Privacy Policy - Org IQ
The Org IQ logo

Privacy Policy

PRIVACY NOTICE

Effective Date: October 10, 2024
Last Updated: October 3, 2025

This privacy notice for Email Vault, LLC d/b/a Org IQ (“Company,” “we,” “us,” or “our”) describes how and why we collect, store, use, and/or share (“process”) your information when you use our services (“Services”), such as when you:

  • Visit our website at https://orgiq.com, or any website of ours that links to this privacy notice
  • Engage with us in other related ways, including sales, marketing, or events

If you do not agree with our policies and practices, please do not use our Services. If you have questions or concerns, please contact us at legal@orgiq.com.


SUMMARY OF KEY POINTS

  • What personal information do we collect? Name, email, payment info, device/browser activity, and (if you opt into cookies) social media and advertising-related info.
  • Do we use cookies? Yes. See our full Cookie Policy.
  • Do we collect sensitive personal information? No. We do not knowingly process sensitive personal data (such as health, biometric, or precise geolocation data).
  • Do we share your data? Yes, with specific vendors and service providers.
  • Do we sell personal data? No.
  • How do we protect your data? We apply encryption, access controls, monitoring, and organizational safeguards. We are pursuing SOC 2 certification.

Do you have rights? Yes. California, Virginia, and other U.S. residents may exercise specific rights by contacting us. EEA/UK residents may exercise GDPR rights.


TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE USE YOUR INFORMATION?
  3. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  4. HOW LONG DO WE KEEP YOUR INFORMATION?
  5. HOW DO WE KEEP YOUR INFORMATION SAFE?
  6. DO WE COLLECT INFORMATION FROM MINORS?
  7. WHAT ARE YOUR PRIVACY RIGHTS?
  8. CONTROLS FOR DO-NOT-TRACK (DNT) FEATURES
  9. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
  10. DO VIRGINIA AND OTHER STATE RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
  11. INTERNATIONAL DATA TRANSFERS & GDPR/UK RIGHTS?
  12. DO WE MAKE UPDATES TO THIS NOTICE?
  13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

1. WHAT INFORMATION DO WE COLLECT?

Information You Provide:

  • Name, email address, payment information (via Stripe: see their Privacy Policy)
  • Social media profile (optional)
  • Feedback, reviews, and testimonials

Information Collected Automatically:

  • IP address, browser type, device data
  • Website interactions, clickstream data
  • Cookies, pixels, and similar tracking technologies
  • Email marketing behavior (open/click data)
  • Company/advertisement preferences (via third-party services, e.g., Storylane or Retention.com, only if you opt into cookies)

You may opt out of cookie-based advertising at: https://app.retention.com/optout.


2. HOW DO WE USE YOUR INFORMATION?

We process your data for:

  • Account creation and management
  • Transactional and administrative communications
  • Marketing and promotional messages (with consent where required)
  • Fraud detection and prevention
  • Legal and regulatory compliance
  • Service improvement and analytics
  • Collecting feedback and testimonials

If additional uses arise, we will seek your consent before processing.


3. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We may share your data with:

  • Vendors and service providers (Stripe, HubSpot, Google, Amazon Web Services, Retention.com, marketing agencies, contractors)
  • Analytics and advertising partners (when cookies are enabled)
  • Professional advisors (lawyers, auditors, consultants)
  • Legal authorities, when required by law
  • Successors in ownership (mergers, acquisitions, reorganizations, bankruptcy)

All vendors are contractually required to use your data only for agreed purposes.


4. HOW LONG DO WE KEEP YOUR INFORMATION?

We retain data only as long as necessary for each purpose:

  • Payment/transaction data: up to 7 years (for legal/tax purposes)
  • Marketing data: until you opt out or request deletion
  • User accounts: up to 2 years after termination
  • Backups/archives: securely retained and periodically deleted
  • Anonymized data: may be retained indefinitely

5. HOW DO WE KEEP YOUR INFORMATION SAFE?

We apply technical and organizational safeguards, including:

  • Encryption at rest and in transit
  • Access controls and role-based permissions
  • Security monitoring and logging
  • Periodic audits and penetration testing
  • Vendor security reviews

We are actively pursuing SOC 2 certification to further strengthen our controls.


6. DO WE COLLECT INFORMATION FROM MINORS?

We do not knowingly collect data from individuals under 18. In compliance with COPPA, we do not knowingly collect data from children under 13. If we discover such data, we will delete it. Parents may contact legal@orgiq.com for assistance.


7. WHAT ARE YOUR PRIVACY RIGHTS?

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your personal data
  • Request data portability
  • Withdraw consent
  • Object to processing (including marketing)
  • Opt out of targeted advertising or profiling
  • Appeal decisions if we decline your request

You can exercise rights by emailing legal@orgiq.com. We will verify your identity before fulfilling requests.


8. CONTROLS FOR DO-NOT-TRACK (DNT) FEATURES

We do not currently respond to browser-based DNT signals due to the lack of a uniform standard.


9. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

Yes. Under the California Consumer Privacy Act (CCPA) and Shine the Light law, California residents may request:

  • Disclosure of the categories of data we collect and share
  • Access to their specific personal data
  • Deletion of personal data (with exceptions)
  • Correction of inaccuracies
  • Opt-out of data sharing for targeted advertising (we do not sell personal data)
  • Non-discrimination for exercising these rights

To exercise, email legal@orgiq.com.


10. DO VIRGINIA AND OTHER STATE RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

Yes. Residents of Virginia, Colorado, Connecticut, and Delaware may request:

  • Confirmation of processing
  • Access, correction, and deletion of personal data
  • Opt-out of profiling, targeted advertising, or data sales (which we do not engage in)
  • Appeal if we decline a request (email us; we respond within 60 days)

11. INTERNATIONAL DATA TRANSFERS & GDPR/UK RIGHTS

If you are located in the EEA or UK, we process your personal data under the following legal bases:

  • Consent (for marketing or cookies)
  • Contract (to deliver services you request)
  • Legitimate interests (service improvement, security)
  • Legal obligations (tax, compliance)

Your data may be transferred to the United States and safeguarded through contractual protections (e.g., Standard Contractual Clauses).

GDPR/UK rights include access, correction, deletion, restriction, portability, objection, and lodging a complaint with your local supervisory authority.


12. DO WE MAKE UPDATES TO THIS NOTICE?

Yes. We may update this policy periodically. Updates become effective 180 days after posting unless otherwise required by law. Continued use of our Services indicates acceptance.


13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

Email: legal@orgiq.com

Mail:
Email Vault, LLC d/b/a Org IQ
221 W 9th St #396
Wilmington, DE 19801
USAIf you are unsatisfied with our response, you may lodge a complaint with your local data protection authority or the U.S. Federal Trade Commission (FTC) at www.ftc.gov.

Have Questions About Our Data Privacy?