Privacy Policy

    Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.

    Effective Date: December 18, 2025

    Table of Contents

    Introduction

    Thank you for visiting pestai.io (the "Website"). Your privacy is important to us. This Privacy Policy (the "Policy") describes the types of information Pest AI and/or app.pestai.io (the "Company", "us", "we", or "our") may collect from you or that you may provide when you visit the Website and the products, features, materials, and services we offer (collectively with the Website, the "Services"). This Policy also describes our policies and procedures for collecting, using, maintaining, protecting, and disclosing that information.

    This Policy applies to information we collect on the Website and through your use of the Services generally (including when you register for an account), and through communications between you and the Website (including email, text, and other electronic messages).

    Important Notice

    This Policy does not apply to information collected by third parties, including any websites, services, and applications that you elect to access through the Services.

    Please review this Policy carefully. By accessing or using the Services (or by clicking on "accept" or "agree" to this Policy when prompted), you agree to the terms of this Policy on behalf of yourself or the entity or organization that you represent. If you do not agree to any term in this Policy, you should refrain from further use of our Services.

    Changes to Our Privacy Policy

    This Policy was last revised on the date noted at the top of this page. We may update this Policy from time to time. If we make material changes, we will post the updated Policy on this page and notify you of such changes by means of:

    • • An email to the email address specified in your account
    • • A message on the Services
    • • A notice on the Website home page

    Your continued use of the Services after we make changes is deemed to be acceptance of those changes, so please check the Policy periodically for updates.

    Information We Collect

    We receive several types of information about you from various sources, including:

    Information and Content That You Give Us

    We collect personal information that you knowingly choose to disclose. This may include:

    • Personal Information (or Data): Your name, address, email address, phone number, username, password, and any other information you directly provide us on or through the Services.
    • Correspondences: Records of your email messages together with your email address, phone number, and our responses.
    • User Content: Information or content you submit to be published or displayed on public areas of the Services or transmitted to other users or third parties.
    • Transaction Information: Information about any purchase or transactions made on the Services, including payment information.
    • Search Queries: Your search queries on the Website.

    Information We Collect Automatically

    We may use various technologies to collect certain information about your equipment, browsing actions, and patterns whenever you interact with the Services. These technologies include:

    • Activity Information: Details of your visits to our Services, including content views, features used, and actions taken.
    • Equipment Information: Information about your computer and internet connection, including your operating system, IP address, browser type, and language.
    • Location Information: Information about the location of your device, including GPS location.

    Technologies We Use

    Cookies

    Small data files stored on the hard drive of your computer that help us enhance your experience.

    Web Beacons

    Small files embedded in webpages and emails to track usage and effectiveness.

    JavaScripts

    Code snippets that help monitor usage of online components.

    Entity Tags

    HTTP mechanisms to accelerate website performance.

    HTML5 Local Storage

    Data cached in your browser to store information for revisits.

    Resettable Device Identifiers

    Advertising identifiers found on mobile devices for tracking and targeting purposes.

    This Policy does not cover the use of tracking technologies by third parties.

    Demographic Information

    We may collect demographic, statistical, or aggregate information that does not identify you personally, but helps us provide better services, such as gender, age, race, household income, and political affiliation.

    How We Use Your Information

    We may use the information we collect about you in a variety of ways, including to:

    1
    Provide the Services and content to you
    2
    Respond to comments and questions, and provide customer service
    3
    Communicate with you about your order, purchase, or account
    4
    Operate, maintain, improve, and analyze the Services
    5
    Send promotional communications and offers
    6
    Allow you to participate in interactive features
    7
    Enforce our legal rights or comply with legal obligations

    How We Share Your Information

    We may share your information in the following circumstances:

    Subsidiaries and Affiliates

    For business purposes.

    Service Providers

    For supporting services such as payment processing and analytics.

    Sale or Transfer of Company

    In case of a merger, restructuring, or sale.

    Legal Obligations

    To comply with court orders, legal processes, or government requests.

    Enforcing Rights

    To enforce our legal rights.

    Marketing Service Providers

    For promotional communications.

    Third-party Platforms

    If you use features linking the Services to external platforms or networks.

