Privacy Policy
Last updated: September 13, 2026
Effective date: May 18, 2026
1. Introduction and Scope
Claimory LLC, a California limited liability company ("Claimory," "we," "our," or "us"), is committed to protecting the privacy and security of your personal information. This Privacy Policy ("Policy") describes how we collect, use, store, share, disclose, and protect information in connection with the Claimory platform, including the website located at claimory.io, our web application, mobile applications (iOS and Android), application programming interfaces (APIs), and all related services, features, content, and functionality (collectively, the "Service").
This Policy applies to all users of the Service, including shop owners, administrators, team members (technicians, estimators), customers who access the customer portal, and visitors to our website. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree to this Policy, you must not access or use the Service.
This Policy should be read in conjunction with our Terms of Service, which govern your use of the Service. Capitalized terms used but not defined in this Policy have the meanings given to them in our Terms of Service.
Claimory LLC is located in California, United States. Our mailing address is in Section 21. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored in, and processed in the United States.
2. Information We Collect
We collect information in three categories: information you provide to us directly, information collected automatically, and information obtained from third-party sources.
2.1 Information You Provide Directly
When you register for an account, use the Service, contact us, or otherwise interact with us, you may provide:
- Account and Profile Information: Full name, email address, phone number, job title or role, profile picture, and login credentials
- Business Information: Shop name, business address, business phone number, tax identification number, business license information, team member names and roles, insurance carrier preferences, and DRP (Direct Repair Program) affiliations
- Claim and Job Data: Insurance claim details (claim numbers, dates of loss, policy information), customer names and contact information, vehicle information (VIN, make, model, year, license plate), repair estimates and supplement details, photos and documents (damage photos, repair documentation, authorization forms), adjuster contact information and notes, cash job details, invoices, and payment records
- Financial and Billing Information: Payment method details (processed and stored by Stripe - we do not store full card numbers), billing address, subscription plan selection, invoicing records, and transaction history
- Communications: Messages sent through the Service (SMS, email, in-app), customer portal communications, support tickets and correspondence with our team, feedback and feature requests
- Customer Portal Data: Information provided by your customers when they access the customer portal, including their name, email, phone number, and any communications submitted through the portal
- Documents and Media: Files, photographs, images, videos, PDFs, and other documents uploaded to the Service
2.2 Information Collected Automatically
When you access or use the Service, we automatically collect:
- Device Information: Hardware model, operating system and version, browser type and version, screen resolution, device identifiers, and device language settings
- Log and Usage Data: IP address, date and time of access, pages and features visited or used, click patterns, referring and exit URLs, search queries within the Service, session duration, and frequency of use
- Location Information: Approximate geographic location inferred from your IP address (we do not collect precise GPS location unless you explicitly enable it in the mobile application)
- Performance Data: Page load times, error logs, crash reports, and diagnostic information used to maintain and improve the Service
- Cookies and Similar Technologies: Information collected via cookies, web beacons, pixels, local storage, and similar technologies (see Section 9)
2.3 Information from Third-Party Sources
We may receive information about you from third-party sources, including:
- Payment Processor: Stripe may provide us with limited transaction information such as payment status, subscription status, and billing alerts (Stripe does not share your full payment card details with us)
- Authentication Providers: If you sign in using a third-party authentication method (e.g., Google), we may receive your name, email address, and profile picture from that provider
- Publicly Available Sources: Business registration data, publicly available business information, and information from public databases
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery and Operations
- Provide, operate, deliver, and maintain the Service
- Create, manage, and authenticate your account
- Process subscription payments and manage billing
- Enable claim tracking, management, and coordination features
- Facilitate communications between your shop, customers, carriers, and team members
- Deliver SMS and email communications on your behalf
- Provide customer portal access and functionality
- Enable data storage, file management, and document hosting
3.2 AI-Powered Features
- Generate AI-assisted email drafts, claim summaries, and next-step recommendations
- Provide AI-powered Claim Audit insights
