This Privacy Notice for ItemLine LLC ("ItemLine," "we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at https://itemline.app or any website of ours that links to this Privacy Notice
- Download and use our mobile application (ItemLine), or any other application of ours that links to this Privacy Notice
- Use ItemLine — a B2B business operations platform for wholesale distributors, retail store owners, and their teams. Features include inventory management, purchase order tracking, AI-powered vendor invoice scanning, expiration date tracking, sales invoicing, client relationship management, delivery route planning with a live map, a client-facing invoice portal, a B2B supplier discovery and ordering network (HubLine), product catalogue design and export, QuickBooks Online sync, and an AI business assistant (PulseLine). Available on web and mobile. Intended for business use by adults (18+) only.
- Engage with us in other related ways, including any marketing or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at support@itemline.app. For the fastest response, you can instead use our contact form (or Settings, then Support, in the app), which goes straight into our support ticket system; messages sent by email may take longer to answer. This does not change any response deadlines that applicable law gives you.
Summary of Key Points
This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by reading the full section it links to.
- What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. See What Information Do We Collect?
- Do we process any sensitive personal information? Some information may be considered "special" or "sensitive" in certain jurisdictions — for example, racial or ethnic origins, sexual orientation, and religious beliefs. We do not process sensitive personal information.
- Do we collect any information from third parties? We do not collect any information from third parties.
- How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We process your information only when we have a valid legal reason to do so. See How Do We Process Your Information?
- In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. See When and With Whom Do We Share Your Personal Information?
- How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information — though no method of transmission or storage can be guaranteed 100% secure. See How Do We Keep Your Information Safe?
- What are your rights? Depending on where you are located, applicable privacy law may give you rights over your personal information. See What Are Your Privacy Rights?
- How do you exercise your rights? The easiest way is by contacting us at support@itemline.app. We will consider and act on any request in accordance with applicable data protection laws.
1. What Information Do We Collect?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products, participate in activities on the Services, or otherwise contact us. The personal information we collect may include the following:
- Account registration: names, email addresses, and passwords (stored as a cryptographic hash — we never store your plain-text password)
- Contact or authentication data: phone numbers and mailing addresses
- Business profile: business name and logo
- Team members: team member display names, usernames, and staff pins (stored as cryptographic hashes)
- Client records: your clients' names, contact names, phone numbers, email addresses, physical addresses, visit notes, and visit frequency preferences
- Vendor records: your vendors' names, contact names, phone numbers, and email addresses
- Invoice and purchase order data — invoice numbers, dates, line items, amounts, tax, and payment status
- Inventory and product data — names, UPC barcodes, descriptions, categories, quantities, costs, and prices
- Expense records and receipt images you upload
- Route data — sequences of client stops you configure for delivery planning
- Social content — promotional text and social media post content you generate or save
- Catalogue data — product selections, design preferences, and catalogue PDFs you export
- Network profile — your public business display name, logo, description, city and state (not street address), product categories, fulfillment options, and order contact information, visible to other registered users as you configure it. Contact information visibility defaults to hidden and can be set to visible only to authenticated users or publicly.
- Messages — B2B messages you send through the ItemLine Network
- Client portal — client email addresses and hashed passwords for clients you invite to the portal
- Push notification subscription tokens — for the web app, your browser's push subscription; for the iPhone and Android apps, your device's push token (and, on iPhone, a running count of unread notifications used for the app-icon badge)
- Sign-up plan choice — the plan you pick while signing up, kept with your email address until you finish setting up your business, then deleted (or deleted automatically after 30 days if you never finish)
- Launch waitlist — if you use the "Notify me" box on our website, the email address you enter. We use it only to email you about the ItemLine beta launch, and you can ask us to remove it at any time
- Contact and support messages — what you send us through the website contact form, from inside the app (Settings, Support), or by replying to or emailing our support address: your name, email address, the message, any files you attach, and, if you are signed in, a link to your ItemLine account. Our support team members read these messages, reply to them, and add internal notes, and we keep a record of which team member did what on each conversation
- Records of acceptance — which version of our Legal Terms, Privacy Policy, and Acceptable Use Policy you (or your team members and client-portal users) accepted, and when
Sensitive Information. We do not process sensitive information.
Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and its associated security code. All payment data is handled and stored by Stripe. See their privacy notice at stripe.com/privacy.
Social Media Login Data. We may let you register using your existing social media account details (such as Google). If you choose to register this way, we collect certain profile information from the social media provider, as described in How Do We Handle Your Social Logins? below.
