Privacy Policy
Last updated: September 24, 2024
Privacy Policy
This Privacy Policy describes how we collect, use, and protect your personal information when you use our B2B SaaS platform. We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Information We Collect
Personal Information You Provide
- Account Information: Name, email address, password
- Profile Information: Company details, job title, profile picture
- Organization Information: Company name, website, industry, team size
- Billing Information: Address, payment method details (processed securely through third-party providers)
- Communications: Messages, support requests, feedback
Automatically Collected Information
- Usage Data: Pages visited, features used, time spent, clicks and interactions
- Technical Data: IP address, browser type, device information, operating system
- Performance Data: Response times, error logs, system performance metrics
- Location Data: General location based on IP address (not precise location)
Cookies and Similar Technologies
We use cookies and similar technologies as described in our Cookie Policy.
2. How We Use Your Information
We process your personal information for the following purposes:
Service Provision and Management
- Create and manage your account and organization
- Process payments and manage subscriptions
- Provide customer support and technical assistance
- Send transactional emails (welcome, billing, security alerts)
Service Improvement and Analytics
- Analyze usage patterns to improve our platform
- Conduct A/B testing and feature optimization
- Monitor system performance and security
- Generate anonymized analytics and reports
Communication and Marketing
- Send product updates and feature announcements
- Provide educational content and best practices
- Conduct customer satisfaction surveys
- Send marketing communications (with your consent)
Legal and Security
- Comply with legal obligations and regulations
- Prevent fraud, abuse, and security incidents
- Enforce our Terms of Service
- Protect the rights and safety of our users
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: To provide our services and fulfill our contractual obligations
- Legitimate Interests: To improve our services, ensure security, and conduct business operations
- Consent: For marketing communications and non-essential cookies
- Legal Obligations: To comply with applicable laws and regulations
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your data with:
Service Providers
- Payment Processors: Stripe, PayPal, LemonSqueezy for secure payment processing
- Email Services: Resend, AWS SES, Mailgun for transactional and marketing emails
- Analytics Providers: Google Analytics, PostHog, Plausible for website analytics
- Cloud Infrastructure: Vercel, AWS, or similar providers for hosting and data storage
- Customer Support: Third-party tools for providing customer support
Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, property, and safety.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Security
We implement comprehensive security measures to protect your personal information:
- Encryption: Data is encrypted in transit (TLS) and at rest
- Access Controls: Strict access controls and authentication mechanisms
- Regular Security Audits: Ongoing security assessments and vulnerability testing
- Employee Training: Regular security awareness training for our team
- Incident Response: Documented procedures for security incident response
6. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with legal obligations:
- Account Data: Retained while your account is active and for 30 days after deletion
- Billing Records: Retained for 7 years for tax and legal compliance
- Analytics Data: Aggregated data retained for up to 26 months
- Legal Hold: Data may be retained longer if required for legal proceedings
7. Your Rights Under GDPR
If you are located in the European Union, you have the following rights:
Right of Access
Request a copy of the personal information we hold about you.
Right of Rectification
Request correction of inaccurate or incomplete personal information.
Right of Erasure (Right to be Forgotten)
Request deletion of your personal information under certain circumstances.
Right of Portability
Request your data in a structured, commonly used format for transfer to another service.
Right to Object
Object to the processing of your personal information for marketing purposes or legitimate interests.
Right to Restrict Processing
Request limitation of processing under certain circumstances.
To exercise these rights, please contact us at support@example.com. We will respond within 30 days.
8. International Data Transfers
Your personal information may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place, including:
- Adequacy Decisions: Transfers to countries with adequate data protection
- Standard Contractual Clauses: EU-approved contractual protections
- Privacy Shield: For transfers to certified US companies (where applicable)
9. Children's Privacy
Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will delete it promptly.
10. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws. We will:
- Post the updated policy on our website
- Update the "Last Updated" date
- Notify you of material changes via email or platform notification
- Obtain consent where required by law
11. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@example.com Response Time: We aim to respond within 48 hours
For GDPR-related inquiries, you may also contact your local data protection authority.
This Privacy Policy is effective as of the date listed above and applies to all users of our platform.