- Portions of Your Data may be transmitted to and processed by Anthropic, our primary AI provider, and in limited secondary cases by Google AI Studio, to power these features (see Section 5)
3.3 Service Improvement and Analytics
- Monitor, analyze, and improve the performance, functionality, and user experience of the Service
- Understand usage patterns, trends, and preferences
- Conduct research and development for new features
- Generate aggregated, anonymized, and de-identified statistical data and reports
3.4 Communication
- Send transactional and administrative notifications (e.g., account confirmations, billing receipts, security alerts, service announcements)
- Respond to your inquiries, support requests, and feedback
- Send product updates, feature announcements, and marketing communications (where permitted and with appropriate consent)
3.5 Security and Compliance
- Detect, investigate, and prevent fraud, unauthorized access, abuse, and other harmful or illegal activity
- Enforce our Terms of Service, this Policy, and other applicable agreements
- Comply with applicable laws, regulations, court orders, legal processes, and government requests
- Establish, exercise, or defend legal claims
- Protect the rights, property, safety, and security of Claimory, our users, and the public
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, we process your personal data based on the following legal grounds under the General Data Protection Regulation (GDPR) and equivalent legislation:
- Performance of a Contract (Art. 6(1)(b)): Processing necessary to perform our contract with you (i.e., our Terms of Service), including account creation, service delivery, billing, and customer support
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate business interests, such as improving the Service, fraud prevention, security, analytics, and direct marketing (where not overridden by your data protection rights)
- Consent (Art. 6(1)(a)): Processing based on your freely given, specific, informed, and unambiguous consent, such as for certain marketing communications, optional AI features, and cookies. You may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal
- Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with applicable legal obligations, including tax, accounting, regulatory, and law enforcement requirements
- Vital Interests (Art. 6(1)(d)): Processing necessary to protect the vital interests of any natural person, in rare emergency circumstances
5. AI Data Processing
Claimory offers AI-powered features that use artificial intelligence to provide enhanced functionality. This section provides transparency about how your data is used in connection with AI features.
5.1 What Data Is Processed by AI
When you use AI features, portions of Your Data, such as claim details, claim activity logs, customer communications, and contextual information, may be transmitted to and processed by our primary AI service provider, Anthropic, PBC (the "Claude" model family), to generate responses, summaries, drafts, recommendations, and insights. In limited secondary cases (for example, embedding generation, document parsing, or model fallbacks where Anthropic capacity is unavailable) we may also use Google LLC (Google AI Studio / Gemini API). Customer claim data is never used to train any third-party AI or machine-learning model.
5.2 How AI Data Is Handled
- Data sent to Anthropic and Google AI Studio is transmitted securely using industry-standard TLS encryption
- We use Anthropic's API under their commercial terms. As of the date of this Policy, Anthropic's API does not use customer-submitted data to train, improve, or fine-tune their models. Where Google AI Studio is used as a secondary provider, we operate under terms that exclude customer claim data from training datasets.
- We do not store AI-generated outputs permanently unless you explicitly choose to save them within the Service
- AI processing is performed on demand. Data is sent to the AI provider at the time of the request and is not continuously shared or streamed
5.3 Your Choices Regarding AI
AI features are optional productivity tools. You are not required to use them. If you do not wish for your data to be processed by AI providers, simply do not use the AI-powered features. If your subscription plan includes AI features by default, contact info@claimory.io to discuss alternative arrangements.
5.4 AI Action Logs and Retention
Each call to an AI feature produces an audit log entry in the table ai_action_logs for chat and review actions. These records support troubleshooting, safety review, billing reconciliation, and security auditing. They follow the same retention rules described in Section 11 and are scoped by workspace through row-level security. AI action log entries are deleted when the underlying workspace is deleted, subject to the thirty (30) day request window described in Section 11.
6. Data Sharing and Disclosure
Claimory does not sell, rent, lease, or trade your personal information to third parties for their own commercial or marketing purposes.
We may share your information only in the following circumstances and with the following categories of recipients:
6.1 Service Providers and Sub-Processors
We share information with third-party service providers who perform services on our behalf, subject to contractual obligations requiring them to protect your data:
- Supabase, Inc. - Database hosting, user authentication (including password hashing and session management), file and document storage, real-time data synchronization, and backend infrastructure. Data stored on Supabase infrastructure.
- Stripe, Inc. - Payment processing, subscription management, billing, and financial transaction handling. Stripe receives your billing information and payment credentials and processes them under its own privacy policy and PCI DSS compliance. Where your repair shop enables in-portal payments, Stripe (via Stripe Connect) also processes the payment you make to the shop; the shop is the merchant of record for that transaction.
- RevenueCat, Inc. - In-app subscription management and receipt validation for the iOS app (the Starter plan purchased through an Apple in-app purchase). RevenueCat receives a pseudonymous app user identifier (your Claimory user id), a workspace identifier, and Apple purchase, transaction, and subscription-status metadata. It does not receive card numbers; Apple handles the payment.
- Vercel, Inc. - Hosts and delivers the Claimory website and app to your browser, including our content delivery network and edge functions. Vercel receives the standard connection details every website gets when it loads a page, such as browser type and IP address, used to serve pages and help block abuse.
- Telnyx LLC - Powers the text messages a shop sends and receives through Claimory, such as appointment and status updates. Telnyx receives the phone numbers and the wording of messages sent and received.
- Twilio Inc. - A backup text-message provider used on some message paths alongside Telnyx. Where this path is active, Twilio receives the phone numbers and the wording of messages sent and received.
- Microsoft Corporation - Powers the optional email integration, and only when a shop chooses to connect its own Microsoft 365 or Outlook mailbox to send and receive claim email inside Claimory. Microsoft receives the messages, attachments, and mailbox details for the account the shop connects, plus the secure tokens that authorize the connection, used only to send and sync that shop's claim email. Operated in the United States.
- Google LLC (Gmail / Google Workspace) - Powers the optional email integration, and only when a shop chooses to connect its own Google mailbox to send and receive claim email inside Claimory. Google receives the messages, attachments, and mailbox details for the account the shop connects, plus the secure tokens that authorize the connection, used only to send and sync that shop's claim email. Operated in the United States.
- Anthropic, PBC - Primary artificial intelligence provider (Claude model family) used to power AI features. Receives claim and contextual data during AI feature usage (see Section 5). Operates under zero-training terms for API customers.
- Google LLC (Google AI Studio) - Secondary AI provider used in limited cases (embeddings, document parsing, fallback when primary provider is unavailable). Receives only the data scoped to the active request.
- OpenRouter, Inc. - AI routing sub-processor used for document text extraction and SMS rewrites. Acts as a thin proxy in front of Anthropic and Google models. Receives only the prompt content and document/SMS text scoped to the active request.
- Google LLC (Analytics) - Web analytics services (Google Analytics) used to understand aggregate usage. Google may collect browsing metadata through analytics scripts. Loaded only after you accept analytics cookies.
- Resend - Transactional email delivery for messages we send to you on our own behalf (welcome emails, password resets, billing notices, security alerts). Resend receives only the recipient address and message content needed to deliver each email.
- Cloudflare, Inc. - Bot and abuse detection on public forms (trial signup, contact, demo request) using Cloudflare Turnstile. Cloudflare receives minimal browser and network metadata needed to score automated traffic.
- Sentry - Application error and performance monitoring. Sentry receives stack traces and contextual metadata about exceptions. We configure Sentry to redact common personal-information fields where technically feasible.
- Tavily - Web search sub-processor used for AI background research (for example, state regulations or repair-procedure references). Tavily receives only the search query scoped to the active request.
- ip-api.com - Estimates a website visitor's approximate location (country, region, and city) for our own site analytics. Before the lookup, we shorten and anonymize your network address, so ip-api.com receives only a truncated network prefix, not your full IP address (see Section 10).
- Google LLC (Google Ads) - Measures whether Claimory's own ads led to a signup, including Enhanced Conversions. Google receives ad-click and conversion identifiers, and for Enhanced Conversions a scrambled version of your email that cannot be read back, used only to match a signup to an ad. Loaded only after you accept marketing cookies (see Section 9). Operated in the United States and European Union.
- Photon (Komoot GmbH) - Address autocomplete and geocoding. The address text you type is sent to return matching locations. Operated in Germany (European Union).
- Nominatim (OpenStreetMap Foundation) - Address autocomplete and geocoding fallback. The address text you type is sent to return matching locations. Operated in the European Union.