Geocoding Data. When you add client addresses, we send those addresses to the Google Geocoding API (operated by Google LLC) to obtain GPS coordinates for route planning and the map. If Google cannot resolve an address, we may retry it with the Nominatim API (operated by OpenStreetMap). We store the resulting latitude and longitude coordinates alongside the client record. We do not store the raw query sent to these providers beyond the geocoding request itself.
Map Display Data. The map page shows a background map supplied by MapTiler (using OpenStreetMap data). Your browser or device requests those map images directly from MapTiler, so MapTiler receives your IP address and the map area you are viewing. We do not send client names, addresses, or any other business data to MapTiler — your clients' pins are drawn by ItemLine on your own device.
QuickBooks Online Data (optional). If you connect your QuickBooks account, we receive and store OAuth access tokens and refresh tokens (encrypted at rest), your QuickBooks company name, and realm ID. We use these solely to push invoice data to your QuickBooks account on your behalf. Disconnecting the integration deletes these tokens immediately.
Google Drive Data (optional).If you connect Google Drive, we receive and store OAuth access and refresh tokens (encrypted at rest) and the email address of the Google account you connected. We request only the narrow "drive.file" permission, which lets ItemLine see and change only the folders and files it creates itself (a folder per year, such as "ItemLineInvoices-2026") — never the rest of your Drive. We use this solely to save PDF copies of your sent invoices into your Drive on your behalf, and to move a copy to your Drive's trash when you delete that invoice in ItemLine. We do not use, share, or transfer information received from Google APIs for advertising, and our use of that information adheres to the Google API Services User Data Policy, including its Limited Use requirements. Disconnecting (or deleting or resetting your ItemLine account) deletes these tokens immediately; files already saved in your Drive stay there and are yours to keep or delete.
Application Data. If you use our application(s), we may collect the following if you choose to provide access or permission: Push Notifications — we may request to send you push notifications regarding your account or certain features. In the iPhone and Android apps, we store a push token for your device and send the notification (its title, a short message, and a link to the relevant page) through Apple's Push Notification service or Google's Firebase Cloud Messaging; on iPhone we also send a count of unread notifications for the app-icon badge. You can turn these off in your device's settings at any time. Camera, Photos, and Files — used only when you choose to scan a barcode, take or pick a photo, or attach a file (for example a receipt). Barcode scanning happens on your device; only items you choose to attach are uploaded to us. This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for internal analytics and reporting.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to it.
Information automatically collected
In Short: Some information — such as your IP address and browser/device characteristics — is collected automatically when you use our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This does not reveal your specific identity, but may include your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and how and when you use our Services. This information is primarily needed to maintain the security and operation of our Services, and for internal analytics and reporting.
- Log and Usage Data — service-related, diagnostic, usage, and performance information our servers automatically collect, including date/time stamps, pages and files viewed, searches, actions taken, and device event/error information
- Activity log data — a chronological record of actions taken within the account, linked to the actor (owner or staff member) and timestamp, retained for 12 months
- Session data — IP address and browser user agent, collected at login and stored with your session token for security purposes, retained for up to 30 days after the session
- Notification preferences — your push notification settings stored in your account
Google API
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. How Do We Process Your Information?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes only with your prior explicit consent.
We process your personal information for a variety of reasons, including:
- To facilitate account creation and authentication and otherwise manage user accounts, so you can create and log in to your account and keep it in working order.
- To deliver and facilitate delivery of the Services you request.
- To respond to inquiries and offer support for issues you might have with the Services.
- To answer your support requests — we keep your messages, our replies, any attachments, and notes from our support team so that you get consistent help and so we can review how requests were handled.
- To tell you about our launch — if you join the launch waitlist, to email you when the beta opens.
- To send administrative information — details about our products and services, and changes to our terms and policies.
- To fulfill and manage your orders, payments, returns, and exchanges made through the Services.
- To enable user-to-user communications if you choose to use offerings that allow communication with another user.
- To enable team member access — so your team members can access your account under the permissions you configure for them.
- To enable client portal access — so your clients can view their invoices via the Client Portal you invite them to.
- To send transactional emails — order confirmations, invoice delivery, and client portal invites — via our email service provider (Resend).
- To geocode addresses for route planning and map features (Distributor plan).
- To sync data to QuickBooks Online, if you connect that optional integration.
- To save invoice PDFs to your Google Drive, if you connect that optional integration.
