Point Privacy Policy
Version: 1.4
Effective date: October 6, 2026
Entity: American River Tech Solutions, Inc, a Delaware corporation, DBA “Point”, with primary offices in California.
Privacy contact: privacy@getpoint.ai
Website: getpoint.ai
This Privacy Policy explains how Point (“Point,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information.
1. Scope
This Policy applies to personal information we process when we act as a controller or business, including in connection with:
- Point websites, landing pages, blogs, and other online properties;
- Point web, desktop, mobile, and other client applications;
- direct individual accounts;
- account registration, authentication, billing, support, security, sales, marketing, events, and business operations;
- connected-account authorization and account administration;
- use of the Services by Individual Customers; and
- personal information relating to representatives of prospects, customers, suppliers, partners, and other business contacts.
For Organization Customers, the organization may be the controller or business for Customer Content processed in the Services. In that case, Point generally acts as a processor, service provider, contractor, or similar role under the Agreement and Data Processing Addendum. If you use Point through an organization, direct privacy requests about Customer Content to that organization unless Point tells you otherwise.
This Policy does not apply to third-party websites, services, providers, app stores, or integrations that have their own privacy notices.
2. Summary
Point is designed to help users manage professional communication and work, such as email, messaging, calendar, files, tasks, search, summaries, scheduling, and automation. To provide these features, Point may process communications and connected-account data that users authorize, including email, calendar, messaging, and cloud storage content.
Point may use advertising, analytics, and measurement technologies, currently including Google’s, on its public websites and other marketing properties where lawful. Point does not sell Customer Content, does not use Customer Content or connected-account content for cross-context behavioral advertising or retargeting, and does not use Customer Content to train generalized third-party AI models unless you expressly authorize it (and never for Google Workspace API data, as described in Section 6.6).
3. Personal information we collect
The information we collect depends on how you interact with Point. The examples below are illustrative, not exhaustive.
3.1 Identity and contact information
Such as name, email addresses (including additional addresses you add and verify), phone number, job title, employer, organization, role, profile photo, country, and business contact details.
3.2 Account and authentication information
Such as account and organization identifiers, roles and permissions, login and session information, authentication and security settings, device identifiers, and access logs.
3.3 Connected-account information
If you connect an email, calendar, identity, messaging, cloud storage, or other third-party account, we may collect information such as provider account identifiers, email addresses, authorization tokens or token references, granted permissions and access levels, sync status, and related provider metadata.
3.4 Communications and content
Depending on your settings and Connected Accounts, Point may process content such as:
- emails, messages, threads, participants, metadata, and attachments;
- files and folders, including files in cloud storage services you connect (Section 6.10);
- calendar events, invitations, availability, responses, and scheduling information;
- contacts, relationships, groupings, labels, and organization membership;
- tasks, reminders, notes, drafts, notifications, automation actions, and activity records;
- search queries, search indexes, summaries, generated titles and descriptions, and other AI Output;
- prompts, instructions, preferences, memory, and settings;
- voice audio and transcripts when you use voice features; and
- support requests, feedback, and related correspondence.
3.5 Device, usage, and technical information
Such as IP address, device and browser information, app version, language, timezone, approximate location derived from IP address, usage and event data, referral and campaign information, performance and diagnostic data, crash reports, cookies, and similar identifiers, including advertising identifiers on marketing properties.
3.6 Billing and transaction information
Such as billing contact details, payment information handled by our payment processor, invoices, tax information, subscription plan, and payment history.
3.7 Sales, marketing, and relationship information
Such as communication preferences, marketing interactions, event attendance, lead and campaign information, demo or trial participation, survey responses, advertising-cookie choices, audience and conversion information, and opt-out or suppression records.
3.8 Security and compliance information
Such as security and audit logs, abuse reports, fraud and risk indicators, screening results, suspected policy violations, and other information used to protect Point, users, customers, and third parties.
3.9 Inferences and derived information
Point may derive information to provide the Services, such as priority, summaries, labels, groupings, suggested tasks, reminders, scheduling suggestions, style preferences, relationship importance, document organization, and recommendations.
