Legal
Privacy Policy
Last updated: February 1, 2026
Summary: We collect only what we need to provide our services, we never sell your data, and you can export or delete your data at any time. We are GDPR and CCPA compliant.
Information We Collect
We collect information you provide directly to us, such as when you create an account, subscribe to a plan, submit a support request, or communicate with us. This includes:
- **Account Information**: Name, email address, company name, phone number, and billing address.
- **Usage Data**: How you interact with our services, including features used, pages visited, and actions taken.
- **Device Information**: IP address, browser type, operating system, and device identifiers.
- **Payment Information**: Processed securely through our payment provider (Stripe). We do not store full credit card numbers.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices, updates, security alerts, and support messages
- Respond to your comments, questions, and customer service requests
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Personalize and improve your experience
Data Storage and Security
We implement industry-standard security measures to protect your data:
- **Encryption at Rest**: All data is encrypted using AES-256 encryption
- **Encryption in Transit**: All connections use TLS 1.3
- **Access Controls**: Role-based access control with the principle of least privilege
- **Audit Logging**: Complete audit trail of all data access and modifications
- **Regular Backups**: Automated daily backups with point-in-time recovery
Data Sharing
We do not sell, trade, or otherwise transfer your personal information to third parties. We may share information with:
- **Service Providers**: Third-party companies that help us provide our services (hosting, payment processing, email delivery)
- **Legal Requirements**: When required by law, subpoena, or legal process
- **Business Transfers**: In connection with a merger, acquisition, or sale of assets
- **With Your Consent**: When you have given explicit permission
Data Retention
We retain your information for as long as your account is active or as needed to provide services. After account deletion:
- Account data is permanently deleted within 30 days
- Backup copies are purged within 90 days
- Anonymized analytics data may be retained indefinitely
- Legal and compliance records are retained as required by law
Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have certain rights under the GDPR:
- **Right to Access**: Request a copy of your personal data
- **Right to Rectification**: Request correction of inaccurate data
- **Right to Erasure**: Request deletion of your personal data
- **Right to Portability**: Request your data in a portable format
- **Right to Object**: Object to processing of your personal data
- **Right to Restrict**: Request restricted processing of your data
To exercise these rights, contact us at privacy@intraprism.com.
Your Rights (CCPA)
California residents have additional rights under the CCPA:
- **Right to Know**: What personal information we collect, use, and disclose
- **Right to Delete**: Request deletion of personal information
- **Right to Opt-Out**: Opt out of the sale of personal information (we do not sell personal information)
- **Right to Non-Discrimination**: We will not discriminate against you for exercising your rights
Cookies and Tracking
We use cookies and similar tracking technologies to collect usage data and improve our services. See our Cookie Policy for detailed information about the types of cookies we use and how to manage your preferences.
International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Data Processing Agreements with all sub-processors
- Regular compliance audits
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice via email or in-app notification.