Privacy Policy

Effective date: April 4, 2026 · Last updated: April 9, 2026

1. Introduction

OutpostIQ, Inc. (“we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use our website at www.outpostiq.com and our SaaS application (collectively, “the Service”).

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please do not use the Service.

2. Information We Collect

2.1 Information you provide directly

  • Account information (identifiers): Name, email address, and authentication credentials when you create an account
  • Payment information (financial data): Credit card and billing details processed and stored securely by our payment processor, Stripe. We do not store, access, or retain your full card number, CVV, or complete financial account details on our servers.
  • Business data (commercial information): Financial figures, restaurant operating data, recipes, cost information, and other data you input into the modeling tools
  • Communications: Emails, support requests, and other messages you send to us, including their content and metadata
  • Waitlist and marketing information: Email address when you join our waitlist or opt in to marketing communications

2.2 Information collected automatically

  • Usage data (internet activity): Pages visited, features used, time spent on the Service, click patterns, and interaction data
  • Device information: Browser type and version, operating system, device type, screen resolution, and language preferences
  • Log data: IP address, access times, referring URLs, error logs, and HTTP request headers
  • Cookies and similar technologies: Session cookies for authentication and analytics cookies for improving the Service (see Section 7)

2.3 Information from third parties

  • Google OAuth: If you sign in with Google, we receive your name, email address, and profile picture from Google. We do not access your Google Drive, Gmail, or other Google services.
  • Stripe: Payment confirmation, subscription status, and billing-related information
  • Analytics providers: Aggregated, anonymized usage data from Vercel Analytics

2.4 Information we do not collect

We do not collect sensitive personal information as defined under the California Privacy Rights Act (CPRA), including Social Security numbers, driver's license numbers, precise geolocation data, racial or ethnic origin, religious beliefs, biometric data, health information, sexual orientation, or contents of private communications (other than communications you send directly to us).

3. How We Use Your Information

We collect and use your information for the following specific business purposes:

  • Provide and operate the Service: Process your data inputs, generate financial models and projections, store your scenarios, and deliver core application functionality
  • Account management: Create and manage your account, authenticate your identity, process payments, and handle subscription changes
  • Transactional communications: Send necessary service-related emails including account confirmations, password resets, billing receipts, security alerts, and subscription notices
  • Marketing communications: With your consent, send emails about new features, tips, and promotions. You may opt out at any time (see Section 8).
  • Service improvement: Analyze aggregated, anonymized usage patterns to improve features, fix bugs, optimize performance, and develop new functionality
  • Security and fraud prevention: Detect, investigate, and prevent fraud, abuse, unauthorized access, and security threats
  • Legal compliance: Comply with applicable laws, regulations, legal processes, or enforceable governmental requests
  • Enforce our terms: Enforce our Terms of Service and other agreements

We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects on you.

4. How We Share Your Information

We do not sell or share (as defined by the CCPA/CPRA) your personal information. We have not sold or shared personal information in the preceding 12 months. We only disclose your information in the following limited circumstances:

  • Service providers and contractors: We disclose data to trusted third-party service providers who process it on our behalf solely to help us operate the Service. These providers are contractually obligated to protect your data and may not use it for their own purposes. Our current service providers include: Stripe (payment processing), Vercel (hosting and analytics), Neon (database hosting), Google (authentication via OAuth), and Resend (transactional and outreach email delivery).
  • Legal requirements: We may disclose your information if required to do so by law, or in response to valid requests by public authorities (e.g., a subpoena, court order, or government agency)
  • Protection of rights: We may disclose information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our Terms, suspected fraud, situations involving potential threats to the safety of any person, or as evidence in litigation in which we are involved
  • Business transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of the transaction. We will provide notice before your personal information becomes subject to a different privacy policy.
  • With your consent: We may share your information for other purposes with your explicit, informed consent

Categories of information disclosed to service providers in the preceding 12 months:

  • Identifiers (name, email) — disclosed to: Stripe, Google, Resend, Vercel
  • Financial information (payment data) — disclosed to: Stripe
  • Internet activity (usage data, log data) — disclosed to: Vercel
  • Commercial information (subscription status) — disclosed to: Stripe

5. Data Security

We implement commercially reasonable security measures designed to protect your data, including:

  • Encryption in transit (TLS 1.2+) for all data transmitted between your browser and our servers
  • Encryption at rest for stored data in our database
  • Secure authentication with OAuth 2.0 and secure session management
  • Regular security reviews and monitoring of our infrastructure
  • Principle of least privilege access controls limiting employee and system access to personal data
  • Third-party payment processing through PCI DSS compliant providers (Stripe)

While we take commercially reasonable steps to protect your data, no method of electronic storage or transmission over the Internet is 100% secure. We cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and any applicable regulatory authorities as required by law.

6. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected. Specific retention periods are:

  • Account data: Retained for as long as your account is active. After account deletion, personal data is deleted or anonymized within 30 days.
  • Business data (scenarios, models): Retained for as long as your account is active. Deleted within 30 days of account deletion.
  • Payment records: Transaction records are retained for 7 years after the transaction date as required for tax and accounting compliance.
  • Log and usage data: Retained for up to 90 days for security and debugging purposes, then automatically purged or anonymized.
  • Marketing/waitlist emails: Retained until the subscriber unsubscribes or requests deletion.
  • Support communications: Retained for 2 years after the last communication for quality assurance and dispute resolution purposes.

We may retain certain information for longer periods where required by law (e.g., tax records, legal hold obligations) or to resolve disputes and enforce our agreements.

7. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies:

  • Strictly necessary cookies: Required for authentication, session management, and core functionality. These cannot be disabled as the Service cannot function without them.
  • Analytics cookies: Used by Vercel Analytics to understand how visitors use the Service. These collect aggregated, anonymized data and do not track you across other websites.

We do not use advertising cookies, retargeting pixels, or any form of cross-site tracking. We do not sell data to advertisers. We do not participate in ad networks or data exchanges.

Most web browsers allow you to control cookies through their settings. Blocking strictly necessary cookies may prevent you from using the Service.

8. Your Privacy Rights

Depending on your location and applicable law, you may have the following rights regarding your personal data:

  • Right to know/access: Request information about the categories and specific pieces of personal data we have collected about you, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share your data
  • Right to correction: Request correction of inaccurate personal data we hold about you
  • Right to deletion: Request deletion of your personal data, subject to certain exceptions (e.g., legal retention requirements, fraud prevention, completing a transaction)
  • Right to portability: Request a copy of your personal data in a structured, commonly used, machine-readable format
  • Right to opt out of sale/sharing: We do not sell or share your personal information, so there is no need to opt out. If our practices change, we will provide a clear opt-out mechanism.
  • Right to limit use of sensitive personal information: We do not collect sensitive personal information as defined under CPRA (see Section 2.4)
  • Right to opt out of marketing: Unsubscribe from marketing emails at any time by clicking the “Unsubscribe” link in any marketing email or by contacting us. We will process opt-out requests within 10 business days.
  • Right to withdraw consent: Where processing is based on your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights. We will not deny you services, charge different prices, or provide a different level of quality for exercising your rights.

How to submit a request: To exercise any of these rights, contact us at privacy@outpostiq.com with your request. Please include sufficient information for us to verify your identity (we may request additional information to verify you are the account holder). We will respond to verifiable requests within 45 days. If we need additional time, we will notify you of the extension and the reason.

Authorized agents: You may designate an authorized agent to submit privacy requests on your behalf. Authorized agents must provide proof of authorization (such as a signed letter or power of attorney).

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the rights described in Section 8 above under the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, “CCPA”). In addition:

  • We do not sell personal information (as defined by the CCPA). We have not sold personal information in the preceding 12 months.
  • We do not share personal information for cross-context behavioral advertising.
  • We do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA.
  • You have the right to request that we limit the use and disclosure of your sensitive personal information (though we do not collect sensitive personal information as defined by the CCPA).
  • We do not use personal information for automated decision-making or profiling as defined under the CCPA regulations effective January 1, 2026.

Metrics: In the preceding 12 months, we have received 0 requests to know, 0 requests to delete, and 0 requests to opt out. This disclosure will be updated annually.

10. Other State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have similar rights to those described in Section 8, including the right to access, correct, delete, and obtain a copy of their personal data, and the right to opt out of targeted advertising, sale of personal data, and certain profiling activities. To exercise these rights, contact us at privacy@outpostiq.com.

If you are not satisfied with our response to your privacy request, you may have the right to appeal our decision or file a complaint with your state's attorney general.

11. International Data Transfers

The Service is operated from and our servers are located in the United States. If you access the Service from outside the United States, your personal data will be transferred to, stored, and processed in the United States. The data protection laws of the United States may differ from the laws of your jurisdiction. By using the Service, you acknowledge and consent to the transfer and processing of your data in the United States.

We do not currently offer the Service to users in the European Economic Area (EEA), United Kingdom, or Switzerland, and we do not intentionally collect personal data from residents of those regions. If we expand to serve those regions in the future, we will update this policy with appropriate legal mechanisms for international data transfers.

12. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have inadvertently collected personal information from a child under 18, we will take steps to delete it as soon as possible. If you believe that a child under 18 has provided us with personal information, please contact us at privacy@outpostiq.com.

13. Third-Party Links and Services

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.

14. Changes to This Policy

We review this Privacy Policy at least annually and may update it from time to time. We will notify you of material changes by posting the updated policy on this page, updating the “Last updated” date, and sending notice to the email address associated with your account at least 30 days before the changes take effect. For non-material changes, we will update this page with the revised policy. Your continued use of the Service after the effective date of any changes constitutes acceptance of the revised policy.

15. Contact Us

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us at:

Privacy inquiries: privacy@outpostiq.com
General support: support@outpostiq.com
Website: www.outpostiq.com