3.10 Sensitive personal information
Point does not require sensitive personal information to create an account. However, Customer Content, such as emails, messages, files, or calendar events, may contain sensitive personal information if users or their contacts include it. Sensitive personal information may also include account credentials or tokens and the contents of communications. Point uses sensitive personal information only to provide and secure the Services, comply with law, and for other permitted purposes described in this Policy.
4. Sources of personal information
Point may collect personal information:
- directly from you;
- from your organization, workspace admins, or other users;
- from Connected Accounts you authorize;
- from service providers and other third parties, such as identity, payment, security, analytics, and communications providers;
- from people who communicate or collaborate with you or your organization;
- from your use of the Services;
- from publicly available or business sources;
- from app stores and device platforms; and
- from legal, compliance, fraud-prevention, or security sources.
5. Purposes of processing
Point may process personal information to:
- provide, operate, maintain, and improve the Services;
- create, authenticate, secure, administer, and support accounts;
- connect, sync, search, summarize, prioritize, and organize communications, calendars, files, tasks, contacts, and related content;
- generate AI Output and other user-facing features, such as drafts, summaries, suggestions, and notifications;
- carry out actions, automations, and agent features you request or enable, under your settings, including review, approval, and undo features where available;
- send, receive, and route communications where authorized;
- support scheduling and availability features;
- provide customer support and respond to requests;
- process payments and subscriptions and administer accounts;
- communicate about accounts, security, transactions, service changes, and legal notices;
- personalize the Services based on settings, preferences, and usage;
- measure, debug, analyze, and improve reliability, security, performance, and user experience;
- detect, investigate, prevent, and respond to spam, fraud, abuse, security incidents, unauthorized access, and unlawful activity;
- enforce terms, policies, and legal rights;
- comply with legal, regulatory, tax, accounting, and recordkeeping obligations;
- conduct sales and marketing where lawful;
- measure advertising, attribute campaigns, manage marketing audiences, and conduct targeted advertising or retargeting based on non-Customer-Content information, where lawful and subject to required choices; and
- carry out mergers, acquisitions, financing, reorganizations, or similar business transactions.
6. AI, connected-account data, and advertising limits
6.1 User-facing use
Point uses connected-account data and Customer Content to provide user-facing features requested or enabled by users, such as organization, summarization, search, scheduling, drafting, notifications, document organization, and automation.
6.2 No sale of Customer Content
Point does not sell Customer Content.
6.3 Advertising and retargeting limits
Point may use advertising, analytics, measurement, and retargeting technologies on public websites and other marketing properties where lawful, using information such as website activity, cookie and advertising identifiers, device and approximate location information, campaign and conversion information, and business contact information.
Point does not use Customer Content or connected-account data, including email, calendar, messaging, and cloud storage content, files, prompts, AI Output, search indexes, summaries, authorization tokens, and Google or Microsoft API data, for cross-context behavioral advertising, targeted advertising, retargeting, advertising measurement, audience building, or advertising profile creation.
6.4 Google advertising technology
Point currently uses Google (Google LLC, Google Ireland Limited, or another applicable Google affiliate) as an advertising and measurement vendor, through products such as Google Ads, Google Analytics, and similar Google advertising and measurement services. For these activities Point may make available the categories of marketing-property information described in Section 6.3 and, where lawful, Point-controlled relationship information, such as hashed business contact information or trial or purchase events, together with opt-out and suppression records.
Point will not disclose Customer Content or connected-account data, including Google API data, to Google for advertising, retargeting, audience building, or advertising profile creation. Any audience or conversion products Point uses are based only on Point-controlled relationship information for which Point has appropriate rights, notices, and consent where required.
Google’s privacy role varies by product and configuration and may be that of an independent controller or of a processor or service provider. Point will configure consent and privacy settings where required or appropriate, and will treat disclosures to Google as sale, sharing, targeted advertising, or profiling where applicable law requires.
6.5 Model training
Point does not use Customer Content to train generalized third-party AI models or generalized foundation models unless you expressly authorize it. This exception does not apply to Google Workspace API data, which Point does not use for such training in any case (Section 6.6). Point may use Customer Content to provide and improve the Services for you or your organization, including user-facing features, safety, security, reliability, and quality.
