1. Introduction
BladeOS (“we,” “us,” or “our”) operates the BladeOS platform, accessible at bladeos.net(e.g., bladeos.net/bladesmiths/smithname). BladeOS is headquartered in Quebec, Canada.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you access or use our platform. It applies to all users, including bladesmith account holders (“Smiths”), customer account holders (“Customers”), and visitors who browse the platform without an account.
By using BladeOS, you consent to the practices described in this policy. If you do not agree, please do not use the platform.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect your email address, a hashed version of your chosen password (we never store plaintext passwords), and your display name or business/forge name.
2.2 Profile Information (Smiths)
Smith accounts may provide about/bio text, a custom domain name, and other public-facing profile details such as location, specialty, and professional titles.
2.3 Product & Listing Data
Smiths may upload product listings that include knife details (type, steel, description), pricing, availability status, and product images (JPEG, PNG, GIF, WebP; max 10 MB per image). This information is stored on our servers or an S3-compatible storage service and may be publicly visible.
2.4 Commission & Work Request Data
When users engage with the commission system or the Work Pool marketplace, we collect descriptions of requested work, budget ranges, timelines, submitted quotes, and messages exchanged between parties on our platform.
2.5 Customer Account Data
Customer accounts may include style and budget preferences, work request history, ratings and reviews submitted for Smiths, and messages sent through the platform.
2.6 Verification Data
Smiths who request identity verification may submit identity documents for manual review by our team. Domain verification requires adding a DNS TXT record. Social verification involves linking a Google or Facebook account via OAuth. We receive basic profile data from those providers but do not store their OAuth access tokens after completing the verification check.
2.7 Payment Information
Subscription billing is handled entirely by Stripe. BladeOS does not collect or store credit card numbers, bank account details, or other payment credentials. We store only your Stripe customer ID and subscription plan details (plan tier, status, billing cycle). For information about how Stripe handles your payment data, please review Stripe's Privacy Policy.
2.8 Contact Form Submissions
Contact forms on public bladesmith profiles collect your name, email address, and message. These submissions are stored in our database and associated with the relevant Smith's tenant account.
2.9 File Uploads
Users may upload product images, work request attachments, and Knife Drop images. Uploaded files are stored on our server filesystem or on an S3-compatible storage service (such as Cloudflare R2 or Backblaze B2), depending on platform configuration.
2.10 Social Login Data
If you choose to sign in with Google or Facebook, we receive your email address and basic profile information (name, profile picture) from the OAuth provider. We store only your provider user ID to link your social account to your BladeOS account. Provider access tokens are discarded immediately after we retrieve your profile and are never stored by BladeOS.
2.11 Usage & Technical Data
Our audit logging system records IP addresses, user IDs, action types, affected entities, and timestamps for significant platform events (primarily admin actions). Error tracking via Sentry may capture browser information, stack traces, and contextual data when errors occur.
2.12 Cookies & Local Storage
We use an httpOnly cookie to store your authentication JWT token (7-day expiry). This cookie is not accessible to JavaScript. We also use localStorage to remember your preferred display language (bladeos_locale) and, as a fallback, your authentication token. We do not use third-party advertising or tracking cookies.
2.13 Support Chat
If you use our on-site support chat, we store the messages you send, any images you attach, and the email address you provide (or, if you are logged in, your account email and name) so we can reply. We also store a one-way hashed form of your IP address to prevent spam and abuse. A random identifier is kept in your browser's localStorage so your conversation persists across visits. Support conversations are retained for up to 180 days of inactivity and then automatically deleted.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: Account creation and management, displaying public profiles and product listings, facilitating commissions and Work Pool requests.
- Marketplace Operation: Connecting bladesmiths and customers, processing quotes, managing commission lifecycles, enabling Knife Drops.
- Trust & Verification: Reviewing identity documents, verifying domain ownership, checking social profiles, computing trust scores, displaying verification badges.
- Subscription Billing: Managing your Stripe subscription, enforcing plan limits (e.g., product listing caps), processing billing events.
- Notifications: Sending transactional email and SMS notifications via Brevo (e.g., registration welcome, commission status updates, verification decisions, drop approvals).
- Security & Fraud Prevention: Rate limiting, DDoS protection, audit logging, detecting and investigating abuse or violations of our Terms of Service.
- Platform Improvement: Diagnosing errors (via Sentry), monitoring platform health, improving features and user experience.
- Administration & Moderation: Reviewing flagged content, moderating reviews, managing verification queues, enforcing platform rules.
- Legal Compliance: Fulfilling legal obligations under applicable Canadian law, including responding to valid legal requests.
4. How We Share Your Information
4.1 Public Profile Information
Smith profile information - including forge/business name, bio, product listings, trust scores, verification badges, and reviews - is visible to any visitor on the public bladesmith directory and public profile pages. You control what profile information you make public.
4.2 Third-Party Service Providers
We share data with the following service providers only as necessary to operate the platform:
- Stripe - subscription payment processing, billing portal, invoices.
- Brevo - transactional email and SMS notifications.
- Cloudflare - DNS management, wildcard SSL certificates, CDN, and DDoS protection. Traffic to bladeos.net passes through Cloudflare's network.
- Sentry - error tracking and performance monitoring for both the backend and frontend.
- Backblaze B2 / S3-compatible storage - cloud storage for database backups and (optionally) uploaded files.
- Google & Facebook - OAuth identity verification for social login. We receive limited profile data as described in Section 2.10.
4.3 We Do Not Sell Your Data
BladeOS does not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes.
4.4 Legal Requirements
We may disclose your information if required to do so by law, court order, or government authority, or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with applicable law.
4.5 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your personal information may be transferred as part of that transaction. We will provide notice if your data becomes subject to a materially different privacy policy.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our services. If you delete your account, we will delete or anonymize your personal data within a reasonable period, except where we are required to retain it for legal or regulatory purposes (such as billing records), fraud prevention, or legitimate business interests.
Audit logs are retained for a period necessary to maintain platform security and accountability. Uploaded files (product images, attachments) are deleted when you remove the associated listing or account.
6. Data Security
We implement the following security measures to protect your data:
- Encryption in transit: All communications use HTTPS. Cloudflare provides SSL certificates for the platform.
- Password security: Passwords are hashed using bcrypt before storage. We never store plaintext passwords.
- Authentication tokens: JWT tokens are stored in
httpOnlycookies to prevent JavaScript-based theft. - Tenant isolation: All data in our shared database is scoped to a
tenantIdcolumn, preventing cross-tenant data access. - Rate limiting: API endpoints are rate-limited to prevent abuse and brute-force attacks.
- DDoS protection: Cloudflare provides network-level DDoS protection.
- Database backups: Encrypted incremental database backups are performed regularly using restic.
Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using industry-standard practices.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: You have the right to request access to the personal information we hold about you.
- Correction: You have the right to request correction of inaccurate or incomplete personal information.
- Deletion: You may request deletion of your personal information, subject to certain exceptions (e.g., legal obligations).
- Data Portability: Where technically feasible and required by applicable law, you may request a copy of your data in a structured, machine-readable format.
- Withdrawal of Consent: Where we process your data based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
- Objection & Restriction: In certain circumstances, you may have the right to object to or request restriction of processing of your personal data.
These rights are recognized under the Canadian federal Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector(Law 25 / Bill 64), and the European Union's General Data Protection Regulation (GDPR) for users located in the EU/EEA.
To exercise any of these rights, please contact us at [email protected]. We will respond within the time period required by applicable law.
8. International Data Transfers
BladeOS is operated from Quebec, Canada, and your data is processed primarily in Canada. By using our platform, you acknowledge that your information may be processed and stored in Canada, which may have different privacy laws than your jurisdiction.
Some of our third-party service providers (e.g., Cloudflare, Sentry, Google, Facebook/Meta, Backblaze) may process or store data in the United States or other countries. Where required by law, we ensure appropriate safeguards are in place for such transfers (e.g., standard contractual clauses for EU data).
9. Children's Privacy
BladeOS is intended for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under the age of 18. If you are under 18, please do not use the platform or provide any personal information. If we discover that we have inadvertently collected information from a minor, we will promptly delete it. If you believe we may have collected information from a minor, please contact us at [email protected].
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes, we will update the effective date at the top of this policy and, where required by law, provide additional notice (such as a notification within the platform or via email).
We encourage you to review this policy periodically. Your continued use of BladeOS after changes are posted constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us: