Privacy Notice
Version: 1.1 · Last Updated: August 26, 2026 · Effective Date: July 1, 2026
Introduction
This Privacy Notice explains how Pure Grace AI, LLC (“Company,” “we,” “our,” “us”) collects, uses, discloses, and retains personal information when you visit our website, contact us, request a demo, attend an event or sales call, create or use an account, or otherwise interact with us.
Company acts in two capacities:
- Controller (the party that determines how and why personal information is used) for personal information collected for our own purposes — for example, website visitors, prospects, event attendees, account administration, billing, and marketing. This Privacy Notice covers that processing.
- Processor / Service Provider when we process data on behalf of, and under the instructions of, our customers to provide the Services. That processing is governed by our Data Processing Addendum and the applicable customer agreement, not by this Privacy Notice. For the privacy practices of a Company customer — including to exercise rights over data a customer controls — please contact that customer directly; we will refer such requests to the relevant customer unless we are legally required to respond directly.
We provide notice of our collection practices at or before the point of collection. Short, just-in-time notices linking to this Privacy Notice appear at our demo and contact forms, account signup, checkout/billing pages, event registration, and our cookie banner.
1. Information We Collect
Information you provide to us.
- Contact and inquiry information — when you contact us, request a demo, or attend a sales call: name, email address, company name, job title, phone number, and the contents of your message.
- Account information — when you register for or use the Services: name, email address, role, and authentication credentials (username and password or other access credentials).
- Billing information — payment and billing details. Card payments are collected and processed directly by our third-party payment processor (currently Stripe). We receive only limited billing information — such as your name, email, and the card’s brand and last four digits — and we do not receive or store full payment-card numbers.
Information collected automatically when you use our website.
- IP address and approximate (not precise) location derived from it.
- Device and browser information — browser type, device type, operating system, and date/time of visit.
- Usage information — pages viewed, links clicked, referring pages, and similar first-party analytics data.
- Cookies and similar technologies — see “Cookies” below.
- Advertising click identifier — if you reach us from one of our Google Search ads and then create an account, the click identifier Google placed in the web address is stored with your organization’s record so we can measure which ads lead to signups. It is not stored on your device, and nothing is recorded for visitors who do not create an account. See “Advertising and measurement” in Section 4.
Information from third parties. We may receive information about you from third parties such as data-enrichment providers, marketing partners, and social networks to help us identify and reach prospective customers. We do not use information received from third parties for targeted advertising, and we do not sell or share it.
Sensitive personal information. Some information we collect may be “sensitive personal information” under California law — specifically, account log-in credentials in combination with the password or access credentials that permit access to your account, and payment/financial-account information to the extent it is handled in connection with billing. We use and disclose this information only for the purposes permitted under applicable law (for example, to authenticate users, provide and secure the Services, and process payments) and not to infer characteristics about you. We do not otherwise seek to collect sensitive personal information; please do not send us sensitive personal information unless we specifically request it.
2. How We Use Information
We use personal information to:
- Provide and administer the Services — create and maintain accounts, authenticate users, process transactions, and provide support.
- Operate and improve our website and Services — maintain, secure, analyze, and improve them.
- Communicate with you — respond to inquiries and demo requests and send service and account messages.
- Marketing — send newsletters and promotional materials, measure campaign effectiveness, and score or prioritize prospective business customers for our own sales and marketing. You can opt out at any time (see “Your Rights and Choices”).
- Analytics — understand site traffic and usage trends.
- Security and fraud prevention — protect our website, Services, and users, including using IP addresses to detect and prevent fraudulent or abusive activity.
- Legal and compliance — comply with law and enforce our agreements.
We do not use automated decision-making or profiling that produces legal or similarly significant effects about you. This statement concerns our own controller-capacity processing (our website, accounts, billing, support, and marketing); any customer-directed use of the Services is governed by the applicable customer agreement and our DPA, not by this Notice.
3. Legal Bases (EEA/UK/Switzerland)
Where Applicable Data Protection Law requires a legal basis, we rely on, by purpose: contractual necessity (account creation, authentication, providing support, processing transactions); consent (certain marketing and non-essential cookies, where required — you may withdraw consent at any time); legitimate interests (securing and improving our website and Services, analytics, and B2B marketing), balanced against your rights and subject to your right to object; and legal obligation (tax, accounting, and compliance).
4. How We Disclose Information
We may disclose personal information to:
- Service providers and processors that process it on our behalf under written contract (e.g., hosting, email, analytics, payment processing);
- Marketing service providers (such as email and CRM providers);
- Affiliates and professional advisors;
- A counterparty in connection with a corporate transaction (merger, acquisition, financing, or sale of assets); and
- Government authorities or others as required to comply with law or to establish, exercise, or defend legal claims.