- To protect our Services, including fraud monitoring and prevention.
- To identify usage trends so we can better understand and improve the Services.
- To improve the Service based on aggregated, anonymized usage patterns — we do not sell individual business data.
- To save or protect an individual's vital interest, such as to prevent harm.
- Security and activity audit logging — we log significant actions taken within each business account, linked to the actor and timestamp.
3. What Legal Bases Do We Rely On to Process Your Information?
In Short: We only process your personal information when we have a valid legal reason to do so — such as your consent, to comply with law, to fulfill a contract, to protect your rights, or to pursue our legitimate business interests.
If you are located in the EU or UK
The GDPR and UK GDPR require us to explain the legal bases we rely on. We may rely on:
- Consent — where you have given us permission to use your information for a specific purpose. You can withdraw consent at any time.
- Performance of a Contract — where necessary to fulfill our contractual obligations to you, including providing the Services.
- Legitimate Interests — where reasonably necessary to achieve our legitimate business interests without outweighing your rights and freedoms, for example to:
- Analyze how our Services are used so we can improve them
- Diagnose problems and/or prevent fraudulent activities
- Detect unauthorized access, investigate incidents, and provide account owners with an auditable record of activity in their account
- Legal Obligations — where necessary to comply with law, cooperate with authorities, or exercise/defend our legal rights.
- Vital Interests — where necessary to protect someone's vital interests, such as situations involving potential threats to safety.
If you are located in Canada
We may process your information with your express or implied consent, which you can withdraw at any time. In limited, legally-defined cases we may process information without consent — for example, for fraud detection and prevention, business transactions, legal compliance (e.g. a subpoena or court order), or where information is publicly available as specified by regulation.
4. When and With Whom Do We Share Your Personal Information?
In Short: We may share information in specific situations and with the third parties listed below. We do not sell your personal information.
We share your data with service providers who perform services for us and require access to do that work. We have contracts in place with each of them designed to safeguard your personal information — they cannot use it beyond our instructions, cannot share it with anyone else, and must protect and retain it only for the period we instruct.
| Provider | Purpose | Data shared |
|---|
| Vercel | Hosting, compute, file storage; website testing | All data processed by the application; uploaded files (receipts, logos, catalogue images) |
| Neon | Cloud database | All structured data stored by the application |
| Resend | Transactional email delivery | Recipient email addresses and email content (order notifications, invoice emails, portal invites, support replies, launch waitlist emails), and the emails customers send to our support address |
| OpenAI & Vercel AI Gateway | AI-powered features | Invoice images, prompt text, and summarized business data for AI features |
| Google (Maps Platform — Geocoding) | Address geocoding for route planning and the map | Client address strings only, used to return coordinates |
| OpenStreetMap / Nominatim | Fallback address geocoding | Client address strings only, used to return coordinates; no persistent storage by the provider |
| MapTiler | Background map images on the map page | Your IP address and the map area being viewed, requested directly by your device; no business data |
| Intuit (QuickBooks) | Optional invoice sync integration | Invoice data, client names, and line items — only when you connect and sync |
| Google (Drive) | Optional invoice PDF backup to your own Drive | The PDF of each sent invoice, saved only into folders ItemLine creates in your Drive — only when you connect |
| Google | Sign-in / account authentication | Basic profile information (name, email) when you choose to sign in with Google |
| Stripe | Payment processing | Payment instrument details, handled and stored entirely by Stripe |
| Browser push services (e.g. Google FCM) | Web push notifications | Push notification payload and your browser's push subscription endpoint |
| Apple (Push Notification service) | Notifications to the iPhone app | Your device's push token, the notification text and link, and the unread count for the app-icon badge |
| Google (Firebase Cloud Messaging) | Notifications to the Android app | Your device's push token and the notification text and link |
We may also need to share your personal information in the following situations:
- Business Transfers. We may share or transfer your information in connection with a merger, sale of assets, financing, or acquisition of all or part of our business. We will notify you via email or a prominent notice within the Service before your information becomes subject to a different privacy policy.
- Other Users. When you share personal information (for example, by participating in public areas of the Services) or register through a social network, other users may be able to view your name, profile photo, and descriptions of your activity, and communicate with you within our Services.
- Network Participants. If you publish a profile on the ItemLine Network, the information you choose to make public (as configured in your network settings) is visible to other registered users of the Service. Contact information visibility is controlled by you — it defaults to hidden and can be set to visible only to authenticated users or publicly. When you send a purchase order through the Network, your business name, order reference, and the contact information you opted to share (owner name, phone, address) are disclosed to the receiving supplier.
