Privacy Policy
Last updated: April 30, 2025
This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access our Service or parts of our Service.
- Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Pero AI, Manitoba, Canada.
- Consumer, for the purpose of the CCPA (California Consumer Privacy Act), means a natural person who is a California resident. A resident, as defined in the law, includes (1) every individual who is in the USA for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the USA who is outside the USA for a temporary or transitory purpose.
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
- Country refers to: Canada (specifically Manitoba, where the Company is based).
- Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
- Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
- Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities, including the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
- Personal Data is any information that relates to an identified or identifiable individual. For the purposes of GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity. For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.
- Sale, for the purpose of the CCPA/CPRA, means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information by the business to another business or a third party for monetary or other valuable consideration.
- Sensitive Personal Information, for the purpose of the CPRA, means personal information that reveals: a consumer's social security, driver's license, state identification card, or passport number; a consumer's account log‐in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; a consumer's precise geolocation; a consumer's racial or ethnic origin, religious or philosophical beliefs, or union membership; the contents of a consumer's mail, email, and text messages unless the business is the intended recipient of the communication; a consumer's genetic data; the processing of biometric information for the purpose of uniquely identifying a consumer; personal information collected and analyzed concerning a consumer's health; personal information collected and analyzed concerning a consumer's sex life or sexual orientation.
- Service refers to the Website.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purpose of the GDPR, Service Providers are considered Data Processors.
- Sharing, for the purpose of the CPRA, means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's personal information by the business to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business in which no money is exchanged.
- Third-party Social Media Service refers to any website or any social network website through which a User can log in or create an account to use the Service.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit, IP address).
- Website refers to Pero AI, accessible from https://www.pero-ai.com
- You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under GDPR, You can be referred to as the Data Subject. Under CCPA/CPRA, You can be referred to as the Consumer.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Phone number
- Billing Information (processed by Stripe, see below)
- Account login credentials (may be considered Sensitive Personal Information under CPRA)
- Usage Data
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers, interactions with the Service features, and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
Information from Third-Party Services
-
Google Analytics: We use Google Analytics to monitor and analyze the use of our Service. Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data (primarily Usage Data, potentially including IP address, browser type, pages visited) is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.
You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about visits activity.
For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy
-
Google reCAPTCHA: We use the invisible reCAPTCHA service on our authentication pages (sign-in/sign-up) to protect Our Service from spam and abuse. reCAPTCHA analyzes various information about the user (such as IP address, mouse movements, time spent on the page, browser and device information) to determine whether the user is likely a human or a bot. The use of reCAPTCHA is subject to the Google Privacy Policy and Terms of Use.
Google Privacy Policy: https://policies.google.com/privacy
Google Terms of Use: https://policies.google.com/terms
-
Resend (Transactional Emails): We use Resend to send transactional emails related to Your use of the Service. These include emails such as account verification, password resets, purchase confirmations, and important service updates. To facilitate this, We share Your email address and potentially Your name with Resend. Resend processes this information solely for the purpose of sending these essential communications on Our behalf.
You can view Resend's Privacy Policy here: https://resend.com/privacy
-
Stripe (Payment Processing): We use Stripe for processing payments for services You purchase through Our Service. When You make a payment, You provide Your payment information (such as credit card number, CVC, expiration date) and billing details (name, address, email) directly to Stripe. We do not store Your full credit card number or CVC code on Our servers. We may receive information from Stripe such as the last four digits of your card, card type, expiration date, and billing address to facilitate order fulfillment, manage subscriptions, and for verification purposes. Stripe's use of Your Personal Data is governed by their Privacy Policy.
You can view Stripe's Privacy Policy here: https://stripe.com/privacy
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies (like web beacons, tags, and scripts) to track the activity on Our Service, store certain information, and improve and analyze Our Service.
- Cookies or Browser Cookies: As described in the Definitions. You can manage Your Cookie preferences through Your browser settings. However, disabling essential cookies may affect Service functionality.
- Web Beacons: Small electronic files used in emails or on web pages to track user interactions (e.g., email opens, page visits).
We use both Session and Persistent Cookies for purposes including:
- Necessary / Essential Cookies (Session/Persistent): Authentication, security, providing requested services.
- Functionality Cookies (Persistent): Remembering Your preferences (login, language) for a more personalized experience.
