Legal

Privacy Policy

Last updated August 4, 2026

In short: we collect what we need to run the product, we never sell personal information, customer data loaded into the product is processed on the customer’s instructions under the DPA, bank connections are read-only, and AI providers may not train on your data. This summary is for convenience and is not part of the policy.

1. Who we are and what this covers

This policy is published by BaselineZero, LLC, a Michigan limited liability company (“BaselineZero”, “we”). It covers our websites and our products: Debut, Discovery, Vault, and Debrief (the “Service”).

We act in two roles. For information about visitors, waitlist signups, and our customers’ account holders, we are the controller and this policy applies. For personal information our customers load into the Service (their clients’ staff directories, messages, files, financial records, and similar “Customer Content”), we are a processor acting on the customer’s instructions under our Data Processing Addendum; the customer’s own privacy notice governs that data. If you are a client of one of our customers, contact them first; we will refer any request we receive to them.

2. Information we collect

You provide: name, work email, company details, and password or SSO identity when an account is created; billing details (payment card data is handled by our payment processor and does not touch our servers); support messages; waitlist signups.

Connected services provide, at the customer’s direction: data read from systems the customer connects, such as tickets and contacts from a PSA, device check-ins from an RMM, directory entries from Microsoft Entra, invoices and bills from QuickBooks Online, payroll schedule and amounts from Gusto, and read-only bank account balances and transactions through Plaid. We receive access tokens for these systems and store them in isolated, per-customer key storage; we never receive or store banking credentials.

Collected automatically: product usage events, log and device data (IP address, browser, timestamps), and the access log of portal links (which link was opened, when, and what was done). We use this for security, audit, support, and product improvement.

3. How we use information

To provide, secure, and support the Service; to reconcile expected against actual events (the core of the product); to send transactional messages such as portal invitations, alerts, and weekly letters our customers approve; to bill; to prevent abuse; to comply with law; and, for our own sites, to measure what works. We do not sell personal information and we do not use it for third-party advertising.

4. AI processing

Some features send data to a machine-learning model provider to produce drafts and answers. Providers are bound by data processing agreements, may use the data only to provide the response, and may not use it to train models. AI usage is metered per customer, and every AI-proposed action requires human approval in the product before it takes effect.

5. When we share information

With subprocessors that host and operate parts of the Service (cloud infrastructure, AI model provider, transactional email), listed in Annex III of the DPA.

With connected services, only as directed by the customer who connected them.

With authorities when required by law, after reviewing the demand and, where lawful, notifying the affected customer.

With a successor in a merger, acquisition, or asset sale, under confidentiality and subject to this policy.

6. Portal links

Portal pages are reached through individually issued links rather than accounts. For each link we record the person it was issued to, its scope and expiry, and a log of views and actions. This log exists so our customers can show their clients exactly who saw what; it is visible to the issuing customer.

7. Cookies

The product uses cookies that are necessary to keep you signed in and to protect sessions. Our marketing site uses minimal, privacy-respecting analytics and no cross-site advertising trackers. We honor browser-level opt-out signals recognized by applicable law.

8. Retention and deletion

Account information is kept for the life of the account. Customer Content is kept while the subscription is active and is deleted after the subscription ends; the Service does not provide bulk export; per-customer key storage and its access identity are destroyed as part of offboarding. Backups age out on a fixed schedule after deletion. We keep minimal billing and audit records where the law requires.

9. Security

Data is encrypted in transit and at rest. Each customer’s rows are isolated at the database layer, integration tokens live in per-customer key storage readable only by that customer’s workload identity, production access is restricted and logged, and secret material (passwords and keys belonging to our customers’ clients) is designed never to be stored in the Service at all. Annex II of the DPA describes the measures in detail. If we learn of a breach affecting personal information we will notify affected customers without undue delay and as required by law.

10. Where data lives

We are a United States company and all processing occurs in the United States. We do not offer international transfer mechanisms, and the Service is not directed to persons outside the United States. Anyone using it from elsewhere does so at their own risk, under U.S. law only.

11. Your rights

Depending on your state, you may have rights to access, correct, delete, or receive a copy of your personal information. California residents have the rights described in the CCPA, including to know, delete, correct, and to not be discriminated against for exercising rights; we do not sell or share personal information as those terms are defined in the CCPA. Residents of other U.S. states with comprehensive privacy laws have analogous rights.

To exercise a right, email privacy@baselinezero.com. We will verify the request against the account or link records we hold and respond within the time required by law. If the request concerns data we process for a customer, we will refer it to that customer and assist them.

12. Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.

13. Changes and contact

We will post changes here and, for material changes, notify account owners by email or in the product at least 30 days before they take effect. Questions and requests: privacy@baselinezero.com, or by mail at BaselineZero, LLC, P.O. Box 511002, Livonia, Michigan 48151, USA.