- Client Portal. When you invite a client to the portal, their email address is shared with our email service provider to send the invite. The portal gives that client visibility only into their own invoices from your business — never any other data.
- Legal Requirements. We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe it is necessary to protect the rights, property, or safety of ItemLine, our users, or the public.
5. Do We Use Cookies and Other Tracking Technologies?
In Short: We use a small number of essential cookies and browser storage to operate the Service. We do not use tracking, advertising, or analytics cookies.
We use cookies and similar technologies to gather information when you interact with our Services and to help maintain security, prevent crashes, fix bugs, and save your preferences. Specifically, we use:
- Session cookie — a secure, HttpOnly cookie that identifies your authenticated session. Required to use the Service.
- OAuth state cookie — a short-lived, HttpOnly cookie used during third-party OAuth flows (e.g. QuickBooks, Google Drive) to prevent CSRF attacks. Deleted immediately after the flow completes.
- Local storage — used for transient UI state, such as remembering your selected plan during sign-up. This is stored on your device; the plan you select at sign-up is also kept with your email address on our servers until you finish setting up (see "Sign-up plan choice" above).
We do not use tracking cookies, advertising cookies, or third-party analytics cookies, and we do not permit third parties to use tracking technologies on our Services for advertising purposes.
6. Do We Offer Artificial Intelligence-Based Products?
In Short: Yes — certain features are powered by artificial intelligence, and we do not use your business data to train models for other customers.
As part of the Service, we offer features powered by artificial intelligence, machine learning, or similar technologies ("AI Products") through third-party AI service providers, including OpenAI (via Vercel AI Gateway). Within ItemLine, these power:
- Vendor invoice scanning — images of vendor invoices you upload are processed to extract line items, totals, and dates
- Expiration date detection — product images or labels you scan are processed to detect expiration dates
- PulseLine, the AI business assistant — your business data (invoice totals, order counts, client counts, inventory levels) is summarized and sent to our AI provider to generate contextual business insights in response to your queries
- Social media post generation — your promotion descriptions are sent to our AI provider to generate social media content
Your input, output, and personal information sent to AI Products is used solely to generate the output you requested. We do not use your business data to train AI models for use by other customers. You must not use AI Products in any way that violates the terms or policies of any AI service provider.
To opt out, you can log in to your account settings and update your preferences, or contact us at support@itemline.app.
7. How Do We Handle Your Social Logins?
In Short: If you register or log in using a social media account, we receive certain profile information from that provider.
Our Services let you register and log in using your third-party account details (like Google or Apple). Where you choose to do this, we receive certain profile information from that provider — typically your name, email address, and profile picture. We use this information only for the purposes described in this Privacy Notice. We do not control, and are not responsible for, other uses of your information by your social login provider — we recommend reviewing their own privacy notice.
8. Is Your Information Transferred Internationally?
In Short: We may transfer, store, and process your information in countries other than your own.
The Service is hosted on Vercel's infrastructure and data is stored in Neon's cloud database. Both providers may store and process data in the United States and other countries. Regardless of your location, your information may be transferred to and processed in the facilities of the third parties with whom we share your personal information (see Section 4).
If you are located in the EEA, UK, or Switzerland, we take all necessary measures to protect your personal information in accordance with this Notice and applicable law, including relying on the European Commission's Standard Contractual Clauses where required for cross-border transfers. These can be provided upon request.
9. How Long Do We Keep Your Information?
In Short: We keep your information only for as long as necessary to fulfill the purposes outlined in this Notice, unless a longer period is required by law.
No purpose in this Notice requires us to keep your personal information for longer than three (3) months past the termination of your account, unless a longer retention period is required or permitted by law (such as tax or accounting requirements). Specifically:
- Deleted invoices and orders use soft-deletion — the record is marked deleted but retained for audit integrity; we may purge soft-deleted records after 90 days
- Session data (IP address, user agent) is retained for the session and up to 30 days thereafter, for security purposes
- Activity log entries are retained for 12 months
- Push subscription tokens are deleted automatically when a browser push service reports them expired or invalid
- QuickBooks OAuth tokens are deleted immediately when you disconnect that integration
- Google Drive OAuth tokens are deleted immediately when you disconnect that integration
- iPhone and Android push tokens are deleted automatically when Apple or Google reports them invalid (for example, after the app is uninstalled)
- Support conversations (messages, attachments, and notes) are kept for as long as we need them to help you and for our records, and we delete them on request unless we are required to keep them
- Launch waitlist email addresses are kept until you ask us to remove yours, or until we no longer need them to tell you about the launch
- Sign-up plan choices are deleted once you finish setting up your business, or automatically after 30 days
When we no longer have an ongoing legitimate need to process your information, we delete or anonymize it, or — where that isn't possible (e.g. backup archives) — securely isolate it from further processing until deletion is possible.