- NHTSA (U.S. Department of Transportation) - Vehicle identification number (VIN) decoding through the public NHTSA vPIC database to auto-fill a vehicle's year, make, and model. NHTSA receives only the VIN submitted for decoding; no personal contact details are sent. Operated in the United States.
6.2 Legal and Compliance Disclosures
We may disclose your information if we believe in good faith that such disclosure is necessary to:
- Comply with applicable laws, regulations, legal processes, court orders, or enforceable governmental requests
- Enforce our Terms of Service, this Policy, or other applicable agreements
- Detect, prevent, investigate, or address fraud, security, or technical issues
- Protect the rights, property, safety, or security of Claimory, our users, or the public, as required or permitted by law
- Respond to valid subpoenas, warrants, court orders, or other legal process
6.3 Business Transfers
If Claimory is involved in a merger, acquisition, asset sale, joint venture, corporate reorganization, financing, bankruptcy, dissolution, or similar transaction, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
6.4 With Your Consent
We may share your information with third parties when you explicitly direct us to do so or provide your informed consent.
6.5 Aggregated and De-Identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. Such data is not considered personal information and may be used for any lawful purpose, including industry benchmarking, analytics, and research.
6.6 Workspace and Team Access
Information within your Claimory workspace is accessible to team members you invite based on the permission levels you assign. As the workspace owner or administrator, you control who has access to what data within your workspace. Customer portal users see only the information you choose to make available to them.
6.7 Claimory Staff Access for Support and Security
A small number of authorized Claimory staff (designated super-administrators) may access workspace data for the limited purpose of providing customer support, diagnosing reported issues, investigating suspected abuse, or responding to a confirmed security incident. Where staff access requires impersonating a workspace user (for example, to reproduce a bug a customer reported), the impersonation session is itself recorded in our audit log (table: super_admin_impersonation_sessions) with the staff member's identity, the workspace impersonated, the start time, the end time, and the stated reason. Staff are bound by confidentiality obligations and may not use workspace data for any purpose other than the limited support, security, or legal-compliance purpose described above.
7. Google API Services and Limited Use Disclosure
Claimory integrates with Google APIs to provide email functionality inside the Service. When you connect a Google account (typically Gmail), Claimory requests a limited set of OAuth scopes from Google. This section discloses exactly which scopes Claimory requests, how Claimory uses the data those scopes return, and the limitations Claimory accepts under Google's Limited Use requirements.
7.1 Google OAuth Scopes Requested by Claimory
When you connect a Google account through Settings > Connected accounts, Claimory may request the following OAuth scopes:
- https://www.googleapis.com/auth/gmail.send : send email on your behalf when you compose and send a message from inside Claimory
- https://www.googleapis.com/auth/gmail.readonly : read email metadata and message bodies in order to sync your inbox into the Service, thread incoming replies under the relevant claim, surface unread counts, and let you reply without leaving Claimory
- https://www.googleapis.com/auth/userinfo.email and https://www.googleapis.com/auth/userinfo.profile : identify which Google account is connected and display the connected account's name and avatar in the Claimory user interface
7.2 How Claimory Uses Data Received from Google APIs
- gmail.send: Claimory composes and transmits adjuster, customer, and team emails on your behalf only when you click Send in the Send Email dialog inside the Service. Claimory does not send email autonomously without your explicit action.
- gmail.readonly: Claimory pulls inbox messages so the Service can thread incoming replies under the relevant claim, surface unread counts on the claim timeline, and present message content inside the claim's Email tab so you can review and reply from one place.
- userinfo.email and userinfo.profile: Claimory uses the connected account's email address and profile picture only to identify which Google account is connected and to display that identity in the Settings > Connected accounts panel and in send-from selectors. Claimory does not use this information for any other purpose.
7.3 Limited Use of Google User Data
Claimory's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Claimory:
- Does not transfer Gmail data to any third party except as necessary to provide or improve the user-facing features described above (for example, transmitting an outbound message through Google's own send infrastructure, or rendering a message inside the Service)
- Does not use Gmail data to develop, improve, or train generalized or personalized artificial intelligence or machine learning models. Claimory's AI features (described in Section 5) are not trained on user Gmail content.