6.6 Google API Services: Limited Use
Point’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This applies to data Point receives from Google APIs with your authorization, including Gmail, Google Calendar, Google Drive, Google Sign-In, and related Google Workspace APIs (“Google user data”). In particular:
- Point uses Google user data only to provide and improve user-facing features that are visible in the Services and that you use or enable;
- Point transfers Google user data to others only as necessary to provide or improve those features, for security purposes, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent;
- Point does not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising, and does not sell it;
- Point does not allow humans to read Google user data unless you give affirmative consent for specific data, it is necessary for security purposes (such as investigating abuse), it is necessary to comply with applicable law, or the data is aggregated and anonymized and used for internal operations as permitted by applicable law; and
- Point does not use Google Workspace API data, including Gmail, Google Calendar, and Google Drive data, to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
These restrictions apply even though Point separately uses Google advertising and measurement services on its marketing properties: Google user data is never sent to Google advertising services.
6.7 Microsoft connected-account data
Point uses data from Microsoft services you connect, such as Outlook, Microsoft 365, OneDrive, and Microsoft Entra ID, accessed through Microsoft APIs, only to provide and improve user-facing Services, operate and secure the Services, comply with law, and act on user or Customer instructions. Point does not use Microsoft connected-account data for advertising, retargeting, sale, or sharing.
6.8 Human access
Point limits human access to Customer Content to circumstances such as support you request, security and abuse investigation, legal compliance, troubleshooting and service operation, or with your consent. Access to Google user data is further limited as described in Section 6.6.
6.9 Private Notes
Scope. This section covers the Private Notes feature, including information about people who do not have a Point account. Its restrictions apply to Candidate Facts, saved Private Notes, and copies or technical representations maintained for the feature, and take precedence over broader permissions elsewhere in this Policy. Other features’ processing of original communications remains governed by the rest of this Policy, and Point does not use those provisions to repurpose Private Notes.
Information and sources. When the feature is enabled, Point may prepare proposed facts about a sender from messages the participating user receives (“Candidate Facts”), such as professional developments, stated expertise, ordinary interests, meeting preferences, or non-sensitive life events, together with related references and the user’s selection or correction instructions. Point does not enrich these records from public sources, profile databases, or other users’ communications, and does not create separate profiles of people merely mentioned in a message.
Excluded information. The feature is designed to exclude special-category and other sensitive information, such as information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, health, sex life or sexual orientation, genetic or biometric data, immigration status, or criminal history, as well as government identifiers, credentials, financial identifiers, precise locations, and detailed information about children, including where revealed indirectly. Automated processing can make errors, which users can correct or report. Preparing candidates may involve processing sensitive content in source messages for the purpose of excluding it.
Saving and use. Candidate Facts are shown to the receiving user and become saved Private Notes only when the user affirmatively saves a selection they can review and change. Saved Private Notes are used only for that user, such as in their notes about the sender and as context when that user requests help communicating with the sender. Point does not use candidate or note content for marketing, advertising, sale, cross-user profiling, unrelated features, model training, or general product improvement. Non-content operational information may be used to operate, secure, and measure the feature.
Access and disclosures. Candidate Facts and Private Notes are not made available to other users or workspace administrators through ordinary features or permissions. Point and its authorized providers process them as necessary to deliver the feature, under corresponding restrictions, and limited access may occur for security, support you request, privacy requests, or legal obligations. Point does not disclose this content to advertising partners, data brokers, or prospective investors or purchasers for their independent use, and a successor continuing the Services must maintain these restrictions. Information a user chooses to include in a communication is handled like that communication.
Retention. Unsaved Candidate Facts are kept only for a limited period and are deleted earlier when, for example, the user dismisses them, deletes the source message, disconnects the source account, disables the feature, or closes the account. Saved Private Notes are kept while the account or workspace is active unless the user deletes them or deletion is otherwise required; they are separate from the source messages. Deleted notes are not automatically recreated. Backup copies are handled as described in Section 10, and information retained for a legal obligation or claim is restricted to that purpose.
Legal basis and people who are not Point users. Where GDPR or similar law applies and Point acts as controller, Point relies on legitimate interests (helping users recall information from their existing relationships and prepare user-controlled communications) where those interests are not overridden by the rights of the person described, and on legal obligations where applicable. A user’s choice to use the feature is not consent on behalf of the person described. Where processing requires an additional legal condition, notice, or control, Point will not undertake it unless the requirement is met. Where an organization controls the information, Point processes it on that organization’s behalf.
