Privacy Policy
How Piripro, Inc. handles personal data.
Who we are: Piripro, Inc. ("Piri", "we"), a Delaware corporation. Contact: privacy@piri.pro.
1. Scope — two different roles
This policy covers personal data we handle in two distinct roles, and it matters which one applies to you:
- As a controller — for data about our website visitors, prospects, and the administrators/users of customer accounts (e.g. sign-in identity, billing contacts, marketing subscribers). We decide how and why this data is used, and this policy governs it.
- As a processor — for the data our business customers put into Piri about their own end customers, properties, and jobs. We process that data only on the customer's instructions under our Data Processing Addendum. If you are an end customer of a business that uses Piri, that business — not Piri — is the controller of your data; direct privacy requests to them.
2. Data we collect (as controller)
- Account and identity data — name, work email, and authentication identifiers, handled via our identity provider (Auth0).
- Billing data — company billing contact and payment status. Card details are collected and stored by our payment processor (Stripe), not by Piri.
- Usage and device data — log data, IP address, device and app version, and product interaction events, used to operate, secure, and improve the Service.
- Communications — messages you send us (e.g. demo requests, support) and your marketing preferences.
- Cookies and similar technologies — used only for authentication and security (keeping you signed in and protecting the account). We do not use advertising cookies, and we do not run third-party analytics or tracking on the Service.
3. Customer Data we process (as processor)
When a business uses Piri, it submits data about its own end customers — such as names, service addresses, phone numbers, property and unit details, and job history. We process this data solely to provide the Service to that business, on its instructions, under the DPA. We do not use it for our own purposes, sell it, or use it for advertising.
4. How we use data (as controller)
To provide, secure, maintain, and improve the Service; to process payments and manage subscriptions; to communicate about the Service and provide support; to send marketing about Piri where permitted (you can opt out at any time — every marketing email includes an unsubscribe link and our postal address, as required by law); and to comply with legal obligations.
5. Legal bases
Where required (e.g. GDPR), we rely on: performance of a contract (providing the Service), legitimate interests (securing and improving the Service), consent (marketing where required), and legal obligation. Where U.S. state privacy laws apply, we honor applicable rights described in Section 8.
6. How we share data — subprocessors
We do not sell personal data. We share it with vendors who process it on our behalf under contract, and only as needed to run the Service:
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting and data storage |
| Auth0 (Okta) | Authentication and identity |
| Stripe | Payment processing, quotes, and invoices |
| Cloudflare | DNS, CDN, and network security |
| QuickBooks (Intuit) | Accounting sync — only where a customer enables it |
We may also disclose data to comply with law, enforce our agreements, or protect rights and safety, and to a successor in a merger or acquisition. The authoritative subprocessor list lives in the DPA; we will keep it current there.
7. Where data is stored
Piri is hosted in the United States (AWS). If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. Where personal data originates from a jurisdiction that restricts such transfers, the transfer mechanism in DPA §9 applies.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to opt out of marketing. To exercise these as a controller-held data subject, contact privacy@piri.pro. If your data is held by Piri as a processor (i.e. you are an end customer of a business using Piri), contact that business; we will assist them in responding as required by the DPA.
9. Data retention
We retain personal data for as long as needed to provide the Service and for legitimate business and legal purposes. Customer Data is retained for the life of the account; on termination it is available for export for 30 days as described in the Terms, after which we may delete it in the ordinary course, subject to the DPA. Backups are deleted on their ordinary rotation. We keep billing and tax records for as long as the law requires.
10. Security
We use reasonable technical and organizational measures to protect personal data, including encryption in transit, access controls, and reliance on reputable infrastructure providers. No system is perfectly secure; we cannot guarantee absolute security. See the security measures annex in the DPA.
11. Children
The Service is a business tool not directed to children, and we do not knowingly collect personal data from anyone under 18.
12. Changes
We may update this policy; the current version is always at piri.pro/privacy. For material changes we will provide reasonable notice.
13. Contact
Privacy questions: privacy@piri.pro. Piripro, Inc., a Delaware corporation.