Privacy Policy

Last updated 2026-06-29

This Privacy Policy explains how IntentPath Oy ("IntentPath Oy", "IntentPath", "we", "us", or "our") handles personal data in connection with IntentPath AI (the "Service"). IntentPath is a SaaS product that our customers install on their own websites to detect buyer intent, find conversion leaks, run an AI buyer assistant, and deploy on-site conversion playbooks.

Who we are and our two roles

We handle personal data in two distinct capacities, and it is important to understand the difference:

  • Visitor data on customer websites — we are a processor. When a customer installs our script and IntentPath observes the behavior of that website's visitors, the customer (the website owner) is the data controller and IntentPath acts as their processor, handling that data only on their documented instructions. This processing is governed by our Data Processing Agreement.
  • Account data — we are the controller. For the information you give us to open and run an IntentPath account (your name, email, organization details, and billing), we are the data controller and this Policy describes how we use it.

Data we collect

Account data (we control). When you sign up and use IntentPath, we collect your name, email address, organization/workspace details, team members you invite, authentication data, and billing information (processed by Stripe — we do not store full card numbers). We also keep basic product and support logs needed to run and secure your account.

Visitor and analytics data (we process on the customer's behalf). IntentPath is built to understand visitor intent without identifying individuals. On a customer's website, the widget records:

  • A pseudonymous visitor ID — a random identifier stored in the visitor's browser localStorage that groups a visitor's activity. It is not linked by us to a real-world identity.
  • A session ID and technical context — page URL, path, and title, referrer, and UTM campaign parameters.
  • Behavioral events — page views, clicks (including CTA clicks, rage clicks, and dead clicks), scroll depth, exit intent, and form start/submit signals.

We apply the following safeguards to visitor data by design:

  • Raw IP addresses are never stored. An IP is converted to a salted SHA-256 hash used only for rate-limiting and security; the raw address is not retained.
  • No form field values. We detect that a form was started or submitted, but we do not capture what was typed. Passwords, payment fields, textareas, and message bodies are never captured.
  • Emails and phone numbers are masked from any incidentally captured text before it is stored.

How we use data

We use the data above to:

  • detect visitor intent and surface conversion leaks;
  • generate AI conversion audits and recommendations;
  • generate and deploy on-site conversion playbooks;
  • power the AI buyer assistant using approved knowledge only;
  • report assisted conversions and revenue impact;
  • provide, secure, bill for, and improve the Service.

AI processing. To generate audits, classify intent, create embeddings, and answer buyer questions, we send relevant prompts and approved site content to Google's Gemini API for inference. The AI buyer assistant answers only from knowledge the customer has approved. We do not use customer or visitor data to train third-party foundation models.

Legal bases (GDPR)

Where the GDPR or similar laws apply, we (and our customers, for visitor data) rely on the following legal bases:

  • Consent — for non-essential analytics and product tracking on customer websites, obtained by the customer through their consent configuration (see below).
  • Legitimate interests — for loading the essential widget, security, abuse prevention, and keeping the Service reliable, balanced against your rights.
  • Contract — to create and operate your account, provide the Service, and handle billing.

Consent and cookies

Each customer chooses a consent mode for their website that determines what runs before a visitor consents:

  • Strict (EU) — only an essential widget load occurs before consent; no analytics or product tracking runs until the visitor consents.
  • Balanced — a middle-ground configuration.
  • Basic — the least restrictive configuration.

The widget exposes window.IntentPath.consent({analytics, product}) so a website's own consent tooling can grant or revoke consent. We use essential cookies (for authentication/session and to remember a consent choice) and, where consent is given, analytics/product cookies. See our Cookie Policy for details.

Subprocessors

We use the following subprocessors to operate the Service. Each is bound by appropriate data protection terms. Some process data in the United States; where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses (SCCs).

NamePurposeRegion
SupabaseDatabase, authentication, storageEU
ResendTransactional email deliveryEU/US
StripeBilling and payment processingEU/US
Google (Gemini API)AI inference and embeddingsUS
VercelApplication hostingGlobal

International transfers

Our primary database, authentication, and storage are hosted in the EU. Some subprocessors (such as Google Gemini, and in some cases Stripe and Resend) process data in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, to protect it.

Data retention

We keep account data for as long as your account is active and as needed to comply with legal, tax, and accounting obligations. Tracking and analytics events are retained on a rolling window and are deleted when the associated website or account is deleted. On deletion, associated visitor data is removed or irreversibly anonymized.

Your rights

Subject to applicable law, you have the right to request access to, rectification of, erasure of, restriction of, or portability of your personal data, to object to certain processing, and to withdraw consent at any time (which does not affect processing already carried out).

Account holders can export their data and submit a deletion request directly in the app under Settings → Privacy. You can also contact us at privacy@yourdomain.com. For visitor data on a customer's website, the website owner is the controller — direct your request to them, and we will assist them in fulfilling it.

Security

We take reasonable technical and organizational measures to protect personal data, including:

  • row-level security (RLS) for strict tenant isolation between workspaces;
  • storing only a salted hash of IP addresses, never the raw address;
  • encrypting secrets and credentials at rest;
  • encryption in transit (TLS) across the Service.

To be transparent: IntentPath does not currently hold a SOC 2 or equivalent certification. We will update this Policy if that changes.

Children

The Service is a business tool and is not directed to children. It is not intended for anyone under the age of 16, and we do not knowingly collect personal data from children.

Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify account holders of material changes.

Contact

For privacy questions or to exercise your rights, contact us at privacy@yourdomain.com. For data protection matters you can reach our data protection contact at dpo@yourdomain.com. IntentPath Oy is located in Helsinki, Finland (VAT FI00000000).