Privacy Policy
Your privacy is our priority. Learn how we protect and manage your data.
Effective Date: 2024-12-15
Version: 2.0
1. Information We Collect
Information You Provide Directly
- Account Information: Name, email address, password, startup stage, industry, and profile preferences
- Business Content: Business ideas, plans, goals, vault content, chat conversations with PivotPal, and responses to plan generators
- Communication Data: Messages you send us, feedback, support requests, and survey responses
- Payment Information: Billing address and payment details (processed securely by our payment processor Stripe)
Information We Collect Automatically
- Usage Data: Features used, time spent on platform, click patterns, session recordings (anonymized), and interaction patterns
- Technical Data: IP address, browser type, device information, operating system, referring URLs, and access logs
- Cookies and Tracking: Session cookies, preference cookies, analytics cookies, and tracking pixels (with your consent)
- Performance Data: Error logs, crash reports, and system performance metrics
Information from Third Parties
- Social Login: If you use social media login, we receive basic profile information
- Referral Data: Information about referrals and referral rewards from our referral program
- Payment Data: Transaction confirmations and payment status from Stripe
2. How We Use Your Data
Service Operation and Delivery
- Platform Functionality: Operating LeanPivot.ai, processing AI requests, managing your vault content, and tracking your progress
- Account Management: Creating and maintaining your account, subscription management, and providing customer support
- AI Processing: Using your inputs to generate personalized responses through PivotPal and our plan generators
- Payment Processing: Handling subscriptions, processing payments, managing billing, and issuing refunds
Personalization and Improvement
- Content Personalization: Tailoring content, recommendations, and AI responses based on your startup stage and preferences
- Service Improvement: Analyzing usage patterns to improve features, fix bugs, and develop new functionality
- Research and Development: Improving AI models and developing new features (using anonymized or aggregated data)
- Quality Assurance: Monitoring service performance and ensuring optimal user experience
Communication and Marketing
- Essential Communications: Service updates, security alerts, billing notifications, and policy changes
- Marketing Communications: Newsletter, product updates, and promotional content (with your consent, opt-out anytime)
- Referral Program: Managing referral rewards, tracking referral performance, and processing coin transactions
Legal and Security
- Security: Preventing fraud, protecting against security threats, and maintaining platform integrity
- Legal Compliance: Complying with applicable laws, responding to legal requests, and enforcing our terms
- Business Continuity: Backup and disaster recovery, business transfers, and regulatory compliance
3. Legal Bases for Processing (GDPR)
Purpose | Legal Basis |
---|---|
Service delivery | Performance of contract |
Marketing emails | Consent |
Legal compliance | Legal obligation |
Platform improvements | Legitimate interest |
4. Data Retention
- Active Accounts: Data retained while your account is active and for legitimate business purposes
- Account Deletion: Most data deleted within 30 days of account deletion request
- Legal Retention: Some data retained longer for legal compliance (payment records, legal claims)
- Anonymized Data: Aggregated, anonymized data may be retained indefinitely for analytics
- AI Interactions: Chat histories stored for your convenience, can be deleted through account settings
- Financial Records: 7 years for tax and legal compliance requirements
5. Your Rights
GDPR Rights (EU Residents)
- Access your personal data
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Data portability
- Object to processing
- Restrict processing
CCPA Rights (California Residents)
- Know what data we collect
- Delete personal information
- Opt-out of data sales (we don't sell data)
- Non-discrimination for exercising rights
7. International Data Transfers
LeanPivot.ai operates globally, and your data may be transferred to and processed in countries other than your own:
Data Transfer Safeguards
- Adequacy Decisions: We transfer data to countries with adequate protection as determined by applicable law
- Standard Contractual Clauses: EU-approved contractual protections for transfers to non-adequate countries
- Data Processing Agreements: Contractual safeguards with all service providers handling your data
- Certification Programs: Partners certified under Privacy Shield successors or similar frameworks
Primary Data Locations
- United States: Primary data processing and storage location
- European Union: Data processing for EU users may occur within the EU
- Cloud Providers: AWS, Google Cloud infrastructure with global presence
- AI Processing: AI services may process data in multiple jurisdictions with appropriate safeguards
9. Data Security and Protection
Encryption
TLS 1.2+ in transit, AES-256 at rest
Access Control
Role-based access and MFA
SOC 2 Compliance
Annual security audits
24/7 Monitoring
Threat detection and response
10. AI Data Processing and Protection
AI Data Processing and Protection
AI Data Usage Principles
- Purpose Limitation: Your data is used only to generate responses for you, not to train public AI models
- Confidentiality: Your business ideas, plans, and conversations remain confidential
- Data Minimization: We only process the minimum data necessary for AI responses
- No Cross-User Training: Your proprietary business information is never used to improve responses for other users
Third-Party AI Processors
- Trusted Partners: Enterprise-grade AI services (OpenAI, Anthropic) with strict data protection agreements
- Contractual Protection: All AI service providers are prohibited from using your data for their own purposes
- No Persistent Storage: Third-party AI processors don't retain your data beyond processing your immediate request
User Control
- Session Storage: Chat histories stored for your convenience and can be deleted through account settings
- Aggregated Analytics: Usage patterns analyzed in aggregate without identifying individuals
- Deletion Rights: You can request deletion of your AI interaction history at any time
11. Contact Information
Privacy-Specific Contacts
- Privacy Officer: privacy@leanpivot.ai
- Data Protection: dpo@leanpivot.ai (for GDPR-related requests)
- Security Issues: security@leanpivot.ai
- General Support: support@leanpivot.ai
Self-Service Options
- Privacy Center: Manage your privacy settings
- Account Settings: Update preferences and manage data directly
- Cookie Settings: Manage cookie preferences
- Contact Form: General contact form for non-urgent inquiries
Business Information
- Company: LeanPivot Solutions, LLC
- Address: Available upon request for legal correspondence
- EU Representative: Contact privacy@leanpivot.ai for EU representative information
- Response Time: We respond to privacy inquiries within 72 hours
Supervisory Authorities
You have the right to file a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO)
- EU: Your national Data Protection Authority
- California: California Attorney General
Last updated: 2024-12-15