Choices and rights. Users can correct or delete notes and disable the feature. People described in candidates or notes may contact privacy@getpoint.ai, whether or not they have a Point account, to exercise applicable rights (Sections 12 and 13). Where Point acts for an organization, Point may refer the request to it and assist as required. Requests are verified proportionately, subject to applicable exceptions and the rights of others.
6.10 Cloud storage connections
Scope. This section explains how Point processes data from cloud storage services you connect, such as Microsoft OneDrive, Google Drive, and Dropbox. It applies in addition to the rest of this Policy.
Access you grant. When you connect a cloud storage service, you may choose the access Point receives, such as read-only access or read-and-write access, and whether to include files others have shared with you where the service supports it. The service asks you to grant the corresponding permissions. Depending on the service, a permission may be broader than the features Point uses at a given time; for example, Google Drive offers a read-only permission and a full access permission. Point uses the permissions you grant only as described in this Policy, and you can change or revoke them in Point or in the service’s own settings.
Information Point accesses. Point may access information about the files and folders in the connected storage, such as names, locations, file types, dates, sharing status, and the names and email addresses of people associated with a file, such as its owner or last editor, as well as change notifications from the service. Point may also access the content of files, including files it imports and files you open or use in Point.
Files Point imports. Point may import the content of a selection of files to make them searchable and usable in Point. Point may select files automatically using criteria such as file type and size, recent activity, and your actions in Point, and also imports files you choose, for example by opening, pinning, or adding them to your work in Point. Settings may let you include or exclude folders. Point may list other files by metadata only and may exclude certain files from processing.
Storage, use, and visibility. For imported files, Point may store a copy of the file, text extracted from it, search index data, and related derived information, such as a title or organization in Point’s document features. Point uses this information to show, search, and organize your files, to answer your questions and requests, and to support features you use or enable. Files from your connected cloud storage are designed to be visible in Point only to you, subject to Section 16 and to legal obligations; you share files through the storage service itself. If you attach a file to a message or other item in Point, that copy is handled like other attachments and content of that item.
AI processing. To provide these features, Point may send file information and content to AI and other service providers that process data on Point’s behalf (Section 8), under terms that restrict their use of it. Point does not use data from connected cloud storage for advertising, retargeting, sale, or sharing (Section 6.3), and Google Drive data is subject to Section 6.6.
Read-and-write access. With read-only access, Point can read your files but does not change them. If you grant read-and-write access, Point may create, change, organize, or move files and folders in the connected storage when you ask it to, or as part of features you enable, such as agents acting under your settings. Point may keep records of the changes it makes and, where available, information that allows a change to be undone. Point is designed not to permanently delete files in your connected storage.
Retention. Point generally keeps file listings while the storage service is connected, and keeps imported content while it remains relevant to your use of Point. Imported content may be removed when a file is no longer selected, is deleted or moved to trash in the service, or Point loses access to it, typically within a reasonable period. Records kept to undo a change are kept only for a limited period.
Disconnecting. When you disconnect a cloud storage service, Point stops syncing and lets you choose to:
- keep the information already in Point, hidden from search and other features until you reconnect or remove it; or
- remove the information from Point.
If Point’s access ends in another way, for example because you revoke it in the service’s settings, Point may keep the information hidden until you choose to reconnect, keep, or remove it. Disconnecting a storage connection does not by itself withdraw access you granted Point for other features of the same provider account, such as email or calendar, which you can review in that provider’s account settings. Copies attached to other items in Point stay with those items.
When you delete your Point account, Point deletes your cloud storage connections and the information imported from them, subject to Section 10 (including backups and legal holds).
7. Legal bases for EEA, UK, and similar laws
Where GDPR, UK GDPR, or similar laws apply, Point relies on one or more of the following legal bases:
- Contract. To provide the Services, administer accounts, process payments, provide support, and take steps requested before entering a contract.
- Legitimate interests. To operate, secure, improve, and market our business; prevent fraud and abuse; communicate with business contacts; maintain records; and enforce rights, where those interests are not overridden by applicable rights and interests.
- Consent. Where required, such as for non-essential cookies, advertising technologies, marketing communications, optional integrations, or optional processing.