- Does not allow humans to read user emails except: (a) with your explicit consent, including when you direct Claimory support to investigate a specific issue; (b) when necessary for security purposes such as investigating abuse or responding to a confirmed security incident; or (c) when required to comply with applicable law
- Does not use Gmail data to serve advertisements of any kind
- Does not sell, rent, lease, or trade Gmail data to any third party for any purpose
7.4 Revoking Google Access
You can revoke Claimory's access to your Google account at any time using either of the following methods:
- Inside Claimory: navigate to Settings > Connected accounts, locate the connected Gmail account, and click Disconnect
- Through your Google account: visit https://myaccount.google.com/permissions, locate Claimory in the list of third-party apps, and select Remove Access
7.5 Retention of Gmail Data
Cached Gmail messages and metadata stored inside Claimory (within Supabase) are retained for the duration of the connected account's active workspace, plus a thirty (30) day grace window after the account is disconnected to support data-retrieval requests and accidental-disconnect recovery. After the grace window expires, cached Gmail data is permanently deleted from Claimory's active systems. Backup retention follows the schedule described in Section 10.
7.6 Compliance Attestation
Claimory's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. International Data Transfers
Claimory is headquartered in Los Angeles, California, United States. Your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from the laws of your country of residence.
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we rely on the following legal mechanisms for the transfer of personal data to third countries:
- Standard Contractual Clauses (SCCs): We may use the European Commission's Standard Contractual Clauses (or UK equivalent) as a legal mechanism for data transfers to countries not covered by an adequacy decision
- Adequacy Decisions: Where the European Commission, UK, or Swiss authorities have determined that a country provides an adequate level of data protection
- Consent: In certain cases, we may rely on your explicit consent for the transfer of your personal data
- Contract Performance: Where the transfer is necessary for the performance of a contract between you and Claimory
By using the Service, you acknowledge and consent to the transfer, storage, and processing of your information in the United States and other jurisdictions as described in this Policy. We take appropriate safeguards to ensure that your personal data remains protected in accordance with this Policy.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect and store information about your interaction with the Service.
9.1 Types of Cookies We Use
- Strictly Necessary Cookies: Essential for the operation of the Service. These include session cookies for authentication, security tokens, CSRF protection, theme preference, and your cookie-consent state. These cannot be disabled.
- Analytics Cookies: Google Analytics 4, plus Claimory's own first-party analytics that stays on Claimory infrastructure. These collect information about pages visited, scroll depth, click events, and session duration to help us understand and improve the Service. They load only after you accept analytics cookies.
- Marketing Cookies: Google Ads conversion tracking, including Enhanced Conversions, which sends a hashed (SHA-256) version of your email to Google to measure ad-driven signups. They load only after you accept marketing cookies.
9.2 Managing Cookies
Most web browsers are set to accept cookies by default. You can usually modify your browser settings to decline cookies or to alert you when cookies are being sent. Please note that disabling cookies may affect the functionality and performance of the Service, and some features may not work properly.
9.3 Do Not Track and Global Privacy Control
The Service does not currently respond to "Do Not Track" (DNT) browser signals, as there is no universally accepted standard for how companies should respond to them. We do, however, honor the Global Privacy Control (GPC) signal: when your browser sends GPC, we treat it as an opt-out of the sale or sharing of personal information and do not load analytics or marketing cookies.
10. Data Security
We implement and maintain commercially reasonable administrative, technical, physical, and organizational security measures designed to protect your personal information from unauthorized access, disclosure, alteration, destruction, loss, and misuse. These measures include:
- Encryption: Data is encrypted both in transit (using TLS/HTTPS) and at rest (using AES-256 or equivalent encryption provided by our infrastructure providers). OAuth refresh and access tokens for connected third-party mailboxes (for example, Gmail and Outlook) are additionally encrypted at the column level using pgcrypto-backed AES symmetric encryption with a key held only on the database server, so a leak of application credentials alone does not expose mailbox credentials. One exception: the approximate-location lookup performed through ip-api.com (see Section 6.1) travels over standard HTTP rather than HTTPS. Because we shorten and anonymize the network address before that lookup, only a truncated network prefix (not an individual visitor's full IP address) is sent.
