Privacy Policy

    Last updated: June 1, 2026

    1. Information We Collect

    We collect information you provide directly (account registration, profile data, support requests) and information collected automatically (usage data, device information, cookies).

    2. How We Use Your Information

    We use collected information to provide and improve our services, personalize your experience, communicate with you about your account and updates, ensure security and prevent fraud, and comply with legal obligations.

    3. Data Processing & AI

    Prospect data processed through our HBX engine is used solely for generating behavioral insights for the requesting user. We employ zero-retention AI processing — prospect data is not stored in or used to train our AI models.

    4. AI-Generated Communications

    With your explicit consent, GTM Heroes may send you marketing communications that are composed, personalized, or delivered using artificial intelligence. This includes:

    • AI-generated email messages tailored to your behavioral profile
    • AI-generated SMS messages
    • AI-powered voice calls for outreach purposes

    You will only receive these communications if you have provided explicit, affirmative consent (e.g., by checking the consent box on our Relationship Lens tool). You may withdraw this consent at any time by emailing [email protected] or clicking the unsubscribe link in any message.

    5. Cookies & Tracking

    We use a cookie consent banner that allows you to choose which categories of cookies to accept: Essential (required), Analytics & Tracking, and Marketing. Your preferences are stored locally and can be changed at any time.

    We use a list of sub-processors to deliver the Service. Our current sub-processor list is available at gtmheroes.ai/sub-processors. We will notify customers of material changes to this list with at least 30 days advance notice via the mechanism described on the sub-processor page.

    6. Data Sharing

    We do not sell your personal information. We may share data with service providers who assist in operating our platform, when required by law, or in connection with a merger or acquisition — always with appropriate safeguards.

    7. Your Rights

    Depending on your jurisdiction, you may have the right to:

    • Access, correct, delete, or port your personal data
    • Object to or restrict certain processing
    • Withdraw consent for marketing communications (including AI-generated voice, email, and SMS)
    • Change your cookie preferences at any time
    • Opt out of the sale or sharing of personal information (California residents under CCPA)

    Contact [email protected] to exercise your rights.

    8. Security

    We implement industry-standard security measures including encryption in transit and at rest. We are pursuing SOC 2 Type II audit; our current controls align to the AICPA Trust Service Criteria for Security, Availability, and Confidentiality. Audit timeline and auditor selection are in progress, and the Type II report will be made available to enterprise customers under NDA upon completion. See our Security page for details.

    9. Contact

    For questions about this policy, contact us at [email protected].