Legal

Privacy Policy

Last updated: February 1, 2026

Summary: We collect only what we need to provide our services, we never sell your data, and you can export or delete your data at any time. We are GDPR and CCPA compliant.

Information We Collect

We collect information you provide directly to us, such as when you create an account, subscribe to a plan, submit a support request, or communicate with us. This includes: - **Account Information**: Name, email address, company name, phone number, and billing address. - **Usage Data**: How you interact with our services, including features used, pages visited, and actions taken. - **Device Information**: IP address, browser type, operating system, and device identifiers. - **Payment Information**: Processed securely through our payment provider (Stripe). We do not store full credit card numbers.

How We Use Your Information

We use the information we collect to: - Provide, maintain, and improve our services - Process transactions and send related information - Send technical notices, updates, security alerts, and support messages - Respond to your comments, questions, and customer service requests - Monitor and analyze trends, usage, and activities - Detect, investigate, and prevent fraudulent transactions and other illegal activities - Personalize and improve your experience

Data Storage and Security

We implement industry-standard security measures to protect your data: - **Encryption at Rest**: All data is encrypted using AES-256 encryption - **Encryption in Transit**: All connections use TLS 1.3 - **Access Controls**: Role-based access control with the principle of least privilege - **Audit Logging**: Complete audit trail of all data access and modifications - **Regular Backups**: Automated daily backups with point-in-time recovery

Data Sharing

We do not sell, trade, or otherwise transfer your personal information to third parties. We may share information with: - **Service Providers**: Third-party companies that help us provide our services (hosting, payment processing, email delivery) - **Legal Requirements**: When required by law, subpoena, or legal process - **Business Transfers**: In connection with a merger, acquisition, or sale of assets - **With Your Consent**: When you have given explicit permission

Data Retention

We retain your information for as long as your account is active or as needed to provide services. After account deletion: - Account data is permanently deleted within 30 days - Backup copies are purged within 90 days - Anonymized analytics data may be retained indefinitely - Legal and compliance records are retained as required by law

Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have certain rights under the GDPR: - **Right to Access**: Request a copy of your personal data - **Right to Rectification**: Request correction of inaccurate data - **Right to Erasure**: Request deletion of your personal data - **Right to Portability**: Request your data in a portable format - **Right to Object**: Object to processing of your personal data - **Right to Restrict**: Request restricted processing of your data To exercise these rights, contact us at privacy@intraprism.com.

Your Rights (CCPA)

California residents have additional rights under the CCPA: - **Right to Know**: What personal information we collect, use, and disclose - **Right to Delete**: Request deletion of personal information - **Right to Opt-Out**: Opt out of the sale of personal information (we do not sell personal information) - **Right to Non-Discrimination**: We will not discriminate against you for exercising your rights

Cookies and Tracking

We use cookies and similar tracking technologies to collect usage data and improve our services. See our Cookie Policy for detailed information about the types of cookies we use and how to manage your preferences.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including: - Standard Contractual Clauses (SCCs) for EU data transfers - Data Processing Agreements with all sub-processors - Regular compliance audits

Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will promptly delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice via email or in-app notification.