valueIQ

    Privacy Policy

    Effective Date: December 1, 2025
    Last Updated: December 1, 2025
    Version: 2.0

    Introduction

    Welcome to valueIQ, an AI-powered value selling copilot and pricing analysis platform. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, including the Pricing Analyst agent and related AI services.

    By accessing or using valueIQ, you agree to the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.

    This policy applies to information we collect through our platform, website, applications, APIs, and all electronic communications between you and valueIQ.

    Information We Collect

    We collect several categories of information from and about users of our services:

    Personal Information You Provide

    Information that identifies you personally, which you provide directly to us:

    Account Information

    Email address, username, and encrypted password; Full name, first name, and last name

    Profile Information

    Company name, job role, professional title, and department; Industry and company size

    Contact Information

    Email address and phone number (if provided); Business address

    Payment Information

    Billing address and payment method details (processed securely through Stripe); Subscription tier and credit balance

    Communication Data

    Messages, support tickets, feedback, and correspondence with us; Survey responses and feature requests

    User-Generated Content

    URLs submitted for analysis; Pricing data, competitor information, and market data; Value models, customer profiles, and analysis inputs; Reports, presentations, and exported materials

    Information Collected Automatically

    When you access our services, we automatically collect certain information:

    Device Information

    Browser type, version, and settings; Operating system and device type; Screen resolution and display settings

    Usage Data

    Pages viewed, features used, and time spent on pages; Click patterns, navigation paths, and interaction sequences; Value models created, analyses performed, and outputs generated; Credit consumption and feature utilization patterns

    Technical Data

    IP address and browser identifiers; Unique device identifiers; API endpoints accessed and request metadata

    Log Data

    Access times and session duration; Error logs, performance data, and API calls; Authentication events and security logs

    Location Data

    General geographic location (city/country level) based on IP address

    AI-Related Data Collection

    Given the AI-powered nature of our services, we collect additional information specific to AI operations:

    Input Data

    Prompts, queries, and instructions you provide to our AI agents; Customer data and business information used to generate value models; Pricing parameters, competitive data, and market information submitted for analysis

    Output Data

    AI-generated value models, value stories, and pricing analyses; Recommendations, insights, and suggestions produced by our AI services; Exported reports, presentations, and communications

    Interaction Data

    Your feedback on AI outputs (ratings, corrections, acceptances, rejections); Modifications you make to AI-generated content; Patterns in how you use and refine AI outputs

    Cookies and Tracking Technologies

    We use cookies, web beacons, and similar technologies to collect information. For detailed information, please see our Cookie Policy.

    Third-Party Data

    Information we receive from third-party services:

    • Authentication Providers: Profile information from Google or other OAuth providers
    • Payment Processors: Transaction data from Stripe
    • Analytics Services: Aggregated usage statistics from Google Analytics
    • Web Data Services: Publicly available data extracted via Firecrawl for pricing analysis

    How We Use Your Information

    We use the information we collect for the following purposes:

    Service Delivery and Operations

    • Provide, operate, and maintain our AI-powered pricing intelligence platform
    • Process and fulfill your requests for value models, pricing analysis, and reports
    • Power our AI agents (Value Model Generator, Customer Data Integrator, Value Story Creator, and Pricing Analyst)
    • Manage your account, authentication, and access permissions
    • Process payments, manage subscriptions, and track credit usage
    • Send service-related notifications, updates, and alerts
    • Provide customer support and respond to inquiries

    AI Model Operations

    • Process your inputs through our AI systems to generate outputs
    • Analyze patterns to improve AI accuracy, relevance, and usefulness
    • Detect and correct potential errors, biases, or inaccuracies in AI outputs
    • Develop safety measures and content filters for AI systems

    Platform Improvement and Analytics

    • Analyze usage patterns to improve features and user experience
    • Monitor and analyze trends, performance, and service quality
    • Develop new features, products, and AI capabilities
    • Conduct research and testing to improve our algorithms
    • Optimize platform performance, reliability, and security
    • Benchmark pricing models and value metrics (using aggregated, anonymized data only)

    Communications

    • Send technical notices, updates, and security alerts
    • Provide customer support and respond to your requests
    • Send promotional materials and marketing communications (with consent)
    • Conduct surveys and gather feedback
    • Share product updates, new features, and best practices

    Security and Compliance

    • Detect, prevent, and address fraud, abuse, and security issues
    • Enforce our Terms of Service and policies
    • Comply with legal obligations and respond to legal requests
    • Protect the rights, property, and safety of valueIQ and our users
    • Monitor and log system access for security purposes
    • Maintain audit trails for regulatory compliance

    AI Training and Model Improvement

    How We Use Data for AI Development

    We are committed to transparency about how data may be used in connection with our AI services:

    Aggregated and Anonymized Data

    We may use aggregated, de-identified data derived from user interactions to:

    • Improve the accuracy and performance of our AI models
    • Develop new AI features and capabilities
    • Conduct research on pricing strategies and value metrics
    • Create industry benchmarks and best practices

    Your Customer Data

    • We do not use your identifiable Customer Data to train our foundational AI models without explicit consent
    • Your specific business information, customer details, and proprietary data remain confidential
    • AI outputs generated for you are based on your inputs and our pre-trained models

    Opt-Out Rights

    You may opt out of having your interaction data used for AI improvement purposes by contacting us at legal@valueiq.ai. Opting out will not affect your access to or use of our services.

