🛡️ Privacy Policy

ImpactMatrix is committed to protecting your privacy and ensuring the security of your data.

Last Updated: January 24, 2026

Privacy at a Glance

  • • We collect only the data necessary to provide our sustainability assessment and planning services
  • • Your company data is never sold to third parties
  • • Community tier users contribute anonymized data to improve platform insights
  • • You have full control over your data with export and deletion rights
  • • We use industry-standard encryption and security practices

1. Information We Collect

1.1 Account Information

When you create an account with ImpactMatrix, we collect:

  • Full name and email address
  • Company name, industry, and size
  • Job title and role
  • Password (encrypted and never stored in plain text)
  • Account creation date and authentication method

1.2 Sustainability Assessment Data

To provide our services, we collect:

  • Environmental practices and metrics (energy use, emissions, waste management)
  • Social initiatives (diversity, employee welfare, community engagement)
  • Governance structures and policies
  • Economic sustainability measures
  • Technological sustainability approaches
  • Connectedness and stakeholder engagement data
  • SDG alignment and goals

1.3 Usage Information

We automatically collect:

  • Pages visited and features used
  • Time spent on the platform
  • Device type, browser, and operating system
  • IP address and general location
  • Referral source

1.4 Payment Information

For paid subscriptions, we process securely through Stripe and maintain:

  • Subscription tier and status
  • Payment history and transaction IDs
  • Billing address
  • Last four digits of credit card (via Stripe)

2. How We Use Your Information

2.1 Service Provision

  • Provide sustainability assessments and recommendations
  • Generate customized reports and dashboards
  • Track progress towards sustainability goals
  • Facilitate collaboration within your organization
  • Enable consortium creation and partnerships

2.2 Platform Improvement

We use aggregated and anonymized data to:

  • Improve our algorithms and recommendations
  • Develop new features and functionality
  • Create industry benchmarks and insights
  • Train our AI models for better assessments

Community Tier Note: Community tier users contribute anonymized assessment data to help improve platform insights. This data is stripped of all identifying information. Premium and Enterprise users retain full data privacy.

3. Data Sharing and Disclosure

âś“ We Do NOT Sell Your Data

ImpactMatrix does not sell, rent, or trade your personal information or company data to third parties.

3.2 Service Providers

We share data with trusted service providers:

  • Stripe: Payment processing (PCI-compliant)
  • AWS: Cloud hosting and data storage
  • SendGrid: Email delivery
  • Google OAuth: Authentication (optional)
  • OpenAI: AI-powered recommendations (anonymized queries only)

4. Data Security

4.1 Security Measures

  • Encryption: All data uses TLS/SSL encryption in transit
  • Data at Rest: Sensitive data is encrypted in databases
  • Access Controls: Role-based access with multi-factor authentication available
  • Security Audits: Periodic vulnerability assessments and penetration testing
  • Infrastructure: Hosted on AWS with SOC 2 compliance
  • Passwords: Hashed using bcrypt with strong salting

4.2 Data Breach Notification

In case of a data breach, we will notify affected users within 72 hours via email with details about the incident and steps being taken.

5. Your Rights and Choices

5.1 Access and Portability

You can request a copy of your data in machine-readable format (JSON/CSV) through your account settings or by contacting us.

5.2 Deletion

You may request deletion of your account and data at any time. Upon request, we will:

  • Delete your account and personal information within 30 days
  • Remove your data from active systems and backups
  • Retain only anonymized data for legal compliance

5.3 Opt-Out of Communications

You can opt out of marketing emails by clicking the unsubscribe link or updating notification preferences. Note that you cannot opt out of essential service communications.

6. Data Retention

We retain data according to the following schedule:

  • Account Data: While active, deleted within 30 days of closure
  • Assessment Data: For duration of subscription plus 90 days
  • Payment Records: 7 years for tax compliance
  • Support Communications: 2 years
  • Backup Data: Removed within 90 days of deletion request

Contact Us

If you have questions about this Privacy Policy or your data, please contact us:

Email: privacy@impactmatrix.io

Data Protection Officer: dpo@impactmatrix.io

Response Time: We aim to respond within 72 hours

For complete Terms of Service, visit Terms of Service.

Ask Privacy Questions