1. Our Role
For our marketing sites, prospective customers, and account holders, we act as a data controller. For personal information that a Tenant workspace processes about its own consumers, clients, employees, or contacts through the platform, we act as a service provider / data processor on the Tenant's behalf, and the Tenant is the controller/business. You should consult the Tenant's own privacy notice for information about how they process consumer data. If you are a consumer of a Tenant and wish to exercise a privacy right, please contact the Tenant directly; we will assist the Tenant in responding.
2. Information We Collect
2.1 Information you provide.
- Account & billing: name, business name, email, password (hashed), phone, billing address, and payment identifiers (payment card data is handled directly by our PCI-compliant processor and is not stored by us).
- Workspace configuration: brand assets, sender identities, templates, integrations, and user roles.
- Consumer records uploaded by Tenants: name, contact info, mailing address, date of birth, portions of Social Security number, credit reports, dispute letters, financial account information, and other nonpublic personal information the Tenant chooses to store.
- Support & communications: messages, attachments, and call/meeting notes.
2.2 Information collected automatically.
- Device and connection data (IP address, user-agent, OS, browser, locale, timezone).
- Usage data (pages viewed, features used, timestamps, referring URLs, error events).
- Cookies and similar technologies (see Cookie Policy).
2.3 Information from third parties.
We may receive information from identity-verification services, payment processors, integrated third-party services you authorize (e.g., credit-monitoring APIs, print/mail vendors, email/SMS providers), publicly available sources, and marketing/analytics partners.
3. How We Use Information
- Provide, secure, maintain, and improve the Services.
- Authenticate users, prevent fraud, enforce terms, and detect abuse.
- Process payments and manage subscriptions.
- Respond to support requests and communicate about the Services.
- Send transactional notices and, with any legally required consent, marketing messages you can opt out of at any time.
- Analyze usage to improve performance, reliability, and features.
- Comply with legal obligations and enforce our agreements.
We do not sell personal information and we do not use Tenant-submitted consumer personal information to train third-party foundation models.
4. Legal Bases (EU/UK GDPR)
Where GDPR applies, we rely on: (a) performance of a contract; (b) our legitimate interests in operating and securing the Services (balanced against your rights); (c) consent, where required (e.g., non-essential cookies, marketing); and (d) compliance with legal obligations.
5. How We Share Information
We share personal information only as necessary for the purposes above, with:
- Subprocessors and service providers that host, secure, analyze, or deliver parts of the Services (cloud infrastructure, database, authentication, storage, transactional email, SMS, print/mail fulfillment, error monitoring, analytics, payment processing, and AI inference providers) under written contracts that restrict their use of the data.
- Tenants, when we are processing on their behalf.
- Integrated third-party services you or a Tenant explicitly connect.
- Legal and safety recipients, when required by law, subpoena, or to protect rights, property, safety, or to investigate fraud or abuse. We will challenge overbroad requests where lawful and appropriate.
- Corporate transactions, in connection with a merger, acquisition, financing, or sale of assets, subject to contractual and legal safeguards.
6. International Transfers
We are based in the United States and may process personal information in the U.S. and other jurisdictions. Where required, we use Standard Contractual Clauses, the UK IDTA/Addendum, or another approved transfer mechanism.
7. Data Retention
We retain personal information only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Tenant Content is retained per the Tenant's configuration and, following termination, may be retained for up to 30 days to enable export before deletion. Backup copies are purged on a rolling basis in accordance with our retention schedule.
8. Security
We implement administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit (TLS 1.2+), encryption at rest, role-based access control, least-privilege administration, audit logging, isolated per-tenant database policies (row-level security), secret management, dependency and vulnerability scanning, code review, incident response planning, and mandatory security training for personnel with access to production systems. No method of transmission or storage is 100% secure. You are responsible for using strong, unique credentials and enabling any available multi-factor authentication.
9. Your Privacy Rights
Subject to verification and applicable law, you may have the right to: (a) access the personal information we hold about you; (b) correct inaccurate information; (c) delete information; (d) receive a portable copy; (e) opt out of certain processing (including “sharing” for cross-context behavioral advertising and profiling with legal or similarly significant effects); and (f) withdraw consent where processing is based on consent. To exercise these rights, use our contact page. We will not discriminate against you for exercising a right. You may also appeal a decision by replying to our response.
California residents: Under the CCPA/CPRA, we have not sold personal information or shared it for cross-context behavioral advertising in the preceding 12 months. Categories of personal information we collect are listed in Section 2; retention criteria are described in Section 7.
10. Children's Privacy
The Services are not directed to children under 16. We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it.
11. GLBA & Financial Privacy
Consumer information processed for Tenants may constitute nonpublic personal information under the Gramm-Leach-Bliley Act. We limit access to such information to authorized personnel with a legitimate business need, encrypt it in transit and at rest, and process it only as directed by the Tenant. Tenants are responsible for providing GLBA privacy notices to their own consumers.
12. Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects concerning individuals solely on the basis of automated processing without meaningful human review. AI-generated suggestions surfaced in the Services are intended for review and approval by a qualified human.
13. Do Not Track
Because there is no consensus industry standard for “Do Not Track” signals, our sites do not currently respond to them. We do honor Global Privacy Control (GPC) signals as an opt-out of “sharing” under U.S. state laws where applicable.
14. Changes to this Policy
We will post any material changes here and update the “Last updated” date. Where required by law, we will provide additional notice.
15. Contact
Privacy inquiries and rights requests may be submitted through our contact page.