TerritoryIO

Privacy Policy

Effective date: August 12, 2026 · Last updated: August 12, 2026

This Privacy Policy describes how TerritoryIO (“TerritoryIO,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the TerritoryIO website, web application, mobile applications (iOS and Android), and related services (collectively, the “Services”). This page is the public privacy policy URL for TerritoryIO, including for Apple App Store and Google Play Store listings.

Contents

  1. Who we are
  2. Scope of this policy
  3. Information we collect
  4. How we use information
  5. Legal bases (where applicable)
  6. How we share information
  7. Mobile app specifics
  8. Cookies, sessions, and similar technologies
  9. Data retention
  10. Security
  11. International transfers
  12. Your rights and choices
  13. Children’s privacy
  14. Third-party services and links
  15. Changes to this policy
  16. Contact us

1. Who we are

TerritoryIO is a multi-tenant sales intelligence platform that helps organizations manage territories, accounts, campaigns, competitive intelligence, and related sales workflows through our web portal and mobile apps.

For privacy requests, contact us at hello@territoryio.com.

2. Scope of this policy

This policy applies to:

  • The TerritoryIO web application and public website pages
  • The TerritoryIO mobile applications for iOS and Android
  • Related APIs, authentication, notifications, and support channels

TerritoryIO is typically used by businesses. Customer organizations (“Customers”) control the business data they upload or configure in their tenant (for example accounts, contacts, equipment, and campaign data). Where we process that data on a Customer’s behalf, the Customer is the data controller for that business content and we act as a processor/service provider, except where we determine the purposes of processing (such as operating our platform accounts, security, billing, and product analytics).

3. Information we collect

3.1 Account and profile information

  • Name, work email address, and password (stored in hashed form)
  • Organization / company name and related tenant settings
  • Role and permission information within your organization
  • Optional multi-factor authentication (MFA) enrollment data and backup codes (hashed)
  • Profile preferences and settings you configure in the Services

3.2 Business and customer content

Depending on how your organization uses TerritoryIO, this may include:

  • Accounts, contacts, territories, campaign definitions and results
  • Equipment and competitive intelligence records
  • Imported files (such as CSV/XLSX) and mapping templates
  • Brochures or documents uploaded for extraction and comparison
  • AI chat / assistant prompts and responses generated within the product
  • Notes, leave-behind materials, notifications, and similar workflow content

3.3 Device, session, and technical information

  • IP address, approximate location derived from IP, browser type, and device type
  • Device identifiers used for session security and mobile sync
  • Push notification tokens (mobile) to deliver alerts you enable
  • Log data, diagnostic information, and timestamps of authentication and API activity
  • Usage events needed to operate features such as credits, rate limits, and audit trails

3.4 Payment and subscription information

If your organization purchases a paid plan, payment card details are processed by our payment provider (for example Stripe). TerritoryIO does not store full card numbers on our servers. We may receive limited billing metadata such as subscription status, invoices, and payment confirmation.

3.5 Communications

  • Emails and messages you send to us (support, verification, password reset)
  • In-app notification preferences and delivery status

4. How we use information

We use information to:

  • Provide, operate, secure, and improve the Services
  • Authenticate users, manage sessions, and enforce role-based access and tenant isolation
  • Send transactional messages (verification, password reset, security alerts, product notices)
  • Deliver push and in-app notifications related to campaigns, opportunities, and account activity
  • Process imports, generate insights, run AI-assisted features, and support offline mobile sync
  • Meter usage (such as credits), administer subscriptions, and prevent abuse or fraud
  • Maintain audit logs and comply with legal obligations
  • Respond to support requests and investigate security incidents

We do not sell personal information. We do not use Customer business content to train public foundation models for unrelated third parties, except as needed to provide AI features inside TerritoryIO under our configured providers and contractual controls.

