←Home

Privacy Policy

How Datapoint collects, uses, shares, and protects personal information.

May 20, 2026

Effective May 20, 2026

This Privacy Policy explains how Impel Intelligence, Inc. (“Datapoint,” “we,” “us”) collects, uses, shares, and protects personal information when you visit trydatapoint.com, use our customer dashboard and APIs, or encounter Datapoint-powered research questions inside a partner mobile application that has integrated our SDK.

This Policy applies to three groups of people:

  • Customers — individuals who use the Datapoint dashboard, APIs, or website to commission research.
  • Respondents — end users of partner mobile applications who answer Datapoint-powered questions.
  • Publishers — app developers and other partners who integrate our SDK to display questions in their products.

1. Information We Collect

1.1 From Customers

  • Account information: name, email address, password, employer, role, billing address, and similar details you provide when signing up or upgrading.
  • Customer inputs: research questions, prompts, target audience descriptions, screening criteria, brand assets, and any other content you submit to the Service.
  • Payment information: processed by our payment providers; we receive limited transaction metadata (not full card numbers).
  • Communications: messages you send to our team, support tickets, survey responses about our product.
  • Usage data: pages viewed, features used, queries run, IP address, device and browser information, timestamps, and similar telemetry.

1.2 From Respondents (via Partner Apps and the SDK)

When you encounter a research question through a partner application that has integrated our SDK, we may collect:

  • Your response content (e.g., selected option, free-text answer).
  • Technical identifiers provided by the operating system or app, such as a mobile advertising identifier (where available and permitted), a per-app or per-session pseudonymous ID, device model, operating system version, and app identifier.
  • Approximate (coarse) location derived from IP address.
  • Contextual signals about when and where in the app the question was shown, including timestamps and ad-slot placement.
  • Information the publisher chooses to pass to us about its audience composition (e.g., age band, gender, language preference), where the publisher has the legal basis to share that information.

We do not ask respondents for their name, email address, phone number, precise GPS location, or government identifiers. We do not knowingly collect responses from children under 13 (or the applicable minimum age in the user’s jurisdiction).

1.3 From Publishers

  • Account, billing, and contact information.
  • Information about the apps you integrate, including app store identifiers, platform, audience descriptions, and traffic sources.
  • SDK telemetry: error logs, fill rates, latency metrics, response volumes, and revenue events.

1.4 From Third Parties

  • Analytics providers, advertising attribution providers, and fraud-detection providers.
  • Identity and authentication providers (e.g., single sign-on).
  • Publicly available sources, including company websites and public profiles, used for sales outreach and lead enrichment.

2. How and Why We Use Information

We use information for the purposes described below. The table summarizes the most common processing activities, and identifies the legal basis we rely on for individuals protected by the EU/UK GDPR.

Purpose Categories of Data Used Legal Basis (GDPR/UK GDPR) / Authority
Delivering questions to respondents and collecting responses through partner apps and other surfaces Device and app context; coarse location; response content; technical identifiers Performance of a contract with the publisher; legitimate interests in operating the research network; consent where required
Generating reports for customers Aggregated/de-identified response data; customer inputs Performance of contract with customer; legitimate interests
Detecting fraud, bots, and low-quality responses Technical identifiers; behavioral signals; response patterns Legitimate interests in research integrity; legal obligations
Training, evaluating, and improving AI and analytics models De-identified and aggregated response data; customer inputs (in accordance with customer agreements) Legitimate interests in product improvement; consent where required
Account management, billing, and customer support Account, contact, and payment information; communications Performance of contract; legitimate interests; legal obligations
Marketing and product communications Contact information; product usage signals Consent; legitimate interests (with opt-out)
Compliance, security, and legal claims Logs; identifiers; relevant content Legal obligations; legitimate interests; vital interests

3. AI and Model Training

Datapoint Reports are generated by AI systems that synthesize human responses. We use de-identified and aggregated response data to evaluate, fine-tune, and improve the AI models and analytic pipelines that power the Service. We do not train AI models using customer-identifying information for the benefit of other customers. Where required by applicable law, we obtain consent before using personal data to train AI models, and we honor opt-out requests as described in Section 8.

4. Cookies and Similar Technologies

Our website and dashboard use cookies and similar technologies (such as local storage and pixels) to authenticate users, remember preferences, measure performance, and support marketing. You can manage cookies through your browser settings and, where applicable, through the cookie preference center available at trydatapoint.com.

Inside partner mobile applications, we rely on the device identifiers and signals the operating system makes available; respondents can manage these through their device privacy settings (e.g., Apple’s App Tracking Transparency, Google’s Advertising ID controls).

5. How We Share Information

We share information only as described below.

