1. Introduction
This Privacy Policy explains how Easy Pivot ("we", "us", or "our") collects, uses, discloses, and protects personal information when you visit our website, use our business intelligence and analytics platform (the "Service"), or otherwise interact with us. This policy applies to personal information we collect through the Service, our website, email communications, and customer support interactions. It is designed to comply with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), the General Data Protection Regulation (GDPR) where applicable, and other applicable privacy laws.
2. Personal Information We Collect
- •We collect the following categories of personal information, as categorized under the CCPA/CPRA:
- •Identifiers: name, email address, account username, and account ID.
- •Commercial Information: subscription plan, billing status, payment history (processed through our payment processor; we do not store full payment card numbers).
- •Internet or Other Electronic Network Activity: IP address, browser type and version, operating system, device identifiers, pages viewed, features used, clickstream data, and session timestamps.
- •Professional or Employment-Related Information: job title and company name, where voluntarily provided.
- •Inferences: aggregated usage patterns and preferences derived from your activity to improve the Service.
- •Customer Data You Provide: datasets, dashboards, reports, queries, and other content you upload or create within the Service. This data is processed solely to provide the Service to you and is treated as confidential.
- •Communications: content of support tickets, emails, and chat interactions with our team.
3. Sensitive Personal Information
We do not collect sensitive personal information (as defined under the CPRA, such as social security numbers, financial account details, precise geolocation, racial or ethnic origin, or biometric data) for the purpose of inferring characteristics about you, unless you choose to include such information in data you upload to the Service. If you upload datasets containing sensitive information, you are responsible for ensuring you have the lawful basis and appropriate safeguards to do so. Under the CPRA, you have the right to limit the use of your sensitive personal information; because we do not use sensitive information beyond what is necessary to provide the Service, this right is automatically satisfied.
4. How We Collect Your Information
- •Directly from you: when you register, fill in forms, contact support, or otherwise provide information to us.
- •Automatically: through cookies, log files, and similar technologies when you use the Service (see Section 6).
- •From third parties: if you sign in through Google or another OAuth provider, we receive the basic profile information (name, email address) that you authorize that provider to share with us.
- •From our service providers: hosting providers, analytics providers, and payment processors may share limited information with us as necessary to deliver their services.
5. How We Use Your Information
- •To provide, operate, maintain, and improve the Service and its features.
- •To authenticate your account, maintain session security, and protect against unauthorized access.
- •To process billing and manage your subscription (including invoices and payment reminders).
- •To send you transactional and service-related communications (verification codes, security alerts, billing notices, service updates).
- •To respond to your support requests and resolve technical issues.
- •To analyze usage patterns and improve product quality, functionality, and user experience, using aggregated and de-identified data where possible.
- •To detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms of Service.
- •To comply with legal obligations, enforce our agreements, and protect our rights and the rights of others.
6. Cookies and Similar Technologies
- •Essential Cookies: required for the Service to function — session authentication, security, and preference storage (language, theme). These cannot be disabled without affecting core functionality.
- •Analytics Cookies: we use Google Analytics 4 ("GA4") to understand how visitors use the Service (e.g., pages visited, session duration, feature usage). Analytics cookies (such as the "_ga" cookie) are only set after you accept analytics cookies through our cookie consent banner, and we use Google Consent Mode so that no analytics data is collected or transmitted until you grant consent. You may withdraw consent at any time by declining in the banner, clearing your browser cookies, or contacting us at privacy@epivotlabs.com.
- •Attribution Cookies: when you first visit the Service, we set a first-party cookie (named "utm_data", stored for 30 days) that records how you arrived — campaign parameters in the link you followed (for example utm_source or utm_campaign), the referring website, and the landing page. If you later create an account, this information is associated with your account so we can measure which channels bring users to the Service. This cookie is first-party, is used solely for our own signup-source statistics, is never shared with third parties or used for advertising, and is not required for the Service to function. You can block or delete it through your browser settings at any time.
- •Preference Cookies: remember your choices (e.g., timezone, dashboard layout) to personalize your experience.
- •We do not use advertising or third-party tracking cookies on the Service.
- •You can control cookies through your browser settings or through the cookie consent banner displayed on our site. Disabling essential cookies may prevent you from using the Service.
7. How We Share Your Information
- •We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising. Under the CCPA/CPRA, we disclose personal information only for the following "business purposes":
- •Service Providers: We share information with trusted vendors who help us operate the Service, including: cloud hosting and infrastructure providers; email delivery services (for transactional emails and verification codes); payment processors (Stripe, Inc. — for billing); customer support tools; and analytics providers. All service providers are contractually bound to use your information only to perform services on our behalf and to protect it with appropriate safeguards.
- •Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to this Privacy Policy and applicable law.
