PrimoDato is committed to complying with the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), and related California privacy laws. This page summarizes how PrimoDato approaches CCPA compliance, the categories of personal information we process, the rights available to California residents, and how to exercise those rights. It should be read together with our Privacy Policy and, where applicable, our Data Processing Agreement.
1. Regulations We Follow
For California residents and, where applicable, other U.S. state privacy laws that grant similar rights, PrimoDato follows:
- California Consumer Privacy Act (CCPA)
- California Privacy Rights Act (CPRA)
- California Online Privacy Protection Act (CalOPPA), where it applies to our website notices
For individuals in the EEA, United Kingdom, and Switzerland, see our GDPR Compliance page.
2. Our Role
PrimoDato may act as a "business" or a "service provider" under the CCPA depending on the context. We act as a business for account registration, billing, customer support, product analytics, and our own website operations. We act as a service provider when customers use the Services and instruct us to store or handle personal information on their behalf in connection with their workspace and workflows.
3. Categories of Personal Information
Depending on how you use PrimoDato, we may collect the following categories of personal information:
- Identifiers such as name, business email address, account ID, and IP address.
- Commercial information such as plan selection, credit purchases, and invoice history.
- Internet or network activity such as search queries, reveal activity, and feature usage.
- Professional or employment-related information you choose to provide in your profile.
- Inferences drawn from product usage to improve the Service and prevent abuse.
We do not collect Social Security numbers, financial account numbers, precise geolocation, or biometric identifiers as part of the ordinary use of PrimoDato.
4. Sources and Business Purposes
We collect personal information from:
- You, when you create an account, contact us, or use the platform.
- Your organization, when a teammate invites you or an administrator manages your workspace.
- Service providers that support billing, hosting, email, and security.
We use this information to:
- Provide, operate, maintain, and improve the PrimoDato platform.
- Process purchases, manage subscriptions, and issue credits.
- Deliver support, security monitoring, and fraud prevention.
- Comply with legal obligations and enforce our agreements.
5. Sale, Sharing, and Sensitive Personal Information
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. We do not broker customer account data to third parties for their independent marketing use. We share information only where necessary to operate PrimoDato, fulfill customer instructions, comply with law, or protect rights and security.
We do not use or disclose sensitive personal information for purposes that require a "Limit the Use of My Sensitive Personal Information" opt-out under the CPRA.
6. Your Rights Under the CCPA
California residents may have the following rights:
- Right to know: request the categories and specific pieces of personal information we collected.
- Right to delete: request deletion of personal information, subject to legal exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell or share personal information as those terms are defined under the CCPA.
- Right to limit use of sensitive personal information, where applicable.
- Right to non-discrimination: we will not deny goods or services, charge a different price, or provide a different level of service for exercising your rights.
7. How to Exercise Your Rights
You may exercise your CCPA rights by contacting privacy@primodato.com. We may request reasonable verification information before acting on a request. An authorized agent may submit a request on your behalf if they provide proof of authorization and we can verify your identity.
We will confirm receipt of a verifiable consumer request within 10 business days and respond within 45 days, or notify you if we need additional time as permitted by law.
8. Retention
We keep personal information only for as long as necessary for the purposes described in our Privacy Policy, including legal, contractual, tax, accounting, and security requirements. Typical retention periods match those described on our GDPR Compliance page.
9. Service Providers
PrimoDato currently relies on the following core service providers and infrastructure partners:
- Dodo Payments
- Vercel
- MongoDB Atlas
- Upstash Redis
- Resend
- AWS
10. Other Privacy Notices
For European data protection rights, visit GDPR Compliance. For cookies and similar technologies, visit our Cookie Policy.