Privacy Policy
Pen and Paper Solutions LLC
Last Updated: December 13, 2025
Overview
This Privacy Policy explains how Pen and Paper Solutions LLC ("we," "us," or "our") collects, uses, and protects information in connection with Ductwork, including our open-source Ruby gem, commercial Ductwork Pro offering, and associated websites.
What We Collect
Account Information
When you create an account on our website, we collect:
- Email address
- Password (stored securely using industry-standard hashing)
- Name and/or company name (if provided)
Payment Information
We use Stripe to process payments. When you purchase a Ductwork Pro license:
- Payment details (credit card number, billing address) are collected and processed directly by Stripe. We do not store your full payment information on our servers.
- We receive and store limited information from Stripe, including your name, email, the last four digits of your card, and transaction history, to manage your subscription and provide receipts.
For details on how Stripe handles your data, see Stripe's Privacy Policy.
API Keys
When you purchase a license, we generate an API key that allows you to download Ductwork Pro. We log API key usage (download requests, timestamps) to prevent abuse and provide support.
Website Analytics
We use Google Analytics to understand how visitors use our websites. This includes pages visited, time on site, referral sources, and general geographic region. This data is aggregated and not personally identifiable. We have IP anonymization enabled.
Support Communications
If you contact us for support, we retain the correspondence to provide better assistance and improve our product.
The Ductwork Gems
Open-Source Gem
The open-source Ductwork gem does not collect, transmit, or store any data. It runs entirely within your own infrastructure.
Ductwork Pro
Ductwork Pro does not include telemetry or "phone home" functionality. The gem runs entirely within your infrastructure. Your API key is used only to authenticate downloads from our package server—it does not transmit usage data, pipeline configurations, or any information about your application back to us.
How We Use Your Information
We use collected information to:
- Create and manage your account
- Process purchases and manage your license
- Provide API keys for downloading Ductwork Pro
- Respond to support requests
- Send transactional emails (purchase confirmations, license renewals, important security notices)
- Improve our documentation and websites
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Third-Party Services
We use the following third-party services that may process your data:
- Stripe — Payment processing (Privacy Policy)
- Google Analytics — Website analytics (Privacy Policy)
Cookies
Our websites use cookies for:
- Essential functionality — Maintaining your logged-in session
- Analytics — Google Analytics cookies to understand site usage
You can control cookie preferences through your browser settings, though disabling essential cookies may prevent you from logging in.
Data Retention
- Account data: Retained while your account is active. You may request deletion at any time.
- Transaction records: Retained for 7 years after your last transaction for tax and legal compliance.
- Website analytics: Retained for 14 months per Google Analytics default settings.
- Support correspondence: Retained indefinitely to provide context for ongoing support.
Your Rights
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and associated data (subject to legal retention requirements)
- Export your data in a portable format
To exercise these rights, contact us at contact@getductwork.io. We will respond within 30 days.
Security
We protect your information using:
- HTTPS encryption for all web traffic
- Secure password hashing (bcrypt or similar)
- Stripe's PCI-compliant payment processing
- Regular security updates to our infrastructure
Children's Privacy
Our services are not directed at children under 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this policy from time to time. If we make significant changes, we will notify you by email or by posting a notice on our website prior to the change taking effect.
Contact
For privacy-related questions or to exercise your data rights:
Pen and Paper Solutions LLC