Legal
Privacy Policy.
Last updated August 23, 2026
The privacy of your data, and it is your data and not ours, matters to us. This policy lays out what we collect and why, how it is handled, who else touches it, and what rights you have over it.
We have never sold personal data and we never will. We do not run advertising, we set no advertising cookies, and we do not share your information with data brokers.
Who this policy is about
db.garden is operated by DB.GARDEN LLC, an Oregon limited liability company at 4912 Hampton Ct, Lake Oswego, OR 97035, United States. For the information described in this policy, that company is the data controller.
This policy covers how we handle information about visitors to db.garden, about people considering it, and about customers and the people on their accounts.
It does notcover the information a customer puts into db.garden about their own clients. We handle that on the customer's instructions, and the customer, not us, decides what happens to it. The next section explains that in full, and it is the section to read if you are a homeowner who received a link from your designer.
Your clients, who never signed up
db.garden is used by landscape designers to design gardens for other people. So most of the personal information inside it belongs to those other people: homeowners who never created an account here and never agreed to anything with us.
For a project, a designer may store:
- A client's first and last name, and the same for a second contact
- Email addresses, phone numbers, and mobile numbers
- The street address of the property being designed
- Photographs of the property
- The planting design, the plant list, and the prices quoted
- Any comments or approvals the client leaves on the page shared with them
For all of that, the designer is the controller and we are the processor. We store it and process it to run the service for them. We do not use it for our own purposes, we do not market to clients, and we never sell it.
If you are a client who received a link
Your designer chose the software and entered your details, so they are the right first stop for any question about your information, including asking to see it, correct it, or have it removed. If you contact us directly we will help, and we will normally need to route the request through your designer, because they hold the relationship and we have no way to verify who you are.
The page you were sent is reachable by anyone who has its link. The link contains a long random code that cannot be guessed or found by searching, and those pages are excluded from search engines. It is still a link, so treat it like one and do not post it publicly.
What we collect and why
Our guiding principle is to collect only what we need.
Identity and access
Signing up asks for an email address and a password, and nothing else. Your name and your firm name are optional and come later, if you want them to appear on the pages and the emails your clients see. You can add a logo for the same reason. We use your email address to set up the account and to send the emails the product needs to send.
Billing information
If you subscribe, you give your card and billing address to Stripe. None of it touches our servers. We store no card number, no last four digits, and no record of individual transactions. What we keep is the identifier Stripe uses for your customer record and your current subscription state, which is what tells the product your account is active. Your billing history and the card on file are read from Stripe each time you open your billing page, and are not kept afterwards.
What you create in the product
We store the projects, plant palettes, budgets, schedules, uploaded photographs, and client details you put into db.garden, because that is what the product is for. We keep it while your account exists. See what happens when you delete something, or cancel.
Sign-in and IP address
We log the IP address used to create an account, and the IP addresses used to sign in, for security and for fraud prevention. We keep that for as long as the account is active.
Anti-bot checks
The sign-in and signup forms in the application use Cloudflare Turnstile to tell people apart from scripts. It looks at things like the IP address, how the browser behaves, and how long you have been on the page, and returns a pass or fail to us. We see the result, not the underlying signals. Without it, one script can open hundreds of accounts, so we have a legitimate interest in running it.
Website analytics
We use Umami to count page views and see which pages bring people in. It runs in three places: this marketing site, the signed-in application, and the project pages designers publish for their clients. It sets no cookies, does not follow you across other sites, and builds no profile of you. It records the page, the referring site, a country, and a browser type.
Cookies
The application uses essential cookies only: a session cookie that keeps you signed in, a cookie that remembers preferences, and cookies Stripe sets on the checkout page to detect fraud. You can block cookies in your browser, and the app will not be able to keep you signed in if you do.
This marketing site also runs Google Analytics and Google Ads, through Google Tag Manager. Those set cookies that identify your browser between visits and let us measure which advertisements bring people here. That is advertising measurement, and we would rather say so plainly than describe it as something else. It runs on this marketing site only, never in the application and never on the project pages designers publish for their clients.
Forms on this website
The newsletter box in the footer stores the email address you enter, along with which page you entered it on. Nothing else. There is an unsubscribe link on every newsletter we send, and you can also ask us to remove the address.
The inquiry form for firms asks for your company name, a contact name, an email address, how many seats you need, which tools you use today, and anything you write in the message box. We store it so we can answer you, and we email it to ourselves so that it reaches a person. We do not use it for anything else and we do not add you to the newsletter from it.
