Legal

Privacy Policy

Last updated July 2026

This Privacy Policy explains how TD Vision U LLC, a Texas limited liability company (“TD Vision,” “we,” “us,” or “our”), collects, uses, discloses, and safeguards personal information in connection with the nodal.design website (the “Site”) and the Nodal and Nodal+ add-ins for Autodesk Revit (together with the Site, the “Services”). It also describes the rights and choices available to you regarding your personal information.

By accessing the Site or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Services. Capitalized terms not defined here have the meaning given in our Terms of Service.

1. Scope

This Policy applies to personal information we process about visitors to the Site, holders of a Nodal account, and users of the Nodal+ paid subscription. The free Nodal tools are distributed through the Autodesk App Store and, when used without a Nodal account, do not require you to provide personal information to us. This Policy does not apply to third-party websites, products, or services that we do not own or control, including Autodesk Revit.

2. Information We Collect

We collect the following categories of personal information:

  • Account information. When you create an account, we collect your email address, which we use to authenticate you (via a passwordless sign-in link) and to associate your subscription and license with you. We do not use passwords, so we do not collect or store them.
  • Payment and transaction information. Purchases of Nodal+ are processed by our Merchant of Record, Lemon Squeezy (see Section 5). Lemon Squeezy collects your payment details directly; we do not receive or store your full payment card number. We receive limited transaction metadata such as your subscription status, plan, billing period, the country and currency of the transaction, and the last four digits or card brand where provided.
  • License and activation data. To bind a Nodal+ license to your computer(s) and validate it, our licensing provider, Cryptlex (see Section 5), processes your license key, activation status, a hashed device fingerprint, machine hostname, operating system, and application version. A device fingerprint is a technical hardware identifier used to prevent unauthorized license sharing; it is not a biometric identifier and is not derived from any physical characteristic of a person.
  • Support communications. If you contact us (for example, at support@nodal.design), we collect the information you choose to provide, such as your name, email address, license key, and the contents of your message.
  • Usage and device data collected automatically. When you visit the Site, our hosting and network provider, Cloudflare, automatically processes technical data such as your IP address, browser type, referring pages, and request timestamps for security, abuse prevention, and reliability. We use a single essential cookie to keep you signed in (see Section 3).
  • Optional diagnostics. The Nodal add-in may offer to send crash reports and usage diagnostics to help us fix bugs and improve the product. This is opt-in; we collect it only if you enable it.

We do not intentionally collect “sensitive data” as defined under applicable privacy laws (such as government identifiers, precise geolocation, health, biometric, or racial/ethnic data), and we ask that you not send us such information.

3. Cookies and Local Storage

We use a single, strictly necessary cookie to maintain your authenticated session after you sign in. This cookie is essential to the operation of your account and cannot be disabled without preventing sign-in. We do not use advertising, marketing, cross-site tracking, or third-party analytics cookies, and we do not engage in targeted advertising. Because we do not sell personal data or process it for targeted advertising, there is no “Do Not Sell or Share” action for us to honor; we nonetheless respect recognized universal opt-out signals to the extent applicable law requires.

4. How We Use Personal Information

We use personal information for the following purposes:

  • to create and administer your account and authenticate your sign-in;
  • to issue, activate, validate, suspend, and manage your Nodal+ license;
  • to process subscriptions, trials, renewals, cancellations, and refunds through our Merchant of Record;
  • to provide customer support and respond to your requests;
  • to operate, secure, maintain, and improve the Services, including preventing fraud, abuse, and unauthorized license use;
  • to send you transactional communications, such as sign-in links and billing or account notices; and
  • to comply with legal obligations and enforce our Terms of Service.

Where the EU/UK General Data Protection Regulation (“GDPR”) applies, our legal bases for processing are: performance of a contract with you (operating your account and license); our legitimate interests in securing and improving the Services and preventing abuse; your consent (for optional diagnostics), which you may withdraw at any time; and compliance with legal obligations.

