Privacy Policy
Effective date: May 11, 2026
ilgos LLC, a Delaware limited liability company ("ilgos," "we," "us," or "our"), operates the ilgos platform, including the website at ilgos.com, web application, and mobile applications for vendors, customers, and manufacturers (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.
By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
1. Information We Collect
1.1 Information you provide directly
- Account information: Name, email address, phone number, company name, and role when you create an account or are invited to join an organization.
- Business information: Company address, tax identifiers, payment terms, pricing profiles, and other details you configure for your organization.
- Transaction data: Orders, invoices, payment amounts, product information, shipping addresses, and fulfillment details processed through the Platform.
- Communications: Messages sent through our in-app messaging system between vendors and customers, including text, images, and file attachments.
- Support requests: Information you provide when contacting us for assistance, including correspondence and any files you share.
- User content: Product images, documents, descriptions, and other content you upload to the Platform.
- Inquiry information: Brand name, contact details, and other information submitted through our manufacturer inquiry or vendor application forms.
1.2 Information collected automatically
- Usage data: Pages visited, features used, actions taken, timestamps, and interaction patterns within the Platform.
- Device information: Device type, operating system, browser type, screen resolution, app version, and unique device identifiers.
- Network information: IP address, approximate geographic location derived from IP address, and internet service provider.
- Push notification tokens: Device tokens registered for delivering push notifications through our mobile applications. These tokens are associated with your account and store context.
- Cookies and similar technologies: We use essential cookies for authentication and session management. See Section 7 for details.
1.3 Information from third parties
- Authentication provider (Clerk): When you sign in, our authentication provider transmits your identity information to us, including email address, name, and profile data.
- Payment processor (Stripe): Stripe provides us with transaction confirmations, payment method details (last four digits of card, card brand, expiration date), payout information, and dispute notifications. We never receive or store full card numbers, CVVs, or complete bank account numbers.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Operate, maintain, and improve the Platform and its features.
- Process transactions and send related notifications (order confirmations, shipping updates, payment receipts, and invoices).
- Enable communication between vendors and their customers through in-app messaging.
- Provide AI-powered features, including the AI assistant, Smart Order processing, and product enrichment (see Section 5).
- Generate analytics and reports for your organization (e.g., sales dashboards, customer insights, product performance).
- Authenticate users and enforce role-based access control within organizations.
- Deliver push notifications and system notifications related to your account and activity.
- Detect, prevent, and address fraud, abuse, security issues, and technical problems.
- Respond to support requests and communicate with you about your account.
- Comply with legal obligations, enforce our Terms of Service, and protect our rights.
3. How We Share Your Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We share information only in the following circumstances:
- Between connected parties: When a customer places an order with a vendor, both parties can see transaction details, contact information, and order history relevant to their relationship. Manufacturers can see aggregated product adoption data across their distributor network but do not receive individual customer data.
- Service providers: We share information with trusted third-party services that help us operate the Platform. These providers are contractually obligated to use your information only for the purposes of providing services to us and to maintain appropriate security measures:
- Clerk (authentication and user management)
- Stripe (payment processing and financial services)
- Railway (cloud hosting, infrastructure, and database)
- OpenAI / Anthropic (AI model providers — see Section 5)
- Amazon S3-compatible storage (file and image uploads)
- Resend (transactional email delivery)
- Sentry (error monitoring and crash reporting)
- PostHog (first-party product analytics; see Section 7)
- QuickBooks Online (accounting sync; only when a Vendor explicitly connects their QuickBooks account)
- Legal compliance: When required by law, regulation, legal process, subpoena, court order, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: In connection with a merger, acquisition, bankruptcy, dissolution, reorganization, or sale of all or a portion of our assets, your information may be transferred as a business asset. We will notify you via email or prominent notice on the Platform before your information becomes subject to a different privacy policy.
- With your consent: When you explicitly authorize sharing beyond the circumstances described above.
4. Vendor Data Processing
Vendors who use the Platform to manage their business are data controllers of their customer data (e.g., customer names, contact information, order history, and pricing). ilgos processes this data on behalf of the Vendor to provide the Platform's functionality. Vendors are responsible for:
- Ensuring they have the appropriate legal basis to collect and process their customers' personal information.
