Shuffle Studio

Privacy Policy

Shuffle Works, Inc. d/b/a Shuffle Studio

Effective Date: April 11, 2026

This Privacy Policy describes how Shuffle Works, Inc., a Delaware corporation doing business as Shuffle Studio (“Company,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information through our website at shufflestudio.io (the “Site”), our client portal, and the digital systems design, development, hosting, and management services we provide (collectively, the “Services”).

By accessing or using the Site or Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, do not use the Site or Services.

1. Information We Collect

1.1 Information You Provide Directly

We collect personal information that you voluntarily submit to us, including:

Contact and Intake Forms. Name, email address, phone number, organization name, current website URL, project description, budget range, desired timeline, services of interest, and how you heard about us.

Newsletter Subscriptions. Name and email address.

Account Registration. If you access our client portal, we collect your name, email address, and authentication credentials.

Payment Information. When you purchase a service or product, our third-party payment processor (Stripe, Inc.) collects your payment card details, billing address, and related financial information. We do not store payment card numbers on our servers.

Communications. Any information you include in emails, support requests, or other correspondence with us.

1.2 Information Collected Automatically

When you visit the Site, we may automatically collect device and browser information (browser type and version, operating system, device type, screen resolution), usage data (pages visited, referring and exit URLs, time and date of access, clickstream data), and network information (IP address and approximate geographic location derived from your IP address).

1.3 Information from Third-Party Sources

We may receive information about you from third-party services integrated with our platform, including payment confirmations from Stripe and bot-detection signals from Cloudflare Turnstile.

2. How We Use Your Information

We use the personal information we collect for the following purposes: (a) Service Delivery — to respond to inquiries, process transactions, deliver purchased services, provide project updates, and manage client portal access; (b) Customer Relationship Management — to maintain records of client interactions, project history, and service engagements in our internal business systems; (c) Communications — to send transactional messages and, where you have opted in, marketing communications about our services; (d) Site Operations and Security — to operate, maintain, and secure the Site, including bot detection, fraud prevention, and protection against unauthorized access; (e) Improvement — to analyze usage patterns and improve the Site and Services; and (f) Legal Compliance — to comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

3. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

Service Providers. We engage third-party companies to perform services on our behalf. These providers are contractually obligated to use your information only to perform the services we request and to maintain appropriate security measures. Our current service providers include: Stripe, Inc. (payment processing — name, email, payment details, transaction records), Cloudflare, Inc. (DNS, CDN, web application firewall, bot detection — IP address, device/browser metadata, security tokens), and Railway Corp. (application and database hosting — all data stored in our application database).

Professional Advisors. We may share information with our attorneys, accountants, and other professional advisors in connection with the services they provide to us, subject to their professional obligations of confidentiality.

Legal Requirements and Protection of Rights. We may disclose your information if required to do so by law, or if we believe in good faith that such disclosure is necessary to comply with a legal obligation, protect and defend our rights or property, prevent or investigate possible wrongdoing, or protect the personal safety of users or the public.

Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or other similar transaction, your personal information may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a different privacy policy.

4. Cookies and Similar Technologies

We use a limited set of cookies and client-side storage mechanisms. Essential cookies are required for the Site to function properly, including session management and authentication for the client portal. Preference cookies store your display preferences such as light or dark mode theme selection. Cloudflare Turnstile uses security tokens to distinguish legitimate users from automated traffic when you submit forms — these are not used for tracking or advertising purposes.

We do not use third-party advertising cookies, cross-site tracking pixels, or behavioral advertising technologies on the Site. You can control cookies through your browser settings; disabling essential cookies may impair Site functionality.

5. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Form submissions are retained for the duration of the business relationship and for three (3) years following the last interaction. Client portal accounts are retained for the duration of the active partnership and for one (1) year following deactivation. Payment records are retained in accordance with applicable tax and financial reporting obligations (generally seven years). Upon termination of a partnership agreement, we will provide a complete data export upon request.

6. Data Security

We implement administrative, technical, and physical safeguards designed to protect your personal information, including encryption of data in transit using TLS/SSL, encrypted database connections and access controls, role-based access controls restricting internal access on a need-to-know basis, web application firewall and DDoS protection provided by Cloudflare, and regular review of security practices and infrastructure.

No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee its absolute security.

7. Your Privacy Rights

Regardless of your location, you may access the personal information we hold about you, correct inaccurate or incomplete personal information, delete your personal information (subject to certain legal exceptions), and opt out of marketing communications at any time by following the unsubscribe instructions in any marketing email or by contacting us directly.

California Residents — CCPA/CPRA. If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. You have the right to know the categories and specific pieces of personal information we have collected, the right to request deletion, the right to request correction, and the right to non-discrimination for exercising your rights. We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.

Categories of personal information collected in the preceding 12 months include: Identifiers (name, email, phone, IP address — from you directly and automatically collected), Commercial Information (services purchased, transaction history — from you directly and Stripe), Internet or Network Activity (browser type, pages visited, referring URL — automatically collected), and Professional or Employment Information (organization name, role — from you directly).

To exercise your rights, submit a verifiable request to hello@shufflestudio.io. We will verify your identity before processing any request. You may also designate an authorized agent to submit a request on your behalf.

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with consumer privacy statutes may have similar rights. To exercise your rights, contact us using the information in Section 11.

8. Children’s Privacy

The Site and Services are intended for use by businesses and organizations and are not directed to individuals under the age of sixteen (16). We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe we have inadvertently collected such information, please contact us at hello@shufflestudio.io.

9. Third-Party Links

The Site may contain links to third-party websites or services that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We encourage you to review the privacy policies of any third-party site you visit.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective Date” at the top of this page and, where appropriate, provide additional notice (such as a prominent notice on the Site or email notification to active clients). Your continued use of the Site or Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Shuffle Works, Inc. d/b/a Shuffle Studio

Email: hello@shufflestudio.io

Web: shufflestudio.io/get-started

This Privacy Policy is provided for informational purposes and does not constitute legal advice. Shuffle Works, Inc. recommends consulting with a licensed attorney for guidance on compliance with applicable privacy laws.