Legal

Privacy Policy

Effective August 20, 2026 · Panoverse Inc., a Delaware corporation

Security and compliance

SOC 2 Type IISecurity, availability, confidentiality
ISO/IEC 27001Information security management certified
GDPREU General Data Protection Regulation
CCPA / CPRACalifornia consumer privacy compliance
Panoverse holds a SOC 2 Type II attestation — controls operating continuously against the Trust Services Criteria for security, availability and confidentiality, verified by an independent auditor — and is certified to ISO/IEC 27001 for its information security management system. Data processing complies with the GDPR and the CCPA/CPRA (compliance regimes, neither of which has a certifying body). Reports and certificates are available under NDA through security@panoverse.com, along with our DPA and subprocessor list.

Read-only access, revocable at any time

Every platform connection uses OAuth with read-only scopes. We hold no ability to publish, modify or delete anything in your accounts. You can revoke from the platform side or through us at any time; ingestion stops immediately.

Aggregate by design, no consumer PII

The engine works on aggregate and content-level fields: spend, impressions, views, order counts, inventory, review text. We do not pull or store your end consumers' names, addresses, payment details or identity records.

Brand isolation, never pooled

Each brand's data is processed inside its own logical boundary. Your data is never used to serve another client, never pooled into a cross-client model, and never sold. Detection thresholds calibrate to your own historical distribution — that is both the product design and a consequence of the isolation.

Encrypted in transit and at rest

TLS 1.2 or above in transit, AES-256 at rest. Credentials live in a managed secret store separate from business data, granted on least privilege, with access logged.

Zero retention with model providers

Language models are used for explanation and orchestration only. Our agreements with model providers specify zero retention and no training on your data. Numbers come from deterministic statistical computation, never from a model.

Deletion on request

On termination or on request, we delete or return your data within 30 days and confirm in writing. Backup copies age out on their retention cycle, no longer than 90 days.

1. What this policy covers

This policy explains how Panoverse Inc. ("we") collects, uses and protects information. It covers panoverse.com and its subpages, and the growth engine service we provide to clients.

We handle two kinds of data under different rules: business contact details you give us on this site, and the operational data a client authorises us to ingest during an engagement.

2. What we collect on this site

When you submit the demo form we collect the name, work email, company and phone number you enter, plus which page you came from (pricing, case study and so on). Every field is one you typed; we collect nothing covertly.

We do not use advertising cookies, we do not track you across other sites, and we do not feed your browsing to ad networks.

3. Client operational data

During an engagement, clients authorise ingestion of their commerce orders, ad spend, inventory, creator campaigns and public review data through read-only OAuth or platform exports. For that data the client is the controller and we are the processor, acting on their instructions.

We do not pull end consumers' names, addresses, payment details or identity records. Review text is labelled for theme and sentiment for analysis, never to identify an individual.

4. How we use it

Form details are used only to arrange and follow up the demo you asked for. Client operational data is used only to deliver the service to that client: detecting signals, building evidence chains, producing actions and measuring outcomes.

  • We do not train cross-client models on your data
  • We do not sell, rent or barter data
  • We never use one client's data to serve another
  • We do not name you as a public reference without written permission

5. Who we share with

Only with subprocessors necessary to deliver the service: cloud infrastructure and database providers, model providers (contracted for zero retention and no training), and the email and scheduling tools bound by confidentiality agreements with us. The subprocessor list is available from privacy@panoverse.com.

If legal process compels disclosure, we will notify the affected client first wherever the law allows.

6. How long we keep it

Demo form details are kept until 24 months after the business relationship ends, unless you ask for deletion sooner. Client operational data is retained for the engagement and deleted or returned within 30 days of termination or request; backups age out within 90 days.

7. How we protect it

TLS 1.2 or above in transit, AES-256 at rest, credentials in a managed secret store separate from business data, access on least privilege with audit logging. The full posture is set out in the Security and compliance section below.

No system can promise absolute security. If an incident affects your data we will notify you within the timeframe applicable law requires, stating what we know, what was affected and what we have done.

8. Your rights

Wherever you are, you can ask to access, correct, export or delete the information we hold about you, and ask us to stop contacting you for business purposes. Email privacy@panoverse.com and we will respond within 30 days.

If you are in the EEA or the UK, the GDPR gives you those rights plus the rights to object, to restrict processing and to lodge a complaint with a supervisory authority. Our lawful basis for processing your business contact details is legitimate interest — corresponding with you about the service you asked about.

If you are a California resident, the CCPA/CPRA gives you rights to know, delete, correct and opt out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioural advertising. Exercising these rights will not get you treated differently.

9. International transfers

We operate from the United States, and data may be processed there and in our subprocessors' regions. Transfers involving the EEA, the UK or Switzerland rely on Standard Contractual Clauses.

10. Minors

The service is for businesses, not for individuals under 16, and we do not knowingly collect information from minors.

11. Changes and contact

When this policy changes we update the effective date at the top, and we email clients of record about material changes. Questions to privacy@panoverse.com; security matters to security@panoverse.com.

Contact

Legal and terms: legal@panoverse.com
Privacy and data rights: privacy@panoverse.com
Security review and documentation: security@panoverse.com