Sale/Share. “Sale” under California and similar laws means disclosing personal information for monetary or other valuable consideration, and “share” means disclosing it for cross-context behavioral advertising. We do not sell personal information, and we do not currently share personal information for cross-context behavioral advertising. We do not use the Meta Pixel, the LinkedIn Insight Tag, or any similar social-media tracking pixel. Our advertising is described in the next paragraph.
Advertising and measurement. We advertise on Google Search. When you arrive from one of our ads, Google adds a click identifier to the web address. If you then create an account, we store that identifier with your organization’s record so that we can later tell Google the click led to a signup — this is how we learn which ads are worth running.
We want to be precise about what this does and does not involve. The identifier is read from the web address only at the moment an account is created. It is not stored in a cookie or anywhere else on your device, and nothing is recorded for visitors who do not create an account. We do not place a Google advertising tag on our website or in the Services. We delete the identifier once the signup has been reported to Google, or after 90 days, whichever comes first.
We have enabled Google’s Restricted Data Processing for this data, which limits Google’s use of it to delivering ads, measurement and reporting, debugging, security, and fraud prevention.
We do not use remarketing or retargeting. We do not build or upload audience lists, and we do not use Customer Match or Enhanced Conversions. Because this measurement uses no cookie and no device storage, declining non-essential cookies does not affect it and there is no advertising profile to opt out of. If you would like the identifier stored with your account deleted sooner than the 90-day limit above, you can ask us using the details in Section 14, and we honor Global Privacy Control signals as described in Section 6.
If we introduce any further advertising or tracking tools, we will update this Notice before or when we do, describe the affected information, provide a way to opt out of any resulting sale or share, and honor Global Privacy Control signals where required.
5. Cookies and Similar Technologies
We use cookies and similar technologies that fall into categories including strictly necessary, functional/preferences, and analytics/performance cookies. You can manage non-essential cookies through our cookie settings and banner where available and through your browser controls.
Third-party tracking. Our website does not use third-party advertising or tracking technologies that build a profile of your activities over time and across other websites and services. Our use of Google Ads is limited to measuring whether one of our own ads led to a signup, and is described in Section 4. We will update this Notice if that changes.
6. Do Not Track and Global Privacy Control
Because there is no common industry standard for “Do Not Track” (DNT) signals, our website does not respond to browser DNT signals. We do honor Global Privacy Control (GPC) signals on our website as a request to opt out of the sale/sharing of personal information for users in jurisdictions where this is required.
7. Data Retention
We retain personal information only as long as necessary for the purposes described in this Notice or as required by law, then delete or de-identify it. The table below describes how we decide how long to keep each type of information:
| Category | How long we keep it |
|---|---|
| Demo/inquiry and prospect information | Kept while you remain an active prospect or contact; deleted or de-identified when no longer needed for our sales or marketing |
| Account records | Kept for the life of the account, then deleted or de-identified within a reasonable period after closure, unless a longer period is required for legal, tax, audit, security, or dispute reasons |
| Billing/transaction records | Kept as required by tax and accounting law (generally up to 7 years) |
| Marketing data | Kept until you opt out or it is no longer needed |
| Advertising click identifier | Deleted once the signup has been reported to Google, or 90 days after it was captured — whichever comes first |
| Security logs / IP addresses | Kept for a limited period for security purposes, then deleted |
| Support tickets | Kept for a limited period after the issue is resolved, then deleted unless needed longer for legal or security reasons |
| Backups (including deleted-account data) | Routine backups are overwritten on a rolling cycle; data deleted from active systems is removed from backups in the ordinary course, unless preserved for security, continuity, or legal reasons |
8. International Transfers
We may process and store personal information in the United States and other countries whose data-protection laws may differ from yours. Where required for transfers from the EEA, United Kingdom, or Switzerland, we use appropriate safeguards, which may include:
- the European Commission’s Standard Contractual Clauses (SCCs) for EEA transfers;
- the UK International Data Transfer Addendum (or the UK Addendum to the SCCs) for UK transfers, as applicable; and
- the SCCs with Swiss amendments for transfers subject to the Swiss FADP, as applicable.
You may request a copy of the relevant safeguards by contacting us at privacy@puregraceai.com.
9. Security and Cybersecurity
We maintain reasonable technical, administrative, and organizational measures designed to protect personal information against unauthorized access, use, or disclosure, appropriate to the nature of the information we handle and the size of our business. We review these measures from time to time.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you have reason to believe your interaction with us is no longer secure, please contact us at privacy@puregraceai.com.
