Privacy Policy

Hiro Analytics  |  Last updated: April 30, 2026

Hiro Analytics Inc. (“Hiro Analytics,” “we,” “us,” or “our”) provides retention marketing analytics services that help agencies and brands analyze their marketing performance across channels and platforms. This Privacy Policy explains how we collect, use, store, and protect information in connection with our services.

We never sell your data — never have, never will.

Scope and Application

This Privacy Policy applies to:

  • Account Holders: Businesses and agencies that sign up for and use Hiro Analytics services.
  • Authorized Users: Individuals granted access to Hiro Analytics by Account Holders.
  • Website Visitors: Anyone who visits hiroanalytics.com.

Important Distinction: Our Dual Role

Hiro Analytics operates in two distinct capacities:

  • As a Data Controller: For information we collect directly about you (account information, billing details, website interactions).
  • As a Data Processor: For marketing and e-commerce data we process on your behalf from integrated platforms (Klaviyo, Attentive, Postscript, Sendlane, Yotpo, and similar services).

What This Policy Does Not Cover

This policy does not govern the data practices of the third-party platforms you integrate with Hiro Analytics (such as Klaviyo, Shopify, Attentive, etc.). Please refer to those platforms’ privacy policies for information about their data practices.

For detailed information about how we process data from your integrations on your behalf, please refer to our Data Processing Agreement.

1. Account and Business Information (We are the Controller)

When you sign up for Hiro Analytics, we collect:

  • Contact Information: Name, email address, company name.
  • Account Credentials: Login information and authentication data.
  • Billing Information: Payment details, billing address, tax identification (processed through our payment processor).
  • Company Information: Business type, industry, company size.
  • Communication Records: Support tickets, feedback, and correspondence with our team.

Why we collect this: To create and manage your account, provide customer support, process payments, and communicate about service updates and changes.

2. Platform Integration Data (We are the Processor)

When you connect third-party platforms to Hiro Analytics, we collect and process data through their official APIs:

Messaging Engagement Data

  • Message metadata (campaign names, IDs, send times, subject lines, template HTML).
  • Engagement metrics (opens, clicks, unsubscribes).
  • Message performance data across email, SMS, WhatsApp, and push channels.

Profile Data (Anonymized)

  • Profile ID (anonymized identifier — not linked to PII).
  • Email and SMS subscription consent status (subscription date, unsubscribe date).
  • Channel preferences.
  • Source properties (e.g., referring source).
  • Custom properties and behavioral tags (e.g., last active, last updated).

Order and Transaction Data

  • Order ID.
  • Profile ID (anonymized).
  • Order value and currency.
  • Order date and time.
  • Discount and shipping amounts.
  • Product line items and metadata.

Why we collect this: To provide analytics, generate reports, track marketing attribution, analyze campaign performance, and deliver the retention marketing insights you contracted for.

Historical data window for integration data. Where the connected platform makes it available, Hiro Analytics ingests historical engagement data going back to January 1, 2023, and order data going back to the beginning of your integration, to support multi-year cohort, retention, and lifetime-value analyses. For your account specifically, data is retained as set out in the Retention and Deletion section below.

What We Do NOT Collect from Integrations

Hiro Analytics does not collect, process, or store the following personally identifiable information (PII) from your integrated platforms:

  • Email addresses of end users.
  • Phone numbers.
  • Customer names.
  • Physical addresses (billing or shipping).
  • Date of birth.
  • Government-issued identifiers (SSN, passport numbers, etc.).
  • Payment processing metadata or credit card information.
  • Order notes or customer comments.
  • Return or refund reasons.

All profile data is processed using anonymized identifiers, ensuring we can provide analytics without accessing or storing personal information about your customers. Some custom properties, tags, or message metadata that pass through your connected platforms’ APIs may incidentally contain personal information that you or your customers placed in free-text fields (for example, a name typed into a custom property). Hiro Analytics does not request or intentionally use such fields, and we do not attempt to extract or correlate personal information from them. If you become aware that a custom property contains regulated personal data, please contact us at help@hiroanalytics.com so we can suppress that field for your account.

3. Usage and Technical Information

We automatically collect:

  • Log Data: IP addresses, browser type, operating system, access times.
  • Usage Data: Features used, pages viewed, actions taken within the platform.
  • Device Information: Device type, unique device identifiers.
  • Performance Data: System performance metrics, error logs.

Why we collect this: To maintain platform security, prevent fraud, troubleshoot technical issues, and improve service performance.

4. Cookies and Similar Technologies

We use cookies and similar tracking technologies to:

  • Maintain your login session.
  • Remember your preferences and settings.
  • Analyze platform usage and optimize user experience.
  • Perform conversion rate testing and A/B testing.

You can control cookies through your browser settings. Note that disabling cookies may limit some platform functionality.

