Privacy Policy
Last updated August 17, 2026
This policy is written from what the product actually does, not from a template. The most important facts: your working records are private, your public face is a single profile card you control, contact sharing works differently depending on who is reaching out to whom, your data is never used to train AI models, and both your data export and your account deletion are buttons in the product rather than support tickets.
The short version
- Your working records are private. Markets, products, documents, deals and notes are visible to you alone, and most record types cannot be published at all. The server refuses to publish them whatever an app asks for. The one exception is a project you choose to share for support: relevant organizations then see its title, summary and stage, never its tasks, documents or details, and you can withdraw it any time.
- Sharing runs in two directions, and they work differently. When you reach out to a provider or an advisory firm, your contact details travel with your request, and the screen you send from lists exactly what is about to be shared. When somebody else wants to reach you, they have to ask, and nothing of yours is revealed until you accept.
- Two things are visible by default, both of them the reason people join: your company profile is discoverable by the support organizations on the platform, and a service provider who registers a listing is listed publicly. Each is one switch away from private, in your profile.
- There are no passwords. You sign in with a single-use email link, so there is no password for us to store or lose.
- We never see your card number. Apple handles in-app subscriptions, and Stripe handles card payments on the web, where we are the seller of record.
- Your data is not used to train AI models, ours or anyone else’s. We do not train on it, and we do not authorize our providers to.
- We do not sell personal data. This website runs no cookies and no advertising trackers, and the signed-in product contains no third-party analytics or advertising SDKs.
- Downloading your data and deleting your account are buttons in the product, not support tickets.
Who we are
The Promote:Global platform (the mobile apps, the web console at app.promoteglobal.org, and this website) is operated by PromoteGlobal, LLC, a Florida limited liability company registered at 7901 4th St N, STE 300, St. Petersburg, FL 33702, United States. For the personal data described in this policy, we are the controller. You can reach us about anything on this page at hello@promoteglobal.org, and we answer privacy requests within 30 days.
We are a small company. That is relevant to one thing on this page: we have not appointed a data protection officer, because the law does not require one of a business of our size doing the kind of processing described here. Privacy questions come to the address above and a human reads them.
One exception to our being the controller: when your account belongs to a company workspace, records tagged to that company belong to the company, which is the controller for them. We process those on the company’s behalf, and we will sign a data processing agreement with any company that asks for one.
What we hold
Most of this comes directly from you. Sometimes an organization provides it on your behalf: a facilitator such as your trade agency may create your seat and enter your name and email address to invite you. Either way, the same policy applies from the moment the account exists.
- Account: your email address and an optional display name. That is the whole identity. No password, no phone number. Sign-in links are single-use and stored only as a hash.
- Your vault: the business records you create, such as markets, projects, tasks, products, documents, deals, compliance notes and your company profile. They are stored on our servers so they can sync across your devices. Working records are private; the profile is discoverable by default and yours to unlist, and a project is only ever visible to others if you share it for support, and then as its title, summary and stage alone.
- Assistant conversations: what you asked our AI assistant and what it answered, kept so your conversations have continuity across your devices.
- Consent receipts: every consent question you answer is recorded with your answer, the timestamp, and the version of the wording you were shown. The record is append-only, so changing your mind writes a new receipt rather than editing history.
- Files you upload: logos, evidence files, message attachments and knowledge documents, together with a ledger of who owns each file and what it is attached to.
- Messages: what you send to counterparts and to support, and when each side last read a conversation.
- What you shared, and with whom: when you send a request to a provider or an advisory firm, we store the list of fields you were shown and the values actually delivered, frozen at the moment you sent it.
- Device push tokens: if you enable notifications, the device token and platform (iOS or Android), and nothing else about the device.
- Usage metering: a monthly count of AI actions per account to enforce your plan’s allowance (your remaining allowance is always visible in your profile), a log of AI calls (feature, model, token counts), and a ledger of what each action cost your allowance.
- Billing status: your plan, its status, and where it was bought. For App Store subscriptions, the product identifier, status, expiry and Apple’s transaction identifier. For web subscriptions, your customer reference at Stripe. Never a card number.
- Partner applications: if you apply to partner with us through this website, the organization details, contact name, email, markets, services and summary you submit, our correspondence with you about it, and any internal note we write while reviewing it.