    Your Privacy Rights

    Depending on your state of residence, you may have certain rights regarding your personal information. We are committed to complying with all applicable state laws. This section outlines the rights available to residents of states with comprehensive privacy laws.

    Your California Privacy Rights

    If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). These rights include:

    • The Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell.
    • The Right to Delete: You have the right to request the deletion of your personal information that we have collected.
    • The Right to Opt-Out of Sale or Sharing: You have the right to direct us not to sell or share your personal information.
    • The Right to Correct: You have the right to request the correction of inaccurate personal information.
    • The Right to Limit Use and Disclosure of Sensitive Personal Information: You have the right to limit the use and disclosure of your sensitive personal information.
    • The Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

    To exercise these rights, please contact us using the information in the "Contact Us" section below. We will verify your request using the information associated with your account. You may also designate an authorized agent to make a request on your behalf.

    Your Virginia, Colorado, and Other State Privacy Rights

    Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights to those of California residents. These rights may include:

    • The right to access your personal information.
    • The right to correct inaccuracies in your personal information.
    • The right to delete your personal information.
    • The right to obtain a copy of your personal information.
    • The right to opt out of the processing of your personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

    To exercise these rights, please contact us using the information in the "Contact Us" section below.

    Communications Choices and Opt-Outs

    We provide you with choices regarding the communications you receive from us.

    Email Communications

    For commercial email communications, we comply with the CAN-SPAM Act. You may opt-out of receiving promotional emails from us by following the unsubscribe instructions provided in those emails. Please note that even if you opt-out of receiving promotional emails, we may still send you non-promotional emails, such as those about your account or our ongoing business relations.

    SMS and Text Message Communications

    We comply with the Telephone Consumer Protection Act (TCPA) and applicable state laws for all SMS and text message communications. We will obtain your prior express written consent before sending you any marketing text messages. You can opt-out of receiving text messages at any time by replying "STOP" to any message you receive from us. Message and data rates may apply.

    Phone and Telemarketing Communications

    We comply with the TCPA and all applicable state telemarketing laws. We will not contact you by phone for marketing purposes if you are on the National Do Not Call Registry or any applicable state Do Not Call list, unless we have your prior express written consent. When we do contact you, we will do so only during permissible calling hours and will honor any request to be placed on our internal do-not-call list.

    Data Security and Breach Notification

    We have implemented administrative, technical, and physical measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Services, you are responsible for keeping this password confidential.

    Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Services. Any transmission of personal information is at your own risk.

    Tenant Isolation & Cross-Contamination Controls

    Partner data is logically isolated at the database layer. Every record is keyed to an owning organization and protected by PostgreSQL Row-Level Security (RLS) policies enforced on every query. Access tokens are scoped to a single organization, so one partner's data — including AI conversation history, leads, and integration credentials — cannot be read or modified by another partner.

    Voice and messaging AI sessions run in per-partner contexts with separate knowledge bases and prompts. Third-party integrations use partner-specific API credentials stored in an encrypted secret vault and are never shared across partners.

    Database Systems

    Our primary application database is PostgreSQL, hosted on Supabase (running on AWS). Authentication is handled by Supabase Auth (JWT, bcrypt-hashed credentials, MFA for administrators). Serverless business logic runs on Supabase Edge Functions in isolated containers. CRM workflows use GoHighLevel; transactional email is delivered via Resend; AI inference is provided through the Lovable AI Gateway and the partner-selected model provider. All vendors in our production data path are SOC 2 Type II attested (or equivalent) and operate under signed Data Processing Agreements.

    Additional Security Measures

    • Encryption: TLS 1.2+ in transit, AES-256 at rest for databases, backups, and object storage.
    • Access control: Least-privilege, role-based access; SSO and MFA required for administrative accounts; periodic access reviews.
    • Secret management: API keys and integration tokens stored in an encrypted secret vault and rotated on personnel changes or suspected compromise.
    • Input validation & hardening: Server-side schema validation, parameterized queries, output sanitization, and a Content Security Policy.
    • Audit logging & monitoring: Authentication events, administrative actions, and access to sensitive records are logged and monitored for anomalies.
    • Backups & recovery: Automated daily backups with point-in-time recovery; encrypted and access-controlled.
    • Vulnerability management: Automated dependency scanning, security headers, and a responsible-disclosure policy at /.well-known/security.txt.
    • Personnel: Confidentiality agreements and mandatory security training for all team members with production access.
    • Data integrity: Database constraints, transactional writes, and webhook signature verification on inbound integrations.

