Privacy Policy

Last updated: March 15, 2026

At CubicleERP ("we," "us," or "our"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and related services (collectively, the "Services"). By using our Services, you agree to the terms of this Privacy Policy.

1. Information We Collect

We collect information in several ways to provide and improve our Services:

Personal Information You Provide

  • Account Information: Name, email address, phone number, company name, job title, and password when you create an account.
  • Billing Information: Payment method details, billing address, and transaction history when you subscribe to a paid plan.
  • Profile Information: Profile picture, bio, preferences, and other details you choose to provide.
  • Communications: Content of messages sent through our support channels, emails, or in-platform communications.

Information Collected Automatically

  • Usage Data: Pages visited, features used, click patterns, time spent on the platform, and interaction data.
  • Device Information: Browser type, operating system, device identifiers, screen resolution, and language settings.
  • Log Data: IP addresses, access times, referring URLs, and error logs.
  • Location Data: Approximate geographic location derived from your IP address.

Information from Third Parties

  • Single Sign-On (SSO): Profile information from identity providers (e.g., Google, Microsoft) if you use SSO to authenticate.
  • Integrations: Data from third-party services you connect to CubicleERP, such as email providers, calendar apps, or payment processors.
  • Public Sources: Publicly available business information used to enhance your account profile.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and improve our platform, including processing transactions, managing your account, and delivering customer support.
  • Personalization: To customize your experience, recommend features, and tailor content and communications based on your usage patterns and preferences.
  • Analytics & Improvement: To analyze usage trends, monitor platform performance, diagnose technical issues, and develop new features and products.
  • Communication: To send transactional notifications (e.g., account confirmations, billing receipts), product updates, security alerts, and, where permitted, promotional materials.
  • Security & Compliance: To detect and prevent fraud, enforce our Terms of Service, comply with legal obligations, and protect the rights and safety of our users and the public.
  • AI & Machine Learning: To train and improve our AI-powered features such as lead scoring, predictive analytics, and automated workflows. Your business data is not used to train models shared with other customers.

3. Data Storage & Security

We take the security of your data seriously and implement industry-leading measures to protect it:

  • Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
  • Infrastructure: Our Services are hosted on SOC 2 Type II and ISO 27001 certified cloud infrastructure with data centers in the United States, European Union, and Asia-Pacific regions.
  • Access Controls: Strict role-based access controls (RBAC) ensure that only authorized personnel can access customer data, and all access is logged and audited.
  • Backups: Automated daily backups with point-in-time recovery capabilities. Backups are encrypted and stored in geographically separate locations.
  • Monitoring: Continuous security monitoring, intrusion detection systems, and regular penetration testing by independent third-party firms.
  • Incident Response: We maintain a comprehensive incident response plan and will notify affected users within 72 hours of discovering a data breach, in compliance with applicable regulations.

Data is retained for as long as your account is active or as needed to provide you with our Services. Upon account termination, we will delete or anonymize your personal data within 90 days, except where retention is required by law.

4. Third-Party Services

We may share your information with third-party service providers who assist us in operating our platform:

  • Payment Processors: We use Stripe and other PCI-DSS compliant payment processors to handle billing. We do not store your full credit card number on our servers.
  • Analytics Providers: We use analytics services to understand platform usage and improve the user experience. These providers collect anonymized or pseudonymized data.
  • Cloud Infrastructure: Our platform is hosted on reputable cloud providers that maintain strict security and compliance certifications.
  • Communication Services: Email delivery, push notifications, and in-app messaging are handled by trusted third-party providers under strict data processing agreements.
  • Customer Support Tools: Support ticketing and live chat platforms process conversations to help us assist you effectively.

All third-party providers are contractually obligated to protect your data and use it only for the specific purposes for which it was shared. We conduct regular security assessments of our vendors and require them to maintain adequate data protection standards.

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

5. Cookies

We use cookies and similar tracking technologies to enhance your experience on our platform:

  • Essential Cookies: Required for the platform to function properly, including authentication, session management, and security features. These cannot be disabled.
  • Performance Cookies: Help us understand how users interact with our platform by collecting anonymized usage data, page load times, and error reports.
  • Functional Cookies: Remember your preferences, language settings, and display options to provide a personalized experience.
  • Marketing Cookies: Used to track visitors across our website and display relevant advertisements. These are only enabled with your explicit consent.

You can manage your cookie preferences at any time through your browser settings or our in-platform cookie consent tool. Please note that disabling certain cookies may impact the functionality of our Services.

We also use pixel tags, web beacons, and similar technologies in our emails to track open rates and engagement, which helps us improve our communications.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you at any time.
  • Right to Rectification: You can request correction of inaccurate or incomplete personal data.
  • Right to Erasure: You can request deletion of your personal data, subject to legal retention requirements.
  • Right to Portability: You can request your data in a structured, machine-readable format for transfer to another service.
  • Right to Restrict Processing: You can request that we limit how we use your data in certain circumstances.
  • Right to Object: You can object to the processing of your data for direct marketing or where processing is based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw that consent at any time without affecting prior processing.

To exercise any of these rights, please contact us at privacy@cubicle-erp.com. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.

For users in the European Economic Area (EEA), we process data under the lawful bases set forth in the GDPR. For California residents, we comply with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

7. Children's Privacy

Our Services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have inadvertently collected personal data from a child under 16, we will take steps to delete such information as promptly as possible.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@cubicle-erp.com so we can take appropriate action.

8. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy.
  • Notify you via email or an in-platform notification at least 30 days before the changes take effect.
  • Provide a summary of the key changes for your convenience.

Your continued use of our Services after the updated policy takes effect constitutes your acceptance of the changes. We encourage you to review this policy periodically.

9. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

CubicleERP, Inc.

Data Protection Officer

100 Market Street, Suite 400

San Francisco, CA 94105, United States

Email: privacy@cubicle-erp.com

Phone: +1 (555) 123-4567

If you are not satisfied with our response to your privacy concern, you have the right to lodge a complaint with your local data protection authority.

Ready to transform your business?

Join thousands of businesses using CubicleERP to streamline operations and boost productivity.