- Informing their customers about how their data is used, including the use of the ilgos Platform.
- Responding to data subject requests from their customers (e.g., access, deletion, correction).
- Complying with all applicable privacy and data protection laws in their jurisdiction.
We will reasonably assist Vendors in responding to data subject requests that we receive directly, and we will process Vendor customer data only in accordance with these Terms and applicable law.
4.1 Data processing commitments
When processing Vendor customer data, ilgos commits to the following:
- Processing data only in accordance with the Vendor's documented instructions and the functionality of the Platform.
- Ensuring that persons authorized to process data are subject to confidentiality obligations.
- Maintaining the subprocessor list set forth in Section 3 (service providers) and providing reasonable notice before engaging new subprocessors that handle Vendor customer data.
- Providing reasonable assistance with security assessments and data protection impact assessments where required by applicable law.
- Notifying the affected Vendor without undue delay (and in any event within 72 hours of confirmation) upon becoming aware of a personal data breach involving their customer data.
- Upon termination of a Vendor's account and upon written request, returning or deleting Vendor customer data within a reasonable period, except as required for legal compliance or permitted retention periods described in Section 6.
Vendors that require a formal Data Processing Addendum ("DPA") may request one by contacting legal@ilgos.com. ilgos will make a DPA available that incorporates appropriate standard contractual clauses and data protection terms as required by applicable law.
5. AI Features and Data Processing
ilgos uses artificial intelligence to power features such as the AI assistant, Smart Order (voice, camera, and text-based ordering), product description enrichment, and product matching. When you use these features:
- Your input (text, images, or voice recordings) is sent to our AI model providers (currently OpenAI and/or Anthropic) for processing via their API services.
- We include relevant context from your store data — which may include product names, pricing, order details, customer information, and communications — to provide accurate and contextual responses. Context is scoped to the data your role and permissions allow you to access within the Platform.
- AI conversation history is stored on our servers to enable continuity within sessions.
- We do not use your data to train third-party AI models. Our agreements with AI providers prohibit the use of API inputs and outputs for model training.
- Voice recordings and images submitted through Smart Order are processed in real time for transcription and product matching. Audio and image inputs are not permanently stored after processing is complete; however, transient copies may exist briefly in processing queues and system logs before automatic deletion.
- AI outputs reflect automated processing and may contain errors or inaccuracies. You should review AI outputs before relying on them for pricing, purchasing, fulfillment, or compliance decisions.
- You should not submit unnecessary sensitive personal information (e.g., government IDs, financial account credentials, or protected health information) to AI features.
- AI features rely on third-party services and may be subject to their availability, performance, and usage policies.
6. Data Retention
We retain your information for the following periods:
- Account data: Retained for as long as your account is active. Upon account deletion request, we will remove your personal profile information (name, email, phone, avatar) within 30 days and confirm deletion via email. Deletion of your profile does not result in the erasure of all records associated with your account — the exceptions below describe data that is retained after account deletion for legal, regulatory, or operational reasons.
- Transaction records: Retained for a minimum of 7 years following the transaction date to comply with tax, accounting, and financial record-keeping regulations. This includes order records, invoices, payment records, and associated financial data.
- Messages: Retained for the lifetime of the vendor-customer relationship on the Platform. Upon account deletion, messages may be retained in anonymized or redacted form to preserve the other party's records, as messages form part of shared business communications between two parties.
- Usage logs: Raw logs are deleted after 90 days. Aggregated and anonymized analytics data may be retained indefinitely.
- AI conversations: Retained for 90 days to enable session continuity, then automatically deleted.
- Push notification tokens: Deleted when you log out of the mobile application, uninstall the app, or request account deletion.
- Backup copies: Content deleted from our production systems may persist in encrypted backup archives for up to 30 days before automatic removal.
7. Cookies and Tracking
We use functional and operational cookies and similar technologies:
- Authentication cookies: Managed by Clerk to maintain your signed-in session and authenticate API requests.
- Session cookies: To remember your preferences (e.g., theme selection, active store context).
