The short version. You can browse every demo without an account. We ask once whether you are happy with measurement (analytics and advertising); say no and nothing about your visit is recorded beyond ordinary server logs. If you buy something, we need your email address, a record of what you bought, and a log of what you downloaded. We never see your card details — Stripe handles payment. Every file we deliver is watermarked with your account reference, and we explain that in §5 because you deserve to know. We do not sell your data and we do not use it for advertising.
The data controller for AICDE Showroom, at promptweb.aicdesolution.com.my (the Service), is AICDE SOLUTION, a sole proprietorship registered with the Companies Commission of Malaysia (SSM) under registration number 202403330017 (003678700-H), with its place of business at No. 55A, Jalan Indah 8/13, Taman Bukit Indah, 79100 Iskandar Puteri, Johor, Malaysia.
Contact for anything in this policy, including data requests: ashertee@aicdesolutions.com.
We are a one-person business. We have not appointed a Data Protection Officer, because we are not required to. Requests go to the address above and are handled by the owner.
Viewing the gallery and the demos requires no account. We set no cookies at all for anonymous visitors unless you allow analytics — see §10. Our hosting provider records standard server logs (IP address, timestamp, requested path, user agent) for security and abuse prevention.
| Data | Where it comes from |
|---|---|
| Email address | You, or your Google account |
| Account identifier (UID) | Generated by Firebase Authentication |
| Sign-in method (Google or email link) | Your choice |
| Whether your email is verified, and when | Firebase Authentication |
| Account creation date and last sign-in date | Firebase Authentication |
We never receive your Google password, and we do not operate passwords of our own. If you sign in with Google, we receive your email address and Google's confirmation that it is verified — nothing else from your Google account.
| Data | Note |
|---|---|
| Order records: what you bought, amount, currency, date, Stripe session reference | Kept by us |
| Licence records: scope of access and expiry date | Kept by us |
| Your confirmation that you requested immediate access, and when you gave it | Kept by us; evidence of the purchase terms you agreed to |
| Billing details and card data | Collected and held by Stripe, not by us. We never see or store your card number |
We record each delivery, to detect abuse and to trace leaks:
To stop automated abuse of sign-in and download endpoints, we use bot-protection technology that assesses whether a request is likely to come from a real browser. This may involve your IP address, browser characteristics and interaction signals being processed by our bot-protection provider. We receive only the pass/fail result and a score — not a profile of you.
Where the EU or UK GDPR applies, our legal bases are as follows.
| Purpose | Data | Legal basis |
|---|---|---|
| Create and operate your account; verify your email | Account data | Performance of a contract |
| Take payment and deliver what you bought | Order and licence records | Performance of a contract |
| Keep proof of the purchase terms you agreed to, and defend chargebacks | Consent record | Legitimate interests — establishing and defending legal claims |
| Keep accounting and tax records | Order records | Legal obligation |
| Email you a reminder before your licence expires | Email address, expiry date | Legitimate interests — keeping you informed about a service you bought |
| Detect fraud, abuse, credential sharing and leaks | Delivery logs, hashed IP, fingerprints | Legitimate interests — protecting the business against a real and demonstrated risk |
| Block automated abuse | Bot-protection signals | Legitimate interests — keeping the Service available |
| Respond to your support requests | Whatever you send us | Performance of a contract; legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and concluded it is not — the data involved is minimal, IP addresses are hashed, and the alternative is being unable to sell the product at all. You can object at any time; see §9.
Every copy of a prompt or design system we deliver contains an identifier tied to your account. We are telling you plainly because a watermark you were never told about would not be fair, and in several jurisdictions would not be lawful.
The identifier appears in two forms in each delivered file:
Why: the product is text. Once delivered it can be copied infinitely at no cost. The fingerprint lets us identify the source if a file is redistributed. It is a deterrent and an investigative tool, nothing more.
What it is not: it does not track where you use the file, does not phone home, and does not report anything back to us. It is inert text. We only learn something if a copy reaches us from elsewhere and we compare it against our delivery records.
How long: delivery records are kept as described in §8. Removing or altering the fingerprint is a breach of our Terms of Service §9.