- Legal obligations. To comply with applicable legal obligations.
- Vital interests or public interest. Rarely, where necessary under applicable law.
You may withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal.
8. How we disclose personal information
Point may disclose personal information to:
- Affiliates for the purposes described in this Policy;
- service providers and processors that provide services such as hosting and infrastructure, storage, AI processing, search, communications and notifications, security, monitoring, analytics, customer support, and payments; a list of subprocessors is available on request or where Point publishes it;
- advertising, marketing, analytics, and measurement partners, including Google where enabled, where lawful and subject to required choices (not including Customer Content or connected-account data);
- third-party providers you authorize, such as email, calendar, messaging, cloud storage, identity, or app-store providers;
- organization admins and other users according to workspace settings, roles, and permissions, and recipients of communications you send;
- professional advisers, such as legal, accounting, audit, tax, and insurance advisers;
- payment processors and financial institutions;
- business partners where relevant to the relationship and lawful;
- government, regulatory, judicial, or law-enforcement authorities where required or appropriate under law;
- counterparties in business transactions, such as actual or prospective acquirers, investors, or lenders, subject to appropriate protections; and
- others with your direction or consent.
Point does not disclose personal information except as described in this Policy, the Agreement, or as permitted or required by law.
9. International transfers
Point is based in the United States, and personal information may be processed in the United States and other countries where Point, its Affiliates, or service providers operate.
Where required, Point uses appropriate transfer mechanisms and safeguards, such as adequacy decisions, standard contractual clauses and their UK and Swiss equivalents, and supplementary measures.
For Organization Customers where Point acts as processor, international transfers are governed by the Agreement and Data Processing Addendum.
10. Retention
Point retains personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, account administration, security, legal compliance, tax and accounting, dispute resolution, and enforcement. Retention varies with the type of information, user settings, Customer instructions, legal requirements, and technical constraints.
| Category | Typical retention approach |
|---|---|
| Account and authentication records | For the life of the account, then for a reasonable period for security, legal, and backup purposes. |
| Customer Content in active accounts | While the account or workspace is active, unless deleted earlier by users, settings, or Customer instructions. |
| Deleted Customer Content | Removed from active systems within a reasonable period; backup copies may persist until overwritten under backup cycles. |
| Connected-account tokens | Until the connection ends or the account is deleted, unless retention is required for security or legal reasons. |
| Search indexes and other derived service data | Generally while the related content or account is retained. |
| Data from connected cloud storage services | As described in Section 6.10. |
| Billing, tax, and transaction records | As required for tax, accounting, audit, and legal obligations. |
| Security, audit, and system logs | As needed to protect the Services, investigate issues, and comply with law. |
| Marketing and advertising records | Until you opt out or withdraw consent where applicable, or they are no longer needed; suppression records kept to honor opt-outs. |
| Support communications | As needed to provide support, improve the Services, resolve disputes, and comply with law. |
| Point chat messages delivered to other people | In each recipient’s account, as described in Section 16.1, including after the sender deletes their account. |
After content is deleted, limited non-content records, such as file names and internal identifiers in deletion or audit records, may remain. When you delete your account, Point deletes or de-identifies your personal information, subject to backup cycles, legal holds, and the other exceptions described in this Policy.
For Organization Customer processor data, retention and deletion may be governed by the Agreement, Data Processing Addendum, Service Documentation, and Customer instructions.
11. Security
Point uses administrative, technical, and organizational measures appropriate to the nature of the data and the risks involved, such as encryption, access controls, monitoring, and incident response.
No method of transmission, storage, or processing is completely secure, and Point cannot guarantee absolute security.
12. Your choices and rights
Depending on where you live and how you use Point, you may have rights to:
- access personal information;
- receive a copy of personal information;
- correct inaccurate personal information;
- delete personal information;
- restrict or object to processing;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- limit use and disclosure of sensitive personal information;
- withdraw consent where processing is based on consent;
- appeal a denied privacy request where applicable; and
- lodge a complaint with a data protection authority.
To make a request, contact privacy@getpoint.ai or use any request method made available in the Services. Point will honor requests as required by applicable law.
We may need to verify your identity and authority before responding. Authorized agents may submit requests where permitted by law and after verification.