5. Legal bases (where applicable)

If you are in a region that requires a legal basis for processing (such as the EEA/UK), we rely on:

  • Contract — to provide the Services you or your organization request
  • Legitimate interests — for security, product improvement, and fraud prevention
  • Consent — where required (for example certain optional notifications or cookies)
  • Legal obligation — when we must retain or disclose information to comply with law

6. How we share information

We may share information with:

  • Your organization — administrators and authorized users within your tenant, according to roles and permissions
  • Service providers — hosting, email delivery, payment processing, analytics/diagnostics, AI providers, and push notification infrastructure (such as Firebase Cloud Messaging), under appropriate agreements
  • Professional advisors — when needed for legal, accounting, or security matters
  • Authorities — when required by law, court order, or to protect rights, safety, and security
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate protections

Because TerritoryIO is multi-tenant, we design the platform so one organization’s data is not available to another organization’s users. Platform administrators may access tenant data only as needed for support, security, impersonation/audit workflows that your organization enables, or legal compliance.

7. Mobile app specifics

When you use the TerritoryIO mobile apps, we may additionally process:

  • Push notification tokens to send campaign, opportunity, and account alerts
  • Device IDs for secure sessions, token refresh, and offline sync
  • Locally cached data on your device to support offline or low-connectivity use; clearing app data or uninstalling removes local caches
  • App diagnostics needed to troubleshoot crashes and improve reliability

You can disable push notifications in your device settings. Doing so may limit alerts but will not prevent core sign-in and data access features that do not depend on push delivery.

TerritoryIO mobile apps are intended for authorized business users (for example sales representatives) of Customer organizations. Access is controlled by your organization’s administrators.

8. Cookies, sessions, and similar technologies

The web application uses cookies or equivalent local storage as needed for authentication, session continuity, CSRF protection, and essential application functionality. We use these technologies to keep you signed in securely and to operate the product. Where non-essential cookies are introduced in the future, we will update this policy and provide choices as required by law.

9. Data retention

We retain information for as long as needed to provide the Services, fulfill the purposes described in this policy, meet legal and accounting requirements, resolve disputes, and enforce agreements.

  • Account credentials and profile data are kept while your account is active
  • Session and device records are retained according to security and operational needs and may be revoked by you or administrators
  • Customer business content is retained for the life of the Customer subscription/tenant unless deleted by authorized users or as otherwise agreed
  • Audit logs and security records may be retained longer where needed for compliance and investigations

When an organization closes its account or requests deletion, we will delete or de-identify personal data within a reasonable period, except where retention is required by law or needed for legitimate security, dispute, or billing purposes.

10. Security

We implement administrative, technical, and organizational measures designed to protect information, including encrypted transport (HTTPS), hashed passwords, JWT-based API authentication with refresh-token controls, role-based access, tenant isolation controls, and MFA options for privileged roles.

No method of transmission or storage is completely secure. Please use a strong unique password, enable MFA when available, and notify us promptly of any suspected unauthorized access.

11. International transfers

We may process and store information in the United States and other countries where we or our service providers operate. If personal data is transferred across borders, we use appropriate safeguards required by applicable law (such as contractual protections with processors).

12. Your rights and choices

Depending on your location and role, you may have rights to:

  • Access, correct, or update personal information
  • Request deletion or restriction of processing
  • Object to certain processing or request data portability
  • Withdraw consent where processing is based on consent
  • Opt out of certain non-essential communications

If you use TerritoryIO through your employer or another organization, many requests should be directed first to your organization administrator, because they control tenant membership and business content. You may also contact us at hello@territoryio.com. We may need to verify your identity before fulfilling a request.

California and similar U.S. state privacy laws: we do not sell personal information and do not share it for cross-context behavioral advertising as those terms are commonly defined. You may still contact us to exercise applicable rights.

13. Children’s privacy

The Services are designed for business use and are not directed to children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

14. Third-party services and links

The Services may integrate with or link to third-party products (payment processors, email providers, map/places data providers, AI providers, and push notification platforms). Their privacy practices are governed by their own policies. We encourage you to review those policies when you use third-party features.

15. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, where appropriate, provide additional notice. Continued use of the Services after an update means you acknowledge the revised policy, to the extent permitted by law.

16. Contact us

Questions about this Privacy Policy or TerritoryIO privacy practices:

  • Email: hello@territoryio.com
  • Product: TerritoryIO web and mobile applications
  • Public policy URL: /privacy
Home · Sign in · Privacy Policy