We do not use cookies or similar technologies for cross-context behavioral advertising, and we do not share data with third-party advertising networks. The cookies we use are limited to first-party functional, analytics, and product-improvement purposes.

Hiro Analytics recognizes the Global Privacy Control (GPC) signal sent by privacy-preference-enabled browsers and extensions. When we receive a GPC signal, we treat it as a valid request to opt out of any “sale” or “share” of personal information for the corresponding browser/device, in accordance with applicable U.S. state law.

Do Not Track. Some browsers offer a “Do Not Track” (“DNT”) signal that allows users to express a preference not to be tracked across websites. Because there is no industry-standard interpretation of DNT signals, Hiro Analytics does not currently respond to DNT browser signals. We do, however, honor Global Privacy Control (GPC) signals as described above, and we do not engage in cross-context behavioral advertising or share personal information with third-party advertising networks regardless of any DNT setting.

5. Voluntary Communications

If you contact us with questions, feedback, or support requests, we retain:

  • Email correspondence.
  • Chat transcripts.
  • Support ticket information.
  • Feedback and feature requests.

Why we collect this: To provide customer support, improve our services, and maintain records for quality assurance.

How We Use Your Information

For Account Holders and Users — we use your account information to:

  • Provide and maintain our services: Create accounts, authenticate users, process payments.
  • Communicate with you: Send service updates, security alerts, billing notifications, and respond to inquiries.
  • Improve our platform: Analyze usage patterns, identify bugs, develop new features.
  • Ensure security: Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations: Maintain records, respond to legal requests, enforce our Terms of Service.

For Integration Data — we process integration data solely to provide analytics services contracted by you:

  • Generate reports and dashboards: Campaign performance, attribution analysis, revenue tracking.
  • Calculate metrics: Customer lifetime value, cohort analysis, retention rates.
  • Provide insights: Marketing channel effectiveness, customer journey analysis.
  • Support decision-making: Data-driven recommendations for marketing optimization.

Data is never used for: (i) training generalized or third-party AI/ML models; (ii) building or improving any model that is used outside of your individual account; (iii) marketing to your customers or end users; (iv) cross-context behavioral advertising; (v) sharing with other Hiro Analytics customers; or (vi) any purpose other than providing the services you have contracted for. Where we use machine learning to power features within your account (for example, anomaly detection or AI search), the underlying models are scoped to your data and are not used to make automated decisions that produce legal or similarly significant effects on individuals.

Data Sharing and Disclosure

We Do Not Sell Your Data. Hiro Analytics has never sold customer data and never will. We do not share, rent, or sell your information to third parties for their marketing purposes.

Limited Sharing with Service Providers (Sub-processors)

We share data only with trusted service providers who help us deliver our services:

Sub-processorPurposeData Access
Amazon Web Services (AWS) Cloud infrastructure and data storage. Integration data and account data, stored encrypted at rest.
Retool Application platform on which the Hiro Analytics web application is built, including the customer-facing reporting, analysis, and support interfaces. All integration data processed under the Agreement; access by Hiro personnel is role-based and limited to reporting, analysis, and support.
Stripe Payment processing. Billing information only.

All sub-processors are contractually obligated to use data only for specified purposes, implement appropriate security measures, comply with applicable data protection laws, and not share data with unauthorized parties. The current sub-processor list is published at hiroanalytics.com/sub-processors.

Legal Obligations

We may disclose information when required to:

  • Comply with valid legal process (subpoenas, court orders).
  • Enforce our Terms of Service.
  • Protect the rights, property, or safety of Hiro Analytics, our customers, or others.
  • Investigate potential violations or security incidents.
  • Respond to government or regulatory inquiries.

In such cases, we will make reasonable efforts to notify you unless prohibited by law.

Business Transfers

If Hiro Analytics is involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

Data Processing Principles

  1. Data Minimization — We collect only the data necessary to provide our analytics services. We do not collect PII from end users and use anonymized identifiers wherever possible.
  2. Purpose Limitation — Data is used solely for analytics, reporting, and insight generation. Integration data is processed exclusively to deliver services to you and is never shared with third parties for unrelated purposes.
  3. Anonymization — All customer profile data is processed using anonymized identifiers rather than personal identifiers, ensuring privacy by design.
  4. Retention Limitation — We retain data only as long as necessary for the purposes for which it was collected, in accordance with the documented retention schedule set out in the Retention and Deletion section below.
  5. Security — All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Measures include role-based access controls, multi-factor authentication, regular security audits, incident response procedures, and continuous monitoring.
  6. Transparency — We are committed to being transparent about our data practices and providing you with control over your information.

Legal Basis for Processing

For Account Data (We are Controller):

  • Contract: Processing necessary to provide services you’ve requested.
  • Legitimate Interest: Improving our services, preventing fraud, ensuring security.
  • Consent: Where explicitly provided (e.g., marketing communications).
  • Legal Obligation: Compliance with applicable laws and regulations.