    AI Output Accuracy

    We strive to provide accurate and useful AI outputs. However, you should be aware that:

    • AI outputs are generated probabilistically and may contain errors or inaccuracies
    • You should verify AI-generated content before relying on it for business decisions
    • We implement quality measures but cannot guarantee the accuracy of all outputs
    • AI recommendations do not constitute professional, legal, financial, or tax advice

    Data Sharing and Third-Party Disclosure

    We do not sell your personal information. We may share your information in the following circumstances:

    Service Providers and Business Partners

    We share information with trusted third-party service providers who perform services on our behalf:

    ProviderPurposeData Shared
    SupabaseDatabase hosting, authentication, backend infrastructureAccount data, usage data, application data
    Google AnalyticsUsage analytics and performance monitoringAnonymized usage data, device information
    StripePayment processing and subscription managementPayment information, billing data
    FirecrawlWeb scraping and data extraction servicesURLs submitted for analysis
    Email Service ProvidersTransactional and marketing email deliveryEmail addresses, communication preferences

    These service providers are contractually obligated to: use your information only for the purposes we specify; protect your data with appropriate security measures; not share your data with unauthorized parties; delete data upon termination of services as required.

    Legal Requirements and Protection

    We may disclose your information if required by law or in good faith belief that such action is necessary to:

    • Comply with legal obligations, court orders, or government requests
    • Enforce our Terms of Service and other agreements
    • Protect against legal liability
    • Investigate fraud, security issues, or technical problems
    • Protect the rights, property, or safety of valueIQ, our users, or the public

    Business Transfers

    If valueIQ is involved in a merger, acquisition, bankruptcy, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change via email and/or prominent notice on our platform, explain any choices you may have regarding your information, and ensure the acquiring entity honors this Privacy Policy or provides notice of changes.

    With Your Consent

    We may share your information for any other purpose with your explicit consent.

    Aggregated or De-Identified Data

    We may share aggregated or de-identified information that cannot reasonably be used to identify you for research, marketing, analytics, benchmarking, or other purposes. This includes:

    • Industry pricing benchmarks and trends
    • Anonymized usage statistics
    • Aggregated platform metrics

    Data Storage, Retention, and Security

    Data Storage

    Your information is stored on secure servers provided by Supabase, which uses industry-standard cloud infrastructure (AWS). Data may be stored and processed in:

    • United States (primary)
    • Canada
    • European Union (for EU users, where available)
    • Other locations as necessary for service delivery

    By using our services, you consent to the transfer of your information to these locations, subject to appropriate safeguards described in the International Data Transfers section.

    Data Retention

    We retain your personal information for as long as necessary to:

    • Provide our services to you
    • Comply with legal obligations (tax, accounting, audit requirements)
    • Resolve disputes and enforce our agreements
    • Support business operations and analytics

    Typical retention periods:

    Data CategoryRetention Period
    Account DataDuration of account plus 90 days after deletion
    Usage DataUp to 26 months for analytics purposes
    AI Interaction DataUp to 24 months for service improvement
    Transaction Records7 years for financial compliance
    Support Communications3 years after resolution
    Security Logs2 years for audit and compliance

    Upon account deletion, we will delete or anonymize your personal information within 90 days, except where retention is required by law or for legitimate business purposes as described above.

    Security Measures

    We implement comprehensive technical and organizational security measures to protect your information:

    Encryption

    • Data encrypted in transit using TLS 1.3
    • Data encrypted at rest using AES-256

    Access Controls

    • Role-based access control (RBAC) with principle of least privilege
    • Multi-factor authentication (MFA) for team members
    • Regular access reviews and permission audits

    Authentication

    • Secure password hashing using bcrypt with salting
    • Token-based authentication with short expiration
    • Session management and automatic timeout

    Infrastructure Security

    • Continuous security monitoring and intrusion detection
    • Web Application Firewall (WAF) protection
    • DDoS mitigation and rate limiting
    • Network segmentation and isolation

    Development Practices

    • Secure software development lifecycle (SDLC)
    • Regular code reviews and security testing
    • Vulnerability scanning and penetration testing
    • Dependency monitoring and patch management

    Database Security

    • Row-level security (RLS) policies
    • Parameterized queries to prevent SQL injection
    • Encrypted backups with offsite storage
    • Point-in-time recovery capabilities

    Organizational Measures

    • Security awareness training for all employees
    • Background checks for employees with data access
    • Confidentiality agreements and data handling policies
    • Incident response procedures and business continuity plans

    Data Breach Notification

    In the event of a data breach that affects your personal information, we will:

    • Notify affected users within 72 hours of becoming aware of the breach (or as required by applicable law)
    • Notify relevant supervisory authorities as required
    • Provide information about the nature of the breach, data affected, and recommended protective steps
    • Document the breach and our response for compliance purposes

    Important: While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.

