Privacy PolicyTerms of ServiceSubprocessorsCookie NoticeSMS Policy

Who we are

## The legal entity collecting your personal information.

### AI Syndicate Collective LLC

A Florida limited liability company operating the AI Syndicate brand, website, and SaaS product.

**Mailing address:** 7901 4TH ST N, STE 300 St. Petersburg, FL 33702 United States

### Privacy contact

Privacy questions, access requests, deletion requests, or complaints: [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com).

We respond within 30 days. Complex requests may take up to 60 days, in which case we'll keep you informed.

Information we collect

## The personal data we collect, where it comes from, and why.

| Category | Examples | Source | Purpose |
| --- | --- | --- | --- |
| Account data | Email, name, hashed password, MFA factors (TOTP secret, recovery phone). | From you at signup. | Create and secure your account, authenticate sign-ins, enable recovery. |
| Customer content | Workspaces, tracked domains, audit results, dashboard configuration. | From you through the product. | Provide the service. We don't mine or sell your content. |
| Payment data | Billing name/address, last four digits of card, Stripe customer ID, transactions. | Via Stripe. We never see full card numbers. | Process subscriptions, invoices, refunds, fraud prevention. |
| Communications | Emails to support, in-product messages, feedback. | From you. | Respond to inquiries, provide support, improve the product. |
| Usage data | Features used, page views, click events, error logs. | Automatically from normal use. Site-wide analytics via Google Analytics 4 (loaded through Google Tag Manager) run only after you allow Analytics cookies. | Measure feature engagement, debug, prioritize improvements. Not marketing profiles. |
| Device & log data | IP, browser type, OS, request timestamps. | Automatically via HTTP requests. | Deliver the site, fraud prevention, security, error handling. |
| SMS opt-in data | Mobile phone number, opt-in timestamp, consent record, delivery receipts. | From you when you opt in (Settings → Security). | Send one-time verification codes for account recovery. Never marketing. |
| Cookies | Auth cookies, session preferences, and consent-based analytics and advertising cookies. | Stored by your browser. | Keep you signed in, remember preferences, and (with consent) measure usage and ads. See Cookie Notice. |
| OAuth identity | If you sign in with Google: email, name, Google account ID. | From the OAuth provider. | Create or sign you into your account. |

How we use your data

## Specific purposes we process personal information for.

### Operate the service

Create and maintain accounts, authenticate sign-ins, store workspaces, run audits, deliver dashboards, process subscriptions.

### Security & fraud prevention

Detect and prevent unauthorized access, abusive behavior, fraudulent payments, malware, and security threats.

### Customer support

Respond to support requests, send transactional notices (sign-in alerts, receipts, security notifications).

### Product improvement

Analyze aggregated usage to identify bugs and prioritize features. Aggregated or anonymized where possible.

### Communications you've requested

If opted in: product updates and announcements. Unsubscribe link in every marketing email's footer.

### Legal compliance

Comply with applicable laws, respond to lawful requests, defend against legal claims, enforce our agreements.

Legal basis (GDPR)

## If you're in the EU, UK, or similar jurisdictions, the legal basis for each activity.

| Processing activity | Legal basis |
| --- | --- |
| Creating accounts, delivering features, processing payments. | **Contract** (Art. 6(1)(b)) |
| Sending SMS verification codes after opt-in. | **Consent** (Art. 6(1)(a)) |
| Marketing emails (if opted in). | **Consent** (Art. 6(1)(a)) |
| Securing the platform, preventing fraud. | **Legitimate interests** (Art. 6(1)(f)) |
| Aggregated product analytics. | **Legitimate interests** (Art. 6(1)(f)) |
| Site analytics cookies (Google Analytics 4) and advertising pixels + conversion events (Meta, OpenAI). | **Consent** (Art. 6(1)(a)) — off by default, gated on our consent banner |
| Tax records, financial reporting, legal requests. | **Legal obligation** (Art. 6(1)(c)) |

How we share

## We don't sell your data. We share only what's necessary, with the parties below.

### Service providers (subprocessors)

Vendors who help us operate the service, bound by data processing agreements requiring confidentiality, security, and authorized use only.

### Legal & safety

We may disclose data when needed to comply with the law, valid legal process, or protect rights, property, or safety.

### Business transfers

In a merger or acquisition, your data may transfer. We'll notify you and offer meaningful choice before a new policy applies.

### With your consent

Any other sharing happens only with your explicit consent.

### Aggregated / de-identified data

We may share aggregated statistics that can't reasonably identify you.