When you write to us
If you email us a question, we keep the correspondence and your email address, so that we have the history if you write again. If you answer a survey or agree to a call, we keep what you tell us, and we ask before recording anything.
Artificial intelligence
Some features send content from your account to AI models run by Anthropic. This deserves its own section because it is the one place where your work, and sometimes your client's property, leaves our infrastructure at your request.
- What leaves. The project text you submit to the feature, which can include your typed notes and site descriptions, and any photographs you upload to it. Both go to Anthropic, which is where every AI feature that is switched on is routed. OpenAI appears in the table because a design rendering feature is wired to it, and that feature is switched off, so nothing reaches them today. If we ever route a feature elsewhere, this section and the table below change with it before it happens.
- When. Only when you use an AI feature. Nothing is sent in the background, and nothing about your account is sent speculatively.
- What the providers may do with it. We use their business offerings under terms that do not permit your content to be used to train their general models.
- What we keep. The suggestion comes back into your project like any other content and stays there until you remove it.
We do not use your content or your clients' content to train any model of our own.
Companies that process data for us
We use other companies to run parts of db.garden. Every one of them that handles personal data is listed here, along with what reaches them. Each is bound by a contract to process it only on our instructions.
| Company | What they receive | Why |
|---|---|---|
| DigitalOcean | Everything in the application and the database | Hosting and the managed database, in a US region |
| Supabase | Email address and authentication identity | Signing in and session management |
| Stripe | Name, email address, billing address, card details | Payments and subscription billing |
| Resend | Recipient email address and message contents | Sending every email the product sends |
| Anthropic | Project text, plant notes, and photographs you submit to an AI feature | AI plant suggestions and site analysis |
| OpenAI | A design canvas image and a text description of it | AI design rendering, a feature that is not switched on today |
| DigitalOcean Spaces | Uploaded photographs, logos, and site plans | File storage |
| ImageKit | Plant catalog imagery | Resizing and delivering images |
| Cloudflare | IP address and signals about the browser on sign-in forms | Blocking automated signups and credential stuffing |
| Umami | Page views, referrer, country, browser. No cookies | Website analytics |
| Pages you visit on this marketing site, your IP address, and cookies that identify your browser across visits | Advertising measurement, through Google Analytics and Google Ads | |
| Sentry | Error reports, which can include an account identifier | Finding and fixing crashes |
If we add or change a sub-processor that handles personal data, we will update this table. Write to [email protected]if you would like advance notice of changes for your firm's own compliance records.
When we access or disclose information
To run the service you asked for. The companies in the table above receive what they need to do their part and nothing else.
To help you. Nobody here reads the contents of your account except for limited reasons and, where it is your content, with your permission. If we need to open your account to solve a support case, we ask you first.
When an automated process breaks. We get alerts when a job fails part way through. Where we can fix it without looking at personal data, we do. In the rare case where we have to look, we look at the minimum that will resolve it, and then we fix the underlying cause.
To keep the service safe. We read logs and metadata as part of ordinary security work, and we may look at an account when investigating a report of abuse. That is a last resort.
Aggregated and de-identified data. We may aggregate or de-identify information and use it for any purpose, including improving the product. De-identified means it cannot be traced back to you.
When the law requires it. We are a US business and our infrastructure is in the United States. We do not respond to government requests for customer data unless compelled by valid legal process, and we will only respond to requests from outside the United States when they come through the US government under a mutual legal assistance treaty. Our policy is to notify the affected customer before disclosing anything, unless we are legally prohibited from doing so. If a tax authority audits us, we disclose the minimum billing information required.
If the business changes hands. We have no plans for that. If it happened, we would tell you well before any personal information moved or became subject to a different policy.
Your rights over your information
We apply the same rights to every customer, wherever you live, rather than only to the ones a particular law covers.
- To know. What is collected, what it is used for, and who it is shared with. That is what this page is.
- To access. A copy of the personal information we hold about you.
- To correct. Most of it you can change yourself in your account. Ask us for the rest.
- To erasure. To have your information deleted, subject to the limits the law allows. Deleting some information means the account can no longer work, in which case the request becomes a request to close the account.
- To portability. To receive your information in a usable format and take it elsewhere. Export is available in the app while the subscription is active, and we will produce an export for you if it is not.
- To restrict or object. To ask us to limit how we use your information, or to object to a particular use.