For Integration Data (We are Processor):

  • Contract: Processing on your behalf as specified in our Data Processing Agreement.
  • Legitimate Interest: Your legitimate interest in business analytics.
  • Consent: Where you have obtained consent from data subjects.

Your responsibility: As the data controller for integration data, you are responsible for ensuring you have a lawful basis to share data with Hiro Analytics and that your customers are appropriately informed about this processing.

Your Rights and Choices

You have the right to:

  • Access: Request a copy of the information we hold about you.
  • Rectification/Correction: Correct inaccurate or incomplete information.
  • Erasure/Deletion: Request deletion of your information (subject to legal retention requirements).
  • Restriction: Request that we limit how we use your information.
  • Portability: Receive your data in a structured, machine-readable format.
  • Object: Object to certain processing activities.
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time.
  • Opt out of “sale” or “sharing” of personal information: Hiro Analytics does not sell or share personal information, but you have the right to direct us not to do so. You can submit such a request at any time using the methods below.
  • Limit use of sensitive personal information: Where applicable, you may direct us to limit our use and disclosure of sensitive personal information to those uses necessary to provide services.
  • Opt out of profiling and automated decision-making technology (ADMT): To the extent we use automated processing that produces legal or similarly significant effects, you may opt out as required by applicable law.
  • Non-discrimination: We will not discriminate or retaliate against you for exercising any of these rights.
  • Authorized agent: You may designate an authorized agent to submit a request on your behalf, subject to verification.
  • Appeal: If we deny a privacy rights request, residents of states whose laws provide an appeal right (including Virginia, Colorado, Connecticut, Texas, Oregon, Delaware, Maryland, Montana, New Hampshire, New Jersey, Indiana, Kentucky, Rhode Island, Tennessee, and Minnesota) may appeal that decision by replying to the denial within 60 days. We will respond to appeals within 60 days.

To exercise any of these rights, contact us at help@hiroanalytics.com with subject line “Data Subject Rights Request.” We will respond within 30 days (extendable by an additional 45 days where reasonably necessary, with notice to you) and may require identity verification.

If you receive a data subject rights request from one of your customers, please contact us immediately. We will assist you in responding in accordance with applicable data protection laws.

State-Specific Privacy Disclosures

California Residents

In the preceding 12 months, Hiro Analytics has collected the following categories of personal information, as defined in Cal. Civ. Code § 1798.140: identifiers (such as name, email address, IP address), customer records (such as billing information), commercial information (such as subscription and transaction records), internet or network activity (such as platform usage logs), and professional information (such as company name and role). We collect this information directly from you, automatically through your use of our services, and from our payment processor. We use it for account creation and management, service delivery, billing, security, fraud prevention, customer support, and product improvement. We disclose it to categories of service providers including cloud infrastructure providers, payment processors, and internal tooling vendors, each bound by written contracts that restrict their use of the information.

We do not collect sensitive personal information as defined under the CCPA. We do not sell or share personal information, as those terms are defined under the CCPA, and have not done so in the preceding 12 months. We do not use personal information for cross-context behavioral advertising.

Retention periods for each category are described in the Retention and Deletion section below.

California residents have the rights described in the Your Rights and Choices section above, including the right to know, the right to delete, the right to correct, the right to opt out of sale/share, the right to limit use of sensitive personal information, the right to opt out of automated decision-making, and the right to non-discrimination. To exercise any of these rights, contact us at help@hiroanalytics.com.

California “Shine the Light” (Cal. Civ. Code § 1798.83). California residents who have an established business relationship with Hiro Analytics may request information once per calendar year about personal information (if any) we disclosed to third parties for those third parties’ own direct marketing purposes during the preceding calendar year. Hiro Analytics does not disclose personal information to third parties for their direct marketing purposes, and therefore has no information to report under this law. To submit a “Shine the Light” request, contact us at help@hiroanalytics.com with the subject line “California Shine the Light Request.”

Nevada Residents (NRS 603A.340)

Nevada law gives consumers the right to direct certain operators of websites and online services not to sell their “covered information.” Hiro Analytics does not sell covered information as defined under Nevada law, and we have no plans to do so. Nevada residents who wish to submit a verified request opting out of any future sale of their covered information may contact us at help@hiroanalytics.com with the subject line “Nevada Opt-Out Request.”

Virginia, Colorado, Connecticut, Texas, Oregon, Delaware, Maryland, Minnesota, Montana, New Jersey, New Hampshire, Indiana, Kentucky, Rhode Island, Tennessee, Utah, Iowa, and Nebraska Residents

Residents of the above states have the rights described in the Your Rights and Choices section above, including the right to access, correct, delete, port, opt out of sale/share, opt out of targeted advertising, and (where applicable) opt out of profiling that produces legal or similarly significant effects. Residents of states whose laws provide an appeal right may appeal a denial of any rights request as described above. We do not engage in targeted advertising and do not sell personal information.

