Skip to main content

Legal

Privacy policy

Last updated 2026-07-20

Information we collect

We collect account details, service usage data, and technical diagnostics needed to provide and secure 1Footer.

How we use information

We use personal information to deliver services, support users, improve platform reliability, prevent abuse, and comply with legal obligations.

Framer plugin

Connecting creates a 10-minute sign-in session and a 15-minute plugin credential. The credential is limited to listing and adding 1Footer sites and reading footer data. The plugin keeps it in browser session storage, clears it at expiry or reset, and never stores it in persistent local storage. Our server stores only hashes of authentication secrets with their scope, expiry, revocation state, linked 1Footer account, and operational timestamps.

Beyond temporary authentication data, 1Footer receives only a user-entered domain, a selected 1Footer site ID, and the requested footer data version. After installation, the managed component sends its site ID, data version, and a persistent signed token scoped to reading only that site's public footer JSON, without an account credential or cookie, to check for published updates on load, focus, visibility, restored connectivity, and about every 15 seconds while the page is visible. The token is visible in published component source and cannot list or edit sites. Automatic updates keep the Framer-localized logo and badge assets; new images require an explicit plugin refresh. Requests explicitly omit the page referrer. Browsers may still send Origin for cross-origin access; it is not stored as Framer identity. We do not receive Framer account identity, project details or URLs, canvas selections or code contents, publish status, or deployment data. Installation and refresh outcomes stay inside Framer. If you explicitly connect optional Framer Server API publishing, 1Footer stores the encrypted project API key, project URL and identifiers, and sync or deployment status needed to publish that managed footer.

Expired or revoked credentials stop working immediately. Hashed authentication records and minimal audit timestamps may remain for security and abuse prevention; raw secrets are not retained in the database. Account-linked authentication records are deleted when the associated 1Footer account is deleted.

Data sharing

We do not sell personal data. We may share information with trusted infrastructure and analytics providers strictly to operate and secure the service.

Data retention

We retain information for as long as necessary to provide services, maintain records, resolve disputes, and satisfy compliance requirements.

Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict use of your personal information.

Contact

Privacy questions can be sent to hello [at] 1footer [dot] com.