Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.
Table of Contents
Introduction
Thank you for visiting pestai.io (the "Website"). Your privacy is important to us. This Privacy Policy (the "Policy") describes the types of information Pest AI and/or app.pestai.io (the "Company", "us", "we", or "our") may collect from you or that you may provide when you visit the Website and the products, features, materials, and services we offer (collectively with the Website, the "Services"). This Policy also describes our policies and procedures for collecting, using, maintaining, protecting, and disclosing that information.
This Policy applies to information we collect on the Website and through your use of the Services generally (including when you register for an account), and through communications between you and the Website (including email, text, and other electronic messages).
Important Notice
This Policy does not apply to information collected by third parties, including any websites, services, and applications that you elect to access through the Services.
Please review this Policy carefully. By accessing or using the Services (or by clicking on "accept" or "agree" to this Policy when prompted), you agree to the terms of this Policy on behalf of yourself or the entity or organization that you represent. If you do not agree to any term in this Policy, you should refrain from further use of our Services.
Changes to Our Privacy Policy
This Policy was last revised on the date noted at the top of this page. We may update this Policy from time to time. If we make material changes, we will post the updated Policy on this page and notify you of such changes by means of:
- • An email to the email address specified in your account
- • A message on the Services
- • A notice on the Website home page
Your continued use of the Services after we make changes is deemed to be acceptance of those changes, so please check the Policy periodically for updates.
Information We Collect
We receive several types of information about you from various sources, including:
Information and Content That You Give Us
We collect personal information that you knowingly choose to disclose. This may include:
- Personal Information (or Data): Your name, address, email address, phone number, username, password, and any other information you directly provide us on or through the Services.
- Correspondences: Records of your email messages together with your email address, phone number, and our responses.
- User Content: Information or content you submit to be published or displayed on public areas of the Services or transmitted to other users or third parties.
- Transaction Information: Information about any purchase or transactions made on the Services, including payment information.
- Search Queries: Your search queries on the Website.
Information We Collect Automatically
We may use various technologies to collect certain information about your equipment, browsing actions, and patterns whenever you interact with the Services. These technologies include:
- Activity Information: Details of your visits to our Services, including content views, features used, and actions taken.
- Equipment Information: Information about your computer and internet connection, including your operating system, IP address, browser type, and language.
- Location Information: Information about the location of your device, including GPS location.
Technologies We Use
Cookies
Small data files stored on the hard drive of your computer that help us enhance your experience.
Web Beacons
Small files embedded in webpages and emails to track usage and effectiveness.
JavaScripts
Code snippets that help monitor usage of online components.
Entity Tags
HTTP mechanisms to accelerate website performance.
HTML5 Local Storage
Data cached in your browser to store information for revisits.
Resettable Device Identifiers
Advertising identifiers found on mobile devices for tracking and targeting purposes.
This Policy does not cover the use of tracking technologies by third parties.
Demographic Information
We may collect demographic, statistical, or aggregate information that does not identify you personally, but helps us provide better services, such as gender, age, race, household income, and political affiliation.
How We Use Your Information
We may use the information we collect about you in a variety of ways, including to:
Your Privacy Rights
Depending on your state of residence, you may have certain rights regarding your personal information. We are committed to complying with all applicable state laws. This section outlines the rights available to residents of states with comprehensive privacy laws.
Your California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). These rights include:
- The Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell.
- The Right to Delete: You have the right to request the deletion of your personal information that we have collected.
- The Right to Opt-Out of Sale or Sharing: You have the right to direct us not to sell or share your personal information.
- The Right to Correct: You have the right to request the correction of inaccurate personal information.
- The Right to Limit Use and Disclosure of Sensitive Personal Information: You have the right to limit the use and disclosure of your sensitive personal information.
- The Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise these rights, please contact us using the information in the "Contact Us" section below. We will verify your request using the information associated with your account. You may also designate an authorized agent to make a request on your behalf.
Your Virginia, Colorado, and Other State Privacy Rights
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights to those of California residents. These rights may include:
- The right to access your personal information.
- The right to correct inaccuracies in your personal information.
- The right to delete your personal information.
- The right to obtain a copy of your personal information.
- The right to opt out of the processing of your personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.
To exercise these rights, please contact us using the information in the "Contact Us" section below.
Communications Choices and Opt-Outs
We provide you with choices regarding the communications you receive from us.
Email Communications
For commercial email communications, we comply with the CAN-SPAM Act. You may opt-out of receiving promotional emails from us by following the unsubscribe instructions provided in those emails. Please note that even if you opt-out of receiving promotional emails, we may still send you non-promotional emails, such as those about your account or our ongoing business relations.
SMS and Text Message Communications
We comply with the Telephone Consumer Protection Act (TCPA) and applicable state laws for all SMS and text message communications. We will obtain your prior express written consent before sending you any marketing text messages. You can opt-out of receiving text messages at any time by replying "STOP" to any message you receive from us. Message and data rates may apply.
Phone and Telemarketing Communications
We comply with the TCPA and all applicable state telemarketing laws. We will not contact you by phone for marketing purposes if you are on the National Do Not Call Registry or any applicable state Do Not Call list, unless we have your prior express written consent. When we do contact you, we will do so only during permissible calling hours and will honor any request to be placed on our internal do-not-call list.