- Access Controls: Role-based access controls (RBAC), multi-factor authentication options, least-privilege access principles, and regular access review for our team members
- Infrastructure Security: Hosting on enterprise-grade cloud infrastructure (Supabase and Vercel) with provider-level DDoS protection and network firewall rules, plus continuous infrastructure monitoring and alerting
- Rate Limiting and Security Logging: Rate limits protect sign-up, contact, shared-file, signing, and API endpoints, and failed authentication on protected requests is recorded in a security event log retained for 90 days. Public sign-up, contact, and demo-request forms are additionally protected by Cloudflare Turnstile to deter automated abuse.
- Payment Security: Payment processing is handled by Stripe, which is certified as a PCI DSS Level 1 Service Provider - the highest level of certification available. We never store full credit card numbers on our servers.
- Incident Response: Defined security incident response procedures for the detection, investigation, containment, and notification of security events
- Vendor Assessments: Due diligence on the security practices of our third-party service providers
No method of transmission over the internet and no method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee its absolute security, and you use the Service at your own risk. In the event of a security breach involving your personal information, we will notify you and the applicable supervisory authorities in accordance with applicable law.
11. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, as described in this Policy, unless a longer retention period is required or permitted by applicable law.
- Active Account Data: For as long as your account is active and for a commercially reasonable period thereafter
- Post-Termination Data: After account termination, you have thirty (30) calendar days to request a copy of your data by emailing info@claimory.io, and we will provide it within the timeframe required by applicable law. After this period, we may delete your data from active systems, subject to our backup and retention obligations
- Backup Data: Backup copies of your data may be retained for up to ninety (90) days following deletion from active systems as part of standard backup rotation procedures
- Legal and Compliance Data: We may retain certain information for longer periods as required by applicable tax, accounting, financial reporting, regulatory, or legal requirements
- Aggregated and Anonymized Data: Aggregated, anonymized, and de-identified data that does not identify you may be retained and used indefinitely
- Dispute and Litigation Data: Information relevant to a pending or anticipated dispute, investigation, or legal proceeding may be retained until the matter is resolved and any applicable statute of limitations has expired
12. Your Privacy Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Right to Access: Request confirmation of whether we process your personal information and obtain a copy of the personal information we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete personal information
- Right to Deletion (Erasure): Request deletion of your personal information, subject to certain legal exceptions and retention requirements
- Right to Restriction: Request restriction or limitation of the processing of your personal information under certain circumstances
- Right to Data Portability: Request a copy of your personal information in a structured, commonly used, machine-readable format, and request that we transmit it to another controller
- Right to Object: Object to the processing of your personal information, including processing based on legitimate interests or for direct marketing purposes
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
- Right to Opt-Out of Automated Decision-Making: Object to decisions made solely by automated means, including profiling, that produce legal or similarly significant effects
Self-service data export: Authenticated users can exercise the rights of access and data portability directly in the app. You can download a machine-readable (JSON) copy of your Claimory account and workspace data anytime from Settings > Account > Export my data, with no email request needed.
Self-service deletion: Authenticated users can permanently delete their Claimory account and all associated data at any time from Account > Danger Zone > Delete account. The in-app flow soft-deletes your workspace memberships, removes any workspace where you are the last owner (cascading to claims, customers, supplements, and documents), records the request in our security audit log, and removes your authentication record. Some records held by our third-party processors (for example, payment and tax records kept by our payment processor, or transactional email and log data) may be retained by those providers for the period they or applicable law require, and residual copies clear from our encrypted backups on our standard backup cycle rather than instantly. To exercise any other right, or to request deletion if you cannot access the in-app flow, please contact us at info@claimory.io. We will respond to your request within the timeframe required by applicable law (generally thirty (30) to forty-five (45) days). We may request additional information to verify your identity before fulfilling your request.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA).
