Legal

Privacy Policy

Last Updated: February 2026

1. Introduction

BoardKit™ ("we," "our," or "us") respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit boardkit.co ("Site") and use our products and services ("Services").

2. Information We Collect

Information You Provide: Name, email address, billing address, and payment information when you make a purchase. Payment processing is handled by Stripe; we do not store your credit card numbers. We also collect information you provide when you contact us via email, and organizational information you input when using our AI-powered tools (Policy Generator, Board Packet Generator) to generate documents.

Information Collected Automatically: Pages visited, time spent on pages, click patterns, referring URLs, browser type, operating system, and device type. We use privacy-respecting analytics tools to understand how visitors use our Site. We do not use invasive tracking or sell your data to advertisers.

3. How We Use Your Information

We use your information to process purchases and deliver digital products, send order confirmations and delivery emails, provide customer support, generate AI-powered governance documents based on your inputs, improve our products and services, send product updates to existing customers (you may opt out at any time), and comply with legal obligations.

We do not sell your personal information to third parties, use your data for targeted advertising, share your organizational data submitted to AI tools with other customers or third parties, or use your AI tool inputs to train AI models.

4. Third-Party Services

We use Stripe for payment processing, Vercel for website hosting, SendGrid for email delivery, and Anthropic as our AI model provider for governance tools. We only share the minimum information necessary for each service to function. We do not share your information with third parties for their marketing purposes.

5. AI Tool Data Handling

When you use BoardKit™ AI tools, the organizational information you enter (company name, sector, stage, governance parameters) is sent to our AI provider to generate your documents. We do not permanently store the specific inputs you provide to AI tools after your document is generated. Your inputs are not used to train or improve AI models. You retain full ownership of all documents generated through our AI tools. We treat all AI tool inputs as confidential business information.

6. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your information, including TLS/SSL encryption for all data in transit, Stripe PCI-DSS compliant payment processing, access controls limiting employee access to customer data, and regular security review of our systems and third-party integrations.

No method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Data Retention

Purchase records are retained for the duration of your customer relationship and as required for tax and legal purposes (typically 7 years). Email communications are retained for customer support purposes. AI tool inputs are not retained after document generation. Analytics data is aggregated and anonymized, and retained for up to 24 months.

8. Your Rights

Depending on your jurisdiction, you may have the right to access the personal information we hold about you, correct inaccurate personal information, delete your personal information, opt out of marketing communications, and export your data in a portable format. To exercise any of these rights, contact us at privacy@boardkit.co. We will respond within 30 days.

9. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). We do not sell personal information. You may request disclosure of the categories and specific pieces of personal information we have collected. Contact privacy@boardkit.co.

10. Children's Privacy

Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered customers and posted on this page with an updated "Last Updated" date.

12. Contact Us

For privacy-related inquiries, email privacy@boardkit.co.