- Product-usage events: the app counts its way through onboarding, so we can see where people get stuck. It is a fixed list of about twenty named steps, such as choosing a market or creating a first project, each recorded with the app version and your language setting. While you are signed in, an event carries your account id. Before an account exists it carries only an anonymous per-install id. Never anything you typed, and never sent to anyone but us.
- Sign-in throttling: every request for a sign-in link is counted against your email address and against the network address it came from, both stored only as one-way hashes, beside a count and the ten-minute window it belongs to. It is what stops a stranger flooding your inbox with links, and the rows are swept within a day.
- What we do not hold: no readable IP address anywhere in our database. The addresses behind the throttle above are one-way hashes and cannot be turned back into an address. Any IP-level record of your visit is a short-lived technical log kept by our hosting provider, on their schedule, not a row in our tables.
How sharing actually works
This is the part of the product we most want you to understand, because it is the part built most deliberately. Every record carries a visibility level, and every working record defaults to private: visible to you, and to your team in a company workspace, and to nobody else.
A company account can publish exactly two things beyond its vault: its company profile, and a project summary (title, summary, stage) if you turn on that project’s Discoverable switch, with contact details stripped before anyone sees it. Products, deals, documents, tasks and everything else in a company vault cannot be published to the platform at all. The server refuses the write regardless of what any app asks for.
Two defaults are ON, and we would rather you read it here than discover it later. Your company profile is discoverable by the support organizations on the platform, because being findable by them is the reason most members join. And if you register as a service provider, your listing is public by default, because a directory nobody can see is not a directory. Both are single switches you can turn off at any time, and turning discoverability off puts your profile back in your private vault where nothing can find it.
Everything else is off until you turn it on: letting organizations ask to be introduced, letting them ask to collaborate on a project, and including your performance metrics in what you share. When you answer any of these, either way, we write a receipt with the wording you saw. Where a withdrawal exists it is enforced at the point the data is read, and the newest answer always wins; if a grant and a withdrawal ever carry the same timestamp, the withdrawal wins.
When you contact someone, and when they contact you
These are two different mechanisms and it matters which one you are in.
You reaching out. When you send a request to a service provider or an advisory firm, your contact details travel with the request. The screen you send from lists what is about to be shared, in the same words every time: your company name, your contact details, what you asked for, and the project or product you attached. We freeze both halves of that at the moment you send: the promise you were shown and the values delivered. Neither can widen afterwards. They can only narrow, and only when you withdraw. Asking a named firm to work with you is, in practice, telling that firm how to reply to you, and the product now says so plainly rather than implying an acceptance step that does not exist on this path.
Someone reaching out to you. Discovery and matching show your published business profile and never your contact details. When an organization asks to be introduced to you, your details stay out of the data we serve until you accept. Acceptance is what reveals them, and that gate is enforced in the database query itself, not in the app. If you shared your company card with an organization and later withdraw it, the organization keeps the request it made and loses your contact details.
Cohorts. If you join a cohort, for example a trade agency’s export program, content shared at cohort level becomes visible to that organization, and you choose separately whether your contact details go with it.
Read receipts. In a conversation, the other side can see when you last read it, and you can see the same about them. There is no way to turn this off today. If we add one, this page will say so.
Advisory access. If you share a project with an advisory firm, you are granting access to the individual people at that firm you shared it with, and you can revoke it. Closing an engagement also revokes it, as long as no other engagement with that firm is still open, because cutting off a firm that is still doing other work for you would be the wrong kind of tidy. Work the firm itself contributed belongs to the firm.
Businesses who are not members
Counterpart discovery searches the open web to find real companies in a market, so some of the information it returns is about businesses that never signed up with us, and about the people who work there. This is the hardest privacy question in the product and we would rather set it out in full than bury it.
What happens: we turn your brief into search queries (market, product and category keywords, never your contact details), send them to a web search provider, and pass what comes back to our AI to summarize and rank. What comes back is business listing information of the kind you would see yourself on a search results page: company name, category, address, phone number and website, with a link to the source for each one. Every result is labeled unverified, and the model is instructed never to invent a contact and never to describe a lead as verified, vetted or screened. We found them on the open web, and the product says only what it found.