- Analytics / Performance Cookies (Session/Persistent): Used by Us or third parties like Google Analytics to collect information about traffic and user behavior. This helps us understand how the Service is used and improve it. Data collected is typically aggregated and anonymized but can involve identifiers like IP addresses or Cookie IDs.
For more information about the cookies we use and your choices regarding cookies, please visit our separate Cookies Policy [If you have one - link here] or this section of our Privacy Policy.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service, including monitoring usage and ensuring security (e.g., via reCAPTCHA).
- To manage Your Account: Registration and access to Service functionalities.
- For the performance of a contract: Fulfilling purchases, subscriptions, or other agreements with You via the Service (includes payment processing via Stripe).
- To contact You: Sending essential transactional emails (via Resend), updates, security alerts, or responding to inquiries via email, phone, SMS, or other electronic means.
- To provide You with news, special offers, and general information about similar goods, services, and events (Marketing Communications), only if You have opted-in to receive such information. You can opt-out at any time.
- To manage Your requests: Attending to Your support requests or inquiries.
- For business transfers: Evaluating or conducting mergers, acquisitions, or asset sales where user data may be transferred.
- For data analysis: Identifying usage trends, determining campaign effectiveness, improving Our Service, products, marketing, and user experience (e.g., using Google Analytics).
- To comply with legal obligations: Responding to legal requests or preventing fraud.
- For other purposes: With Your consent, or for purposes disclosed at the time of collection.
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following conditions:
- Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
- Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with You and/or for any pre-contractual obligations thereof.
- Legal obligations: Processing Personal Data is necessary for compliance with a legal obligation to which the Company is subject.
- Vital interests: Processing Personal Data is necessary in order to protect Your vital interests or of another natural person.
- Public interests: Processing Personal Data is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Company.
- Legitimate interests: Processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Company (e.g., providing and improving the Service, security, fraud prevention, direct marketing analysis - where not overridden by Your data protection interests or fundamental rights and freedoms).
We will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Sharing Your Personal Information
We may share Your personal information in the following situations:
- With Service Providers: We share information with third-party vendors and service providers who perform services on our behalf, such as payment processing (Stripe), email delivery (Resend), website analytics (Google Analytics), security services (Google reCAPTCHA), hosting, customer support, etc. These providers are contractually obligated to protect your data and use it only for the services they provide to Us.
- For business transfers: In connection with mergers, asset sales, financing, or acquisition of our business. We will notify You before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
- With Affiliates: Sharing information within Our corporate group, requiring them to honor this policy.
- With business partners: If offering joint promotions or services, with Your consent where required.
- With other users: Information You choose to share publicly (if applicable on the Service).
- For Legal Reasons: To comply with legal obligations, respond to valid requests by public authorities, protect Our rights or property, prevent wrongdoing, ensure safety, or defend against legal liability.
- With Your Consent: For any other purpose disclosed to you, with your explicit consent.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy and to comply with our business requirements and legal obligations. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (e.g., tax/accounting laws), resolve disputes, enforce our legal agreements and policies, and for the purposes it was collected.
Generally, Account data is retained as long as the Account is active and for a reasonable period thereafter in case You decide to re-activate the services or for record-keeping purposes. Usage Data is generally retained for a shorter period, except when needed for security, service improvement, or legal requirements mandate longer retention. We will delete or anonymize Your Personal Data when it is no longer needed.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices in Canada and potentially in other locations where our Service Providers operate (e.g., USA for Google, Stripe, Resend). This means Your information may be transferred to — and maintained on — computers located outside of Your state, province, country, or other governmental jurisdiction where data protection laws may differ.
If You are located in the European Economic Area (EEA), UK, or Switzerland, Your Personal Data may be transferred outside these areas. We will ensure such transfers comply with applicable data protection laws by relying on mechanisms such as:
- Adequacy decisions by the European Commission (Canada is recognized as providing adequate protection for commercial organizations under PIPEDA).
- Standard Contractual Clauses (SCCs) approved by the European Commission with our Service Providers where necessary.
- Other valid transfer mechanisms permitted under GDPR.
Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to these transfers. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy.
Deleting Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You, subject to certain exceptions.
You may be able to update, amend, or delete certain information directly within Your Account settings, if applicable.
You may contact Us using the details below to request access to, correction of, or deletion of any personal information You have provided.
