Mockup First

Privacy Policy

How Mockup First handles the information it holds, and which third parties receive any of it.

Last updated September 11, 2026

1. Who we are

Mockup First is an agency operating platform published by Print Helpers LLC (“we”, “us”). It is used by our own staff to run the agency, and by our clients and referral partners through their own restricted portals. Questions about this policy, or a request to see or delete information, go to support@mockupfirst.com.

2. What we collect

  • Account information — the name, email address, role and password of each person we issue a login to. Passwords are stored only as a one-way hash; we cannot read them.
  • Business records — clients and their contacts, projects, tasks, files, invoices, payments and partner commissions. This is the agency’s own operating data, and most of it describes organisations rather than individuals.
  • Communications — the content of emails and text messages exchanged with a client through the platform, call records and voicemail transcripts supplied by our telephony provider, and notes staff write on a record.
  • Payment details — see section 4. We do not receive or store card numbers.
  • Technical information — the IP address a request came from, used for rate limiting on public forms, and the session cookie described in section 7.

3. How we use it

To run the agency and deliver work a client has asked for: managing projects and tasks, quoting and invoicing, collecting payments a client has agreed to, corresponding with clients, keeping the books, and giving each client and partner a portal showing only their own records. We do not sell information and we do not use it for advertising.

4. Card payments

Card details are entered directly into fields served by our payment gateway and are never sent to, seen by, or stored on our servers. When a client agrees to a stored card for scheduled payments, the gateway keeps the card and gives us a reference to it. What we hold is that reference plus the brand, the last four digits and the expiry month — enough for a person to tell two cards apart and nothing that could be used to charge a card anywhere else.

5. Who else receives information, and why

We share information with the service providers below, only to the extent each one needs to perform its function. Each processes data under its own terms and privacy policy.

  • Intuit QuickBooks Online — when a payment is booked to the accounts, we send the client’s business name and the details of that sale (amount, date, description, the account and item it is booked to). We read the connected company’s name and its list of accounts and items so the entry can be filed correctly. Nothing else is sent, nothing is read back into the platform beyond that, and disconnecting QuickBooks in our settings stops the exchange immediately.
  • Google (Workspace) — sends email on our behalf from our own mailboxes, and reads free/busy times and creates events on our calendar when a visitor books a call.
  • Twilio SendGrid — an alternative provider for the same outbound email.
  • Dialpad — carries text messages and calls between the agency and a client, and supplies the call records and transcripts shown in the platform.
  • NMI (through Betterpay) — our payment gateway; it receives the card details a client enters and processes the charge.
  • Instantly — an outbound email tool; we import contacts who have replied with interest into our own marketing board.
  • Anthropic — assists with drafting and summarising inside the platform. Content is sent only for the request being made.
  • Amazon Web Services — stores files uploaded to a project or a task.

We may also disclose information where the law requires it, or to protect our rights, safety or property.

6. Security

  • All traffic to the platform is encrypted in transit (HTTPS).
  • Credentials for the services above are encrypted at rest with AES-256-GCM, using a key held in the server environment and never in the database — a copy of the database on its own cannot reveal them.
  • Passwords are hashed, never stored in a readable form.
  • Access is restricted by role: a client sees only their own client's records, a referral partner sees only their own sales and commissions, and staff see only the clients they are assigned to.
  • No security is absolute, and we do not claim otherwise.

7. Cookies and tracking

We set one cookie, and it exists to keep a signed-in person signed in. There are no advertising cookies, no analytics trackers and no third-party tags on this site.

Email we send from the platform may contain a small tracking image so the sender can tell whether a message was opened. It records only that the message was opened and when. Blocking images in your mail client prevents it.

8. How long we keep it

Business and financial records are kept for as long as we need them to run the agency and to meet our tax and accounting obligations. Everything else is kept while it is useful for the purpose it was collected for. Write to us at support@mockupfirst.com to ask what we hold about you, to correct it, or to ask us to delete it; we will do so unless we are required to keep it.

9. Children

The platform is a business tool. It is not directed at children and we do not knowingly collect information from anyone under 13.

10. Changes

If this policy changes, the date at the top of this page changes with it. Material changes affecting people who hold a login will also be sent to them by email.