What we keep: your result set is cached against your account for twelve hours, so that asking the same question again is free and returns the same list rather than a different one. After that we stop using it, and your next search overwrites it. We do not build a marketing database out of these companies, we do not enrich them with anything, we do not sell them, and we do not contact them. Anything you deliberately save into your own vault is then yours, and this policy treats it like the rest of your vault.
If you are one of those businesses: write to hello@promoteglobal.org and we will remove what we hold about you and tell you what the source was, so you can go to the source too. You do not need an account with us to ask, and we will not ask you to make one.
AI processing
The AI assistant, matching, HS code suggestions and counterpart discovery all run through our servers. The apps hold no AI provider keys and never talk to a model provider directly. Every AI request goes to our API, which assembles what the model needs and makes the call.
Model inference and the embeddings behind search run on a European provider, named in the subprocessor list below, on European infrastructure. What reaches the model is the question you asked plus the member-visible business data our server assembles for that specific request. Your data is not used to train models. We do not train on it, and we do not authorize our providers to. Counterpart discovery additionally uses a web search provider, also listed below, as described in the section above.
Where your files sit: knowledge documents and other uploads are stored by our hosting provider’s file storage, in the tiers described under Files. An earlier version of this page said that knowledge files sat in European object storage. That was written against a configuration we had planned and not yet turned on, so we have corrected it rather than leave it standing.
Automated decisions
The platform suggests; people decide. Matching ranks potential counterparts, the assistant drafts answers, and HS code suggestions arrive marked unverified until you confirm them. No decision with legal or similarly significant effects on you is made solely by software: introductions happen because a person accepted them, and codes count because you confirmed them. If that ever changes for a future feature, we will say so at the point of use and give you a route to a human.
Aggregates and de-identified data
We build aggregate, de-identified insights from platform activity, such as corridor-level trade trends. Once data is genuinely de-identified it no longer describes you or your business. We do not sell personal data, and member-level data never becomes a product. If data can still identify you, it is personal data and everything on this page applies to it.
Files
Uploaded files live in one of two tiers, decided by what the file is when it is uploaded and never changeable afterwards by asking differently. The public tier holds only organization logos, images meant to render on directory pages to anyone. Everything else, including evidence files and message attachments, is private: the bytes are served through a single endpoint that checks on every request whether this specific caller may read this specific file, and private files are never cached in any shared cache.
Payments and billing
There are two ways to pay, and a different company handles the card in each.
In the apps, subscriptions are bought through Apple. Apple takes the payment, holds the payment instrument, and collects and remits the tax. We receive the product identifier, the subscription status, the expiry date and Apple’s transaction identifier, and we verify Apple’s billing notifications cryptographically before they touch any account.
On the web, subscriptions are bought through Stripe, and we are the seller of record: the sale is ours, and so is the tax obligation on it. Stripe hosts the payment page, so your card number is entered on Stripe’s systems and never reaches ours. Stripe receives what it needs to take the payment and meet its own obligations, which includes your email address and the billing and tax details you enter there. We store your plan, its status and your customer reference at Stripe, so that the Manage billing button can open your billing portal. We never store a card number.
Some accounts are sponsored by a facilitator such as a trade agency, and some are on the free tier. Neither involves a payment processor at all.
Email, notifications, and sign-in
We send email through Resend: sign-in links, partner application confirmations, and service notifications. We do not run marketing automation, and we do not sell or rent your address to anyone.
Push notifications go through Apple and Google. Some are silent, content-free ticks that only ask the app to refresh its data. This is built but not yet switched on, so today no push notification is sent by either service.
Signing in works by email link: you enter your address, we email you a single-use link, and clicking it signs you in. Access tokens are short-lived and refreshed automatically, and deleting your account revokes every session immediately.
How we protect it
Rather than gesture at appropriate technical and organizational measures, here are the ones you can see from how the product behaves. And because no system is invulnerable, the commitment that goes with them: if a breach affects your personal data we will notify you and the relevant authorities without undue delay, and within 72 hours where the law requires it. We have deliberately not promised a flat 72 hours to everyone regardless of jurisdiction, because we are a small team and we will not promise a detection speed we cannot guarantee.
- All traffic between your devices and our servers is encrypted in transit.
- Sign-in links are single-use and stored only as cryptographic hashes, and access tokens are short-lived.
- Private files are served through a single endpoint that authorizes every request, and those responses are never cached in any shared cache.