### Ad measurement (consent-gated)

With your Marketing consent — and only then — we run the Meta Pixel (Facebook & Instagram) and the OpenAI conversion pixel (ChatGPT Ads), and we send matching **"Lead" conversion events** when you submit our GEO-Score form or book a call: client-side from your browser and server-side to Meta's Conversions API and OpenAI's conversion API. Server-side events fire only if you granted Marketing consent when you took that action, carry a shared event ID so they're deduplicated with the browser pixel, and stay off under GPC.

### What we don't do

We never sell your personal information. The only advertising "sharing" we do is the consent-gated ad measurement described above — the Meta and OpenAI pixels plus their matching conversion events — and only after you opt in via our consent banner.

Subprocessor list

## Third parties we rely on to deliver the service.

We provide at least 30 days' notice of new or replaced subprocessors via email or in-product notification, except where an urgent security or legal need requires immediate replacement.

| Provider | Purpose | Data accessed | Location |
| --- | --- | --- | --- |
| **Supabase** | Auth, database, file storage | Account data, customer content | US (us-east-1) |
| **Vercel** | Hosting, CDN, serverless functions | Device/log data, request metadata | US + global edge |
| **Stripe** | Payment processing, billing | Payment data, billing info | United States |
| **Resend** | Transactional email (codes, resets, receipts) | Email address, message contents | United States |
| **Twilio** | SMS verification codes (opt-in only) | Phone number, verification metadata | United States |
| **Instantly** | Lead email nurture / follow-up (after you opt in via a form) | Email, name, website | United States |
| **Calendly** | Scheduling discovery & strategy calls you book with us | Name, email, scheduling details | United States |
| **Google (OAuth)** | Optional 'Sign in with Google' | Email, name, Google account ID | US + global |
| **Google (Tag Manager & Analytics 4)** | Consent-gated site analytics — tags load via Google Tag Manager; GA4 stays off until you allow Analytics cookies | Usage and device data (only after you allow Analytics) | US + global |
| **Cloudflare** | DNS, DDoS protection, security | IP address, request metadata | Global edge |
| **NameBright** | Domain registrar | Domain ownership records | United States |

### Data Processing Addendum (DPA)

We make a Data Processing Addendum available to customers who require one under applicable data protection law. Contact [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com) to request a copy. Our DPA incorporates the European Commission's Standard Contractual Clauses (SCCs) for any onward transfers of EU/UK personal data.

Sensitive personal information

## What we collect and how we use it.

Under California's CPRA and similar laws, certain data categories are treated as "sensitive personal information." We collect the following:

- **Account credentials** — hashed passwords and authentication factors (TOTP secrets, recovery phone numbers).
- **Government identifiers** — we do *not* collect Social Security numbers, driver's license numbers, passport numbers, or similar identifiers.
- **Precise geolocation** — we do *not* collect precise GPS coordinates. Our infrastructure providers may log IP-derived approximate region for security purposes only.
- **Biometric / health / racial / sexual orientation data** — we do *not* collect any of these.

We use the sensitive PI we do collect (account credentials and authentication factors) **solely to provide the service** — to authenticate you, secure your account, and enable recovery. We do not use this information to infer characteristics about you, and we do not disclose it for any cross-context behavioral advertising, profiling, or marketing. California residents have the right to limit our use of sensitive PI, but because we do not use it for any secondary purpose, no further limitation is necessary.

Global Privacy Control (GPC)

## We honor browser-based opt-out signals.

Some browsers and extensions send a **Global Privacy Control** (GPC) signal indicating your preference to opt out of the sale or sharing of personal information. **We honor GPC signals.** AI Syndicate does not sell personal information. We "share" personal information for cross-context behavioral advertising only via our own consent-gated ad measurement — the Meta Pixel (Facebook and Instagram), the OpenAI conversion pixel (ChatGPT Ads), and their matching client- and server-side conversion events — and it is all off by default. When we detect a GPC signal, we automatically keep the pixels off and suppress the conversion events, so no advertising data is shared. You can also control this anytime via **Privacy preferences**, consistent with California Attorney General guidance and similar US state law requirements.

EU representative (GDPR Art. 27)

## Our position on EU representation.

AI Syndicate Collective LLC is established in the United States and does not currently have an establishment in the EU. To the extent our processing falls within the territorial scope of the EU GDPR (Article 3(2)), we will appoint an EU Representative as required by Article 27. As of the effective date of this policy, our EU-resident user base is below the threshold at which we believe appointment is required; we will document any change to this position and update this section accordingly.

EU residents may contact us directly at [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com) in any official EU language; we will respond in English.

International transfers

## Where your data is processed.

### Primary processing in the US

Our services are operated from the United States. By using our products, you understand that your data will be transferred to, stored, and processed in the US, which may have different protections than your jurisdiction.

### EU/UK safeguards

For data transferred from the EU, EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum.

