SightLift Privacy Policy
Last updated: August 12, 2026
Introduction
This Privacy Policy explains how SightLift, Inc. ("SightLift," "we," "us") collects, uses, shares, and otherwise processes personal information, and describes your privacy choices and rights.
We use the terms "controller" and "processor" as defined under the EU GDPR. Most U.S. laws follow similar concepts; California uses "Business" (≈ controller) and "Service Provider" (≈ processor).
This Policy applies where SightLift is the controller of your personal information, collected through:
- our website at sightlift.ai and any pages that link to this Policy (the "Sites");
- our sales, marketing, and events activity ("Corporate Operations"); and
- certain limited data we collect when you use the SightLift product (the "Service"), as described in Notice to End Users below.
1. Information we collect
1a. Information you provide. When you contact us, request a demo, fill in a form on the Sites, attend an event, or correspond with us, we may collect your name, business email, phone, company, job title, and anything you enter in a message. We may keep records of these communications, including notes, and (where you are told and applicable law permits) recordings or transcripts of sales calls and meetings.
1b. Information we collect automatically. When you visit the Sites, we automatically collect standard technical data: IP address, device and browser type, operating system, referring URL, pages viewed and links clicked, timestamps, approximate (city-level) location, and similar usage statistics. See §4 (Cookies).
1c. Account information for the Service. To administer the Service we collect account identifiers: your login (OIDC subject via our identity provider), email, display name, and organization/tenant. We also collect basic usage logs (sign-ins, IP address, features used).
1d. Information from other sources. We may receive business-contact and firmographic data from partners, event co-sponsors, data enrichment providers, and public sources, and combine it with the above.
2. How we use information
- provide, secure, operate, and improve the Sites and the Service, and create/administer accounts;
- respond to your enquiries, demos, and support requests;
- send administrative and service messages (security alerts, changes, invoices);
- send marketing communications consistent with your choices (you can unsubscribe anytime);
- analyze and improve our Sites, Corporate Operations, and product, and develop new features;
- for sales-call training/quality assurance where permitted and disclosed;
- detect, prevent, and investigate fraud, abuse, and security incidents;
- comply with law and enforce our agreements; and
- for any purpose you consent to.
3. How we share information
We share personal information with:
- service providers / subprocessors who help run our business (hosting, identity, analytics, email, CRM, payment) under confidentiality and data-protection terms (see the subprocessors inventory);
- affiliates, for the purposes in this Policy;
- professional advisers and in connection with a merger, financing, or sale of the business;
- authorities or third parties where necessary to comply with law, enforce our rights, or protect safety; and
- others with your consent or at your direction.
We do not sell personal information. See §4 on "sharing" for targeted advertising and your opt-out.
4. Cookies & tracking
We use cookies and similar technologies (such as pixels and web beacons) on the Sites: some essential to how the Sites work, and others to understand how visitors engage with the Sites (analytics) and to support our marketing. Cookies may be set by us (first-party) or by the third-party providers whose services we use (for example, analytics and embedded forms). You can control or block non-essential cookies through your browser settings. Where required by law, we honor recognized opt-out preference signals, including the Global Privacy Control (GPC).
We do not use cookies to serve third-party advertising, and we do not sell your personal information. Our analytics is configured without advertising features: no advertising account is linked to our analytics property, no advertising-personalization signals are collected, and our analytics provider processes the data as our service provider under data-processing terms. We do not treat our use of analytics cookies as a "sale" or "share". You can exercise your choices as described in §6 (Your rights & choices).
5. Legal bases (EEA / UK / Switzerland)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (or steps at your request); legitimate interests (running, securing, and marketing our business, where not overridden by your rights); consent (e.g., certain marketing and cookies); and legal obligation. You may withdraw consent at any time without affecting prior processing.
6. Your rights & choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, to opt out of sale/sharing or targeted advertising and profiling, and to withdraw consent. To exercise them, email [email protected]. We will respond as required by law and will not discriminate against you for exercising a right.
- Marketing opt-out: use the unsubscribe link in any marketing email. We may still send service/account messages.
- California (CCPA/CPRA): you have the rights above, including to know, delete, correct, opt out of sale/sharing, and limit use of sensitive personal information; we do not discriminate for exercising them.
- Other U.S. states: we honor analogous rights (access, correction, deletion, portability, opt-out of targeted advertising/profiling), with an appeal path where we decline.
- If your data reached us through a customer's use of the Service, direct your request to that customer (see the Notice below).
7. Data retention
We keep personal information only as long as needed for the purposes above, then delete or anonymize it:
- Account and transaction records: for the life of the relationship, and afterward only as long as needed to meet legal, tax, and accounting obligations, after which we delete or de-identify them.
- Marketing and support records: until you opt out or they are no longer needed.
- Cookie / analytics data: for the limited retention period configured in our analytics tools.
Personal data we process through the Service on a customer's behalf is retained under the DPA, not this Policy.
8. International transfers
Our servers are in the United States. If we transfer personal information from the EEA, UK, or Switzerland, we use an approved mechanism (e.g., the EU Standard Contractual Clauses and the UK Addendum).
9. Artificial intelligence
SightLift's product uses AI/LLM providers to classify and summarize AI-usage data on our customers' behalf (see the DPA and AI Governance Policy). With respect to the personal information covered by this Policy: we do not use it to train foundation models, and we do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
10. Children
The Sites and Service are not directed to children under 18, and we do not knowingly collect their personal information. If you believe a child provided us information, contact us and we will delete it.
11. Security
We maintain administrative, technical, and physical safeguards appropriate to the risk, consistent with our Information Security Policy. No method of transmission or storage is perfectly secure.
Notice to End Users
If you use SightLift because your employer or another organization (our "customer") gave you access, or because your AI-assistant usage was uploaded or connected to the Service by that organization, then that organization (not SightLift) is the controller of that data. Administrators at that organization can access, configure, export, and delete data in their account. For that data, this Policy does not apply; refer to your organization's privacy notices and direct requests to them. SightLift processes it as a processor under the DPA. This Policy governs only the limited controller-side data described in §1c (the account you use to administer the Service) and your interactions with our Sites and Corporate Operations.
Changes to this Policy
We may update this Policy from time to time. We will post the new version here with an updated "Last updated" date and, for material changes, provide more prominent notice.
Contact us
SightLift, Inc., Attn: Privacy, 116 Lincoln St, Apt 6B, Boston, MA 02111 · [email protected]. If you contacted us through or on behalf of a customer organization, your information may also be subject to that organization's privacy practices.