  • With customers: Aggregated and de-identified research results in the form of Reports. We do not share raw, respondent-identifying data with customers.
  • With publishers: Aggregated information about questions served, response volumes, and revenue events relating to their integration.
  • With service providers: Cloud hosting, AI model providers, analytics, error monitoring, customer support, payment processing, fraud prevention, and communications providers, in each case acting as our processors/service providers under appropriate contractual protections.
  • Corporate transactions: In connection with a merger, acquisition, financing, or sale of assets, information may be transferred to the relevant counterparties and their advisors, subject to confidentiality and continued protection under this Policy.
  • Legal and safety: Where we reasonably believe disclosure is required by law, legal process, or government request, or where necessary to protect the rights, property, or safety of Datapoint, our users, or others.
  • With your consent: In any other case, with your direction or consent.

We do not sell respondent personal information for money. Certain disclosures — for example, sharing aggregated insights with customers for cross-context use — may be considered “sharing” or “selling” under some U.S. state privacy laws. You can exercise your opt-out rights as described in Section 8.

6. International Data Transfers

We are based in North America and use service providers in the United States, Canada, the European Economic Area, and other regions. When personal information is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) and implement supplementary measures as appropriate.

7. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, including to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically:

  • Customer account data: for the duration of the account, plus a reasonable period afterward for legal and accounting purposes.
  • Respondent responses and technical identifiers: typically retained in identifiable form for a limited period for quality control and fraud detection, and then aggregated or de-identified for ongoing analytical use.
  • Billing records: for the period required by applicable tax and accounting law.

When personal data is no longer required, we delete it or irreversibly de-identify it.

8. Your Rights and Choices

Depending on where you live, you may have some or all of the following rights:

  • Access: request a copy of the personal information we hold about you.
  • Correction: ask us to correct inaccurate or incomplete information.
  • Deletion: ask us to delete personal information, subject to certain exceptions.
  • Portability: receive your personal information in a structured, commonly used format.
  • Objection and restriction: object to, or ask us to restrict, certain processing, including processing based on legitimate interests.
  • Withdraw consent: where processing is based on consent, withdraw consent at any time without affecting prior processing.
  • Opt out of sale/sharing and targeted advertising: where applicable under U.S. state privacy laws.
  • Opt out of AI training use of your data: where applicable; see below.
  • Non-discrimination: we will not discriminate against you for exercising these rights.
  • Lodge a complaint with a supervisory authority: in the EEA/UK, with your local data protection authority; in Canada, with the Office of the Privacy Commissioner of Canada or your provincial regulator (e.g., the Commission d’accès à l’information in Quebec).

To exercise these rights, contact sales@trydatapoint.com. We may need to verify your identity before fulfilling the request. You may also use an authorized agent where permitted by law.

8.1 Respondent Controls

If you are a respondent and want to limit or delete the data we have collected about your interactions with our research questions, please contact us at the email above and, where possible, share the mobile advertising identifier or app context so we can locate your information. You can also reset or limit advertising identifiers through your device settings.

9. Security

We use administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, and destruction. These include encryption in transit, access controls, logging, and vendor security reviews. No system is completely secure, and we cannot guarantee the security of information transmitted to or from the Service.

10. Children

The Service is not directed to children under 13 (or the applicable minimum age in the user’s jurisdiction). We do not knowingly target research questions to children, and publishers are contractually required not to enable our SDK in child-directed contexts. If you believe a child has provided personal information to us, please contact us and we will take appropriate steps to delete it.

11. U.S. State Privacy Disclosures

This section provides additional disclosures for residents of U.S. states with comprehensive privacy laws, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others.

  • Categories of personal information we collect: identifiers, internet or other electronic network activity information, geolocation information (coarse), commercial information, professional information, and inferences. For respondents, we generally collect pseudonymous identifiers and response content.
  • Sources, purposes, and disclosures: as described in Sections 1, 2, and 5.
  • Sensitive personal information: we do not intentionally collect sensitive personal information from respondents. If a customer chooses to ask questions that could elicit such information, that customer is responsible for ensuring appropriate legal basis and disclosures.
  • Right to opt out: California, Colorado, Connecticut, and other state residents may opt out of sale, sharing, and targeted advertising at trydatapoint.com/privacy/opt-out or by emailing sales@trydatapoint.com. We honor recognized opt-out signals (e.g., Global Privacy Control) where required.
  • Right to limit use of sensitive personal information: where applicable.
  • Authorized agents and appeals: we accept requests from authorized agents and provide an appeals process for denied requests, as required by applicable state law.

12. Canadian Privacy Disclosures

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector (Law 25), and other applicable provincial privacy laws. Quebec residents have additional rights, including the right to data portability and the right to be informed about decisions based on automated processing of their personal information. To exercise these rights or to contact our privacy officer, please use the contact details below.

13. EEA/UK Disclosures

Impel Intelligence, Inc. is the controller of personal data described in this Policy, except where we act as a processor for customers (for example, in respect of certain customer inputs). Our representative and data protection contact can be reached at sales@trydatapoint.com. We process personal data on the legal bases described in the table in Section 2.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by email. The “Effective” date at the top of this Policy indicates when it was last updated.

15. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Impel Intelligence, Inc.

548 Market Street, San Francisco, California 94104

Email: sales@trydatapoint.com

Website: trydatapoint.com