Privacy Policy

Effective: June 2026

Slabkast (“we,” “us,” or “our”) is a product of Monolit Group Ltd, a private company registered in New Zealand, which is the data controller responsible for your personal information. We operate the website at slabkast.com and the application at app.slabkast.com (together, the “Service”). This Privacy Policy explains what information we collect, how we use it, the legal bases on which we rely, and the choices you have regarding your data.

1. What Data We Collect

When you create an account and use the Service, we may collect the following information:

Account information

  • Full name
  • Email address
  • Phone number
  • Country
  • Business name
  • Password (stored securely using hashing — we never store or see your plaintext password)

Usage data

  • Pages visited and features used within the Service
  • Browser type, device information, and operating system
  • IP address and approximate location
  • Date and time of access

User-generated content

Any photos, images, slab data, project information, and other content you upload to or create within the Service. This content may include personal information about your own clients (such as a client’s name or project details) — see section 10 below.

2. How We Use Your Data

We use the information we collect for the following purposes:

  • Account management: To create and manage your account, authenticate your identity, and provide customer support.
  • Service delivery: To operate, maintain, and improve the Service, including processing your slab imagery and managing approval workflows.
  • Communication: To send you account-related notifications, billing information, product updates, and responses to your enquiries.
  • Analytics: To understand how users interact with the Service so we can improve the user experience and develop new features. We use only first-party, aggregate analytics and do not use third-party advertising trackers.
  • Legal compliance: To comply with applicable laws and regulations, and to protect our rights and the rights of our users.

3. Legal Bases for Processing

Where data protection laws such as the EU/UK General Data Protection Regulation (GDPR) apply, we rely on the following legal bases to process your personal information:

  • Performance of a contract: to create your account, deliver the Service, and process billing.
  • Legitimate interests: to secure, maintain, and improve the Service, and to communicate with you about it — provided these interests are not overridden by your rights.
  • Consent: where required, for optional communications such as marketing. You may withdraw consent at any time.
  • Legal obligation: to comply with applicable laws, tax, and accounting requirements.

4. Third-Party Service Providers

We use trusted third-party service providers to operate the platform. These fall into the following categories: payment processing, cloud hosting and infrastructure, database and storage, and email delivery. Our payment processing is handled by Stripe; we do not store your full payment card details — all card data is handled directly by Stripe.

These providers have access only to the data necessary to perform their functions, act on our instructions, and are bound by confidentiality and data protection obligations. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

5. Data Retention

We retain your data as follows:

  • Active accounts: Your data is retained for as long as your account is active and you continue to use the Service.
  • Deleted accounts: When you request account deletion, we will retain your data for up to 90 days to allow for recovery or to resolve any outstanding issues. After 90 days, your data will be permanently purged from our systems.
  • Paused accounts: If your account is paused (e.g., after a trial ends without payment), your data is retained so you can reactivate. If a paused account remains inactive for 24 consecutive months, we may delete the associated data after giving you notice.

We may retain certain data longer if required by law or to resolve disputes.

6. Your Rights

Depending on your location, you have some or all of the following rights regarding your personal data:

  • Access: You can request a copy of the personal data we hold about you.
  • Correction: You can update or correct your account information at any time through the Service, or by contacting us.
  • Deletion: You can request that we delete your account and associated data.
  • Data portability: You can request an export of your data in a standard, machine-readable format.
  • Objection and restriction: You can object to, or ask us to restrict, certain processing of your data.
  • Withdraw consent: Where we rely on consent, you can withdraw it at any time without affecting prior processing.
  • Complain: You have the right to lodge a complaint with your local data protection or privacy supervisory authority.

California residents have the right to know, access, delete, and opt out of the sale or sharing of their personal information; as noted above, we do not sell or share personal information.

To exercise any of these rights, email us at support@slabkast.com. We will respond to your request within 30 days.

7. Cookies

The Service uses cookies for the following purposes:

  • Session cookies: Essential cookies used to authenticate your session and keep you logged in while you use the Service.
  • Preference cookies: Used to remember your settings and preferences within the Service.

We do not use third-party advertising trackers or sell data to advertisers. We do not embed third-party tracking cookies in the Service.

8. Security Measures

We take the security of your data seriously and implement appropriate technical and organisational measures to protect it, including:

  • Encryption of data in transit using TLS/SSL.
  • Encryption of data at rest in our database.
  • Secure password hashing — we never store plaintext passwords.
  • Access controls limiting who can access production data.
  • Regular security reviews of our infrastructure and code.

In the event of a data breach affecting your personal information, we will notify affected users and the relevant supervisory authorities as required by applicable law and without undue delay.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.

9. Children’s Privacy

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from anyone under 16. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us at support@slabkast.com.

10. Data You Upload About Others (Business Customers)

When you upload content that contains personal information about your own clients or third parties, you act as the data controller for that information and we act as your data processor — processing it only to provide the Service to you and on your instructions. You are responsible for having a lawful basis to upload and share that information.

Business customers who require a Data Processing Agreement (DPA) may request one by contacting support@slabkast.com.

11. International Data Transfers

Your data may be processed and stored in locations outside your country of residence, including the United States and other regions where our cloud service providers operate. By using the Service, you consent to the transfer of your data to these locations.

Where we transfer personal data internationally, we put appropriate safeguards in place as required by applicable data protection laws, including the use of Standard Contractual Clauses or equivalent mechanisms.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy with an updated effective date at the top of this page, and where changes are material, we will take reasonable steps to notify you (for example, by email or a notice within the Service).

Your continued use of the Service after the revised policy takes effect constitutes your acceptance of the changes.

13. Contact

If you have any questions about this Privacy Policy or how we handle your data, or to exercise your rights, please contact us at:

Monolit Group Ltd (Slabkast)
Email: support@slabkast.com
Website: slabkast.com