Privacy Policy
Effective date: July 27, 2026
1. Information We Collect
We collect information you provide directly: name, email address, organization name, and role. We collect usage data: pages visited, features used, and interaction patterns. We do not collect Protected Health Information (PHI). The Service has no field for patient data: referrals are tracked by auto-assigned referral numbers, and free-text entries that look like patient identifiers are rejected before they are saved.
2. How We Use Your Data
We use your data to: provide and improve the Service, process payments, send service-related communications, provide customer support, and ensure security. We do not sell your data. We do not use your data for advertising.
3. Data Storage & Security
Data is stored on Supabase (PostgreSQL) with row-level security enforcing multi-tenant isolation. All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Referral and activity free-text fields are scanned on save and any entry resembling a patient identifier is rejected. Access is controlled via role-based permissions (owner, director, manager, rep).
4. Cookies
We use essential cookies for authentication (Supabase session) and preferences (theme selection). We do not use advertising or tracking cookies. See our Cookie Policy for details.
5. Third-Party Services
We use the following third-party services: Supabase (database & authentication), Stripe (payment processing), Google Maps (territory mapping & routing), and Anthropic (AI coaching). Each service processes data under its own privacy policy and our data processing agreements.
6. Data Retention
We retain your data for as long as your organization is open. Cancelling your subscription alone does not delete anything: your organization and data remain available while the account stays open. When you close your organization, data is retained for 30 days for recovery purposes, then permanently deleted. You may request expedited deletion by contacting support; urgent requests are handled within a reasonable support window rather than instantly. See our Cancellation Policy for the difference between the two.
7. Your Rights
You have the right to: access your personal data, correct inaccurate data, request deletion of your data, export your data in a portable format (CSV/XLSX via the Export Center), and object to processing. To exercise these rights, contact us at support@territoryintelpro.com.
8. State Privacy Laws
We comply with applicable state privacy laws including the California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), and similar legislation. We do not discriminate against users who exercise their privacy rights.
9. Children’s Privacy
The Service is not intended for individuals under 18. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email 30 days before taking effect. Continued use after changes constitutes acceptance.