Data Security and Breach Notification
We have implemented administrative, technical, and physical measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Services, you are responsible for keeping this password confidential.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Services. Any transmission of personal information is at your own risk.
Tenant Isolation & Cross-Contamination Controls
Partner data is logically isolated at the database layer. Every record is keyed to an owning organization and protected by PostgreSQL Row-Level Security (RLS) policies enforced on every query. Access tokens are scoped to a single organization, so one partner's data — including AI conversation history, leads, and integration credentials — cannot be read or modified by another partner.
Voice and messaging AI sessions run in per-partner contexts with separate knowledge bases and prompts. Third-party integrations use partner-specific API credentials stored in an encrypted secret vault and are never shared across partners.
Database Systems
Our primary application database is PostgreSQL, hosted on Supabase (running on AWS). Authentication is handled by Supabase Auth (JWT, bcrypt-hashed credentials, MFA for administrators). Serverless business logic runs on Supabase Edge Functions in isolated containers. CRM workflows use GoHighLevel; transactional email is delivered via Resend; AI inference is provided through the Lovable AI Gateway and the partner-selected model provider. All vendors in our production data path are SOC 2 Type II attested (or equivalent) and operate under signed Data Processing Agreements.
Additional Security Measures
- • Encryption: TLS 1.2+ in transit, AES-256 at rest for databases, backups, and object storage.
- • Access control: Least-privilege, role-based access; SSO and MFA required for administrative accounts; periodic access reviews.
- • Secret management: API keys and integration tokens stored in an encrypted secret vault and rotated on personnel changes or suspected compromise.
- • Input validation & hardening: Server-side schema validation, parameterized queries, output sanitization, and a Content Security Policy.
- • Audit logging & monitoring: Authentication events, administrative actions, and access to sensitive records are logged and monitored for anomalies.
- • Backups & recovery: Automated daily backups with point-in-time recovery; encrypted and access-controlled.
- • Vulnerability management: Automated dependency scanning, security headers, and a responsible-disclosure policy at
/.well-known/security.txt. - • Personnel: Confidentiality agreements and mandatory security training for all team members with production access.
- • Data integrity: Database constraints, transactional writes, and webhook signature verification on inbound integrations.
Breach Notification
In the event of a data breach involving your personal information, we will notify you and any applicable regulatory authorities in accordance with applicable state and federal laws. This includes providing you with information about the nature of the breach, the types of information that may have been compromised, and the steps we are taking to address the breach and mitigate its effects.
Children's Privacy
Our Services are not intended for children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we learn we have collected or received personal information from a child under 13 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 13, please contact us.
We comply with the Children's Online Privacy Protection Act (COPPA) and other applicable laws regarding children's privacy. For more information about COPPA and children's privacy, please visit the Federal Trade Commission's website.
Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Services. Upon cancellation of your account or non-payment, your account and associated data will be placed in an archived mode for a period of two (2) years. After this period, your personal information will be permanently deleted from our systems, unless we are required by law to retain it for a longer period.
Personalization & Your Data
To make this site feel relevant to your business, we store a small amount of information directly in your browser. This data never leaves your device unless you submit a form to us.
What we store in your browser
- • Approximate location (city, region, country) derived from your IP address — refreshed every 24 hours.
- • Company name or website if you provide it in our welcome dialog, plus any public information we look up about it.
- • Your role (owner, operator, technician, etc.) and first name if you share them.
- • Tour-completion flags so we don't re-show the welcome experience.
- • A single consent cookie (
pestai_personalization) to remember your choice below.
Everything except the consent cookie lives in your browser's local storage. We do not sell or share this data. If you submit a form, the information you provided plus the personalization data above is sent to us so we can serve you better.
Your controls
These controls only affect this browser. Status: Personalization is ON
Third-Party Services
We use various third-party services to operate our business and provide our Services. These services may have access to your personal information for the purpose of performing services on our behalf. The third-party services we use include, but are not limited to:
In addition to these services, we may leverage other third-party providers for various services. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies.
International Users
Our Services are intended for and directed to users in the United States. We do not currently offer our Services to users outside of the United States. If you are a user located outside of the United States, you should not sign up for our Services. If you are interested in future possibilities of expansion, please contact us.
Contact Us
We welcome your questions, comments, and concerns about privacy. You can contact us at:
Contact Information
Pest AI
AI Automation Solutions
Address
18653 Ventura Blvd Ste 194
Tarzana, CA 91356
Phone
619-202-8928Privacy Protected
Your privacy and data security are our top priorities. We're committed to transparency and protecting your rights.
References
- California Consumer Privacy Act (CCPA)
- US State Privacy Legislation Tracker
- CAN-SPAM Act: A Compliance Guide for Business
- SMS Marketing Laws by State: A 2025 Compliance Guide
- TCPA, CAN-SPAM & State Law Guide for 2025 Compliance
- TCPA Laws by State: Recent Updates and Compliance
- U.S. State Comprehensive Consumer Data Privacy Law
- Security Breach Notification Chart
- Children's Online Privacy Protection Rule ("COPPA")
Questions About Our Privacy Policy?
If you have any questions about this privacy policy or our data practices, please don't hesitate to contact us.
Contact Privacy Team