10. How Do We Keep Your Information Safe?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the personal information we process, including:
- Passwords and staff PINs stored as bcrypt hashes — never in plain text
- HTTPS encryption in transit for all communications with the Service
- Database credentials and OAuth tokens (including QuickBooks and Google Drive tokens, encrypted at rest) stored as environment variables, never in code
- PIN login rate limiting to prevent brute-force attacks
- Atomic invoice number generation using database-level locks to prevent data races
- Session tokens invalidated on logout
However, no electronic transmission or storage technology can be guaranteed 100% secure, so we cannot promise that unauthorized third parties will never defeat our security. Transmission of information to and from the Services is at your own risk. If you believe your account has been compromised, contact us immediately at support@itemline.app.
11. Do We Collect Information From Minors?
In Short: We do not knowingly collect data from or market to children under 18.
The Service is intended for business use by adults. We do not knowingly collect, solicit, or sell personal information from individuals under 18 years of age (or the equivalent age specified by law in your jurisdiction). By using the Services, you represent that you are at least 18, or that you are the parent or guardian of such a minor and consent to their use of the Services. If we learn that we have inadvertently collected such information, we will deactivate the account and delete the data promptly. If you believe a minor's data has been submitted to the Service, please contact us at support@itemline.app.
12. What Are Your Privacy Rights?
In Short: Depending on your state of residence in the US, or in regions such as the EEA, UK, Switzerland, and Canada, you have rights that give you greater access to and control over your personal information. You may review, change, or terminate your account at any time.
In some regions, you have the right to: (i) request access to and a copy of your personal information; (ii) request rectification or erasure; (iii) restrict processing of your personal information; (iv) request data portability; and (v) not be subject to automated decision-making that produces legal or similarly significant effects without a way to request human review. You may also have the right to object to certain processing. We will consider and act on any request in accordance with applicable data protection laws — specifically, we will respond within 45 days of your request, with a possible one-time 45-day extension if reasonably necessary (we'll notify you if so). We may need to verify your identity before processing certain requests.
If you are located in the UK and are unhappy with how we've handled your personal information, you can complain directly to us, or to the Information Commissioner's Office (ico.org.uk/make-a-complaint, helpline 0303 123 1113). If you are in the EEA or Switzerland, you may likewise contact your Member State data protection authority or the Federal Data Protection and Information Commissioner.
Withdrawing your consent
Where we rely on your consent to process your information, you may withdraw it at any time by contacting us at support@itemline.app. This will not affect the lawfulness of processing before withdrawal.
Account information
You can review, change, or terminate your account at any time by logging in to your account settings, or by contacting us. Upon account termination, we will deactivate or delete your account and information from our active databases, though we may retain some information to prevent fraud, resolve disputes, or comply with legal obligations. Specifically, you can also:
- Disable push notifications at any time through Settings → Notifications, or through your browser's notification settings
- Disconnect the QuickBooks integration at any time through Settings → QuickBooks, which deletes all stored OAuth tokens immediately
- Unpublish your network profile at any time through Settings → Network Profile, which removes it from the public marketplace immediately
Cookies
Most browsers accept cookies by default; you can usually configure your browser to remove or reject them, though this may affect certain features of the Service.
13. Controls for Do-Not-Track Features
Most browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature. Because no uniform technology standard for recognizing and honoring DNT signals has been finalized, we do not currently respond to DNT signals. If a standard is adopted that we must follow, we will describe that practice in a revised version of this Notice.
14. Do United States Residents Have Specific Privacy Rights?
In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to withdraw consent to our processing of it.
