Hiro Analytics Inc.
Last updated: November 21, 2024
Hiro Analytics Inc. (“Hiro Analytics,” “we,” “us,” or “our”) provides retention marketing analytics services that help agencies and brands analyze their marketing performance across channels and platforms. This Privacy Policy explains how we collect, use, store, and protect information in connection with our services.
We never sell your data—never have, never will.
This Privacy Policy applies to:
Hiro Analytics operates in two distinct capacities:
As a Data Controller: For information we collect directly about you (account information, billing details, website interactions)
As a Data Processor: For marketing and e-commerce data we process on your behalf from integrated platforms (Klaviyo, Attentive, Postscript, Sendlane, Yotpo, and similar services)
This policy does not govern the data practices of the third-party platforms you integrate with Hiro Analytics (such as Klaviyo, Shopify, Attentive, etc.). Please refer to those platforms’ privacy policies for information about their data practices.
For detailed information about how we process data from your integrations on your behalf, please refer to our Data Processing Agreement.
When you sign up for Hiro Analytics, we collect:
Why we collect this: To create and manage your account, provide customer support, process payments, and communicate about service updates and changes.
When you connect third-party platforms to Hiro Analytics, we collect and process data through their official APIs:
Why we collect this: To provide analytics, generate reports, track marketing attribution, analyze campaign performance, and deliver the retention marketing insights you contracted for.
Data Retention for Integration Data: - Email and SMS engagement data: From January 1, 2023 to present - Order data: From the beginning of your integration to present (to determine first-time vs. returning customer patterns)
To protect end-user privacy and maintain data minimization principles, Hiro Analytics does not collect, process, or store the following personally identifiable information (PII) from your integrated platforms:
All profile data is processed using anonymized identifiers, ensuring we can provide analytics without accessing or storing personal information about your customers.
We automatically collect:
Why we collect this: To maintain platform security, prevent fraud, troubleshoot technical issues, and improve service performance.
We use cookies and similar tracking technologies to:
You can control cookies through your browser settings. Note that disabling cookies may limit some platform functionality.
If you contact us with questions, feedback, or support requests, we retain:
Why we collect this: To provide customer support, improve our services, and maintain records for quality assurance.
We use your account information to:
We process integration data solely to provide analytics services contracted by you:
Data is never used for: - Training AI or machine learning models (except for your specific analytics) - Marketing our services to your customers - Sharing with other Hiro Analytics customers - Any purpose other than providing services to you
Hiro Analytics has never sold customer data and never will. We do not share, rent, or sell your information to third parties for their marketing purposes.
We share data only with trusted service providers who help us deliver our services:
| Sub-processor | Purpose | Data Access |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and data storage | Integration data, account data |
| Retool | Internal tools for data access and reporting | Limited access for support and analysis |
| Stripe | Payment processing | Billing information only |
All sub-processors are contractually obligated to: - Use data only for specified purposes - Implement appropriate security measures - Comply with applicable data protection laws - Not share data with unauthorized parties
We may disclose information when required to:
In such cases, we will make reasonable efforts to notify you unless prohibited by law.
If Hiro Analytics is involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
Hiro Analytics adheres to the following principles when processing data:
We collect only the data necessary to provide our analytics services. We do not collect PII from end users and use anonymized identifiers wherever possible.
Data is used solely for analytics, reporting, and insight generation. Integration data is processed exclusively to deliver services to you and is never shared with third parties for unrelated purposes.
All customer profile data is processed using anonymized identifiers rather than personal identifiers, ensuring privacy by design.
We retain data only as long as necessary for service provision and in accordance with our data retention policies: - Active accounts: Data retained for the duration of your subscription - Canceled accounts: Data made inaccessible immediately; permanently deleted within 60 days - Legal requirements: Some data may be retained longer to comply with legal, tax, or regulatory obligations
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We implement appropriate technical and organizational measures including: - Role-based access controls - Multi-factor authentication - Regular security audits - Incident response procedures - Continuous monitoring and logging
We are committed to being transparent about our data practices and providing you with control over your information.
Our data processing activities are conducted under the following legal bases:
Your responsibility: As the data controller for integration data, you are responsible for ensuring you have a lawful basis to share data with Hiro Analytics and that your customers are appropriately informed about this processing.
You have the right to:
To exercise any of these rights, contact us at: - Email: brendan@hiroanalytics.com - Subject Line: “Data Subject Rights Request”
We will respond to your request within 30 days and may require verification of your identity to protect your information.
If you receive a data subject rights request from one of your customers regarding data processed by Hiro Analytics on your behalf, please contact us immediately. We will assist you in responding to the request in accordance with applicable data protection laws.
We implement industry-standard security measures including:
In the event of a data breach that affects your information, we will:
All data processed by Hiro Analytics is stored and managed in the United States using Amazon Web Services (AWS) infrastructure.
By using Hiro Analytics services, you acknowledge and consent to the transfer and storage of data in the United States. If you are located outside the United States, please be aware that:
For customers in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on: - Standard Contractual Clauses (SCCs) where applicable - Adequacy decisions recognized by the European Commission - Other lawful transfer mechanisms as required
In some cases, we may be required to retain data longer due to: - Active litigation or regulatory investigations - Legal preservation requirements - Ongoing security incident investigations
We will notify you if a legal hold affects your data.
Hiro Analytics services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a child under 18, we will take steps to delete that information promptly.
If you believe we have collected information from a child, please contact us at brendan@hiroanalytics.com.
We may update this Privacy Policy from time to time to reflect:
When we make significant changes to this policy:
Continued use of our services after changes constitutes acceptance of the updated policy.
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA):
Note: Hiro Analytics does not sell personal information.
To exercise these rights, contact us at brendan@hiroanalytics.com.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including those outlined in the “Your Rights and Choices” section above.
You also have the right to lodge a complaint with your local data protection authority if you believe we have not handled your information in accordance with applicable law.
We may send you emails about: - Service updates and new features - Security alerts and important account information - Tips and best practices for using Hiro Analytics - Company news and product announcements
You can opt out of marketing communications at any time by: - Clicking the “unsubscribe” link in any marketing email - Contacting us at help@hiroanalytics.com - Updating your preferences in your account settings
Note: You cannot opt out of essential service communications (security alerts, billing notices, etc.).
For questions, concerns, or requests regarding this Privacy Policy or our data practices:
Brendan Uyeshiro
Chief Technology Officer
Email: brendan@hiroanalytics.com
Email: help@hiroanalytics.com
Hiro Analytics Inc.
1111b S Governors Ave
STE 25084
Dover, DE 19904
United States
For more detailed information about our data practices, please review:
Thank you for trusting Hiro Analytics with your data. Your privacy and security are our top priorities.