    Breach Notification

    In the event of a data breach involving your personal information, we will notify you and any applicable regulatory authorities in accordance with applicable state and federal laws. This includes providing you with information about the nature of the breach, the types of information that may have been compromised, and the steps we are taking to address the breach and mitigate its effects.

    Children's Privacy

    Our Services are not intended for children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we learn we have collected or received personal information from a child under 13 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 13, please contact us.

    We comply with the Children's Online Privacy Protection Act (COPPA) and other applicable laws regarding children's privacy. For more information about COPPA and children's privacy, please visit the Federal Trade Commission's website.

    Data Retention

    We retain your personal information for as long as your account is active or as needed to provide you with our Services. Upon cancellation of your account or non-payment, your account and associated data will be placed in an archived mode for a period of two (2) years. After this period, your personal information will be permanently deleted from our systems, unless we are required by law to retain it for a longer period.

    Cookies and Other Tracking Technologies

    We and our third-party partners use cookies and similar tracking technologies to provide and support our Services. These technologies are essential for the proper functioning of our application. While you may be able to block or delete cookies through your browser settings, doing so may result in a poor user experience and loss of functionality. The cookies we use may be set by us or by the third-party resources we utilize. You may clear or reset your cookies at any time, but new cookies may be required for the Services to function properly.

    Personalization & Your Data

    To make this site feel relevant to your business, we store a small amount of information directly in your browser. This data never leaves your device unless you submit a form to us.

    What we store in your browser

    • Approximate location (city, region, country) derived from your IP address — refreshed every 24 hours.
    • Company name or website if you provide it in our welcome dialog, plus any public information we look up about it.
    • Your role (owner, operator, technician, etc.) and first name if you share them.
    • Tour-completion flags so we don't re-show the welcome experience.
    • • A single consent cookie (pestai_personalization) to remember your choice below.

    Everything except the consent cookie lives in your browser's local storage. We do not sell or share this data. If you submit a form, the information you provided plus the personalization data above is sent to us so we can serve you better.

    Your controls

    These controls only affect this browser. Status: Personalization is ON

    Third-Party Services

    We use various third-party services to operate our business and provide our Services. These services may have access to your personal information for the purpose of performing services on our behalf. The third-party services we use include, but are not limited to:

    HighLevel
    Google Workspace
    ClickUp
    Stripe
    Gleap
    QuickBooks

    In addition to these services, we may leverage other third-party providers for various services. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies.

    International Users

    Our Services are intended for and directed to users in the United States. We do not currently offer our Services to users outside of the United States. If you are a user located outside of the United States, you should not sign up for our Services. If you are interested in future possibilities of expansion, please contact us.

    Contact Us

    We welcome your questions, comments, and concerns about privacy. You can contact us at:

    Contact Information

    PA

    Pest AI

    AI Automation Solutions

    Address

    18653 Ventura Blvd Ste 194
    Tarzana, CA 91356

    Privacy Protected

    Your privacy and data security are our top priorities. We're committed to transparency and protecting your rights.

    References

    1. California Consumer Privacy Act (CCPA)
    2. US State Privacy Legislation Tracker
    3. CAN-SPAM Act: A Compliance Guide for Business
    4. SMS Marketing Laws by State: A 2025 Compliance Guide
    5. TCPA, CAN-SPAM & State Law Guide for 2025 Compliance
    6. TCPA Laws by State: Recent Updates and Compliance
    7. U.S. State Comprehensive Consumer Data Privacy Law
    8. Security Breach Notification Chart
    9. Children's Online Privacy Protection Rule ("COPPA")

    Questions About Our Privacy Policy?

    If you have any questions about this privacy policy or our data practices, please don't hesitate to contact us.

    Contact Privacy Team

    Stay Ahead with AI-Powered Pest Control Insights

    Join pest control operators getting crucial tips on AI, automation & growth.