Categories of personal information we collect
The table below shows the categories of personal information we have collected in the past twelve (12) months, per applicable state law definitions:
| Category | Examples | Collected |
|---|
| A. Identifiers | Name, postal address, phone, IP address, email address, account name | Yes |
| B. California Customer Records categories | Name, contact information, financial information | Yes |
| C. Protected classification characteristics | Gender, age, race, national origin, etc. | No |
| D. Commercial information | Transaction information, purchase history, payment information | Yes |
| E. Biometric information | Fingerprints, voiceprints | No |
| F. Internet or network activity | Browsing/search history, interactions with our Services | No |
| G. Geolocation data | Coordinates derived from client delivery addresses | Yes |
| H. Audio/visual information | Images, audio, or video recordings | No |
| I. Professional/employment information | Business contact details, job title | No |
| J. Education information | Student records | No |
| K. Inferences | Business performance summaries generated by PulseLine from your own data, used only to respond to your queries | Yes |
| L. Sensitive personal information | — | No |
We retain each collected category for as long as your account has an active association with it, plus 90 days after account termination. We do not collect sensitive personal information as defined by the CPRA (such as Social Security numbers, financial account credentials, precise device geolocation, health information, or biometric data) in the ordinary course of operating the Service.
We do not sell or share your personal information
We do not sell your personal information to third parties for monetary consideration, and we do not share your personal information with third parties for cross-context behavioral advertising purposes. Because we do not sell or share personal information in these ways, we do not offer a "Do Not Sell or Share My Personal Information" opt-out, as none is required. We also do not use sensitive personal information beyond what's necessary to provide the Service, so no opt-out for limiting its use is required either. We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We disclose personal information to our service providers (see Section 4) solely to operate the Service on your behalf — these disclosures are not "sales" or "sharing" under the CCPA/CPRA.
Your rights
Subject to certain exceptions, you may have the following rights under applicable US state privacy laws:
- Right to know whether we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request deletion of your personal data
- Right to obtain a copy of personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of targeted advertising, sale, or profiling that produces legal or similarly significant effects (not applicable, since we do none of these)
- Depending on your state, additional rights to: access categories of processed data (Minnesota); obtain a list of categories or specific third parties we've disclosed data to (California, Delaware, Maryland, Minnesota, Oregon); obtain a list of third parties we've sold data to (Connecticut); review and correct profiling decisions (Connecticut, Minnesota); limit use of sensitive personal data (California); and opt out of voice/facial recognition data collection (Florida)
How to exercise your rights
Contact us at support@itemline.app. Under certain state laws, you can designate an authorized agent to submit a request on your behalf — we may require proof they've been validly authorized. We will need to verify your identity before processing your request, using only the information you provide for that purpose (we will not require you to create a new account to exercise your rights). If we decline to act on your request, you may appeal by emailing us; we'll explain our decision in writing. If your appeal is denied, you may complain to your state attorney general, or, if you're a California resident, to the California Privacy Protection Agency at cppa.ca.gov.
California "Shine the Light" Law
California Civil Code § 1798.83 lets California residents request, once a year and free of charge, information about any personal information we disclosed to third parties for their direct marketing purposes. We do not make such disclosures — no list is available because none exists. To confirm this or make a request, contact us at support@itemline.app.
15. Data About Third Parties You Enter
In Short: ItemLine is a business operations tool. If you enter personal data about your own clients or vendors, you — not ItemLine — are responsible for having a lawful basis to do so.
You may enter personal data about third parties — your clients, vendors, and their employees — into the Service. In this context, you are the "data controller" for that information, and we process it on your behalf as a "data processor."
You are responsible for ensuring you have a lawful basis to collect and enter that third-party data into the Service, and for complying with any privacy laws applicable in your jurisdiction regarding your clients' and vendors' personal data.
16. Do We Make Updates to This Notice?
In Short: Yes, we will update this Notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by a revised "Effective date" at the top. If we make material changes, we will notify you by prominently posting a notice of the changes or by directly notifying you. We encourage you to review this Notice periodically.
18. How Can You Review, Update, or Delete the Data We Collect From You?
You have the right to request access to the personal information we collect from you, details about how we've processed it, correction of inaccuracies, or deletion of your personal information. You may also withdraw your consent to our processing of it, subject to limitations under applicable law. To make such a request, please contact us at support@itemline.app.
7. How Do We Handle Your Social Logins?
In Short: If you register or log in using a social media account, we receive certain profile information from that provider.
Our Services let you register and log in using your third-party account details (like Google or Apple). Where you choose to do this, we receive certain profile information from that provider — typically your name, email address, and profile picture. We use this information only for the purposes described in this Privacy Notice. We do not control, and are not responsible for, other uses of your information by your social login provider — we recommend reviewing their own privacy notice.