13.1 Categories of Personal Information Collected
In the preceding twelve (12) months, we have collected the following categories of personal information (as defined by the CCPA):
- Identifiers: Name, email address, phone number, IP address, account ID
- Government Identifiers (Cal. Civ. Code § 1798.80): Where included in claim or Direct Repair Program (DRP) paperwork that shop users enter or upload, government identifiers such as a Social Security number or driver's license number may be present
- Commercial Information: Subscription and billing records, transaction history, service usage records
- Financial Information: Billing details, payment-method metadata (full card numbers are processed and stored by Stripe, not by us), and invoice and payment records
- Internet/Electronic Activity: Browsing history within the Service, interaction data, log data, search history within the Service
- Geolocation Data: Approximate location derived from IP address, and precise location only where you explicitly enable it in the mobile application
- Visual Information: Photographs, images, and documents (such as damage photos and repair documentation) uploaded to the Service
- Professional/Employment Information: Job title, business affiliation, team role
- Inferences: Profiles or preferences inferred from the above categories
- Sensitive Personal Information: Account login credentials (username/password); and, where present in claim or DRP paperwork, a Social Security number, driver's license number, and precise geolocation (mobile, when enabled). We use this information only to provide and secure the Service and do not use or disclose it for purposes that would require offering a right to limit beyond those described in Section 13.2.
13.2 Your CCPA/CPRA Rights
As a California resident, you have the right to:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share your information
- Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions under the CCPA
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale or Sharing: We do not sell your personal information for monetary consideration. When you enable marketing cookies, we share online identifiers (and, for Google Enhanced Conversions, a hashed version of your email) with Google to measure and improve our own advertising, which California law may treat as "sharing" for cross-context behavioral advertising. Advertising cookies are off by default and load only with your opt-in consent. To opt out, disable marketing cookies using the "Cookie preferences" link in our footer, or email info@claimory.io.
- Right to Limit Use of Sensitive Information: Request that we limit the use and disclosure of sensitive personal information to certain specified purposes
- Right to Non-Discrimination: We will not deny you goods or services, charge you different prices, provide a different level or quality of goods or services, or suggest that you may receive a different price or quality of goods or services for exercising your CCPA rights
13.3 Exercising Your California Rights
To submit a verifiable consumer request, contact us at info@claimory.io. You may also designate an authorized agent to make a request on your behalf by providing written authorization to the agent and verifying your identity with us. We will respond to verifiable requests within forty-five (45) days, with the option to extend by an additional forty-five (45) days if necessary with notice.
13.4 "Shine the Light" (California Civil Code § 1798.83)
California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes during the preceding calendar year. As stated throughout this Policy, we do not share personal information with third parties for their direct marketing purposes.
13.5 Notice at Collection (Cal. Civ. Code § 1798.100(b))
At or before the point we collect your personal information, we provide this notice at collection. The categories of personal information we collect are listed in Section 13.1 (including the Sensitive Personal Information identified there). We collect this information for the business and commercial purposes described in Section 3 (including providing and operating the Service, billing, communications, AI-powered features, security, and compliance). We retain each category for the periods described in Section 11. We do not sell personal information for monetary consideration; if you enable marketing cookies, we may share online identifiers for cross-context behavioral advertising as described in Section 13.2, where you can also opt out. For a fuller description of your rights and how to exercise them, see this Policy in full.
14. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection (FADP), respectively.
14.1 Your GDPR Rights
In addition to the rights listed in Section 12, you have the right to:
- Lodge a Complaint: File a complaint with your local data protection supervisory authority if you believe we have violated your data protection rights. A list of EU supervisory authorities is available at the European Data Protection Board website.
- Object to Processing: Object to the processing of your personal data based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
- Restriction of Processing: Request restriction of processing while we verify the accuracy of your data, assess our legitimate grounds, or when processing is unlawful but you do not want deletion.
14.2 Data Controller
For purposes of the GDPR, Claimory is the data controller of information collected through the Service for our own purposes (e.g., account management, billing). With respect to the claim data, customer data, and other business data entered by shop owners and their teams, Claimory is the data processor acting on your instructions. In such cases, you (the shop owner or business entity) are the data controller and are responsible for compliance with the GDPR with respect to the personal data of your own customers and contacts.
14.3 Data Processing Agreements
If you require a Data Processing Agreement (DPA) for GDPR compliance, please contact us at info@claimory.io.
