Last updated: September 7, 2026

Privacy Policy

Pending Magic is a commission tracking tool for solo creators and small studios. This Privacy Policy explains what we collect from creators and their clients, how we use it, and the choices you have. It should be read alongside our Terms of Service.

What we collect

  • Creator account info: name, email, and password (hashed).
  • Client info a creator adds: names, contact details (email or phone), and anything shared through a work item's tracking page.
  • Work item content: job details, contract terms, pricing and payment status, and messages between a creator and their client. If a creator tracks shipping, we also collect the carrier and tracking number.
  • Contract signing and payment records: when a client signs a contract or amendment, or completes a payment, through a tracking link, we log the IP address and browser/device (user agent) used at the time as an audit trail.
  • Creator billing information: if a creator is on a paid plan, Pending Magic uses Stripe to process the subscription payment. Stripe collects and stores the card details; we don't store full card numbers.
  • App usage and device data: basic diagnostics and analytics to improve performance and reliability, and a device push token if you enable push notifications.

How we use data

  • Provide the service: run creator accounts, generate and serve client tracking pages, send status update notifications, and record contract signatures, payments, and messages.
  • Improve and support: fix bugs, protect against abuse, and make Pending Magic easier to use.
  • Communicate with you: account notices, security alerts, and service updates.

Clients and tracking links

Clients don't create a Pending Magic account. A creator shares a private tracking link that lets a client view a work item's status and, depending on the link, act on it: for example, signing a contract or replying in a conversation. Anyone with that link can see the information on it, so a client's data is only as private as the link a creator shares. We use a client's contact details, if the creator adds them, only to deliver status notifications and secure the tracking link to that client.

Data sharing

We don't sell personal data. We may share limited data with service providers that help us run Pending Magic, for example hosting, email or SMS delivery, push notification delivery, shipping carriers (for tracking sync), authentication, or analytics, under contracts that require them to protect your information. We use Stripe to process a creator's subscription payment for their own Pending Magic account. Separately, if a creator connects a payment processor for their clients (currently Square), Pending Magic facilitates checkout on that creator's tracking pages, but the processor holds the funds and handles any cardholder data under its own privacy practices. If a creator doesn't connect a processor, they handle any payment link or instructions on their own.

Data retention and deletion

We keep data while a creator's account and work items are active. As explained in our Terms of Service, Pending Magic is not a system of record: when a creator deletes a work item, a client, or their account, the related data (contracts, signatures, messages, and the client-facing tracking page) is permanently removed and cannot be recovered by the creator or by us, except where we need to keep certain records for security, compliance, or legal reasons. Deleting a work item or account also breaks the tracking link for any client still viewing it.

Children's privacy

Pending Magic is intended for use by adults running a commission business, and is not directed at children. We don't knowingly collect personal data from children, and creator accounts must be held by an adult.

Security

We use administrative, technical, and organizational safeguards to protect your information. No system is 100% secure, but we work to keep your data safe.

Your choices

  • Creators can access, update, or delete their account and work item data using in-app options, or by contacting support.
  • Clients who want data on a tracking page removed should contact the creator who shared the link with them; a creator can delete the underlying work item at any time.
  • Control notification preferences in your device or account settings where available.

Contact

Send questions about this policy through the contact options on our website.

This page is for general information and isn't legal advice.