Effective date: August 23, 2026 · Version: 1.0
This Privacy Policy explains how Crescendo Labs AI, Inc. ("CrescendoLabs," "we," "us") handles Personal Information in connection with the Services. It applies to our websites, applications, and the Platform. It does not apply to third-party services you connect (which are governed by their own policies, and which may change or discontinue their data access at any time — see Terms §9). Capitalized terms not defined here have the meanings given in our Terms of Service.
Our two roles — this distinction is important:
(a) Information you provide — account registration (name, business name, email), billing details (processed by our payment processor), support communications, and the Customer Data and content you submit.
(b) Information from sources you connect — when you authorize an integration (e.g., QuickBooks, Stripe, or a financial-account connection), we receive data from it at your direction. For financial-account connections, you authenticate directly with your bank inside the provider's own flow (e.g., Plaid Link), and we never receive your online-banking login credentials — we receive an access token, your account balances and transactions, and account type, and at most a masked account number, never your full account or routing number.
(c) Information collected automatically — usage, log, and device information, and cookies/similar technologies (§7).
Sensitive Personal Information. Depending on the features you use, we may process a limited amount of information treated as "sensitive" under some US state laws — for example, work-authorization status and voluntary equal-employment-opportunity (EEO) / demographic information you record about your workforce (kept segregated, access-logged, and never used to make decisions about anyone). We do not collect Social Security or other government ID numbers, full financial-account or routing numbers, or your bank login credentials. We use any such information only to provide the Services and as permitted by law.
We use Personal Information to: (a) provide, operate, secure, and support the Services; (b) analyze your own Business Records to generate Insights and Recommendations for you (§4); (c) produce aggregated, de-identified benchmarks and industry insights (§4); (d) process billing and manage your account; (e) prevent fraud and secure the Services; (f) improve and develop the Services; (g) communicate with you; and (h) comply with law. We do not sell your Personal Information (§6).
Today: analysis. The Services create value by analyzing your own Business Records to generate Insights and Recommendations for you (Terms §11(a)). The Services do not train AI Models on your data as part of providing the Services today.
Recommendations are information, not advice. Insights and Recommendations are best-effort, automatically generated options with confidence levels — not guarantees, and not professional advice (Terms §11(b)). You make all decisions.
Benchmarks are aggregated and de-identified. We may produce aggregated, de-identified benchmarks and industry insights — "businesses in your cohort that did X experienced Y" — using De-Identified Data only, with safeguards (including minimum cohort sizes) so no individual customer is identifiable, and we do not attempt to re-identify it. This is not AI-Model training.
Human involvement. We do not use automated processing alone to make decisions producing legal or similarly significant effects about you without a lawful basis and, where required, a right to human review. If you use Insights or Recommendations to make such decisions about other individuals (for example, your employees), you are responsible for your own compliance with automated-decision-making laws (Terms §11(b)).
We share Personal Information with: (a) service providers / sub-processors who help operate the Services — including cloud and AI providers (e.g., Google Cloud, including Vertex AI), payment processing (our payment processor also acts as an independent controller of the payment information it processes for its own fraud-prevention and regulatory obligations, under its own privacy policy), hosting, support, and website analytics (e.g., Google Analytics, used as our service provider to measure site traffic) — with whom we share only the information they need to perform their function for us, and whom we contractually require not to use your Customer Data to train their own models; (b) parties you direct (e.g., integrations you enable); (c) legal/safety recipients where required by law or to protect rights and safety; and (d) a successor in a merger, acquisition, or financing. Our current sub-processors are listed at https://crescendolabs.ai/legal/subprocessors.
We do not "sell" your Personal Information for money, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under California and other US state laws. Our aggregated, de-identified benchmarks (§4) use data that is no longer Personal Information, so they are not a sale or share. We honor browser Global Privacy Control (GPC) signals, and you may exercise a "Do Not Sell or Share My Personal Information" choice at any time by emailing privacy@crescendolabs.ai.
We use cookies and similar technologies for authentication, preferences, security, and analytics (e.g., Google Analytics for website-traffic measurement). Where we use third-party analytics, we configure the provider as our service provider, with advertising data-sharing features disabled; we do not use analytics data for cross-context behavioral advertising. You can manage cookies through your browser settings.
Retention. We retain Personal Information for as long as needed to provide the Services and for legitimate, disclosed purposes — including to comply with law, meet tax and recordkeeping obligations, support the financial books-and-records and retention requirements that may apply to you (such as securities, investment-adviser, or state insurance recordkeeping rules), resolve disputes, and prevent fraud.
