Privacy Policy

1. Who this policy covers

This policy explains how personal data is handled in connection with our HubSpot Asset Marketplace offerings: the Custom Pillbox Input module and the Custom Promo Card module (each an "Asset").

It distinguishes two very different groups:

2. What the Assets collect

Every Asset is composed solely of HubL templates, CSS, and client-side JavaScript that executes in the visitor's browser. As implemented in this repository, the Asset code contains:

We operate no server-side component and receive no data from your website or your visitors.

HubSpot's Template Marketplace Policies permit removal of templates that track users without informed, explicit opt-in consent. We do not track visitors at all, so no consent mechanism is required by the Assets themselves.

Because the Assets are GPL-licensed, you are free to modify them — including to add tracking. Any tracking, cookie, storage, or third-party script you add becomes your responsibility, and the claims in this section then describe only our unmodified distribution, not your copy.

3. Form input handled by the Custom Pillbox Input module

The Custom Pillbox Input module deserves specific mention because it is an input control.

The module renders a native <select multiple> element whose name attribute you configure (default: custom_pillbox_tags). Tags a visitor selects are written into that element in the browser. If you place the module inside a form, those values are submitted along with the rest of that form.

Where those values go is determined entirely by your form and your portal — typically to HubSpot as CRM or submission data. They never reach us. Consequently:

4. Data we process as a business

Although the Assets themselves collect nothing, we do process limited personal data in running our business:

PurposeDataSourceLawful basis
Responding to support requestsName, email, message content, portal details you choose to shareYou, by contacting usContract / legitimate interests
Marketplace transactionsPurchase and installation records, billing identifiersHubSpotContract / legitimate interests
Legal and accounting recordsTransaction recordsHubSpotLegal obligation

We do not sell personal data, and we do not use support correspondence for marketing without separate consent.

5. Processors and disclosures

We rely on:

We may also disclose data where required by law, or in connection with a merger or acquisition.

6. International transfers

We are based in the United States, and personal data you send us is processed there. Where personal data is transferred outside your jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses.

7. Retention

Support correspondence is retained for 24 months. Transaction and accounting records are retained for as long as required by applicable law. Because the Assets store nothing, there is no Asset-held data to retain or delete.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to withdraw consent. Exercise these rights by contacting daljo628@gmail.com; we respond within the period required by applicable law.

Requests about data collected through your website — including tags submitted via the Custom Pillbox Input module — must be directed to the operator of that website, not to us.

If you are in the EEA or UK you may also lodge a complaint with your local supervisory authority. The Assets are offered free of charge and we do not market or target them to any particular territory, the EEA and UK included, so we have not appointed an Article 27 representative.

9. Children

The Assets are developer tools and are not directed at children. We do not knowingly process personal data from children.

10. How to verify these claims

The Assets are free software, distributed under the GNU General Public License. You do not have to take section 2 on trust: the complete source of each Asset is available to you, and you are free to inspect it for network requests, cookies, storage writes, or tracking code. Neither Asset references an external URL at render time.

If a future release introduces any such behaviour, sections 2 and 3 of this policy will be updated before that release ships.

11. Changes to this policy

We may update this policy. Material changes will be reflected in the effective date above and published at the Privacy Policy URL on our marketplace listing.

12. Contact