- Consent records are append-only, so history cannot be silently rewritten.
- Apple’s billing notifications are cryptographically verified against Apple’s pinned root certificate before they touch any account.
- Our application servers and our database both run in the European Union.
How long we keep things
Most data lives as long as your account does and goes when you delete it. Three windows are fixed numbers enforced by an automated weekly sweep, and we would rather publish the three we actually enforce than five we do not:
- Behavioral signal events, meaning the in-product activity used for corridor and matching aggregates: 24 months.
- AI call logs, meaning feature, model and token counts: 12 months.
- Files that nothing references any more: flagged after a week, and permanently deleted, bytes included, a month after that. A file that is still attached to something is kept for as long as the thing it is attached to.
- Messages, vault records and assistant conversations: for as long as your account exists.
- Everything else we keep to run, meter, secure and defend the platform, including our own administrative action logs and our record of what your AI usage cost, is kept for as long as that purpose lasts and no longer. Where an account has been deleted, those records are keyed to an identity that no longer names you.
- Partner applications, which come from people who are not members: we keep these while we consider them and for our record of the decision afterwards. Write to us and we will delete yours.
When we would disclose data
We do not read the messages you exchange with counterparts, and there is no automated scanning of them. If content is reported to us for abuse, we review what was reported.
Beyond the subprocessors listed below, we would disclose personal data only in three situations. Where the law compels it: we require valid legal process, we push back on requests that are broader than the law allows, and we will tell you unless we are legally barred from doing so. Where it is necessary to prevent a risk of death or serious physical injury. And as part of a reorganisation, financing or sale of the business, in which case this policy continues to apply to the data and we will tell you. We never share your data with anyone for their own marketing.
Your rights, and the buttons that exercise them
Access and portability. Download your data as a single file, self-serve, without contacting anyone. In the app it is Profile, then Your data; in the web console it is Settings, in the account section. The bundle covers what you own and what you wrote: your records, your listings, the messages you sent, your support requests, your consent receipts, your introduction and request history including the list of what each request disclosed, your notifications and devices, your usage meters and AI logs, and your account row including your customer reference at Stripe. It deliberately leaves out one thing, and names it: free text a facilitator wrote about you in confidence, which a human reviews and releases on request instead. It does not include your assistant conversation transcripts or the messages other people sent to you. If something you expected is missing, email us and we will get it for you.
Erasure. Delete account is in the app and in the web console, works without contacting anyone, and is immediate and irreversible. There is no grace period and no undo. It removes your personal vault records, your public listings, your provider listing, your organization and cohort memberships, your uploaded files including the stored bytes, and your notifications; it revokes every session; and it replaces your email address with a non-address so the account can never sign in again. Two things it does not reach automatically today: your assistant conversation history and your device push tokens. Email us and we will erase those too, and we are closing that gap in the product.
If you are the only administrator of an organization that still has other members, you will be asked to transfer it before deleting, so your colleagues are not stranded.
What deletion keeps, and why. Your consent receipts, because they are the proof of what you were asked and what you answered. The other side of two-party history, because an introduction or a message thread involves a counterpart who keeps their side. Billing records, because tax law requires them. And the operational and audit records described above. All of it is keyed to a scrubbed identity that no longer names you. Records belonging to a company workspace stay with the company.
How long the rest takes. Deletion in the live database is immediate. Copies that are not the live database, meaning our provider’s point-in-time backups and any derived copy, are gone within 30 days; those backups exist on a short rolling window and are overwritten in the ordinary course.
Consent history. The Your data screen reads back every consent you have given or withdrawn, with the version of the wording you saw at the time.
Rectification. Your vault is yours to edit, so correcting data is just using the product. For anything you cannot reach yourself, email us.
Objection and restriction. If you want us to stop or limit a particular use of your data while keeping your account, email us and we will act on it.
All of these, by email, get an answer within 30 days: hello@promoteglobal.org.
Complaints. You also have the right to complain to your data protection authority, which in the UK is the Information Commissioner’s Office and in the EU is your national authority. We would appreciate the chance to fix the problem first.