Retention

## How long we keep your data.

### Active accounts

While active, we retain your data to provide the service.

### After deletion

Customer content deleted within 30 days of account deletion, except where law requires longer (e.g. tax records, generally 7 years).

### Backups

Encrypted backups may retain data for up to 30 days beyond deletion, then overwritten on rolling schedules.

### Logs & telemetry

Security and operational logs retained up to 90 days, longer only for investigations or legal compliance.

### Marketing

If you unsubscribe, we keep only enough info (email + unsubscribe timestamp) to honor that choice.

### Business records

Contracts, billing, and similar records retained per applicable tax and recordkeeping laws (commonly 7 years).

Security

## How we protect your data.

### Encryption in transit

All traffic uses TLS 1.2 or higher.

### Encryption at rest

Database storage and backups encrypted by Supabase and Vercel.

### Password protection

Bcrypt/Argon2id hashes — never plaintext. Leaked-password check via HaveIBeenPwned.

### Multi-factor authentication

Users can enable TOTP 2FA and add a backup phone for SMS recovery.

### Access controls

Internal access is restricted to authorized personnel on a need-to-know basis, with audit logging.

### Breach notification

If a personal data breach affects your data, we notify you and applicable regulators without undue delay and within the timeframes required by applicable law — including within 72 hours to a supervisory authority under GDPR Article 33 where the breach is likely to result in a risk to rights and freedoms.

No system is perfectly secure. We use reasonable measures appropriate to the data we hold; we cannot guarantee absolute security.

Your privacy rights

## Rights you have over your personal data, depending on where you live.

### Rights for all users

- **Access** — request a copy of your data.
- **Correction** — fix inaccurate data.
- **Deletion** — delete your account and data, subject to retention obligations.
- **Portability** — export your content in machine-readable format.
- **Unsubscribe** — opt out of marketing (transactional emails continue).
- **Withdraw consent** — for any consent-based processing.

### EU / UK rights (GDPR)

- **Restrict processing** in certain circumstances.
- **Object to processing** based on legitimate interests.
- **Lodge a complaint** with your supervisory authority (UK: ICO; EU: edpb.europa.eu).
- **Automated decisions** — we don't make decisions about you with significant effect.

### California (CCPA / CPRA)

- Right to **know** what we collect, use, disclose.
- Right to **delete** personal information.
- Right to **correct** inaccurate information.
- Right to **opt out of sale or sharing** — we don't sell; the only "sharing" is the consent-gated Meta and OpenAI ad pixels and their matching conversion events, which are off unless you opt in. Manage them via Privacy preferences or GPC.
- Right to **limit use of sensitive PI**.
- Right to **non-discrimination**.
- **Authorized agent** can submit requests with proof.

### Other US state rights

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have substantially similar rights. Email [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com).

If denied, you may appeal by replying to our denial email; we respond within state-specific timeframes.

### How to exercise your rights

**Self-service (recommended).** Signed-in users can export a JSON bundle of all their data, and request account deletion, from **Settings → Privacy · AI controls → Your data** in the dashboard. Exports are immediate. Deletions are scheduled 30 days out so you can cancel if you change your mind; after the grace period the deletion is irreversible.

By email — for non-account holders, complex requests, or rectification: email [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com) from your account email, or another address with verification info. We respond within 30 days (extendable to 60 days for complex requests). No fee unless your request is manifestly unfounded or excessive.

Children

## AI Syndicate is for businesses and adults.

Our service isn't directed to children under 16 and we don't knowingly collect personal information from anyone under 16. If a child has provided personal information to us, email [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com) and we'll promptly delete it.

Cookies

## How we use cookies and similar technologies.

We use cookies to keep you signed in, remember preferences, and understand aggregated site usage. Full details: Cookie Notice.

Third-party links

## Links to external sites.

Our site may link to third-party websites we don't operate. We're not responsible for their privacy practices. Review their privacy policies before sharing data through them.

Changes

## How we update this policy.

We may update this Privacy Policy from time to time. The "Effective date" reflects the latest version. For material changes, we provide prominent notice — typically email to registered users at least 30 days before changes take effect.

**Change history:**

- **July 6, 2026** — Disclosure update: documented Google Tag Manager + Google Analytics 4 (consent-gated analytics, already in use) and the consent-gated "Lead" conversion events (client-side and server-side via Meta's Conversions API and OpenAI's conversion API) that accompany our ad pixels. No new data categories are collected.
- **May 11, 2026** — Initial publication.

## Questions, concerns, or a privacy request?

Email us. We respond within 30 days — usually much sooner.

[Email privacy@aisyndicate.com](mailto:privacy@aisyndicate.com?subject=Privacy%20Request)View Terms of Service