Privacy Policy

Last updated: March 23, 2026

Your Privacy Matters to Us

At Pyro Plot, we take your privacy seriously. This policy explains what information we collect, how we use it, and your rights regarding your data. We believe in transparency and want you to feel confident that your information is safe with us.

Information We Collect

We only collect information that helps us provide and improve Pyro Plot. Here's what we collect:

Account Information

When you create an account, we collect your email address, password (securely hashed), first name, last name, date of birth, country, and state or region. We use Supabase for authentication, which means your credentials are stored securely and encrypted.

Profile & Company Information

You may optionally provide additional profile details such as a phone number. If you add company information, we store your company name, employee count, show budget, full business address, company phone number, and website URL. This information helps personalize your experience and is used only to provide the service.

Project Data

We store the projects you create, including site plans, map coordinates, annotations, firework specifications, fallout zones, wind settings, client information, cost details, and any notes or descriptions you add. This data is necessary to provide the core functionality of Pyro Plot.

Crew Member Data

If you use the crew management feature, we store information about your crew members that you provide, including their names, dates of birth, email addresses, phone numbers, emergency contact details, and credential information (certifications, license numbers, and expiration dates). You are responsible for obtaining appropriate consent from your crew members before entering their personal information into Pyro Plot.

Inventory & Compliance Data

If you use the inventory management feature, we store data about your pyrotechnics magazines, distributors, products, inventory items, transactions, magazine inspections, and audit logs. This data is entered by you and stored to support ATF-style compliance tracking and record-keeping.

Documents & File Uploads

You may upload documents such as insurance certificates, ATF licenses, permits, and other compliance-related files. We store these files securely along with metadata such as file type and file size. Uploaded documents are accessible only to your account.

Feedback

If you submit feedback through the app, we collect the feedback type, your message, and an optional rating. This helps us improve the product and is associated with your account.

Usage Information

We use Vercel Analytics and Vercel Speed Insights to understand how people use Pyro Plot and to monitor performance. This data is anonymous and does not identify you personally. We also track certain product interaction events (such as feature usage and navigation patterns) to help us improve the app. These events do not contain personal information.

Payment Information

Payment processing is handled securely by Stripe. We do not store your credit card information on our servers. Stripe handles all payment data in compliance with PCI-DSS standards. We store your Stripe customer ID and subscription status to manage your account access.

How We Use Your Information

We use your information solely to:

  • Provide and maintain the Pyro Plot service
  • Save your projects and allow you to access them anytime
  • Manage your crew, inventory, and compliance documentation
  • Process your subscription payments
  • Send important account and service updates, including credential expiry reminders
  • Improve and optimize the user experience
  • Respond to your support requests and feedback
  • Enable public sharing of projects you choose to make visible

We will never sell your data to third parties or use it for advertising purposes.

Public Project Sharing

Pyro Plot allows you to set individual projects to "public" visibility, which generates a shareable link that anyone with the URL can view without logging in. Public projects display the project site plan, annotations, and related details. Only projects you explicitly set to public are accessible this way. You can change a project back to private at any time, which immediately revokes public access. We recommend reviewing your project content before making it public to ensure you are not sharing sensitive information.

Third-Party Services

To provide Pyro Plot, we work with trusted third-party services that help us deliver a secure and reliable experience:

Supabase (Database, Authentication & File Storage)

Stores your account information, project data, inventory records, crew details, and uploaded documents securely. Supabase is GDPR-compliant and uses industry-standard encryption.

Mapbox (Interactive Maps & Geocoding)

Provides the mapping functionality that powers site planning, including map tiles, geocoding, and location search services. When you search for locations or interact with the map, your search queries and map viewport data are sent to Mapbox to render results. Mapbox processes this data under its own privacy policy.

Stripe (Payment Processing)

Handles all payment processing securely. Your payment information never touches our servers. Stripe processes billing details under its own PCI-DSS-compliant privacy policy.

Vercel (Hosting, Analytics & Performance)

Hosts the Pyro Plot application and provides anonymous analytics and performance monitoring (Speed Insights) to help us understand usage patterns and optimize the experience.

Mailgun (Transactional Email)

Sends transactional emails on our behalf, such as credential expiry notifications and account-related communications. Mailgun may track whether emails are opened and whether links are clicked to help us ensure reliable delivery. Mailgun processes email data under its own privacy policy.

Google Fonts (Typography)

We load typefaces from Google Fonts to render the Pyro Plot interface. When you visit our site, your browser may make requests to Google's servers to retrieve font files. Google may log these requests under its own privacy policy.

Data Security

We take security seriously and implement industry-standard measures to protect your data. All data is transmitted over encrypted connections (HTTPS/TLS), passwords are securely hashed, and our infrastructure partners maintain SOC 2 compliance. Uploaded files are stored in private, access- controlled storage buckets. While no system is 100% secure, we continuously monitor and update our security practices to keep your information safe.

Your Rights (GDPR Compliance)

You have complete control over your data. Under GDPR and other privacy regulations, you have the right to:

  • Access: View all the personal data we have about you
  • Correction: Update or correct your information at any time
  • Deletion: Request that we permanently delete your account and data
  • Export: Download your project data in a portable format
  • Object: Object to certain types of data processing
  • Withdraw Consent: Withdraw your consent at any time

To exercise any of these rights, please contact us at support@pyroplot.com. We'll respond within 30 days.

Data Retention

We retain your account, project, crew, inventory, and document data for as long as your account is active. If you choose to delete your account, we will permanently remove all of your personal data, projects, uploaded files, crew records, and inventory data, except where we're legally required to retain certain information (such as for tax or accounting purposes). You can request account deletion at any time through your account settings or by contacting us directly.

Cookies, Local Storage & Tracking

We use the following browser storage mechanisms:

  • Authentication cookies: Essential cookies managed by Supabase to keep you logged in and maintain your session. These are strictly necessary for the service to function.
  • Preference cookies: We set a cookie to remember when you dismiss certain in-app notifications (such as feature announcements), so they don't reappear. This cookie persists for up to one year.
  • Local storage: We use your browser's local storage to cache application data for performance (such as recently loaded project data) and to store minor UI preferences. This data stays on your device and is tied to your account.

We also use Vercel Analytics, which uses privacy-friendly tracking that doesn't identify individual users. Our transactional email provider (Mailgun) may track email opens and link clicks. We do not use advertising cookies or sell your browsing data to third parties.

International Data Transfers

Pyro Plot uses cloud services that may store and process data in various countries. When your data is transferred internationally, we ensure that appropriate safeguards are in place to protect your information in accordance with GDPR and other applicable privacy laws.

Children's Privacy

Pyro Plot is intended for professional use by licensed pyrotechnicians and is not directed at children under 18. We do not knowingly collect information from children. If you believe we have inadvertently collected data from a child, please contact us immediately.

Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. If we make material changes, we'll notify you by email or through a prominent notice in the app. We encourage you to review this policy periodically. The "Last updated" date at the top indicates when the policy was last revised.

Contact Us

If you have any questions about this privacy policy, your data, or how we protect your information, we're here to help:

Your trust is important to us. We're committed to protecting your privacy and handling your data with care and respect. Thank you for choosing Pyro Plot for your firework display planning needs.