- To be free of automated decisions. We do not make decisions about you by automated means that would have a legal or similarly significant effect.
- To complain. To your data protection authority, if you are somewhere that has one.
- To be treated the same. We will not charge you more, give you less, or treat you worse for exercising any of these.
To exercise any of them, email [email protected] from the address on the account with Privacy in the subject line, or write to DB.GARDEN LLC, 4912 Hampton Ct, Lake Oswego, OR 97035, United States. We may need to verify who you are first, usually by confirming control of that address. We answer within 30 days. If an authorized agent is acting for you, we will need your written permission before we proceed.
If you are asking about information a designer holds about you rather than about your own account, see Your clients, who never signed up.
How we secure your data
All traffic between your browser and our servers is encrypted with TLS. The database is hosted on managed infrastructure in the United States, and database backups are encrypted. Passwords are handled by Supabase Auth and are never stored by us in a readable form. Payment card numbers never reach our servers at all.
Access to production systems is limited to those who need it and is audited. Client pages are published behind long random links rather than guessable ones. There is more detail on the security page.
No system is perfect. If we discover a breach affecting your information, we will tell you and the relevant authorities within the time the law requires, and we will tell you what actually happened rather than a sanded-down version of it. If you think you have found a vulnerability, please write to [email protected] and we will work with you.
What happens when you delete something, or cancel
When you delete a project, a plant from a palette, or an uploaded file inside db.garden, it stops being reachable through the application straight away. Copies can persist for a period afterwards in encrypted database backups, and for uploaded files also in our file storage. We are tightening that second case so deletion reaches the stored file itself. Until it does, tell us if you need a particular file destroyed and we will remove it by hand.
Canceling a subscription does not delete anything. That is deliberate, and it is different from most software. A garden takes years, and designers come back to old projects, so when a subscription ends we keep your work exactly as it was. The account becomes read-only, and every published client page stops being reachable by the people you sent it to. Subscribe again and it is all there.
Which means that if you want your information actually erased, you have to ask, and you are entitled to. Email [email protected]and ask us to delete the account. We will confirm, because it cannot be undone, then remove it from the live systems within 30 days. Copies held in encrypted backups age out on our hosting provider's rotation after that. We keep only what we are legally required to keep, which in practice is the record of what you paid, for tax purposes.
Data retention
We keep information for as long as it is needed for the purpose it was collected for. In practice:
- Your account and your work: until you ask us to delete it, including after a subscription ends, as described above.
- Sign-in and IP logs: while the account is active.
- Emails we sent you: a record of what was sent and when, kept so that we do not send the same thing twice and so that we can answer questions about it.
- Billing records: as long as tax law requires, typically seven years, even after an account is deleted.
- Support correspondence: kept so that we have the history if you write again.
Where the site and the data live
db.garden is operated from the United States and all of its infrastructure is in the United States. If you are in the European Union, the United Kingdom, or anywhere else outside the United States, information you give us is transferred to and stored in the United States. By using db.garden you consent to that transfer.
Transfers from the EU and the UK
Personal data moved out of the EU or the UK has to keep the protection it had there. Where we handle such data on a customer's behalf we will enter into a data processing agreement incorporating the Standard Contractual Clauses. Ask at [email protected] and we will put one in place for your firm.
California notice
For information customers put into db.garden, we act as a service provider under the California Consumer Privacy Act, not as a business or a third party. We process it only for the purpose the customer signed up for, and we do not retain, use, disclose, or sell it for any other commercial purpose.
Advertising measurement means information about your visit reaches Google. Under California law that can count as "sharing" for cross-context behavioral advertising even though no money changes hands, so we say so here rather than rely on the narrower meaning of "sell". We have never sold personal information for money and never will.
In the last twelve months we have collected the categories of information described in what we collect and why: identifiers, commercial information, internet activity, and geolocation inferred from an IP address. We collect it for the purposes given beside each one there. We have not sold or shared personal information, and we do not process sensitive personal information for the purpose of inferring characteristics. California residents may exercise the rights listed in your rights over your information, and an authorized agent may act for you with written permission from you.
Changes and questions
We will update this policy as the product changes and as regulation requires. When we make a significant change we will change the date at the top and email the address on your account.
Questions, concerns, or a request about your information: write to [email protected] and a person will answer.
Adapted from the Basecamp open-source policies / CC BY 4.0. The original text is copyright 37signals LLC. It has been changed substantially to describe db.garden, and 37signals does not endorse db.garden or this adaptation.