Lawful bases
We are a US company, but our members export across borders, so we hold ourselves to a GDPR-aware standard. We process your account and vault data to provide the service you signed up for, which is performance of a contract. We rely on your recorded consent for discoverability, introductions, collaboration and cohort visibility, which is what the consent receipts described above are for. We rely on our legitimate interest in running a safe, fairly metered platform for security logging, rate limiting, abuse prevention, usage metering and denied-party screening. And we rely on legal obligation for consent receipts and billing history.
Subprocessors
The complete list of companies that receive personal data on our behalf. We will update this list before a new one starts processing, and for material changes we will tell you in the product.
- Vercel: application hosting, file storage for uploads, and this website’s cookieless aggregate analytics. Our application servers run in Vercel’s Paris region.
- Neon: the Postgres database, in a European region, where accounts, vault records and consent receipts live.
- evroc: AI model inference and the embeddings behind search, on European infrastructure.
- Serper: web search retrieval for counterpart discovery. Receives derived market and product queries, never your contact details.
- Resend: transactional email delivery.
- Stripe: card payments and subscription billing on the web, where we are the seller of record.
- Apple: in-app subscription billing, and iOS push delivery when we switch it on.
- Google: Android push delivery through Firebase Cloud Messaging when we switch it on. The messaging library only, with no Google analytics.
- trade.gov (US Department of Commerce): denied-party and sanctions screening. When a name is screened, that name is sent to their Consolidated Screening List service. Nothing else about you goes with it.
- GLEIF: public legal-entity lookups used by our partner trust check. A company name or identifier goes out; the data coming back is public reference data.
- We also read public trade statistics from UN Comtrade, the World Bank WITS and the WTO, and public trade-measure sources. These are one-way reads of published statistics. No personal data of yours goes to them.
International transfers
We are a US company. Our application servers and our database run in the European Union, and so does AI inference. Several of the providers listed above are US companies, so personal data reaches the United States in the course of them providing their service to us.
Where personal data of members in the EEA, the UK or Switzerland is transferred internationally, we rely on the European Commission’s standard contractual clauses, together with the UK addendum where the transfer is from the United Kingdom, or on an approved transfer framework where the provider receiving the data is certified under one. We do not set out the mechanism provider by provider on this page, because it changes when a provider’s certification does; write to hello@promoteglobal.org and we will tell you which one applies to any provider in the list above.
We have not appointed an EU or UK representative. We are a US company with no European establishment, and we will appoint one when our European customer base makes it required of us. If you are in the EEA or the UK and you want to raise something, hello@promoteglobal.org reaches a person directly, and your right to complain to your own national authority is unaffected.
California
If you are a California resident, the rights above are your CCPA and CPRA rights by other names: to know, which is the export; to delete, which is Delete account; and to correct, which is editing in place. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no Do Not Sell link to offer. We do not discriminate against anyone for exercising their rights. Requests can also be made at hello@promoteglobal.org.
Children
Promote:Global is a business platform. It is not directed at anyone under 18, and we do not knowingly collect data from children.
This website
This marketing site sets no cookies and runs no advertising or cross-site trackers. We use cookieless, aggregate analytics from our hosting provider to see which pages are read; it sets nothing on your device, builds no personal profile, and cannot follow you across the web. The app is a different matter, and this page used to say the opposite: it counts its own onboarding steps, tied to your account once you have one, and Product-usage events above says exactly which ones and what rides with them. Those counts go to our own API and to no third party. The console’s public front door — the launching page and the sign-in page, before you are signed in — uses the same cookieless, aggregate page counting as this website, and nothing more. Inside the signed-in product there is no third-party analytics library, no advertising identifier, and nothing that follows you between apps or around the web. Hosting infrastructure keeps short-lived technical logs, including IP address and browser type, for security, as any website’s does; we do not copy those into our own database, and the only trace of your address in our own tables is the hashed sign-in counter described above.
Two things here do send us data. The partner application form submits what you enter to our API, where it is stored as an application with a private status link so we can review it and reply; the confirmation email comes from us via Resend. And if you email us, which is what most buttons here do by opening your own mail app, we receive your address and what you wrote, and use it to reply. Ask to be removed from anything at any time and we will do it.
Changes and contact
If this policy changes we will post the new version here with an updated date. For material changes we will tell you in the product before they take effect, and if a change expands what we share or how long we keep it, we will email you. Every earlier version of this page is kept and available on request. Questions, requests, complaints: hello@promoteglobal.org.