Please note, We cannot delete Your Personal Data when We have a legal obligation (e.g., retaining transaction records for tax purposes), a contractual necessity, or a legitimate interest (e.g., for fraud prevention, security, or dispute resolution) to retain it. We will inform you if we cannot fulfill your request for these reasons.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law Enforcement & Other Legal Requirements
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency). The Company may also disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us. We implement and maintain reasonable administrative, physical, and technical security safeguards designed to protect the Personal Data We collect from loss, misuse, unauthorized access, disclosure, alteration, and destruction. Examples include using encryption (e.g., SSL/TLS) for data transmission, access controls, and secure infrastructure. We also use services like Google reCAPTCHA to enhance security.
However, remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Your Data Protection Rights under GDPR (For EEA/UK Residents)
If You are a resident of the European Economic Area (EEA) or the UK, You have certain data protection rights. The Company aims to take reasonable steps to allow You to correct, amend, delete, or limit the use of Your Personal Data.
- Right of Access: You have the right to access the Personal Data We hold about You.
- Right to Rectification: You have the right to have Your information rectified if that information is inaccurate or incomplete.
- Right to Erasure (Right to be Forgotten): You have the right to request the deletion of Your Personal Data under certain conditions.
- Right to Object: You have the right to object to Our processing of Your Personal Data based on legitimate interests or for direct marketing.
- Right of Restriction: You have the right to request that We restrict the processing of Your personal information under certain conditions.
- Right to Data Portability: You have the right to be provided with a copy of the information We have on You in a structured, machine-readable and commonly used format (where technically feasible).
- Right to Withdraw Consent: If processing is based on consent, You have the right to withdraw Your consent at any time.
To exercise these rights, please contact Us using the contact information below. We may need to verify Your identity before responding to such requests. You also have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. For more information, please contact Your local data protection authority in the EEA or UK.
Your California Privacy Rights (CCPA/CPRA)
This section supplements the information contained in Our Privacy Policy and applies solely to visitors, users, and others who reside in the State of California.
Categories of Personal Information Collected
We have collected the following categories of personal information from Consumers within the last twelve (12) months:
- A. Identifiers: Name, email address, phone number, IP address, online identifiers (like cookie IDs), account name. (Sources: You, Your Device)
- B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)): Name, phone number, address (if billing address collected via Stripe). (Sources: You)
- C. Commercial information: Records of products or services purchased, obtained, or considered. (Sources: You, Our Systems, Stripe)
- D. Internet or other similar network activity: Browsing history, search history, information on a Consumer's interaction with our Website or Service (Usage Data, collected via Cookies, Google Analytics). (Sources: Your Device, Google Analytics)
- E. Geolocation data: Approximate location derived from IP address. We do not collect precise geolocation data without consent. (Sources: Your Device)
- F. Inferences drawn from other personal information: Profile reflecting preferences or characteristics (e.g., based on service usage). (Sources: Our analysis of other collected data)
- G. Sensitive Personal Information: Account log-in credentials. We do not collect other SPI unless explicitly stated and with appropriate notice/consent. (Sources: You)
Use of Personal Information
We use the categories of personal information listed above for the purposes described in the "Use of Your Personal Data" section.
Categories of Personal Information Disclosed for a Business Purpose
In the preceding twelve (12) months, We have disclosed the following categories of personal information for a business purpose to the categories of third parties indicated:
- A. Identifiers: Service Providers (Hosting, Support, Email Delivery [Resend], Analytics [Google], Security [reCAPTCHA]), Payment Processors (Stripe).
- B. California Customer Records personal information: Service Providers (Payment Processors [Stripe]).
- C. Commercial information: Service Providers (Payment Processors [Stripe]).
- D. Internet or other similar network activity: Service Providers (Analytics [Google], Security [reCAPTCHA]).
- E. Geolocation data: Service Providers (Analytics [Google], Security [reCAPTCHA]).
- G. Sensitive Personal Information (Account Log-in): Processed for account management and security; disclosed implicitly to hosting/security Service Providers as needed to provide the Service.
Sale or Sharing of Personal Information
We do not "sell" Personal Information in the traditional sense (exchanging data for money). However, the use of certain third-party analytics and security tools (like Google Analytics and reCAPTCHA) may constitute "Sharing" under the CPRA's definition (disclosure for cross-context behavioral advertising or analytics profiling).
