Plain-language summary: Summit One is a B2B software provider. We use information to operate, secure, support, and improve our services; communicate with business contacts; invoice customers; and meet legal obligations. We do not sell personal information for money and do not provide financial services.
1. Scope
This Privacy Policy applies to information processed by Summit One LLC ("Summit One," "we," "us," or "our") through our public website, hosted order-operations platform, sales and support communications, customer onboarding, and related professional services (collectively, the "Services"). It does not govern a customer’s own privacy practices, products, stores, websites, payment providers, or independent systems.
By using the Services or providing information to us, you acknowledge the practices described in this Policy. If you use the Services on behalf of an organization, your organization may separately control information submitted through its account.
2. Our data roles
Website visitors and business contacts
For information submitted directly to us for sales, account administration, billing, support, security, or website purposes, Summit One generally acts as the business or controller determining why and how the information is processed.
Customer-provided platform data
When a business customer submits information to the platform to manage its orders, locations, employees, suppliers, or end customers, Summit One generally processes that information as a service provider or processor on the customer’s instructions and under the applicable agreement. The customer is responsible for its notices, permissions, legal basis, data accuracy, and responses to end-user requests.
3. Information we collect
Depending on how you interact with Summit One, we may collect:
- Business contact information: name, job title, company, business email, business telephone number, mailing address, and communication preferences.
- Account information: login identifiers, authentication events, role assignments, location membership, settings, and administrator actions.
- Customer content: order references, product or service details, fulfillment instructions, customer contact information supplied by the business customer, status history, internal notes, attachments, and operational records.
- Commercial records: selected plan, order form, subscription term, invoices, payment status, tax-related business information, and support or professional-services history. Payments may be processed by third-party providers; we do not intentionally store complete payment card numbers.
- Device and usage data: IP address, browser and device type, timestamps, approximate location derived from IP, pages or features used, error logs, and security events.
- Communications: messages, call notes, support requests, feedback, and records needed to resolve a request or document a business relationship.
- Information from integrations: data made available through customer-authorized APIs, webhooks, file imports, or connected systems, subject to customer configuration and third-party terms.
We may receive information directly from you, from an authorized customer administrator, automatically through the Services, from customer-selected integration providers, or from lawful business sources used for B2B sales and verification.
4. How we use information
We may use information to:
- Provide, configure, maintain, and improve the Services;
- Authenticate users, manage permissions, monitor performance, and protect accounts;
- Process subscriptions, issue invoices, keep accounting records, and administer contracts;
- Respond to sales inquiries, schedule demonstrations, onboard customers, and provide support;
- Route orders, display operational records, deliver notifications, and generate customer-requested reports;
- Detect, investigate, and prevent fraud, misuse, security incidents, and violations of our terms;
- Develop aggregate or de-identified operational insights that do not reasonably identify a person;
- Comply with applicable law, lawful requests, tax rules, recordkeeping duties, and the establishment or defense of legal claims; and
- Send service notices and, where permitted, relevant B2B marketing communications. Recipients may opt out of non-essential marketing.
Where a legal basis is required, we rely as applicable on performance of a contract, legitimate business interests, consent, and compliance with legal obligations.
5. How we disclose information
We may disclose information to:
- Service providers and subprocessors supporting cloud hosting, authentication, monitoring, customer support, analytics, communications, billing, and professional services under appropriate obligations;
- Customer administrators and authorized users according to account roles, locations, and configured permissions;
- Customer-authorized integrations when a customer directs us to transmit or receive information through a selected service;
- Professional advisers such as auditors, accountants, insurers, and legal counsel;
- Authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or respond to valid legal process; and
- Transaction participants in connection with a financing, merger, acquisition, reorganization, or sale of all or part of the business, subject to appropriate confidentiality and legal requirements.
We do not sell personal information for money. We do not knowingly share personal information for cross-context behavioral advertising. We do not use customer order content to advertise unrelated third-party products.
6. Retention
We retain information for as long as reasonably necessary to provide the Services, maintain the business relationship, satisfy contractual commitments, secure our systems, resolve disputes, and meet legal, accounting, tax, or recordkeeping obligations. Retention periods vary by information type and customer configuration.
Following account termination, customer content may remain in protected backups for a limited period before deletion through normal retention cycles. We may retain limited records such as contracts, invoices, security logs, and suppression lists when reasonably necessary. Customers should request supported exports before account closure.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include encrypted connections, access controls, authentication requirements, monitoring, backup practices, change management, personnel obligations, and incident-response procedures.
No system is completely secure. Customers are responsible for safeguarding credentials, configuring appropriate permissions, keeping account information current, and promptly reporting suspected compromise to security@summitone.app.
8. Choices and rights
You may unsubscribe from non-essential marketing using the instructions in a message or by contacting us. Account users can update certain profile details through an administrator or support request.
Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, or information about processing. Summit One will verify requests and may deny or limit them where permitted. If your information was submitted by a Summit One customer, direct your request to that customer; we will assist the customer as required by contract and law.
9. U.S. state privacy notices
Residents of certain U.S. states may have additional privacy rights. Summit One does not discriminate against individuals for exercising rights granted by applicable law. We may need to verify identity and authority before acting. An authorized agent may submit a request where permitted, subject to verification.
Summit One does not offer consumer financial products, does not sell personal information for monetary consideration, and does not knowingly process sensitive personal information for purposes beyond providing and securing contracted B2B services.
10. Children
The Services are designed for businesses and authorized business users, not children. We do not knowingly collect personal information directly from children under 13 through the website or create accounts for them. If you believe a child has provided information directly to Summit One, contact us so we can review and take appropriate action.
11. International access
Summit One is based in the United States, and information may be processed in the United States and other locations where authorized service providers operate. Customers are responsible for determining whether their use of the Services and transfer of data satisfies applicable cross-border requirements. Contractual terms may be available where required.
12. Changes to this Policy
We may update this Policy to reflect changes in the Services, law, or business practices. The updated version will be posted with a revised effective date. Material changes may also be communicated through the Services or to the account contact when appropriate.
13. Contact us
Questions, privacy requests, or complaints may be directed to:
Summit One LLC
Florida, United States
privacy@summitone.app
For account-specific requests, include your company name and business email. Do not email passwords, complete payment card numbers, government identification numbers, or unnecessary sensitive information.