend under their privacy policy.
- Postmark — newsletter delivery. If you use the Newsletter app, your subscribers' email addresses and delivery events are processed by Postmark under their privacy policy.
- Telnyx — text message delivery. If you use the SMS app, recipient phone numbers and delivery events are processed by Telnyx under their privacy policy.
- Cloudflare — DNS management, CDN, and hosting for customer websites (Cloudflare Pages). Cloudflare may process traffic data as described in their privacy policy.
- Anthropic — AI models (Claude) that build and update websites. Your change requests, your website's files and content, photos you attach to a request, and text we screen before publishing (such as reviews submitted on your site) are processed by Anthropic to do that work, under their privacy policy.
- TypeSafe — spam screening for contact forms on websites we host. The message and form answers are sent to TypeSafe to help judge whether a submission is a genuine inquiry. The sender's name, phone number, and IP address are left out, as are any email addresses or phone numbers typed into the message, and only the domain of their email address is included. TypeSafe does not train its models on it; see their privacy policy.
- X (formerly Twitter) — advertising measurement. We advertise Freewave on X, and our own homepage at freewave.dev loads the X pixel so we can tell whether those ads bring visitors and signups. It tells X that a browser visited the page and may set X cookies; X handles that under their privacy policy. It never runs in your portal, on your website, or on anything your customers see.
- Backblaze B2 — encrypted offsite backups of website files and account data, stored under their privacy policy.
Your website's source files are stored in private git repositories on our own servers — not with a third-party code host — with encrypted offsite backups on Backblaze B2. The Freewave platform itself also runs on our own server infrastructure. We also use Telegram to deliver operational alerts to our own team (for example, that a change request needs attention).
We may use other AI model providers to operate the service. We only use AI providers, and settings, that do not allow your data to be used to train their models, and we add each provider to this list when we start using it.
We do not sell or rent your personal information, or your customers', and we do not share it with anyone else beyond the X pixel on our homepage described above.
Cookies
We use minimal cookies, strictly for functionality:
- Session cookies — to keep you logged in to your portal account. These expire after 24 hours of inactivity.
- Device trust cookies — if you choose to trust a device during login, a secure token is stored to streamline future logins.
The one exception is our own homepage: the X pixel described above may set advertising cookies from X there. If your browser sends a Global Privacy Control signal, the pixel does not load. Otherwise we do not use tracking cookies, analytics cookies, or third-party advertising cookies.
Website Visitor Statistics
Websites we host include a lightweight first-party counter so the site's owner can see how it is performing in their portal (the Site Stats app). When someone visits a page, we record the page address, the referring site, and an approximate location (country, region, and city) derived from the network connection — and we add 1 to a daily total.
This is deliberately not per-visitor tracking. It sets no cookie, stores nothing on the visitor's device, does not use fingerprinting, does not record IP addresses, and cannot follow a visitor between sites or between visits. Only day-level totals are kept, so no individual visitor can be identified from them. Site owners see these totals for their own site only.
People Who Pay a Business That Uses Freewave
Businesses that use Freewave can connect their own Stripe or Square account and take payments from their customers: through a store on their website, a payment request or deposit they send by email, an invoice, or their own pay page. This section covers the people who pay them, and the people they ask to pay.
What we keep. For each payment, request, or invoice, we keep the payer's name and email address, the amount, what it is for, any reference the business adds, and whether it has been paid. When Stripe or Square confirm a payment, we also keep the confirmation they send us. It can include a phone number (when the business asks for one at checkout), a billing address, and part of the card or bank details: for a card, only its brand and last four digits. Full card numbers and bank account numbers go straight to Stripe or Square; we never see or store them. When someone opens a checkout or pay page on freewave.dev, we also see their IP address, which we use only for security and to stop abuse.
Who it belongs to. This information belongs to the business and the person paying, not to us. We hold it on the business's behalf, only to send their requests and show them who has paid. We never use it to market anything, to the payer or to anyone else, and we never sell it.
Where it goes. The details needed to take a payment are passed to the business's own Stripe or Square account. There they are covered by Stripe's privacy policy or Square's privacy notice for people without a Square account, as well as the business's own. The business can see them there, and so can any other service the business has connected to that account. Payment request emails are sent through Resend, listed above.
How long we keep it. For as long as the business has a Freewave account. It is deleted along with the rest of the business's data, on the schedule under Data Retention below. Copies in our encrypted backups are deleted automatically within 180 days after that, and our offsite backup provider clears its last copy within a further 30 days. Deleting it here does not delete the business's own Stripe or Square records.
If you paid a business, or were asked to. The business decides how your details are used, so ask them to see, correct, or delete them. If you write to us instead, we will pass your request to the business and help them with it.
Data Retention
We retain your account information for as long as your subscription is active. After your subscription is cancelled, we retain your website files and account data for 90 days in case you decide to return. We'll send you reminder emails at 30 days, 7 days, and 1 day before deletion. At 90 days your account is closed, your site is taken offline, and your account records are deleted from our systems.
Backups. For a further 180 days after that, an encrypted offsite copy of your website's source files and media is kept in our private backup storage, so an account closed in error can still be recovered. Our account database, which holds your account records and the payment records described above, is backed up every day as well. Those encrypted copies are deleted on a rolling schedule, so your records can stay in them for up to 180 days after they are deleted from our systems. None of these copies is used for any other purpose, and all of them are deleted automatically; our offsite backup provider keeps a deleted copy for up to 30 days more before it is gone for good. If you would rather the copy of your website files be destroyed immediately, contact us and we'll remove it.
If your account is suspended due to non-payment, your data is retained until the suspension is resolved — either by paying the outstanding invoice (which restores your account) or by cancellation (which starts the 90-day retention period).
Contact form submissions are retained for business record-keeping purposes.
If you'd like your data deleted sooner, contact us and we'll remove it within 30 days, subject to any legal obligations we may have to retain certain records.
Data Security
We take reasonable measures to protect your information, including:
- Encrypted connections (HTTPS) for all data in transit
- Secure, httponly cookies with SameSite protections
- Rate limiting on login attempts
- Secrets and credentials stored outside the public web directory
No system is 100% secure, but we take the security of your data seriously and follow industry best practices.
Data Breach Notification
If we discover unauthorized access to your personal data, we will notify you within 30 days of becoming aware of the breach and take immediate steps to remediate the issue. We will also notify relevant authorities as required by applicable law.
Your Rights
You have the right to:
- Access your data — request a copy of the personal information we hold about you
- Correct your data — update inaccurate or incomplete information
- Delete your data — request removal of your personal information
- Export your data — receive your data in a portable format
To exercise any of these rights, email us at [email protected].
If you paid a business that uses Freewave, or got a payment request or invoice from one, your details are that business's to manage, so ask them first. People Who Pay a Business That Uses Freewave, above, explains how we help.
Children's Privacy
Freewave is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this privacy policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. Continued use of the service after changes are posted constitutes acceptance of the revised policy.
Questions?
If you have any questions about this privacy policy or how we handle your data, reach out at [email protected] or call (321) 222-0889.