- Product analytics: We use PostHog Cloud (United States) to understand how the Platform is used so we can prioritize improvements. PostHog is configured to store its session identifier in your browser's local storage (we do not set a PostHog cookie), to skip profile creation for signed-out visitors, and to mask all form-input values and rendered text in any session recordings. Data is held in our PostHog Cloud project in the United States and is not shared with advertisers or used to track you across other websites. The same product-analytics tool is used in our mobile applications.
- Error monitoring: We use Sentry for error tracking and performance monitoring. Sentry collects technical data such as error messages, stack traces, device information, and browser metadata to help us identify and fix issues. Sentry does not track you across other websites.
We do not use advertising cookies, third-party tracking pixels, retargeting tags, or analytics services that track you across other websites or applications. We do not participate in ad networks, data brokers, or sell data to advertisers. We do not engage in cross-context behavioral advertising. If we adopt additional analytics or monitoring tools in the future, we will update this section accordingly.
8. Data Security
We implement industry-standard administrative, technical, and physical security measures to protect your information, including:
- All data in transit is encrypted using TLS 1.2 or higher.
- Data at rest is encrypted in our database and storage systems.
- Passwords are hashed and managed by our authentication provider (Clerk); we never store or have access to plaintext passwords.
- Payment information is handled entirely by Stripe (PCI DSS Level 1 certified); sensitive payment data such as full card numbers never touch our servers.
- Role-based access control ensures users can only access data appropriate for their role within their organization.
- We conduct regular security reviews of our infrastructure and third-party integrations.
While we take reasonable measures to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Platform at your own risk.
9. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information. These rights may include, but are not limited to:
- Right to know / access: Request information about the categories and specific pieces of personal information we have collected about you.
- Right to correction: Request correction of inaccurate or incomplete personal information.
- Right to deletion: Request deletion of your personal information, subject to certain exceptions (e.g., legal retention requirements, active transactions).
- Right to portability: Request a copy of your personal information in a structured, commonly used, machine-readable format.
- Right to object: Object to certain processing activities where applicable.
- Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights.
9.1 U.S. state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with applicable consumer privacy legislation, you may have additional rights under those laws, including:
- The right to know what personal information we collect, use, and disclose.
- The right to opt out of the sale or sharing of personal information. Note: we do not sell personal information or share it for cross-context behavioral advertising.
- The right to limit the use of sensitive personal information. We only use sensitive personal information for purposes necessary to provide the Platform.
- The right to appeal a denial of a privacy rights request.
California residents (CCPA/CPRA): In the preceding 12 months, we have collected the categories of personal information described in Section 1. We have not sold personal information as defined by the CCPA. We have disclosed personal information to service providers for the business purposes described in Section 3. You may designate an authorized agent to submit a request on your behalf by providing written authorization to the agent and verifying your identity with us.
9.2 Exercising your rights
To exercise any of these rights, contact us at privacy@ilgos.com. We will verify your identity before processing your request and respond within 30 days (or such shorter period as required by applicable law). If we need additional time, we will notify you of the extension and the reason for it.
10. Children's Privacy
The Platform is designed for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have inadvertently collected personal information from a child under 18, we will promptly delete that information. If you believe a child has provided us with personal information, please contact us at privacy@ilgos.com.
11. International Data Transfers
The Platform is hosted in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country of residence. By using the Platform, you consent to this transfer and processing.
Where required by applicable law, we implement appropriate safeguards for international data transfers, including standard contractual clauses approved by relevant authorities, service provider agreements with appropriate data protection obligations, and other mechanisms recognized under applicable data protection laws.
12. Do Not Track Signals
Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no uniform standard for how DNT signals should be interpreted, the Platform does not currently respond to DNT signals. However, as described in Section 7, we do not engage in cross-site tracking or behavioral advertising, so our practices are consistent with the intent of DNT signals.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will: (a) update the effective date at the top of this page; (b) post the revised policy on the Platform; and (c) for significant changes, provide additional notice via email or in-app notification at least 15 days before the changes take effect. Your continued use of the Platform after the effective date of a revised policy constitutes acceptance of the changes. If you do not agree to the revised policy, you must stop using the Platform.
14. Contact Us
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, or if you wish to exercise your privacy rights, contact us at: