Privacy Policy

Last updated: 7/17/2025 | Effective date: 7/17/2025

Your Privacy Matters

InfluenceBoard ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy complies with GDPR, CCPA, PIPEDA, LGPD, and other global privacy regulations.

Note: This policy is for informational purposes. For specific legal advice, please consult with a qualified attorney.

1. Information We Collect

1.1 Information You Provide

When you submit our contact form, we collect:

  • Full name
  • Email address
  • Company name
  • Phone number (optional)
  • Budget range
  • Message content
  • Consent confirmations (including age verification)
  • Timestamp of submission

1.2 Information Automatically Collected

Through Google Analytics (only with your consent) and server logs, we collect:

  • IP address (anonymized via Google Analytics IP Anonymization)
  • Browser type and version
  • Operating system
  • Referring website
  • Pages visited and time spent
  • Geographic location (country/city level only)
  • Device information

1.3 Cookies and Similar Technologies

We use the following types of cookies:

  • Essential Cookies: Required for website functionality (no consent needed)
  • Analytics Cookies: Google Analytics (loaded only after your explicit consent)
  • Preference Cookies: Remember your choices (theme, consent preferences)

2. Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Consent: When you submit forms or accept analytics cookies
  • Legitimate Interests: To respond to inquiries and improve our services (we've conducted a legitimate interest assessment)
  • Contract: To provide requested services
  • Legal Obligation: To comply with applicable laws

3. How We Use Your Information

  • Respond to your inquiries (we aim to respond within 1-2 business days)
  • Send follow-up information about our services (only with your explicit opt-in consent)
  • Improve our website and user experience
  • Analyze website traffic and usage patterns (only with consent)
  • Comply with legal obligations and resolve disputes
  • Protect against fraudulent or illegal activity

4. Data Sharing and Third Parties

We share your data only with:

Service Providers (all have signed Data Processing Agreements):

  • Supabase: Database hosting (USA) - SOC 2 compliant
  • SendGrid: Email delivery (USA) - GDPR compliant
  • Vercel: Website hosting (Global CDN) - GDPR compliant
  • Google Analytics: Website analytics (USA) - Privacy Shield certified

We do NOT sell, rent, or trade your personal information. We may disclose information if required by law, court order, or to protect our rights.

5. International Data Transfers

Your data may be transferred to and processed in the United States where our service providers are located. We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) with service providers where required
  • Ensuring providers comply with Privacy Shield, adequacy decisions, or equivalent frameworks
  • Technical and organizational security measures

6. Data Retention

We retain your data for:

  • Contact form submissions: 3 years from submission or until you request deletion
  • Email communications: 3 years from last interaction
  • Analytics data: 26 months (Google Analytics default setting)
  • Legal records: As required by applicable law (typically 6-7 years for tax purposes)

We have implemented automated processes to delete data after retention periods expire.

7. Your Rights

7.1 Rights for All Users

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data ("right to be forgotten")
  • Portability: Receive your data in a structured format
  • Object: Object to certain processing activities
  • Restrict: Request restriction of processing
  • Withdraw Consent: Withdraw consent at any time

7.2 State-Specific Rights (US Residents)

Residents of California, Colorado, Connecticut, Utah, and Virginia have additional rights:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed (we do NOT sell your data)
  • Right to opt-out of targeted advertising (we don't engage in targeted advertising)
  • Right to non-discrimination for exercising your rights

7.3 EU/UK Residents (GDPR)

  • Right to lodge a complaint with supervisory authorities
  • Right to withdraw consent without affecting prior processing
  • Right to object to processing based on legitimate interests

7.4 Brazilian Residents (LGPD)

  • Rights similar to GDPR
  • Right to anonymization, blocking, or deletion of unnecessary data
  • Right to review automated decisions

How to Exercise Your Rights:

Email us at irfan@influenceboard.co with your request. We'll respond within 30 days (or sooner if required by law) and may ask for verification of your identity.

8. Data Security

We implement appropriate security measures including:

  • Encryption in transit (HTTPS/TLS 1.2+)
  • Encryption at rest for stored data
  • Access controls and authentication
  • Regular security assessments
  • Employee training on data protection
  • Incident response procedures

Data Breach Notification

In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach, where feasible, or as required by applicable law.

9. Children's Privacy

Our services are not directed to individuals under 16. We do not knowingly collect personal information from children under 16. If we become aware of such collection, we will delete the information immediately. Our contact forms include age verification to prevent underage submissions.

10. Do Not Track

We respect Do Not Track (DNT) browser settings. When DNT is enabled, we do not load Google Analytics or other tracking scripts.

11. Marketing Communications

We only send marketing emails with your explicit consent (opt-in checkbox must be actively checked). Every email includes an unsubscribe link. You can opt out at any time by:

  • Clicking unsubscribe in any email
  • Emailing us at irfan@influenceboard.co
  • Using the contact form to request removal

12. Accessibility

We are committed to ensuring our privacy practices are accessible to all users. Our website aims to comply with WCAG 2.1 Level AA standards. If you need this policy in an alternative format, please contact us.

13. Updates to This Policy

We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Updating the "Last updated" date
  • Posting a prominent notice on our website for 30 days
  • Emailing you (for significant changes, if we have your consent for communications)

14. Contact Information

Privacy Contact:

InfluenceBoard
Attn: Privacy Team
Email: irfan@influenceboard.co
Website: influenceboard.co

Response Time:

We aim to respond to all privacy requests within 30 days (or sooner if required by law).

Supervisory Authorities:

EU residents may contact their local data protection authority.
UK residents may contact the Information Commissioner's Office (ICO).
US residents may contact their state Attorney General's office.

Appendix: Regional Specific Provisions

πŸ‡ͺπŸ‡Ί European Union (GDPR)

Legal basis: Article 6 GDPR. Your rights: Articles 15-22 GDPR. Data transfers: Article 46 GDPR (SCCs).

πŸ‡ΊπŸ‡Έ United States (State Privacy Laws)

California (CCPA/CPRA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Virginia (VCDPA). No sale of personal information. Opt-out rights available.

πŸ‡§πŸ‡· Brazil (LGPD)

Legal basis: Article 7 LGPD. Rights: Articles 17-22 LGPD. International transfers comply with Articles 33-36 LGPD.

πŸ‡¨πŸ‡¦ Canada (PIPEDA)

Compliance with Schedule 1 principles. Consent and purpose limitation applied.