This policy explains what data we collect, how we handle it, and your rights. We never sell your data.
Jump to a section:
- What we collect and why
- When we access or disclose your information
- Your rights
- How we secure your data
- When you delete content
- Data retention
- Location of site and data
- EU data transfers
- Changes and questions
This policy applies to Row.so — our platform for building, hosting, and monetizing directories. It covers site visitors, prospective customers, and customers (and their authorized workspace members) in relation to how they use Row.so and manage their relationship with us.
It does not cover information about a customer's directory visitors or end users that Row.so processes on a customer's behalf (for example, visitor accounts, comments, submissions, or analytics on a public directory). If you are a visitor of a directory hosted on Row.so, contact that directory's operator for how they handle your information.
What we collect and why
Our guiding principle is to collect only what we need to run Row.so.
Identity and access
When you sign up, we ask for identifying information such as your email address and optionally your name and profile avatar. This lets you create and manage workspaces and directories, and lets us send essential product and account messages. With your consent, we may also send product updates or newsletters.
We never sell your personal information, and we won't use your name or company in marketing without permission.
Billing information
If you subscribe to a paid plan, payment is processed by our payment providers (such as Lemon Squeezy or Polar, depending on configuration). Card details are submitted to the processor and do not hit Row.so servers. We store billing records needed for invoices, account history, and support (for example plan, billing cycle, and limited card metadata returned by the processor).
Product data
We store the content you create in Row.so so the product works as intended — including directories, listings, categories, custom fields, design settings, Google Sheets connection metadata, submission forms, and related configuration. We keep this content while your account is active. If you delete your account, we delete associated content within 60 days (subject to legal retention needs).
Directory analytics
When you enable analytics on a directory, we collect first-party usage signals such as pageviews, referrers, devices, and approximate geolocation derived from IP — so you can understand traffic to your directory. This is separate from marketing analytics on row.so itself.
General geolocation data
We may log the IP address used to sign up and to access your account for security, spam mitigation, and fraud prevention.
Website interactions
On row.so marketing and app pages, we may collect browsing information for analytics and product improvement — for example browser/OS, pages visited, load performance, and referring site.
Anti-bot assessments
We may use CAPTCHA or similar checks to reduce abuse, credential stuffing, and spam. We have a legitimate interest in protecting Row.so and our customers' directories.
Cookies
We use first-party cookies (and limited third-party cookies where needed) for authentication, preferences, and analytics. You can control cookies in your browser; some features may not work if cookies are blocked.
Voluntary correspondence
When you email support@row.so, we keep that correspondence so we can help you and maintain a support history.
When we access or disclose your information
To provide the Services. We use trusted subprocessors (hosting, email, payment, etc.) to operate Row.so.
To help with support. If we need to look at your workspace content to resolve a ticket, we will ask for your consent first whenever practical.
To investigate abuse. Accessing a customer account when investigating potential abuse is a measure of last resort.
When required by law. We may disclose information in response to valid legal process.
Your rights with respect to your information
We aim to offer the same core rights to customers regardless of location, including:
- Right to Know — what personal information is collected and how it is used
- Right of Access — to the personal information we hold about you
- Right to Correction — to fix inaccurate personal information
- Right to Erasure — to request deletion of personal information
- Right to Restrict / Object — in certain situations, to limit or object to processing
- Right to Portability — to receive personal information in a portable format
- Right to Complain — to raise concerns about how we handle your information
Contact support@row.so to exercise these rights.
How we secure your data
Data in transit is encrypted with TLS. We use industry-standard protections for infrastructure and backups. Custom domains can be served with SSL certificates provisioned for your directory host.
What happens when you delete content
If you cancel your account or delete directories/content, that content becomes inaccessible and is purged from active systems within 60 days, subject to backups and legal retention obligations.
Data retention
We keep information for as long as needed for the purposes described in this policy and your choices, after which we delete or aggregate it.
Location of site and data
Row.so is operated globally. If you are in the EU, UK, or elsewhere, information you provide may be transferred to and stored in other jurisdictions. By using the Services, you acknowledge this transfer.
When transferring personal data from the EU
Where required, we rely on appropriate transfer mechanisms such as EU Standard Contractual Clauses so personal data transferred outside the EU remains protected under European standards.
Changes and questions
We may update this policy to reflect new practices or regulations. When we make a significant change, we update the date at the top of this page and take other appropriate steps to notify users.
Questions? Email support@row.so.