10. Children’s Privacy
Our website and Services are directed to businesses and are not intended for, or directed to, individuals under 18, and we do not knowingly collect personal information from them. We do not knowingly sell or share the personal information of consumers under 16 years of age. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
11. Your Rights and Choices
Depending on where you live and applicable law, you may have rights to: access/know the personal information we hold; correct inaccurate information; delete your information; portability; opt out of the sale/sharing of personal information and certain targeted advertising; limit the use of sensitive personal information; withdraw consent; object to or restrict certain processing; and non-discrimination for exercising your rights.
How to exercise rights. Submit a request by emailing privacy@puregraceai.com. You do not need an account to submit a request, and exercising a right will not require you to provide more information than necessary.
- We may need to verify your identity before fulfilling a request and will not require more information than reasonably necessary to do so.
- You may use an authorized agent to submit a request where the law allows; we may require the agent’s proof of authorization and verification of your identity.
- Timing (California and similar laws): we confirm receipt of access/deletion/correction requests within 10 business days and respond within 45 calendar days, extendable by an additional 45 days where reasonably necessary (with notice to you). We act on requests to opt out of sale/sharing and to limit sensitive personal information within 15 business days.
- Where GDPR, UK GDPR, or Swiss data protection law applies, you may also lodge a complaint with a supervisory authority (data protection authority), in particular in your country of residence, place of work, or place of the alleged infringement. We encourage you to contact us first so we can try to resolve your concern.
- Where available, you may appeal a decision by contacting privacy@puregraceai.com.
Opt-out preference signals. We treat Global Privacy Control (GPC) signals as a valid request to opt out of sale/sharing for your browser or device, where required by law.
Marketing opt-out. You can unsubscribe from marketing emails using the link in any such email; we honor opt-outs promptly and in any event within 10 business days.
12. California Privacy Rights
This section provides additional disclosures for California residents under the CCPA/CPRA. Pure Grace AI, LLC does not currently believe it meets the statutory thresholds for a “business” under the CCPA/CPRA. We provide this California Privacy Rights section for transparency and will honor applicable privacy rights where required by law or where we choose to do so as a matter of policy. In the preceding 12 months, we collected the following categories of personal information.
| CCPA category | Examples collected | Sources | Business/commercial purposes | Disclosed to | Sold or shared? |
|---|---|---|---|---|---|
| Identifiers | Name, email, phone, company, job title, IP address, account ID | You; your device; enrichment/marketing partners; social networks | Provide Services; communicate; marketing; security; analytics | Service providers; affiliates; advisors | No sale. Not shared for cross-context behavioral advertising |
| Commercial information | Demo requests, products/services of interest, transaction and billing records | You; your activity | Provide Services; billing; analytics | Service providers (payment, hosting); advisors | No |
| Internet/network activity | Pages viewed, links clicked, referring pages, device/browser data | Automatic via our website | Operate/secure/improve the site; analytics | Service providers (analytics) | No |
| Geolocation (approximate) | Coarse location derived from IP (not precise geolocation) | Automatic | Security; analytics | Service providers | No |
| Professional/employment information | Job title, company, role | You; enrichment partners | B2B marketing; account administration | Service providers; affiliates | No |
| Sensitive personal information | Account log-in credentials with password/access code; financial-account/payment information | You | Authenticate users; provide/secure Services; process payments | Payment processor; hosting | No. Used only for permitted purposes; not used to infer characteristics |
| Inferences | Lead scores / prioritization of prospective business customers | Derived from the contact and activity information we have about you | Our own B2B sales and marketing | Service providers (e.g., CRM / sales tools) | No |
California rights. California residents have the rights described in “Your Rights and Choices,” including the rights to know/access, delete, correct, opt out of sale/sharing, limit the use of sensitive personal information, and non-discrimination, plus the authorized-agent process and response timelines stated above. We update this Privacy Notice at least once every 12 months.
California “Shine the Light” Law (Civil Code §1798.83). If applicable and subject to applicable statutory exemptions, California customers may request, once per calendar year, information about the categories of personal information we disclosed to third parties for those third parties’ own direct marketing purposes during the prior calendar year, and the identities of those third parties. We do not currently disclose personal information to third parties for their own direct marketing purposes. To make a request, contact us at privacy@puregraceai.com with “Shine the Light” in the subject line.
13. Changes to This Notice
We may update this Privacy Notice from time to time. We will post the updated version on this page with a new “Last Updated” date and, for material changes, provide additional notice where appropriate.
14. How to Contact Us
Pure Grace AI, LLC Attn: Privacy 6285 E. Spring St, #457, Long Beach, CA 90808 privacy@puregraceai.com
If you are located in the EU or UK and have questions about how we process your personal information, you can contact us at privacy@puregraceai.com.