Deletion and the structural / identity split. When you request deletion or close your account, we delete or de-identify your Customer Data, and we delete the associated Personal Information held in our separate identity records — except records we are required or permitted to retain (above). The de-identified structural record may be preserved so your books remain complete.
De-Identified Data. We may retain and use De-Identified Data indefinitely (including for benchmarks and product improvement); it is no longer Personal Information, and we will not attempt to re-identify it.
The Services are offered in and operated from the United States, and we process Personal Information in the US. We do not currently offer the Services outside the US.
We maintain reasonable technical and organizational measures designed to protect Personal Information. If we become aware of a security breach affecting your data, we will notify you without undue delay — and, for a confirmed breach affecting your Customer Data, in any event within 48 hours after we confirm the breach (a breach originating on a sub-processor's systems is confirmed when we receive the sub-processor's notice), as committed in our Terms of Service (§14) and Data Processing Addendum (§8). We will notify affected individuals directly, within the time required by law, where we are the controller of the affected data or are otherwise required by law. No system is 100% secure, and we cannot guarantee absolute security.
Depending on where you live, you may have rights to: access/know, correct, delete, obtain a portable copy, opt out of "sale"/"sharing" and targeted advertising, limit the use of Sensitive Personal Information, opt out of certain profiling, withdraw consent, and not be discriminated against for exercising these rights, plus a right to appeal a denied request.
How to exercise. Submit a request by email at privacy@crescendolabs.ai. We will verify your request and respond within the time required by law. You may use an authorized agent. For information you provided that belongs to another business's account (data we process as a service provider — §1), please contact that business, and we will assist them as their processor.
California (CCPA/CPRA). In the past 12 months we have collected the categories in the table below for the purposes in §3, disclosed them to the recipients in §5, and have not sold or shared Personal Information (§6). California residents have the rights in §11, including Shine the Light and GPC honoring.
Collected as a business/controller — your account, billing, and usage data. Cross-refs use the §2 source labels (a) you provide / (b) connected / (c) automatic, the §3 purpose labels (a)–(h), and the §5 recipient labels (a) service providers / (b) parties you direct / (c) legal-safety / (d) successor.
| CCPA category | Collected? | Source (§2) | Purpose (§3) | Disclosed to (§5) | Sold / Shared? |
|---|---|---|---|---|---|
| A. Identifiers (name, business name, email, account ID, IP) | Yes | (a), (c) | (a), (d)–(h) | (a), (c), (d) | No |
| B. Customer records (§1798.80(e)) — contact + billing details | Yes | (a) | (a), (d), (h) | (a) incl. payment processor; (c); (d) | No |
| D. Commercial information — subscription, billing, usage history | Yes | (a), (c) | (a), (d), (f), (g) | (a), (d) | No |
| F. Internet/network activity — usage, log, site-analytics data | Yes | (c) | (a), (e), (f) | (a) incl. analytics provider | No |
| G. Geolocation — approximate, derived from IP | Yes (approx.) | (c) | (a), (e) | (a) | No |
| I. Professional/employment info — your role/title in account + support context | Yes (limited) | (a) | (a), (g) | (a) | No |
| K. Inferences — Insights about your business operations (not consumer profiles) | Limited | derived from (a) | (b) | used to serve you | No |
| C (protected class), E (biometric), H (audio/visual), J (education), L (Sensitive PI) | No (as account holder) | — | — | — | No |
Business data you upload or connect (our service-provider role). Separately, and as your service provider under §1, we process information you provide about your customers, vendors, and employees — including identifiers, financial and commercial records (invoices, bills, bank transactions — masked account numbers only), professional/employment information, and, where you choose to record it, protected-classification / Sensitive PI (voluntary EEO data). You are the controller of that data; we process it on your instructions and do not sell or share it. Requests about it are routed to you (§11).
Other US State Residents (e.g., Virginia, Colorado, Connecticut, Utah, Texas, and others). Residents of states with comprehensive privacy laws have the rights described in §11, exercisable as described there, including the right to appeal.
The Services are for businesses and are not directed to children. Consistent with our eligibility requirement (Terms §4), the Services are intended only for users 18 and older, and we do not knowingly collect Personal Information from anyone under 18. If we learn we have collected it from someone under 18, we will delete it.
We may update this Policy. We will post the updated version with a new "Effective date" and, for material changes, provide additional notice as required by law. Your continued use after the effective date constitutes acceptance of the updated Policy.
Crescendo Labs AI, Inc. — 1500 N Grant St, Ste N, Denver, CO 80203, USA — Privacy: privacy@crescendolabs.ai.