15. Additional U.S. State Privacy Rights
In addition to California, several other U.S. states have enacted comprehensive privacy laws that may apply to you:
15.1 Virginia (VCDPA)
Virginia residents have the right to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of the processing of personal data for targeted advertising, sale, or profiling. You may appeal our response to your request by contacting us at info@claimory.io.
15.2 Colorado (CPA)
Colorado residents have similar rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, or certain profiling.
15.3 Connecticut (CTDPA)
Connecticut residents have the right to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and profiling.
15.4 Nevada (SB 220)
Nevada residents have the right to opt out of the sale of their "covered information" (as defined under Nevada law). We do not sell your covered information. If you are a Nevada resident and wish to submit an opt-out request, please contact us at info@claimory.io.
15.5 Other States
As additional U.S. states enact comprehensive privacy legislation (including but not limited to Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, and Florida), we will comply with applicable requirements. If you are a resident of a state with applicable privacy legislation and wish to exercise your rights, please contact info@claimory.io.
16. SMS and Communication Privacy
The Service includes SMS messaging and email communication features. With respect to these features:
- SMS messages are transmitted through Telnyx LLC. Telnyx may process and temporarily store message content and recipient phone numbers as necessary for delivery.
- We retain records of SMS and email communications sent through the Service as part of claim and customer records. These records are treated as Your Data under our Terms of Service.
- Phone numbers and email addresses used for communication features are stored securely within our infrastructure.
- You, as the shop owner or user, are the data controller for communications you send through the Service. You are responsible for obtaining required consents from recipients under the Telephone Consumer Protection Act (TCPA), the CAN-SPAM Act, and all other applicable laws.
- Message and email opt-out and unsubscribe records are maintained to ensure compliance with applicable opt-out requirements.
17. Children's Privacy
The Service is not directed to, intended for, or designed to attract children under the age of eighteen (18), or the age of majority in the applicable jurisdiction, whichever is greater. We do not knowingly collect, solicit, or maintain personal information from children. If we become aware that we have inadvertently collected personal information from a child without proper parental or guardian consent, we will take reasonable steps to delete such information promptly. If you believe that a child has provided personal information to us, please contact us at info@claimory.io so we can take appropriate action.
This policy is consistent with the Children's Online Privacy Protection Act (COPPA) and similar international protections for minors.
Claim photos and documents uploaded by shops may incidentally include a minor (for example, a child visible in a vehicle photo). This data is not solicited from the minor and is treated as a business record under the same security and retention controls as other claim data. The shop is the data controller for the information it enters and is responsible for obtaining any consent required from the customer (or, where applicable, a parent or guardian) for that information.
18. Third-Party Links and Services
The Service may contain links to third-party websites, applications, or services that are not owned or controlled by Claimory. This Privacy Policy does not apply to third-party services. We have no control over, and assume no responsibility for, the content, privacy policies, data practices, or security of any third-party websites or services. We strongly encourage you to review the privacy policies of any third-party service before providing any personal information or using such service.
19. Data Breach Notification
In the event of a security breach involving your personal information that poses a risk to your rights and freedoms, we will:
- Notify affected users without undue delay, targeting seventy-two (72) hours of becoming aware of the breach
- Notify affected California residents in the most expedient time possible and without unreasonable delay, as required by the California Information Practices Act (Cal. Civ. Code § 1798.82)
- Notify the applicable state attorneys general and/or data protection supervisory authorities as required by applicable law
- Provide a description of the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address the breach
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" and "Effective date" at the top of this page
- Send an email notification to the address associated with your account
- Display a prominent notice or banner within the Service
Your continued use of the Service after the effective date of any updated Policy constitutes your acceptance of the changes. If you do not agree with the updated Policy, your sole remedy is to discontinue use of the Service. We encourage you to review this Policy periodically.
21. Contact Information
If you have any questions, comments, complaints, or requests regarding this Privacy Policy, our data practices, or your privacy rights, please contact us at:
Claimory LLC - Privacy Team
2108 N St Ste N
Sacramento, California 95816, United States
Privacy & Data Requests: info@claimory.io
General & Legal Inquiries: info@claimory.io
Customer Support: info@claimory.io
Security Concerns: info@claimory.io
