Legal Document

Privacy Policy

Pagora respects your privacy and is committed to protecting your personal and business data. This policy explains how we collect, use, and safeguard your information across our platform.

Effective date: March 17, 2025

1. Overview

Pagora ("Pagora", "we", "us", or "our") operates a multi-tenant workspace platform that lets businesses create, manage, and scale websites ,including online stores, service platforms, shipping operations, and personal brand sites. This Privacy Policy explains what personal data we collect across our marketing site and product dashboard, why we collect it, how it's shared, and the choices and rights available to you.

This Policy applies to visitors of usepagora.com, workspace owners and team members ("Workspace Users"), and end customers who interact with sites built on Pagora ("Site Visitors"). Where a Workspace User collects data from their own Site Visitors through a site they've built, that Workspace User acts as the data controller for that data, and Pagora acts as a processor on their behalf, their own privacy policy governs that relationship.

2. Information We Collect

We collect what's needed to run your workspace and sites: your account details, the content you publish, payment information (handled by our payment processor, never stored by us), and basic usage data so the dashboard keeps getting better.

Table showing categories of information collected, with examples and sources
CategoryExamplesSource
Account & WorkspaceName, email, password hash, role, workspace name, team membersProvided by you
Site & ContentPages, product catalogues, media, domain settings, theme configurationProvided by you
PaymentBilling address, plan tier, last 4 card digits, transaction historyOur payment processor
Usage & DeviceIP address, browser type, pages viewed, feature usage, crash logsCollected automatically
CommunicationsSupport tickets, emails, call notes, survey responsesProvided by you

We do not collect more than is necessary to provide the Service, and we never ask for sensitive categories of data (such as government IDs or health information) unless a specific feature you opt into requires it, in which case we'll tell you at the point of collection.

3. How We Use Your Information

We tell you at the point of data collection what we use it for, and we only process your data for the reasons stated below:

Table showing purposes for processing data, with examples and legal basis
PurposeExamplesLegal Basis
Provide the ServiceHosting sites, rendering dashboards, syncing teamsContract
Billing & InvoicingProcessing subscriptions, sending receiptsContract
Security & Fraud PreventionDetecting suspicious logins, rate-limiting abuseLegitimate interest
Product ImprovementUnderstanding which features are used, fixing bugsLegitimate interest
Support & CommunicationResponding to tickets, sending service noticesContract
Marketing (opt-in)Product updates, newslettersConsent

We never use the content of your sites or your customer data to train third-party advertising models, and we don't sell personal information to data brokers.

4. Data Sharing

We share personal data only with the following categories of recipients, and only as needed to operate the Service:

  • Payment processorsto process subscription charges and payouts. We never store full card numbers ourselves.
  • Infrastructure & hosting providerscloud compute, storage, CDN, and email delivery vendors that keep Pagora online.
  • Analytics & product toolingprivacy-conscious analytics tools used to understand aggregate product usage.
  • Professional advisorsauditors, lawyers, and accountants, bound by confidentiality.
  • Legal & regulatory authoritiesonly where required by law, court order, or to protect the rights and safety of our users.
  • Business transfersin the event of a merger, acquisition, or asset sale, with notice provided beforehand.

We do not sell or rent your personal information to third parties for their own marketing purposes.

5. Cookies & Tracking Technologies

Pagora and sites built on Pagora use cookies and similar technologies for essential platform functions, analytics, and (where you opt in) marketing. The full breakdown of categories, retention periods, and your controls live in our dedicated Cookie Policy, including the live preference center where you can manage consent at any time.

6. Data Security

Security is built into the platform, not bolted on. Production data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to customer data is role-based and logged, and every workspace is logically isolated from every other workspace.

SOC 2 Type IIGDPR CompliantISO 27001PCI DSS Level 1

7. International Data Transfers

Pagora is a global platform, and personal data may be processed in countries other than your own, including the United States and the European Union. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on recognised safeguards such as Standard Contractual Clauses or an equivalent legal mechanism, and we hold our infrastructure partners to the same security standards described in Data Security above.

8. Data Retention

We keep data only as long as we need it to provide the Service or meet our legal obligations:

Table showing data retention periods for different types of data
Data TypeRetention PeriodWhy
Account & workspace dataDuration of your account + 30 daysRecovery window after account deletion
Published site contentUntil removed by you or account closureYou control your own content
Billing records7 yearsTax & accounting obligations
Support tickets3 yearsQuality & dispute resolution
Server & security logs12 monthsFraud detection, incident response

9. Your Rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your personal data, subject to legal retention requirements.
  • Export your data in a portable format.
  • Object or restrict certain processing, including marketing.
  • Withdraw consent at any time where processing is based on consent.

Exercise a privacy right
Email our privacy team and we'll respond within 30 days, or sooner where legally required by law.

10. Children's Privacy

Pagora is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Policy as our Service evolves or as laws change. Material changes will be announced via email or an in-product notice at least 14 days before they take effect. The "Last Updated" date at the top of this page always reflects the current version.

12. Contact Us

If you have questions regarding this Policy or about the privacy practices of Pagora, please contact us by email at privacy@pagora.com.