In the preceding twelve (12) months, we may have "Shared" the following categories of personal information:
- A. Identifiers: (e.g., Cookie ID, IP Address) - with Analytics/Security providers (Google).
- D. Internet or other similar network activity: - with Analytics/Security providers (Google).
- E. Geolocation data: (Approximate) - with Analytics/Security providers (Google).
Your Right to Opt-Out of Sale / Sharing: You have the right to direct Us not to Sell or Share Your personal information. To exercise this right, please contact Us or manage your preferences via [Link to Your Cookie Consent Tool / Opt-Out Mechanism - e.g., a "Do Not Sell or Share My Personal Information" link if you implement one]. We also respond to Global Privacy Control (GPC) signals as a valid opt-out request for Sharing via cookies/tracking technologies.
Use and Disclosure of Sensitive Personal Information
We collect account log-in credentials (considered SPI under CPRA) solely for the purpose of authenticating You, managing Your account, and securing Our Service. We do not use or disclose this SPI for purposes other than those permitted by the CPRA regulations (e.g., providing the requested service, security, verifying identity, short-term transient use). You have the right to limit the use and disclosure of Your SPI if it were used for other purposes; however, as We only use it for these permitted essential purposes, this right may not be applicable to Our current practices.
Your Rights under the CCPA/CPRA
You have the following rights regarding Your Personal Information:
- Right to Know: Request disclosure of:
- The categories of personal information collected about You.
- The categories of sources for the personal information collected.
- Our business or commercial purpose for collecting, Selling, or Sharing personal information.
- The categories of third parties to whom We disclose personal information.
- The specific pieces of personal information collected about You.
- Right to Delete: Request deletion of Your personal information, subject to certain exceptions (e.g., completing a transaction, legal compliance, security).
- Right to Correct: Request correction of inaccurate personal information We maintain about You.
- Right to Opt-Out of Sale/Sharing: Direct Us not to Sell or Share Your personal information (as described above).
- Right to Limit Use and Disclosure of Sensitive Personal Information: (As described above, likely limited applicability based on current use).
- Right to Non-Discrimination: You will not be discriminated against for exercising Your CCPA/CPRA rights.
Exercising Your Rights: To exercise the rights described above, please submit a verifiable consumer request to Us by:
- Emailing us at: support@pero-ai.com
- Visiting this page on our website: https://pero-ai.com/support
- [Add Toll-Free Number if required/applicable]
Only You, or someone legally authorized to act on Your behalf, may make a verifiable consumer request related to Your personal information. We will need to verify Your identity or authority before processing Your request.
Children Under 16 (California)
We do not knowingly collect personal information from minors under 16 years of age. If We learn that We have collected personal information from a child under 16 without verification of parental consent (or affirmative authorization for 13-16 year olds regarding Sale/Sharing), We will take steps to remove that information. Our Service is not directed to children under 16. We do not Sell or Share the personal information of consumers We know are less than 16 years of age.
CalOPPA Disclosures (California Online Privacy Protection Act)
CalOPPA requires commercial websites and online services to post a privacy policy. The law requires businesses that collect Personally Identifiable Information (PII) from California consumers to conspicuously post a privacy policy stating exactly the information being collected and those individuals with whom it is being shared, and to comply with this policy.
- Categories of PII Collected: As detailed in the "Types of Data Collected" and "Your California Privacy Rights" sections.
- Third Parties Shared With: As detailed in the "Sharing Your Personal Information" section.
- Reviewing/Changing Your PII: You can review and change your Personal Data by logging into your Account settings (if applicable) or by contacting Us via the methods provided below.
- Policy Changes: We notify users of policy changes as described in the "Changes to this Privacy Policy" section.
- Do Not Track Signals: Our Service does not currently respond to Do Not Track (DNT) signals. DNT is a privacy preference that users can set in certain web browsers. While the Internet industry is still working on DNT standards, solutions, and implementation, we do not alter our data collection and usage practices when we detect a DNT signal from your browser. You can often manage tracking via cookie settings and browser extensions (like the Google Analytics Opt-out Add-on).
Children's Privacy (General & COPPA)
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13 without parental consent. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data without Your consent, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers in compliance with the Children's Online Privacy Protection Act (COPPA).
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us (e.g., links to Google, Stripe, Resend policies). If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, Your rights, or Our data practices, You can contact us:
- By email: support@pero-ai.com
- By visiting this page on our website: https://pero-ai.com/support