- •Legal Compliance: We may disclose information when required by law, subpoena, or other legal process, or when we reasonably believe disclosure is necessary to protect the rights, property, or safety of our users, the public, or our company.
- •With Your Consent: We may share information with third parties when you have given us explicit consent to do so.
8. Data Retention
- •Account Data: retained for as long as your account is active, plus a reasonable period after account deletion to allow for restoration requests, resolve disputes, and comply with legal obligations.
- •Customer Data (dashboards, reports, datasets): retained while your subscription is active. Upon cancellation or termination, you may export your data during the applicable notice period; we then delete or de-identify your data in accordance with our deletion schedule (typically within 90 days, unless legal retention obligations require otherwise).
- •Transaction and Billing Records: retained for at least 7 years to comply with tax and accounting obligations.
- •Logs and Analytics Data: retained in aggregated or de-identified form for up to 24 months; raw logs are retained for a shorter period (typically 30 days) for security monitoring.
- •Communications (support tickets, emails): retained for as long as needed to provide support and for record-keeping, typically up to 3 years.
- •Where retention is required by law, we retain information for the period required by the applicable statute.
9. Data Security
- •We implement administrative, technical, and physical safeguards designed to protect your information:
- •Encryption: data is encrypted in transit using TLS 1.2 or higher, and at rest using industry-standard encryption.
- •Access Controls: access to production systems and customer data is restricted to authorized personnel on a least-privilege basis, protected by multi-factor authentication.
- •Security Monitoring: we monitor systems for unauthorized access, anomalies, and security incidents, and maintain incident response procedures.
- •Backups: customer data is backed up regularly to protect against data loss.
- •Employee Training: our team receives security and privacy training on a regular basis.
- •No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If a security incident affects your data, we will notify you and relevant authorities as required by applicable law.
10. Your Privacy Rights (CCPA/CPRA)
- •If you are a California resident, you have the following rights under the CCPA and CPRA:
- •Right to Know: the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share information.
- •Right to Delete: the right to request deletion of your personal information, subject to certain legal exceptions (e.g., to complete a transaction, detect security incidents, or comply with legal obligations).
- •Right to Correct: the right to request correction of inaccurate personal information we maintain about you.
- •Right to Opt Out of Sale/Sharing: the right to opt out of the "sale" or "sharing" of your personal information. We do not sell your personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; we will update this policy if this changes.
- •Right to Limit Sensitive Information Use: the right to limit the use of sensitive personal information. As noted in Section 3, we do not use sensitive information beyond what is necessary to provide the Service.
- •Right to Non-Discrimination: we will not deny you goods or services, charge you different prices, or provide a different level of service for exercising your privacy rights.
- •Right to Authorized Agent: you may designate an authorized agent to make a request on your behalf, subject to verification.
11. Your Privacy Rights (GDPR and Other Jurisdictions)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may have the following rights under the GDPR: the right to access, the right to rectification, the right to erasure ("right to be forgotten"), the right to restrict processing, the right to data portability, the right to object to processing (including profiling), and the right to withdraw consent at any time. Our lawful bases for processing your personal information include: performance of a contract (providing the Service), legitimate interests (security, fraud prevention, product improvement), legal obligation (compliance), and consent (where you have provided it, such as for optional communications). You also have the right to lodge a complaint with your local supervisory authority.
12. How to Exercise Your Rights
- •To exercise any of the rights described in Sections 10 and 11, you may:
- •Submit a request by email to privacy@epivotlabs.com, or through the "Account Settings" page in the Service where applicable.
- •We will verify your identity before fulfilling most requests (for example, by matching the email address on file with your account, or requiring you to sign in to your account). We may need to request additional information where reasonably necessary to verify your identity.
- •We will respond to verified requests within 45 days of receipt (extendable by an additional 45 days where reasonably necessary, with notice). Under the CCPA, requests to know or delete may be made twice within a 12-month period.
- •If we decline a request, we will explain the reason and, where applicable, provide information about how to appeal the decision.
13. Children’s Privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children under 16. Consistent with the Children’s Online Privacy Protection Act (COPPA), if we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@epivotlabs.com.
14. International Data Transfers
We process and store your information on servers located in the United States and may process it in other countries where our service providers operate. When personal information is transferred across borders, we implement appropriate safeguards, including standard contractual clauses approved by the European Commission where required, to ensure your information is protected to the standards described in this policy.
15. Third-Party Links and Services
The Service may contain links to third-party websites, integrations, or services (for example, Google Sign-In, payment processing). We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party service you connect to or use through the Service. When you connect a third-party data source (such as a database, spreadsheet, or cloud service) to the Service, that third party's privacy policy and terms also apply to your use of that connection.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on this page with a revised "Last Updated" date, and where appropriate, by email or in-product notice at least 30 days before material changes take effect. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy. We encourage you to review this page periodically.
17. Contact Us
- •If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us.