We use the following providers. Each acts as a processor on our behalf, or as an independent controller where noted, and each is bound by its own agreement with us.
| Provider | What they do | What they see |
|---|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Run, Cloud Storage, Cloud Load Balancing) | Sign-in, database, application hosting, static hosting | Email address, UID, order and licence records, delivery logs, server logs |
| Google Analytics (also Google) | Counting visits and which cases get looked at. Only runs if you press Allow — see §10 | A randomly generated visitor id, pages viewed, approximate location from a truncated IP, device and browser type. Not your email, not what you bought |
| Reddit (advertising pixel) | Measuring whether our Reddit ads bring people who go on to buy. Only runs if you press Allow — see §10 | A Reddit-generated identifier, the pages you viewed on this site, and whether a purchase completed. Not your email, not your name, not what you bought |
| Stripe | Payment processing | Your name, email, billing and card details. Stripe is an independent controller for its own fraud-prevention and regulatory purposes |
| Bot-protection provider | Distinguishing humans from automated scripts | IP address, browser characteristics, interaction signals |
| Email delivery provider | Sending sign-in links, receipts and expiry reminders | Your email address and the message content |
We may also disclose data where we are legally required to, where necessary to establish, exercise or defend legal claims, or as part of a sale or reorganisation of the business — in which case we would tell you before your data became subject to a different privacy policy.
We operate from Malaysia. Our providers process data in the United States, the European Union and other locations, so your data will be transferred outside your country, including outside the EEA and the UK.
Where data leaves the EEA or the UK, transfers rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), or on an adequacy decision where one applies, together with the supplementary measures our providers put in place. Copies of the relevant safeguards are available on request from ashertee@aicdesolutions.com.
| Data | Retention | Why |
|---|---|---|
| Account data | Until you delete your account, then up to 30 days in backups | Operating your account |
| Order records and consent records | 7 years from the transaction | Accounting, tax and consumer-law record-keeping obligations. These are kept even if you delete your account |
| Licence records | Until expiry, then 12 months | Handling disputes about access |
| Delivery logs and fingerprints | 24 months from delivery | Leak investigation; a leak often surfaces long after the download |
| Hashed IP addresses | 90 days | Abuse detection |
| Server logs | Per our hosting provider's default, typically 30 days | Security |
| Support emails | 24 months from the last message | Continuity of support |
You have the right to:
Under the CCPA/CPRA you have the right to know what we collect and why, to request deletion, to request correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information, so there is nothing to opt out of — but you may still contact us to confirm that.
Email ashertee@aicdesolutions.com from the address on your account. We respond within 30 days. We may ask you to confirm control of the account email before acting, to make sure we are not handing your data to someone else. Exercising these rights is free; we may charge a reasonable fee only for requests that are manifestly unfounded or excessive, and we will tell you before doing so.
Deleting your account ends your access to any Materials you purchased and does not refund the unused part of a licence period. See Terms §3.
We keep this deliberately small.
| What | Purpose | Type |
|---|---|---|
| Firebase Authentication session | Keeping you signed in | Strictly necessary |
| Language preference | Remembering whether you chose Chinese or English | Strictly necessary (functional) |
| Bot-protection token | Confirming a request came from a real browser | Strictly necessary (security) |
| Your analytics choice | Remembering that you allowed or declined analytics, so we stop asking | Strictly necessary (functional) |
_ga, _ga_<id> | Google Analytics. Only set if you press Allow. | Analytics — consent required |
_rdt_uuid | Reddit advertising pixel, to link an ad click to a later purchase. Only set if you press Allow. | Advertising — consent required |
The strictly necessary ones are needed for a service you have asked for, so we do not ask for consent to use them.
Nothing is measured until you turn it on. The first time you visit we ask, once. Until you press Allow, neither Google Analytics nor the Reddit pixel is loaded at all and no measurement cookie exists — we use Google’s consent mode with every category set to denied by default. If you decline, we remember that and do not ask again.
We do run ads, and pressing Allow includes advertising measurement. We advertise on Reddit. If you allow measurement, Reddit’s pixel records that you visited, which case pages you opened, and whether a purchase completed, so we can tell which ads are worth paying for. Reddit may use that to build advertising audiences.
What we still do not do: we do not set Google’s advertising cookies
(ad_storage, ad_user_data, ad_personalization stay denied
even after you allow), and we never send your email address, name, or what you bought to any
advertising platform.
Changed your mind? Clear this site’s data in your browser and we will ask again on your next visit.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you without undue delay where the risk is high.
The Service is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
We may update this policy. The version and effective date at the top of this page always show the current one. If a change materially affects how we handle your data, we will notify you by email or in the Service before it takes effect.
AICDE SOLUTION
Sole proprietorship registered in Malaysia · SSM no. 202403330017 (003678700-H)
No. 55A, Jalan Indah 8/13, Taman Bukit Indah, 79100 Iskandar Puteri, Johor, Malaysia
ashertee@aicdesolutions.com ·
+60 16-572 4028
Please contact us first — most things are resolved quickly that way. You also have the right to complain to a supervisory authority:
This policy is written in English. Any translation is provided for convenience only; in the event of a conflict, the English version governs.