Privacy Policy
Boardera Software Inc. | Last updated July 28, 2026
Protecting the security and privacy of your personal, business, and product design information (collectively, your "personal information") is important to Boardera Software Inc. ("Boardera", "we", "us", "our"). This Privacy Policy explains what information we collect when you use the Boardera API, how we use it, how we protect it, and your rights regarding that information.
By registering for an API key and using the Boardera API, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy.
1. Information We Collect
Account Information
When you register for API access, we collect information necessary to create and manage your account, including:
- Your name and email address
- Your organization name
- Billing and payment information (processed by third-party payment providers)
Design and Project Data
When you use the API, you may upload or submit:
- Circuit board designs (Gerber files, ODB++ archives, fabrication drawings)
- Bills of materials (BOM files)
- Pick-and-place and centroid files
- Other technical data related to your projects
Usage Data
We automatically collect information about your use of the API, including:
- API call logs (endpoints accessed, timestamps, response codes)
- Token consumption data
- IP addresses and request metadata
- Error and performance data
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing Services: To process your API requests, analyze designs, source components, generate pricing, and deliver results.
- Account Management: To manage your subscription, process payments, and communicate with you about your account.
- Service Improvement: To monitor performance, diagnose issues, and improve the reliability and quality of our Services.
- Security: To detect and prevent fraud, abuse, and security threats.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Anonymized Analytics: Boardera may use anonymized and aggregated data derived from API usage to improve its products, algorithms, and pricing models. This data will not identify you, your organization, or your Designs.
3. Data Hosting and Storage
Hosting Regions: Your data is hosted in the region you select during account setup: either Canada or Europe. Data will not be transferred outside your selected hosting region except as required to provide the Services or as required by law.
ISO 27001 Certification: Boardera is ISO/IEC 27001:2022 certified. We maintain administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of your data, including encryption in transit and at rest, access controls, and regular security assessments.
ITAR Notice: Boardera is not ITAR-registered. Our infrastructure is certified for commercial use only. You must not upload ITAR-controlled technical data or defense articles through the API. If you do so in violation of our Terms of Use, you bear sole responsibility for any resulting regulatory consequences.
4. Data Retention
Designs and project data submitted through the API are retained indefinitely for your ongoing access and use, unless you instruct us otherwise. You may request deletion of specific projects or all of your data at any time by contacting support@boardera.ca.
Account and billing information is retained for as long as your account is active and for a reasonable period thereafter to comply with legal and accounting obligations.
Usage logs and API call metadata are retained for operational and security purposes and may be purged periodically in accordance with our data management policies.
5. Data Sharing and Disclosure
We do not sell your personal information or your Designs to third parties, and we do not share personal information for cross-context behavioral advertising except as described in Section 7.3. We may share your information only in the following circumstances:
- Service Providers: We may share information with trusted third-party service providers who assist us in operating the API, processing payments, or hosting infrastructure. These providers are contractually obligated to protect your data and use it only as directed by Boardera.
- Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
- Safety and Security: We may disclose information to protect the rights, property, or safety of Boardera, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
Design Confidentiality: Boardera will not share your Designs, technical data, or project information with any third party except as strictly necessary to provide the Services (e.g., infrastructure hosting providers). We will not share your Designs with other Boardera customers, partners, or competitors under any circumstances.
6. Payment Information
Payments are processed by third-party payment processors. Boardera does not directly store your credit card numbers or banking details. Payment processors are PCI-DSS compliant and subject to their own privacy policies. We may receive limited payment information such as card type, last four digits, and billing postal code for record-keeping purposes.
7. Cookies, Analytics, and Advertising
7.1 Cookies
The Boardera API itself does not use cookies. The API Portal, including DECODE, uses two kinds of browser storage. Essential cookies and similar local storage keep you signed in, maintain your session, and remember choices you make (including your cookie choice); these are required for the portal to function and are always active. In addition, our analytics and advertising providers set cookies as described in Sections 7.2 and 7.3; these are set only if you consent through the portal's cookie banner. You may block or delete cookies through your browser settings at any time, though blocking essential cookies may prevent you from signing in or using parts of the portal.
7.2 Web Analytics
We use a third-party web-analytics service to understand how the API Portal (including the DECODE application) is used, so that we can operate and improve it. As you browse the portal, we record page-view events on selected pages that include your IP address (from which approximate location may be inferred), the page paths you visit, and the address you arrived from, and the analytics provider sets a cookie holding a pseudonymous client identifier. Before this information is sent, we take commercially reasonable measures to remove identifiers for your projects (such as your DECODE project references) from the page addresses we record; we record those addresses without their query parameters, and we do not send page titles. Pages that could expose sensitive account material (such as API-key management) are not measured at all. We also record product-usage events: for example, that a registration was completed, an analysis finished, or a result was downloaded. These events describe actions, not content: they never include your name, email address, your Designs, or any API-key material.
Where you are signed in to an account with our analytics provider and your settings there allow it, the provider may additionally associate this activity with your account across the devices you use and provide us with aggregated demographic and interest categories (such as age range, gender, and interests). We use everything we collect through this service only to measure and improve usage of our own products. We do not use it to personalize advertising, we do not sell it, and we do not permit the provider to use it to improve the provider's own products or services.
None of this collection runs unless you choose "Accept" on the portal's cookie banner; if you decline, no analytics load. You can change your choice at any time through the Cookie Preferences link, or by blocking or deleting cookies through your browser settings. We can identify our current analytics provider on request.
7.3 Advertising
On our public marketing pages only (the home, features, pricing, enterprise, and registration pages), we also use a third-party advertising platform's tag to measure the effectiveness of our advertising and to build audiences for our advertising on that platform (sometimes called "retargeting"). When you visit those pages with cookies accepted, the tag records your visit, including the page address and your IP address, and sets a cookie holding a pseudonymous identifier that the platform may link to any account you hold with it, under the platform's own privacy terms. This tag does not load on the product surfaces of the portal, such as DECODE, your dashboard, or API-key management.
If you arrive at the portal from one of our advertisements and then register or submit an inquiry, we may also store the advertisement's campaign details and click identifier with your contact record in our customer-relationship system, so that we can measure which campaigns lead to signups. This also happens only if you have accepted cookies. If you decline, those advertising identifiers are discarded rather than stored or transmitted.
We can identify our current advertising platform on request.
8. Communications
We may send you communications related to your account, including:
- Service notifications (maintenance windows, API changes, security alerts)
- Billing and payment confirmations
- Product updates and new feature announcements
You may opt out of non-essential communications at any time. Transactional and security-related communications cannot be opted out of.
9. Your Rights
You have the following rights regarding your personal information:
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may request that we correct inaccurate or incomplete information.
- Deletion: You may request deletion of your personal information and Designs, subject to legal retention requirements.
- Data Export: You may request an export of your data in a machine-readable format.
- Objection: You may object to certain uses of your data, particularly for marketing purposes.
To exercise any of these rights, contact us at support@boardera.ca. We will respond to requests within thirty (30) days.
10. Children
The Boardera API is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
11. Security Measures
Boardera employs industry-standard security measures to protect your data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- API key-based authentication with secure key management
- Rate limiting and anomaly detection
- Regular security assessments and penetration testing
- ISO/IEC 27001:2022 certified information security management system
- Employee access controls on a need-to-know basis
While we take data security seriously, no system is completely secure. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law.
12. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated with reasonable notice. For new users, changes take effect upon posting. For existing users, material changes take effect thirty (30) days after posting.
13. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable therein.
14. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact:
Boardera Software Inc.
Email: support@boardera.ca
© Boardera Software Inc. All rights reserved.