Washington “My Health My Data” Act

Hiro Analytics does not collect, process, or share “consumer health data” as defined by the Washington My Health My Data Act.

Data Security

Technical Measures:

  • Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest.
  • Access Controls: Role-based access control (RBAC) with principle of least privilege.
  • Authentication: Multi-factor authentication (MFA) for all user accounts.
  • Network Security: Firewalls, intrusion detection systems, DDoS protection.
  • Monitoring: Continuous security monitoring and logging.
  • Vulnerability Management: Regular security assessments and penetration testing.

Organizational Measures:

  • Security Policies: Comprehensive information security policies and procedures.
  • Employee Training: Regular security and privacy training for all team members.
  • Access Management: Strict controls on who can access customer data.
  • Incident Response: Documented procedures for identifying and responding to security incidents.
  • Vendor Management: Due diligence and contractual security requirements for all sub-processors.

Data Breach Notification. In the event of a data breach affecting personal information you have provided or that we process on your behalf, we will: notify you without undue delay and, where required by applicable law or our Data Processing Agreement, within the timeframes specified therein (typically within 72 hours of becoming aware of a confirmed breach affecting your data); provide details about the breach and data affected; describe measures taken; advise on protective steps; and cooperate with any notification obligations you may have to your customers.

Data Location and International Transfers

All data is stored and managed in the United States using Amazon Web Services (AWS) infrastructure. By using our services, you acknowledge and consent to data transfer and storage in the United States.

For customers in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs), adequacy decisions recognized by the European Commission, and other lawful transfer mechanisms as required. For UK customers, we rely on the UK International Data Transfer Addendum to the EU SCCs.

Retention and Deletion

We retain personal information only for as long as necessary for the purposes described in this policy. The following schedule sets out our retention practices by category. Where multiple criteria apply, we retain data for the longer of the listed periods.

CategoryRetention period
Account profile (name, email, role)Duration of subscription + 60 days after cancellation.
Authentication and security logs12 months from event.
Billing records and invoices7 years (tax/financial recordkeeping).
Support correspondence3 years from last interaction.
Integration data (engagement, orders) — active accountsFrom data start date through end of subscription.
Integration data — canceled accountsInaccessible immediately on cancellation; permanently deleted within 60 days.
Marketing/contact records (prospects, leads)Until you opt out + 12 months for suppression list maintenance.
Cookies and similar identifiersUp to 13 months from last visit (session cookies are deleted at session end).
Data subject to legal holdDuration of the hold + reasonable disposition window.

We will notify you if a legal hold affects your data due to active litigation, regulatory investigations, or legal preservation requirements.

Children’s Privacy

Hiro Analytics services are not directed to children, and our Account Holders must be 18 or older to register for an account. We do not knowingly collect personal information from anyone under 16 from our website. Through our integrations, we receive only anonymized identifiers from your platforms; we do not knowingly receive identifiable information about children under 13 (which would be subject to the Children’s Online Privacy Protection Act, COPPA), and we do not engage in any processing that would constitute the “sale” of personal information of a minor under 16. If we become aware that we have inadvertently received personal information from a minor, we will take steps to delete that information promptly. Contact us at help@hiroanalytics.com if you believe we have collected information from a child.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, legal requirements, industry best practices, or customer feedback. When we make significant changes, we will update the “Last updated” date, notify you via email, and post the updated policy at hiroanalytics.com/privacy-policy.

Continued use of our services after changes constitutes acceptance of the updated policy.

European Data Protection Rights (GDPR)

If you are located in the EEA, United Kingdom, or Switzerland, you have rights under the GDPR as outlined in the Your Rights and Choices section above. You also have the right to lodge a complaint with your local data protection authority. If we engage in processing that requires the appointment of an EU or UK representative under Article 27 of the (UK) GDPR based on the volume or nature of EEA/UK personal data we process, our representative’s contact details is listed below.

Marketing Communications

We may send you emails about service updates, security alerts, tips for using Hiro Analytics, and company news.

You can opt out of marketing communications at any time by clicking “unsubscribe” in any marketing email, contacting help@hiroanalytics.com, or updating preferences in your account settings. Note: you cannot opt out of essential service communications (which include, but are not limited to, billing notices, security alerts, material changes to this Privacy Policy or our Terms of Service, and notices reasonably necessary to provide the services you have contracted for).

Contact Information

Data Protection Contact: Brendan Uyeshiro, Chief Technology Officer
Email: help@hiroanalytics.com

General Inquiries:
Email: help@hiroanalytics.com

Company Address:
Hiro Analytics Inc.
1111b S Governors Ave, STE 25084
Dover, DE 19904, United States

Related Documents