5. How We Share Personal Information — Service Providers

We do not sell your personal information, and we do not share it for cross-context behavioral or targeted advertising. We disclose personal information only to the service providers (“processors” / “subprocessors”) listed below, each of which is contractually bound to process it solely to provide services to us, and only to the extent necessary for its function:

  • Lemon Squeezy (a Stripe company) — our Merchant of Record and payment provider. As Merchant of Record, Lemon Squeezy is the seller of record for Nodal+ purchases and is responsible for payment processing, billing, sales tax/VAT collection and remittance, refunds, chargebacks, and PCI-DSS compliance. Card data is handled by Lemon Squeezy and its payment infrastructure (Stripe), not by us. Privacy policy: lemonsqueezy.com/privacy.
  • Cryptlex — our licensing provider, which activates and validates Nodal+ licenses and binds them to authorized machines. We are the data controller and Cryptlex acts as our data processor. Privacy policy: cryptlex.com/legal/privacy-policy.
  • Resend — our transactional email provider, used to deliver sign-in links and account and billing notices. Privacy policy: resend.com/legal/privacy-policy.
  • Cloudflare — our hosting, database, and network provider, which serves the Site, stores account data, and provides content delivery, DNS, and security. Privacy policy: cloudflare.com/privacypolicy.

We may also disclose personal information: (a) to comply with applicable law, legal process, or a lawful governmental request; (b) to enforce our agreements or protect the rights, property, or safety of TD Vision, our users, or others; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or provide notice as required by law.

6. International Data Transfers

We are based in the United States, and our service providers may process personal information in the United States and other countries. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we and our processors rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or a valid data transfer framework certification. By using the Services, you understand that your information may be processed in countries whose data protection laws may differ from those of your jurisdiction.

7. Data Retention

We retain personal information for as long as your account is active and for a reasonable period thereafter as needed to provide the Services, comply with our legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Billing and transaction records maintained by our Merchant of Record are retained according to its policies and applicable law. When personal information is no longer required, we delete or de-identify it. You may request deletion at any time as described in Section 9.

8. Data Security

We implement administrative, technical, and organizational measures designed to protect personal information, including encryption in transit (TLS), storage of authentication tokens as irreversible hashes rather than in plaintext, access controls, and reliance on reputable infrastructure providers. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for keeping access to your email account and sign-in links secure.

9. Your Privacy Rights

Texas and other U.S. state residents

Depending on your state of residence — including under the Texas Data Privacy and Security Act (TDPSA) and comparable laws — you may have the right to: (i) confirm whether we process your personal data and access it; (ii) correct inaccuracies; (iii) delete personal data you provided or that we obtained; (iv) obtain a portable copy of data you provided; and (v) opt out of the processing of your personal data for targeted advertising, the “sale” of personal data, or profiling with legal or similarly significant effects. We do not sell personal data, engage in targeted advertising, or conduct such profiling, so there is nothing to opt out of in those respects.

To exercise these rights you may use either of the following methods: (1) email support@nodal.design with your request, or (2) submit a request from your account dashboard. We will not discriminate or retaliate against you for exercising your rights, and we will respond without undue delay and within 45 days (extendable once by an additional 45 days where reasonably necessary, with notice). We may need to verify your identity before fulfilling a request. If we decline your request, you may appeal by emailing us with “Privacy Appeal” in the subject line; we will respond to your appeal within 60 days, and if the appeal is denied you may contact the Texas Attorney General (or your state’s Attorney General) to submit a complaint.

EEA, UK, and Switzerland residents

If the GDPR (or UK GDPR) applies to you, you have the rights to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact support@nodal.design.

California residents

Under the California Consumer Privacy Act, as amended (CCPA/CPRA), you have rights to know, access, correct, delete, and obtain a copy of your personal information, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. You may exercise your rights using the methods above.

10. Children’s Privacy

The Services are intended for professional use and are not directed to children. We do not knowingly collect personal information from anyone under the age of 18. If you believe a minor has provided us personal information, please contact us and we will delete it.

11. Third-Party Links and Services

The Services may link to or interoperate with third-party websites and products (for example, Autodesk Revit, the Autodesk App Store, and our service providers). We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies.

12. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where required by law or for material changes, provide additional notice. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.

13. Contact Us

If you have questions about this Policy or our privacy practices, or wish to exercise your rights, contact us at:

TD Vision U LLC
1020 Highway 377 N, Ste B PMB 3009
Whitesboro, TX 76273, USA
support@nodal.design