🛡️ Privacy Policy
ImpactMatrix is committed to protecting your privacy and ensuring the security of your data.
Last Updated: January 24, 2026
Privacy at a Glance
- • We collect only the data necessary to provide our sustainability assessment and planning services
- • Your company data is never sold to third parties
- • Community tier users contribute anonymized data to improve platform insights
- • You have full control over your data with export and deletion rights
- • We use industry-standard encryption and security practices
1. Information We Collect
1.1 Account Information
When you create an account with ImpactMatrix, we collect:
- Full name and email address
- Company name, industry, and size
- Job title and role
- Password (encrypted and never stored in plain text)
- Account creation date and authentication method
1.2 Sustainability Assessment Data
To provide our services, we collect:
- Environmental practices and metrics (energy use, emissions, waste management)
- Social initiatives (diversity, employee welfare, community engagement)
- Governance structures and policies
- Economic sustainability measures
- Technological sustainability approaches
- Connectedness and stakeholder engagement data
- SDG alignment and goals
1.3 Usage Information
We automatically collect:
- Pages visited and features used
- Time spent on the platform
- Device type, browser, and operating system
- IP address and general location
- Referral source
1.4 Payment Information
For paid subscriptions, we process securely through Stripe and maintain:
- Subscription tier and status
- Payment history and transaction IDs
- Billing address
- Last four digits of credit card (via Stripe)
2. How We Use Your Information
2.1 Service Provision
- Provide sustainability assessments and recommendations
- Generate customized reports and dashboards
- Track progress towards sustainability goals
- Facilitate collaboration within your organization
- Enable consortium creation and partnerships
2.2 Platform Improvement
We use aggregated and anonymized data to:
- Improve our algorithms and recommendations
- Develop new features and functionality
- Create industry benchmarks and insights
- Train our AI models for better assessments
Community Tier Note: Community tier users contribute anonymized assessment data to help improve platform insights. This data is stripped of all identifying information. Premium and Enterprise users retain full data privacy.
3. Data Sharing and Disclosure
âś“ We Do NOT Sell Your Data
ImpactMatrix does not sell, rent, or trade your personal information or company data to third parties.
3.2 Service Providers
We share data with trusted service providers:
- Stripe: Payment processing (PCI-compliant)
- AWS: Cloud hosting and data storage
- SendGrid: Email delivery
- Google OAuth: Authentication (optional)
- OpenAI: AI-powered recommendations (anonymized queries only)
4. Data Security
4.1 Security Measures
- Encryption: All data uses TLS/SSL encryption in transit
- Data at Rest: Sensitive data is encrypted in databases
- Access Controls: Role-based access with multi-factor authentication available
- Security Audits: Periodic vulnerability assessments and penetration testing
- Infrastructure: Hosted on AWS with SOC 2 compliance
- Passwords: Hashed using bcrypt with strong salting
4.2 Data Breach Notification
In case of a data breach, we will notify affected users within 72 hours via email with details about the incident and steps being taken.
5. Your Rights and Choices
5.1 Access and Portability
You can request a copy of your data in machine-readable format (JSON/CSV) through your account settings or by contacting us.
5.2 Deletion
You may request deletion of your account and data at any time. Upon request, we will:
- Delete your account and personal information within 30 days
- Remove your data from active systems and backups
- Retain only anonymized data for legal compliance
5.3 Opt-Out of Communications
You can opt out of marketing emails by clicking the unsubscribe link or updating notification preferences. Note that you cannot opt out of essential service communications.
6. Data Retention
We retain data according to the following schedule:
- Account Data: While active, deleted within 30 days of closure
- Assessment Data: For duration of subscription plus 90 days
- Payment Records: 7 years for tax compliance
- Support Communications: 2 years
- Backup Data: Removed within 90 days of deletion request
Contact Us
If you have questions about this Privacy Policy or your data, please contact us:
Email: privacy@impactmatrix.io
Data Protection Officer: dpo@impactmatrix.io
Response Time: We aim to respond within 72 hours
For complete Terms of Service, visit Terms of Service.
Ask Privacy Questions