Legal
Privacy Policy
Last updated September 28, 2026
This Privacy Policy explains how YG3 (“we,” “us”) collects, uses, and shares Personal Data in connection with yg3.ai, partner portals, and related marketing sites, and how we handle Customer Data in the product.
In short: we use Personal Data to run accounts and the platform. Default Customer Data is stored on US-hosted cloud infrastructure. Private storage (including HIPAA-, SOC 2–, and government-oriented options that still work with YG3) is available on request from our Tampa, Florida facilities. We do not sell Personal Data.
1. Scope
Website and account Personal Data. This Policy applies when YG3 acts as a controller (or “business”) with respect to Personal Data — for example, when you visit our websites, create an account, or communicate with us.
Customer Data. When you use the Services as a Customer, electronic data and information you or your Users submit to the online Services (“Customer Data”) is processed by YG3 to provide those Services. For that Customer Data, the Customer generally determines the purposes and means of processing; YG3 processes it on the Customer’s behalf under our Terms of use and any applicable data processing terms. This Policy does not replace the Customer’s own privacy notices to its end users.
Third-party applications, sites, or AI tools you connect to the Services are governed by those providers’ terms and privacy policies, not this Policy.
2. Personal Data we collect
2.1 Information you provide
- Account and contact data — name, email, company details, billing contacts, and similar information you submit when you register or communicate with us.
- Customer Data — content and records you or your Users submit to the Services (for example profiles, copy, sites, campaigns, leads, and connected-channel data), which we process to provide the Services.
- Support communications — messages you send to our support or security contacts or through in-product support.
2.2 Information collected automatically
- Device and usage data — log data, IP address (or proxy), approximate location derived from IP, browser and device type, pages viewed, and similar diagnostic information when you use our websites or Services.
- Cookies and similar technologies — strictly necessary cookies for authentication and security; optional analytics or preference cookies on marketing pages where used.
- Customer-configured tracking — when a Customer installs our pixel or similar tags, we receive event data for that Customer’s account as directed by the Customer.
2.3 Information from other sources
- Identity providers — if you sign in through a third-party identity service, we receive the profile fields that service shares with us (typically name and email).
- Third-party applications you connect — when you authorize an integration, that application may send data into your workspace under your direction.
- Payment information — payment card details are handled by our contracted payment processor; we do not store full card numbers.
3. How we use Personal Data
- Provide, secure, maintain, and improve the Services
- Authenticate Users and prevent fraud or abuse
- Process subscriptions and send transactional communications
- Provide customer support and respond to security reports
- Comply with law and enforce our agreements
- With appropriate notice or consent, send optional product or marketing communications
We do not sell Personal Data. We do not use Customer Data to train shared foundation models for other customers. See our Security page for related controls.
4. Legal bases (EEA/UK)
Where the GDPR (or UK GDPR) applies, we rely on the following bases as applicable:
| Processing activity | Legal basis |
|---|---|
| Account creation and service delivery | Performance of contract |
| Payment processing | Performance of contract |
| Security, abuse prevention, product improvement | Legitimate interests (secure, reliable Services) |
| Transactional account communications | Performance of contract |
| Optional marketing communications | Consent (where required) or legitimate interests with opt-out |
| Legal compliance | Legal obligation |
5. Where Customer Data is stored
5.1 Standard cloud Services
By default, Customer accounts and Customer Data are hosted on United States cloud infrastructure operated by our contracted service providers, together with other systems needed to deliver the Services. Administrative, technical, and physical safeguards are described at /company/security.
5.2 Private and compliance storage (on request)
Customers who need stronger residency or compliance controls may contact us to arrange private storage options that still work with YG3, including local / on-premises deployments and configurations designed for HIPAA, SOC 2, and government compliance requirements. Those arrangements are hosted from our facilities in Tampa, Florida, where that Customer’s data is stored under the agreed deployment. Scope, controls, and any Business Associate Agreement or other compliance paperwork are set out in a separate written arrangement — contact hello@yg3.ai or security@yg3.ai.
6. How we share Personal Data
We may share Personal Data with:
- Contracted service providers — providers who perform services for us such as IT and system administration and hosting, payment processing, email delivery, analytics, customer support, and similar functions, under contracts that limit their use of Personal Data to providing those services to us. Private Tampa deployments may use a reduced or customer-specific provider set as agreed in writing.
- Third-party applications you connect — when you enable an integration or AI assistant, you direct us to share relevant data with that provider as needed for interoperation.
- Professional advisers — lawyers, auditors, insurers, and similar advisers as needed, subject to confidentiality obligations.
- Authorities — when required by law or to protect rights, safety, or the security of the Services.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, with notice where required by law.
7. Cookies and similar technologies
We use strictly necessary cookies for authentication and security. Marketing pages may use analytics or preference cookies. Where required, we obtain consent for non-essential cookies. You can control cookies through your browser settings; disabling necessary cookies may prevent login.
8. Retention
We retain account and Customer Data for as long as the account is active. After deletion or cancellation, we generally remove or anonymize Personal Data within 90 days, except where longer retention is required for backups, disputes, security logs (typically up to 12 months), or legal obligations. Private-storage customers follow the retention schedule in their written agreement.
9. Security
We maintain administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data and Personal Data, as described at /company/security. No method of transmission or storage is perfectly secure. If we become aware of a breach affecting your Personal Data, we will notify you and regulators as required by applicable law. Private-storage customers receive the control set defined in their written deployment agreement.
10. International transfers
Standard cloud Services are hosted in the United States. Private deployments store Customer Data at our Tampa, Florida facilities (or as otherwise agreed in writing). If you access the Services from the EEA, UK, or elsewhere, Personal Data may be processed in the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or a successor transfer mechanism with our processors.
11. Your rights
EEA/UK: you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may lodge a complaint with your local supervisory authority.
California: you may have rights to know, delete, correct, and opt out of sale or sharing of Personal Data. We do not sell Personal Data and do not share it for cross-context behavioral advertising as those terms are commonly defined under California law. We will not discriminate against you for exercising your rights.
To exercise rights regarding Personal Data we control, email hello@yg3.ai or privacy@yg3.ai. We aim to respond within 30 days (or sooner if required by law). We may need to verify your identity. For Customer Data held in a Customer’s workspace, contact that Customer; we will assist the Customer as required by applicable law and our agreements.
12. Your choices
- Update account profile details in the product
- Disconnect third-party applications at any time
- Cancel paid plans per the Terms
- Request private / compliance storage via hello@yg3.ai or security@yg3.ai
- Opt out of optional marketing email via the unsubscribe link
13. Children
The Services are not directed to children under 16, and we do not knowingly collect their Personal Data. If you believe we have collected such data, contact us and we will delete it.
14. Changes
We may update this Policy by posting a new version at /legal/privacy and updating the date above. Material changes will be noticed by email or in-product where appropriate.
15. Contact
Privacy: hello@yg3.ai / privacy@yg3.ai
Security / private storage: security@yg3.ai
Private storage facilities: Tampa, Florida, USA