If your request relates to Customer Content controlled by an Organization Customer, we may direct you to that organization.
13. California Notice at Collection and state privacy disclosures
This Section applies to California residents and, where similar laws apply, residents of other U.S. states.
13.1 Categories collected, purposes, and retention
| Category | Examples | Purposes | Retention |
|---|---|---|---|
| Identifiers | Name, email address, account and provider identifiers, IP address, device, cookie, and advertising identifiers | Providing the Services, accounts, support, security, communications, billing, analytics, and advertising | As described in Section 10 |
| California Customer Records information | Contact, billing, and account information | Billing, subscriptions, account administration, support, sales, and marketing | As described in Section 10 |
| Commercial information | Plans, purchases, trial status, usage records | Billing, service administration, analytics, and advertising | As described in Section 10 |
| Internet or electronic network activity | Device and usage data, diagnostics, cookies, referral and campaign information | Security, operations, analytics, improvement, and advertising | As described in Section 10 |
| Geolocation data | Approximate location from IP address; timezone | Security, localization, and time-aware features | As described in Section 10 |
| Audio, electronic, visual, or similar information | Messages, emails, files, attachments, support communications, voice audio and transcripts when voice is used | Providing the Services, support, automation, and security | As described in Section 10 |
| Professional or employment-related information | Employer, title, role, organization membership | Account administration, relationship management, and workspace features | As described in Section 10 |
| Inferences | Preferences, priorities, summaries, labels, style settings, and marketing segments from non-Customer-Content activity | Personalization, user-facing features, and, for non-Customer-Content information, sales and advertising where lawful | As described in Section 10 |
| Sensitive personal information | Account credentials or tokens, contents of communications and files, sensitive details in Customer Content | Providing and securing the Services, legal compliance, and customer-authorized processing | As described in Section 10 |
Sources of each category are described in Section 4, and categories of recipients in Section 8. For Candidate Facts and Private Notes, the narrower purposes, disclosures, and retention described in Section 6.9 apply instead of the broader descriptions above.
13.2 Sale, sharing, targeted advertising, and retargeting
Point does not sell Customer Content and does not use Customer Content or connected-account data for cross-context behavioral advertising, targeted advertising, or retargeting.
Point may disclose identifiers, internet or electronic network activity, commercial information, and related inferences from its websites and marketing relationships to advertising, analytics, and measurement partners, including Google where enabled, for purposes such as targeted advertising, retargeting, audience management, and measurement. Some privacy laws treat these disclosures as “sharing,” “targeted advertising,” or “sale” even if no money is exchanged.
Where required, Point will provide a “Do Not Sell or Share My Personal Information” or comparable opt-out method, cookie settings, and handling of legally required opt-out preference signals, and will configure its advertising tools to reflect those choices. Opting out does not affect service, transactional, security, or non-targeted communications.
13.3 Sensitive personal information
Point does not use or disclose sensitive personal information to infer characteristics about you, or for advertising or retargeting, unless Point provides the required right to limit and other legally required notices or controls.
13.4 Rights
California residents may have rights to know, access, correct, delete, obtain a copy of, opt out of sale or sharing, and limit use of sensitive personal information, and to be free from discrimination for exercising these rights.
13.5 Global Privacy Control
Where required by law, Point will honor browser-based opt-out preference signals, such as Global Privacy Control, as an opt-out of sale, sharing, and targeted advertising for the browser or device that sends the signal.
13.6 Minors
Point does not knowingly sell or share personal information of individuals under 16.
14. Cookies, analytics, advertising, and “Do Not Track”
Point may use cookies, pixels, SDKs, local storage, device identifiers, and similar technologies for essential operation, authentication, security, preferences, analytics, performance, marketing, advertising, and measurement where lawful.
| Category | Examples | Choice approach |
|---|---|---|
| Essential and security technologies | Sign-in, session management, security protections, fraud prevention | Required for the Services and generally cannot be disabled through Point’s cookie controls |
| Preference and functional technologies | Language, display, and saved settings | May be configurable in browser, device, or Point settings |
| Analytics and performance technologies | Usage analytics, crash reporting, diagnostics, Google Analytics where enabled | Subject to consent or opt-out where required |
| Advertising and retargeting technologies | Google advertising tags and similar conversion and retargeting technologies | Subject to consent or opt-out where required; may be treated as sale, sharing, or targeted advertising under some laws |
Point’s current advertising and measurement vendor is Google (see Section 6.4). Where required, Point will provide cookie notices, consent mechanisms, and opt-out controls. In jurisdictions requiring opt-in consent for non-essential cookies, such as the EEA, the UK, and Switzerland, Point will seek consent before using advertising or non-essential analytics technologies, and may use consent-signaling tools so that vendor tags respect those choices.
