Privacy Policy
Version 2026-08-01 · Last Updated: August 1, 2026 · Emberline is provided by Emberline, Inc. ("Emberline", "we", "us", "our").
This Privacy Policy explains how Emberline, Inc. collects, uses, discloses, and protects personal information in connection with the Emberline platform, websites, and services (the "Services"). It also describes the choices and rights you have. Please read it together with our Terms of Use and Cookie Policy.
What is personal information
"Personal information" means information that identifies, relates to, or could reasonably be linked with a particular individual or household. It does not include aggregated or de-identified information that cannot reasonably be used to identify you.
Scope and roles
This policy applies to information we handle as a business, such as information about account holders, Workspace Users, website visitors, and prospects. When your Workspace uploads or generates information about your Contacts (leads and clients), you act as the controller of that data and Emberline processes it on your behalf as a service provider/processor, under your instructions and our Terms of Use. If you are a Contact of an Emberline customer, please direct privacy requests to that business.
Information we collect
Information you provide
- Account and profile: your name, email, hashed password, business name, and role.
- Billing: billing contact and payment identifiers; card details are entered on and stored by Stripe, not by us.
- Workspace/CRM content: contacts, notes, messages, emails, documents, listings, and other Member Content you submit.
- Surveys, forms, and support: information you provide when you complete a form, respond to a survey, request a demo, or contact us.
Information collected automatically
- Usage and device data: IP address, browser and device information, pages viewed, and actions taken.
- Security and audit logs: sign-ins, API request logs, and audit events.
- Capture pixel: if you install our first-party site pixel, page-view events on your own sites.
- Cookies and web beacons: as described below and in our Cookie Policy.
Cookies and web beacons
We and our providers use cookies, web beacons (also called pixel tags or clear GIFs), and similar technologies to operate the Services, remember your preferences, keep you signed in, measure performance, and, where applicable, support marketing. Web beacons are small graphics embedded in pages or emails that help us understand activity such as whether an email was opened. For full details and your choices, see our Cookie Policy.
Opt-in and opt-out
Where required, we rely on your consent to send certain communications or set non-essential cookies, and you may withdraw consent at any time. You can opt out of marketing emails from us using the unsubscribe link in those emails or by contacting us. Opting out of service and transactional messages that are necessary to operate your account may not be possible while your account is active.
How we use information
- to provide, secure, maintain, and improve the Services;
- to process payments, manage subscriptions, Add-Ons, seats, and Credits;
- to provide onboarding, support, and communicate with you about your account;
- to power AI-assisted features (for example, lead scoring, email drafting, and inbound parsing), which process the specific content involved in an action you trigger through a third-party AI provider;
- to send promotional messaging where permitted, and to help you send your own communications subject to your obligation to obtain any required consent (including TCPA consent for calls and texts);
- to monitor, detect, and prevent fraud, abuse, and security incidents; and
- to comply with legal obligations and enforce our agreements.
How we disclose information
Service providers and sub-processors
We share information with vendors that help us run the Services, each receiving only what is needed for its function. These include hosting and database (for example, Vercel and Neon), payments (Stripe), email delivery (Resend), caching/queues (Upstash), and an AI model provider (Anthropic) for AI features. We do not sell your personal information, and we do not share Member Content across Workspaces.
Compelled disclosure
We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or security issues.
Business transfers
If Emberline is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy.
Your access, correction, and deletion rights
You can access, update, export (JSON and CSV), and delete much of your information directly in the Services. You may also request access to, correction of, or deletion of your personal information, and object to or restrict certain processing, by contacting us. We will verify your request and respond as required by applicable law. To submit a data subject access request (DSAR), email privacy@emberline.app. If your request concerns Contact data held within a customer's Workspace, we will refer you to that customer, who is the controller.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. Passwords are hashed with argon2id; sessions and API keys are stored hashed; Workspaces are isolated at the database layer using row-level security; and financial records are append-only. No system is perfectly secure; please report any concern to privacy@emberline.app and we will respond promptly.
Data retention
We retain Workspace data while your subscription is active and for 90 days after cancellation to allow export, after which it may be deleted. You can export or permanently delete your Workspace in-app at any time. We may retain certain security, audit, billing, and transaction records longer where required for legal, accounting, or anti-fraud purposes.
International transfers and GDPR
We operate primarily in the United States, and information may be processed in the U.S. and other countries where we or our providers operate. If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal information on lawful bases including performance of a contract, legitimate interests, consent, and legal obligation, and we use appropriate safeguards such as Standard Contractual Clauses for cross-border transfers. You have the rights to access, rectify, erase, restrict, and port your data, to object to processing, and to lodge a complaint with your supervisory authority.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know the categories and specific pieces of personal information we collect, the purposes for collecting it, and the categories of recipients; to request correction or deletion; and to be free from discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond permitted business purposes. To exercise these rights, contact privacy@emberline.app. An authorized agent may submit a request on your behalf with proof of authorization. The categories we collect are:
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email, postal address, phone number, account ID, IP address | Yes |
| Customer records | Billing contact and payment identifiers (card data held by Stripe, not us) | Yes |
| Commercial information | Plan, subscription, Add-Ons, Credit purchases, transaction history | Yes |
| Internet/network activity | Sign-in logs, API request logs, audit events, in-app usage, capture-pixel page views | Yes |
| Geolocation data | Approximate location inferred from IP address | Yes |
| Professional information | Business name, role, and team membership within a Workspace | Yes |
| Contact data you upload | Lead and client records your Workspace stores (you are the controller) | Yes |
| Sensitive personal information | We do not intentionally collect sensitive categories such as government IDs or health data | No |
Canada (PIPEDA)
For individuals in Canada, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, including obtaining consent where required and providing access and correction rights. You may direct questions or complaints to our privacy contact below.
CAN-SPAM
Marketing emails we send include accurate sender information and a working unsubscribe link, and we honor opt-out requests promptly. If you use the Services to send email, you are responsible for your own CAN-SPAM compliance as described in our Terms of Use.
Children (COPPA)
The Services are intended for business use by individuals who are at least 18 years old. We do not knowingly collect personal information from children under 13, and the Services are not directed to children. If you believe a child has provided us information, contact us so we can delete it.
Google API limited use
Where the Services access data through Google APIs, Emberline's use and transfer of information received from those APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We only use such data to provide or improve the specific features you enable, do not transfer it except as necessary to provide those features, comply with law, or with your consent, and do not use it for advertising or allow humans to read it except as permitted.
Governing law
This Privacy Policy is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules, except where applicable data-protection law requires otherwise.
Updates to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app or by email before they take effect, and the "Last Updated" date above will change. Continued use of the Services after an update constitutes acceptance of the revised policy.
Contact
Emberline, Inc.
Privacy and DSAR: privacy@emberline.app
Legal: legal@emberline.app
See also the Terms of Use and Cookie Policy.