    Your Rights and Choices

    Depending on your location, you may have the following rights regarding your personal information:

    Access and Portability

    • Right to Access: Request a copy of the personal information we hold about you, including data categories, processing purposes, and recipients
    • Right to Portability: Request your data in a structured, commonly used, machine-readable format (JSON or CSV) for transfer to another service

    Correction and Deletion

    • Right to Correction: Request correction of inaccurate or incomplete personal information
    • Right to Deletion: Request deletion of your personal information, subject to legal retention requirements and legitimate business needs

    Processing Controls

    • Right to Restrict Processing: Request limitation of how we process your data in certain circumstances
    • Right to Object: Object to processing of your personal information for direct marketing or based on legitimate interests
    • Right to Withdraw Consent: Withdraw consent for processing based on consent, without affecting the lawfulness of prior processing

    AI-Specific Rights

    • Right to Human Review: Request human review of significant decisions made using automated processing
    • Right to Explanation: Request meaningful information about the logic involved in automated decision-making
    • Right to Opt Out of AI Training: Request that your interaction data not be used for AI model improvement

    Complaint Rights

    • Right to Lodge a Complaint: File a complaint with your local data protection authority about our data practices

    How to Exercise Your Rights

    To exercise any of these rights, you can:

    • Email: legal@valueiq.ai
    • Account Settings: Access your account settings to update or delete certain information
    • Data Export: Use the data export feature in your account settings
    • DPO Contact: Contact our Data Protection Officer at legal@valueiq.ai

    Response Timeline: We will respond to your request within 30 days (or as required by applicable law). For complex requests, we may extend this period by an additional 60 days with notice. We may need to verify your identity before processing your request.

    No Fee: We do not charge a fee for most requests. However, we may charge a reasonable fee for manifestly unfounded, repetitive, or excessive requests.

    Marketing Communications

    You can opt out of marketing communications at any time by:

    • Clicking the "unsubscribe" link in any marketing email
    • Updating your communication preferences in account settings
    • Contacting us at legal@valueiq.ai

    Note: Even if you opt out of marketing communications, we will still send you transactional and service-related messages essential to your use of the platform.

    Children's Privacy

    Our services are not intended for children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 16.

    If you believe we have collected information from a child under 16, please contact us immediately at legal@valueiq.ai, and we will take steps to delete such information promptly.

    Minimum Age Requirement: You must be at least 18 years old to create a valueIQ account and use our services. By using our services, you represent that you meet this age requirement.

    International Data Transfers

    Your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States and Canada. These countries may have data protection laws that differ from those of your country.

    Transfer Safeguards

    When we transfer personal data from the EU/EEA, UK, or other jurisdictions with data transfer restrictions, we implement appropriate safeguards, including:

    • Standard Contractual Clauses (SCCs): EU Commission-approved contractual clauses with our service providers
    • UK International Data Transfer Agreement (IDTA): For transfers from the UK
    • Adequacy Decisions: Transfers to countries recognized as providing adequate protection
    • Supplementary Measures: Technical and organizational measures to enhance protection where necessary

    Data Localization

    For certain enterprise customers, we may offer data localization options to store and process data within specific geographic regions. Contact legal@valueiq.ai for more information.

    For more information about international transfers and safeguards, contact us at legal@valueiq.ai.

    Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

    Notification of Changes

    When we make material changes, we will notify you by:

    • Posting a prominent notice on our platform
    • Sending you an email notification (for significant changes)
    • Requiring you to acknowledge the updated policy before continuing to use our services (for substantial changes)
    • Updating the "Last Updated" date and version number at the top of this policy

    Review and Acceptance

    We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes are posted constitutes your acceptance of the updated policy.

    Contact Us

    If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    Privacy Team

    Email: legal@valueiq.ai
    Response Time: Within 5 business days for general inquiries

    Data Protection Officer

    Email: legal@valueiq.ai
    Response Time: Within 30 days for formal data subject requests

    Urgent Matters

    For urgent privacy matters, including suspected data breaches or security incidents, please mark your communication as "URGENT - Privacy Request" and we will prioritize your inquiry.

    BY USING VALUEIQ, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS PRIVACY POLICY AND UNDERSTAND HOW WE COLLECT, USE, AND SHARE YOUR INFORMATION. IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, PLEASE DO NOT USE OUR SERVICES.