Legal
Privacy Policy
1. Introduction
This Privacy Policy describes how engDatabase.com (“we,” “us,” or “our”) collects, uses, and protects your information when you use Engineering Database at engDatabase.com (“Service”).
We are committed to protecting your privacy. We collect only the minimum data necessary to operate the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address and a password. Authentication is handled by Amazon Cognito. We do not store your password directly — it is managed by Cognito’s authentication infrastructure.
2.2 Payment Information
If you subscribe to a paid plan, payment processing is handled entirely by Stripe. We do not receive, store, or have access to your full credit card number or payment credentials. Stripe may share with us limited information such as the last four digits of your card, card brand, and billing country for display and fraud-prevention purposes. Stripe’s handling of your data is governed by Stripe’s Privacy Policy.
2.3 Usage Information
We track credit consumption (database searches and calculator runs) for the purpose of enforcing usage quotas associated with your subscription tier. Usage counts are stored in our database and are associated with your account.
We do not log or store the content of your database queries or calculator inputs beyond what is necessary for the immediate processing of the request.
2.4 Analytics
We use Vercel Analytics to collect basic, anonymized usage metrics such as page views, visit duration, and general geographic region. Vercel Analytics does not use cookies and does not track individual users across sessions. For details, see Vercel’s Analytics Privacy Policy.
2.5 Advertising
Public reference and calculator pages may display advertising served by Google AdSense and direct sponsorships sold by us. Signed-in product pages (database, calculators, account) do not display advertising.
Google AdSense uses cookies and similar technologies to serve and measure ads, and may use cookies, device identifiers, and previous browsing activity to select ads relevant to your interests (personalized advertising).
For visitors located in the European Economic Area, the United Kingdom, or Switzerland, consent for advertising cookies and personalized ads is collected through Google’s certified consent management platform, which is presented as a banner on your first visit. You can update your choices at any time through that banner’s “Manage options” control. Outside those regions no consent banner is shown, and you may manage Google’s ad personalization across all sites at Google Ad Settings. Google’s use of advertising data is governed by the Google Ads Privacy Policy.
Direct sponsor placements link to advertiser destinations. We do not transmit your personal information to direct sponsors. Sponsor destination sites operate under their own privacy policies once you click through.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Authenticate your identity and manage your account.
- Process payments and manage your subscription.
- Enforce usage quotas and rate limits.
- Communicate with you about your account, billing, or service-related matters.
- Detect and prevent fraud, abuse, or violations of our Terms of Service.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Third-Party Services
The Service relies on the following third-party providers, each of which processes data under their own privacy policies:
- Amazon Web Services (AWS): Infrastructure, authentication (Cognito), data storage (DynamoDB), email delivery (SES), and the compute environment that runs the backend. Data is stored in the US-East-1 (N. Virginia) region.
- Stripe: Payment processing.
- Vercel: Frontend hosting and anonymized analytics.
- Google AdSense: Advertising on public reference and calculator pages. Receives the URL and contextual content of ad-bearing pages, IP address, user-agent, and (with consent) advertising cookies for personalized ad selection. See section 2.5 for details.
5. Cookies
The Service uses three categories of cookies:
- Essential cookies: An encrypted session cookie set by us to keep you signed in. Cannot be disabled without breaking sign-in.
- Advertising cookies: Google AdSense sets cookies used to select ads, measure ad performance, and limit ad repetition on public reference and calculator pages. In the EEA/UK/Switzerland these cookies are gated behind the consent banner described in section 2.5.
- Analytics: Vercel Analytics, which does not use cookies, as described in section 2.5.
6. Data Retention
Account information is retained for as long as your account is active. Usage metering data is retained for billing reconciliation and is subject to automatic expiration (TTL) in our database.
If you delete your account, we will delete your account information and associated usage data within 30 days. Stripe may retain transaction records independently as required for financial compliance.
7. Data Security
We implement reasonable technical and organizational measures to protect your information, including:
- Encryption in transit (TLS) for all communications.
- Encryption at rest for stored data (AWS-managed encryption).
- Secure authentication via Amazon Cognito with support for multi-factor authentication.
- WAF (Web Application Firewall) protection against common attack vectors.
- No direct storage of passwords or payment credentials.
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Your Rights
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information associated with your account.
- Delete your account and associated data.
- Export your account information upon request.
To exercise any of these rights, contact us.
9. Children’s Privacy
The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete it.
10. International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service prior to the changes taking effect. Your continued use of the Service after such notice constitutes acceptance of the updated policy.
12. Contact
For questions about this Privacy Policy, contact us.