Privacy Policy

Everlane Group Tools Platform

Last updated: February 14, 2026  ·  Effective: February 14, 2026

At a Glance

We believe in full transparency. Here’s a quick summary of our privacy practices:

  • We collect minimal data — only what’s necessary to provide our tools and services.
  • We never sell your data — your information is not for sale, ever.
  • You control your data — you can request access, correction, or deletion at any time.
  • We protect your data — industry-standard security measures are in place.

1 Who We Are

Everlane Group (“we,” “us,” or “our”) operates the Everlane Group Tools platform, accessible at tools.everlanegroup.co (the “Platform”). This Platform provides internal marketing and advertising tools for authorized team members.

As the data controller, Everlane Group is responsible for determining the purposes and means of processing your personal data in connection with the Platform.

2 Information We Collect

We collect and process the following categories of information:

Account Information
  • Username — Used for authentication and identification within the Platform.
  • Password — Stored in a securely hashed format (bcrypt); we never store plain-text passwords.
  • Account status — Whether your account is active or deactivated.
  • Admin role designation — Whether your account has administrator privileges.
Usage & Session Information
  • Last login timestamp — The date and time of your most recent login.
  • Account creation date — When your account was first created.
  • Session data — Temporary session identifiers used to keep you logged in.
  • Tool usage data — Which tools you access and how you interact with them.
Automatically Collected Technical Information
  • IP address — Collected via standard server logs.
  • Browser type and version — e.g., Chrome 120, Safari 17.
  • Operating system — e.g., Windows, macOS, Linux.
  • Referring URL — The page that directed you to our Platform.
  • Pages visited and access times — Standard server access logs.
Third-Party Platform Data
  • Facebook/Meta Ads data — When you use our advertising tools, we may process campaign data, ad performance metrics, audience insights, and other data retrieved via the Meta Marketing API on your behalf.
  • API credentials and tokens — Access tokens for connected third-party platforms (stored securely and encrypted at rest).

3 How We Collect Information

We collect information through the following methods:

Directly From You

When you create an account, log in, configure tools, or interact with the Platform’s features.

Automatically

Through server logs, session cookies, and security monitoring when you access or use the Platform.

From Third-Party APIs

Via the Meta/Facebook Marketing API and other connected services that you authorize the Platform to access.

From Administrators

Your account may be created and managed by an Everlane Group administrator who provides your initial credentials.

4 Purpose & Legal Basis for Processing

We process your personal data for the following purposes, each with a corresponding legal basis:

Purpose Legal Basis Details
Authentication & access control Contractual Necessity Verifying your identity and granting access to authorized tools.
Platform functionality Contractual Necessity Providing, operating, and maintaining the tools and services you use.
Security & fraud prevention Legitimate Interest Monitoring for unauthorized access, protecting against threats, and maintaining system integrity.
System improvement Legitimate Interest Analyzing usage patterns to improve performance, fix bugs, and develop new features.
Administrative management Legitimate Interest Managing user accounts, roles, and permissions within the Platform.
Legal compliance Legal Obligation Complying with applicable laws, regulations, and legal processes.

5 Third-Party Services

The Platform integrates with and relies on the following third-party services:

Meta (Facebook) Platform

We use the Meta Marketing API to provide advertising tools. When you use these tools, data is exchanged with Meta in accordance with Meta’s Privacy Policy and their Platform Terms.

Amazon Web Services (AWS)

Our Platform is hosted on AWS infrastructure. AWS may process technical data (such as IP addresses) as part of providing hosting services. See AWS Privacy Policy.

CDN-Delivered Libraries

We use Bootstrap (via jsDelivr CDN) for styling. CDN providers may collect standard access logs when resources are loaded. See jsDelivr Privacy Policy.

We carefully evaluate each third-party service for privacy and security compliance before integration. All third-party services are bound by their respective privacy policies and terms of service.

6 Data Sharing & Disclosure

We do not sell, rent, or trade your personal data to any third party.

We may share your data only in the following limited circumstances:

  • With your consent — When you explicitly authorize us to share your data with a third party.
  • Service providers — With trusted providers who assist us in operating the Platform (e.g., hosting, infrastructure), bound by confidentiality obligations.
  • Legal requirements — When required by applicable law, regulation, legal process, or enforceable government request.
  • Safety & security — To protect the rights, safety, or property of Everlane Group, our users, or the public, as required or permitted by law.
  • Business transfers — In connection with a merger, acquisition, or sale of assets, in which case your data would remain subject to this Privacy Policy or an equivalent.

7 Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:

Data Category Retention Period
Account information Duration of account existence + 30 days after deletion
Session data Automatically expires after session end or 30 days (if “Remember me” is selected)
Server access logs 90 days
Security/audit logs 1 year
Third-party API data (cached) Duration of active use; deleted upon tool disconnection

When data is no longer needed, it is securely deleted or anonymized in accordance with industry best practices.

8 Security Measures

We take the security of your data seriously and implement the following measures:

Encryption
  • Passwords are hashed using bcrypt with salting
  • CSRF protection on all forms
  • Secure session management
Access Controls
  • Role-based access control (admin/user)
  • Authentication required for all tool access
  • Account deactivation capabilities
Infrastructure
  • Hosted on AWS with enterprise-grade security
  • Nginx reverse proxy with secure configuration
  • Regular security updates and patching
Monitoring
  • Continuous server and application monitoring
  • Automated process management and recovery
  • Comprehensive logging for audit purposes

While no method of electronic storage or transmission is 100% secure, we strive to use commercially acceptable means to protect your personal data and continuously improve our security posture.

9 Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your personal data (“right to be forgotten”).

Right to Restrict

Request limitation of processing under certain conditions.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

To exercise any of these rights, please contact us using the methods described in Section 13. We will respond to all legitimate requests within 30 days. There is no fee for exercising your rights, except in cases of manifestly unfounded or excessive requests.

10 Cookies & Tracking Technologies

The Platform uses the following cookies and similar technologies:

Cookie / Technology Type Purpose Duration
session Essential Maintains your authenticated session Session / up to 30 days
remember_token Essential Keeps you logged in if “Remember me” is selected 30 days
csrf_token Essential Protects against cross-site request forgery attacks Session

We do not use any analytics, advertising, or third-party tracking cookies. All cookies used by the Platform are strictly essential for its operation. You can control cookies through your browser settings, but disabling essential cookies may prevent the Platform from functioning correctly.

11 Children’s Privacy

The Platform is designed for use by authorized business professionals and is not intended for use by children under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take immediate steps to delete that information.

If you believe a child under 18 has provided us with personal data, please contact us immediately using the methods described in Section 13.

12 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will update the “Last updated” date at the top of this page.
  • For significant changes, we will notify affected users through the Platform (e.g., via a banner or notification upon login).
  • We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

Your continued use of the Platform after changes are posted constitutes your acceptance of the updated Privacy Policy.

13 Contact Us & Data Deletion Requests

If you have any questions about this Privacy Policy, want to exercise your data rights, or wish to request deletion of your data, you can contact us through the following methods:

Email

privacy@everlanegroup.co

Organization

Everlane Group
Attn: Data Privacy

Data Deletion Request

To request deletion of your data:

  1. Send an email to privacy@everlanegroup.co
  2. Include your username and the subject line “Data Deletion Request”
  3. We will verify your identity and process your request within 30 days
  4. You will receive confirmation once your data has been deleted

Related policies:

Terms of Service

© 2026 Everlane Group. All rights reserved.

This privacy policy is clearly marked as belonging to Everlane Group and pertains solely to the Everlane Group Tools platform at tools.everlanegroup.co.