Some browsers send “Do Not Track” signals. There is no uniform standard for responding to them. Point responds to legally required opt-out preference signals, such as Global Privacy Control, where applicable.
15. Marketing choices
Point may send business, product, event, and promotional communications where lawful. You may opt out of marketing emails using the unsubscribe link or by contacting us. Even if you opt out, Point may still send transactional, service, security, legal, billing, and account communications.
16. Organization workspaces
If you use Point through an organization:
- your organization may control the workspace and Customer Content;
- admins may access, manage, export, delete, or restrict information associated with the workspace, according to the Services’ features and the Agreement;
- your organization’s policies may apply; and
- Point may process Customer Content on your organization’s behalf under the Agreement.
Contact your organization for questions about its privacy practices.
16.1 Point chat with people outside your organization
Point chat lets Point users message each other across organizations.
- Being found. Point users may be able to see that you are on Point, and send you a message request, if they have one of your email addresses, for example in their contacts or in accounts connected to Point in their organization. This is on by default, and you can turn it off in your settings. Turning it off stops people from finding you by your email address but does not remove you from chats you have already joined, and people who already know your address may still send you a request, which you can decline or block. Point does not show your email address through this feature and may exclude some addresses from being found.
- Message requests and group chats. Until you accept a request, you see limited information about the sender, such as their name and photo. In some cases, such as when you share an organization on Point with the sender, a chat may connect without a request. You join group chats that include people outside your organization only if you accept.
- Names shown to others. People in other organizations see your name and photo only where you are connected with them on Point or they saved you as a contact; otherwise, and in features such as search and AI summaries, Point may show a stand-in name. Point does not write your name or photo into another organization’s contacts.
- What recipients receive. Point delivers a copy of each message, attachment, and reaction you send into the account on Point where each recipient receives it. Point may keep an in-transit copy of attachments until delivery completes or fails.
- If you delete your account. Your account, profile, verified addresses, connections, blocks, and requests are deleted, and your open cross-organization chats close or you leave them. Messages you already sent stay in recipients’ copies, under a stand-in name, as a sent email stays in its recipients’ mailboxes. A copy held in an organization’s account is that organization’s record, processed by Point on its behalf. A copy held in an account where the recipient is the only member is kept as that recipient’s record, based on their legitimate interest in their correspondence and, where applicable, legal obligations or claims, and is deleted when that recipient deletes their own account.
17. Third-party services
The Services may link to or integrate with third-party services, such as email, calendar, messaging, and cloud storage providers, app stores, payment processors, identity providers, advertising and analytics providers, and AI providers. Third-party services have their own terms and privacy policies, and Point is not responsible for their privacy practices.
When you or your organization connects a Google, Microsoft, Dropbox, Slack, or other provider account, that provider may continue to process personal information under its own terms with you or your organization. Point’s access to that account is limited by the permissions, provider policies, and settings you authorize.
Point’s use of Google as an advertising vendor is separate from Point’s access to Google APIs, such as Gmail, Google Calendar, Google Drive, and Google Sign-In. Point does not use Google API data or Customer Content for Google advertising, retargeting, or advertising profile creation.
18. Children
The Services are not directed to children under 13, and Point does not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Point, contact us.
19. Changes to this Policy
Point may update this Policy from time to time. The updated version will become effective when posted or otherwise communicated, unless a later effective date is stated. If required by law, Point will provide additional notice of material changes.
20. Contact
For questions or requests about this Policy or Point’s privacy practices, contact:
Point
American River Tech Solutions, Inc
4770 Duckhorn Dr, Sacramento, CA 95834
Email: privacy@getpoint.ai
Website: getpoint.ai
For EEA, UK, or Swiss individuals, Point may provide additional representative or data protection officer contact details if required by law.