mortar.design

Legal

Privacy Policy

How we handle your information at Mortar.

Last updated: 13 September 2026

Who We Are

This Privacy Policy explains how Mortar (“Mortar”, “we”, “us”) collects, uses, and protects information when you visit mortar.design or use our project and budget management software for interior designers.

If you have questions about this policy or your data, contact us at privacy@mortar.design, or reach the team at hello@mortar.design.

What We Collect

We collect information in a few straightforward ways:

  • Account data. Your name, email address, and studio details when you create an account.
  • Project data.The clients, rooms, items, budgets, and files you add to the application so it can do its job. When you add an item from a retailer’s website, or import one from Pinterest, we fetch that product’s details (name, price, images, supplier) from the retailer and store them as part of your project.
  • Payment data. Billing is handled by Stripe— we never see or store your card number. Stripe shares limited billing details (such as invoice status) back to us.
  • Usage and device data. Browser type, pages viewed, and general interaction patterns, collected through product analytics (PostHog and, where enabled, Google Analytics).
  • Support conversations. Messages you send us through support, handled via HelpScout.
  • Email delivery data. Delivery and engagement metadata (such as whether an email bounced) from the providers that send email on our behalf, Postmark and Resend.
  • How you found us.When you submit a form, we record with it the website that referred you, any campaign tags (“utm” parameters) on the link you arrived through, and the first page of your visit. We use this only to understand which channels our work reaches people through — it is first-party, it is never sold or shared for advertising, and it is only sent to us if you choose to submit a form. If the form asks how you heard about us, that answer is stored alongside it.
  • Ad click identifiers. If you reach us by clicking one of our Google or Meta ads, the link carries a click identifier. On your first visit we keep it, with the time of that visit, in a first-party cookie called mortar_click for 90 days, so that if you later start a Mortar trial we can tell that ad platform the ad led to a sign-up. It is set once and never updated, holds no name or email address, and you can clear it at any time by clearing your cookies.

How We Use It

  • To provide, operate, and improve the Mortar service.
  • To process billing and payments.
  • To respond to your enquiries and provide customer support.
  • To understand how the site and product are used (product analytics) so we can make them better.
  • To keep the service secure and to meet our legal obligations.

The Client Portal

Designers using Mortar can share a client portal link with their own clients so those clients can view a project, approve selections, and leave feedback. Where a client uses the portal, we hold their name, email address, and any feedback or approvals they submit — strictly to operate the portal for the designer’s project.

The designer’s studio is the data controller for the project and client data entered into Mortar. If you are a client and want to access, correct, or delete your information, please contact the designer or studio that invited you — we act on their instructions for that data.

Third-Party Services You Connect

Mortar can connect to a small number of third-party services at your choice. We only request the access each integration needs.

Pinterest

When you connect Pinterest from Settings, we store only your encrypted OAuth tokens. We read your boards and pins on demand, at the moment you ask, so you can choose what to import into a Mortar board — we do not store your Pinterest pins, boards, images, or profile data. Pins are created on Pinterest only when you explicitly click to publish one from Mortar. Your Pinterest data is never used to train or improve any AI model. Disconnecting Pinterest in Settings permanently deletes the stored tokens.

Google Sign-In

If you sign in with Google, we receive your name, email address, and profile photo from Google to create or match your account. We do not access your other Google data.

Stripe Connect

Designers can connect a Stripe account to accept payments from their clients through the portal. Stripe holds the connected account’s banking and payout details directly — we only receive transaction status and identifiers needed to reconcile invoices.

AI Features

Some features use AI to help you work faster — for example, extracting item details and identifying products from images you or a supplier provide. This processing is performed by our AI providers, Anthropic and Google. Under our agreements with them, our providers do not train on this data.

Cookies & Analytics

We use cookies and similar technologies, and we use PostHog (and, where enabled, Google Analytics) for product and site analytics to understand how people use Mortar. This helps us see which features are useful and where people get stuck.

For more detail on what we set and how to control it, see our Cookie Policy.

Data Hosting & Transfers

Mortar is hosted on Google Cloud, and our database runs on Neon, both in US regions. This means your information is processed and stored in the United States, which may be outside the country you access Mortar from. We rely on our providers’ standard safeguards for these transfers.

We use the following sub-processors to run the service:

  • Google Cloud and Neon— infrastructure and database hosting
  • Stripe— billing and payments (incl. Stripe Connect for designer payouts)
  • Postmark and Resend— email delivery
  • PostHog and Google Analytics — product and site analytics
  • HelpScout— customer support
  • Anthropic and Google— AI processing of item and image data
  • Zyte— retailer product-page retrieval for item scraping
  • Pinterest— for studios that connect a Pinterest account

Data Sharing

We do not sell your personal information. We share it only with the service providers listed above, who process it on our behalf under appropriate obligations, or where required to comply with the law or protect our rights.

Retention & Deletion

We keep your information for as long as your account is active, or as needed to provide the service, meet legal obligations, and resolve disputes. You can request deletion of your account and its data at any time by emailing privacy@mortar.design.

You can disconnect any connected integration (such as Pinterest, or Google sign-in) at any time from Settings, which removes the stored access tokens for that integration immediately.

Security

We take reasonable technical and organisational measures to protect your information, including encryption of stored access tokens and access controls limited to those who need it to do their jobs. No method of transmission or storage is completely secure, but we work to safeguard your data.

Your Rights

We handle Australian personal information in line with the Australian Privacy Act 1988 and the Australian Privacy Principles. If you are in the EU, UK, or elsewhere with similar protections, you may also have rights under laws such as the GDPR or UK GDPR. Depending on where you live, this can include the right to:

  • access the information we hold about you;
  • ask us to correct or delete it;
  • object to or restrict certain processing;
  • withdraw consent where processing relies on it;
  • lodge a complaint with a regulator — in Australia, the Office of the Australian Information Commissioner (OAIC).

To exercise any of these, contact us at privacy@mortar.design.

Contact

Questions about this policy or your data: privacy@mortar.design, or reach the team at hello@mortar.design.