Skip to content

Privacy Policy

Gridavate, LLC and its subsidiaries and affiliates (together, “Gridavate,” “we,” “us,” or “our”) are committed to handling personal information in accordance with applicable privacy laws in the United States. This Privacy Policy explains how Gridavate collects, uses, discloses, and otherwise processes personal information.

Scope and application of this Privacy Policy

Gridavate provides software-as-a-service tools to financial institutions, lenders, and other business customers to help them verify and validate consumer loan information. Gridavate is a business-to-business provider and does not offer services directly to consumers.

This Privacy Policy applies to personal information Gridavate collects directly when you:

  • Visit our websites or use our online services;
  • Interact with our marketing, sales, or support teams;
  • Communicate with us by phone, email, or our “contact us” forms;
  • Apply for a job with us; or
  • Are a business contact at a current or prospective customer, partner, or vendor.

     

This Privacy Policy does not apply to personal information that Gridavate processes on behalf of our financial institution and lender customers in providing our Services. In those engagements, our customer is the “business,” “controller,” or equivalent under applicable privacy laws, and Gridavate acts as a “service provider,” “processor,” or equivalent under contract. Consumers seeking to exercise rights regarding loan-related personal information held by a lender should contact that lender directly. If you contact Gridavate about such information, we will refer your request to the lender that engaged us.

In this Privacy Policy, “you” refers to any individual whose personal information Gridavate collects directly in the circumstances described above.


Information we collect

We collect personal information so that you can interact with our Services, communicate with us, and (where applicable) apply for employment with us. The categories of information we collect depend on how you interact with us.

Information you provide to us

  • Account and contact information: name, business email address, employer, job title, business phone number, and (if you create an account) a username and password.
  • Communications: information you provide when you contact us with inquiries, requests for information, feedback, or support questions. We may record sales and customer support calls for quality assurance and training purposes, where permitted by law and with notice to participants.
  • Marketing and event information: information you provide when you sign up for newsletters, attend our events or webinars, or request a demonstration of our Services.
  • Job applicant information: information you submit when applying for a position with us, including contact information, résumé, work history, education, and any other information you choose to provide. Additional information about how we handle applicant information may be provided at the time you apply.
  • Social media information: content you post to our social media pages or that you direct to us through social media.

Information collected by automated means

When you interact with our websites and online services, we and our service providers obtain certain information by automated means, such as cookies, web server logs, web beacons, and similar technologies. A “cookie” is a small text file that websites send to a visitor’s computer or other Internet-connected device to identify the browser or store information or settings. A “web beacon” (also called a pixel tag or clear GIF) is a small graphic that may be used to transmit information collected through cookies back to a web server.

Information collected by these automated means may include your IP address, identifiers associated with your devices, device and browser characteristics, language preferences, referring and exit pages, clickstream data, dates and times of visits, and information about how you interact with our Services (for example, pages and features you view and search queries).

We use these technologies to: (1) remember your information so you do not have to re-enter it; (2) understand how you use and interact with our Services; (3) tailor the Services to your preferences; (4) measure the usability and effectiveness of our Services and communications; and (5) otherwise manage and improve our Services.

Most web browsers are initially set to accept cookies. You can disable or refuse cookies at any time through your browser settings. On mobile devices, you can manage how the device and browser share certain data through the device’s privacy and security settings. Note that some parts of our Services may not function properly, or may be slower, if you refuse cookies.

We honor the Global Privacy Control (GPC) opt-out preference signal where required by applicable law. For more information about GPC, visit https://globalprivacycontrol.org/.

Because there is not yet a consensus on how companies should respond to web browser-based “do not track” (DNT) signals, we do not respond to DNT signals at this time. For more information about DNT, visit www.allaboutdnt.org.

How we use personal information

We use personal information for the following purposes:

  • To provide, operate, support, and improve our Services and websites;
  • To respond to inquiries, requests, and other communications from you;
  • To send you information about our Services, including marketing communications and special offers (subject to your communication preferences and applicable law);
  • To administer our business relationships with customers, prospective customers, partners, and vendors, including contracting, billing, and account management;
  • To evaluate applications for employment and to administer our recruiting and hiring processes;
  • To perform analytics, research, and statistical analyses about how our Services are used;
  • For quality control, training, and to develop and improve our Services;
  • To comply with applicable laws, regulations, legal process, and our policies;
  • To detect, investigate, and prevent fraud, abuse, security incidents, or other unlawful activity, and to enforce our agreements and protect the rights, property, or safety of Gridavate, our customers, our employees, and others; and
  • For other purposes that we disclose to you at the time of collection, or with your consent.

How we disclose personal information

We may disclose personal information for the purposes described above as follows:

  • Within Gridavate: with our subsidiaries and affiliates.
  • Service providers: with vendors that perform services on our behalf, such as hosting, website operation, analytics, payment processing, customer support, marketing, communications, and similar functions.
  • Professional advisors: with our legal, accounting, audit, insurance, and other professional advisors.
  • Business partners: with selected business partners in connection with joint offerings, events, or marketing activities.
  • Legal and protective disclosures: when we believe disclosure is required by law or appropriate to comply with legal process or a government request, to enforce our agreements, or to protect the rights, property, or safety of Gridavate, our customers, our employees, or others.
  • Corporate transactions: in connection with the actual or potential sale or transfer of all or part of our business or assets, including in connection with due diligence, financing, merger, acquisition, reorganization, or similar transaction.
  • With your direction or consent: with other parties where you direct us to do so or where you have otherwise consented.

Sale and sharing of personal information

Gridavate does not sell personal information in exchange for monetary consideration. We do not knowingly engage in targeted advertising or share personal information for cross-context behavioral advertising as those terms are defined under applicable state privacy laws.

Our websites may use analytics and similar tools provided by third parties (such as web analytics providers). Where these tools are used, the providers may receive information about your interaction with our Services. We honor the Global Privacy Control signal and provide opt-out controls as described in this Privacy Policy. To the extent any disclosure of personal information through cookies or similar technologies on our websites is considered a “sale” or “sharing” under applicable law, you may opt out of certain cookie-based disclosures by enabling the Global Privacy Control in your browser, adjusting your cookie preferences through our website tools where available, or contacting us using the information below.

Data retention

We retain personal information only for as long as necessary for the purposes for which it was collected, and as required to comply with our legal, regulatory, tax, accounting, and reporting obligations. The criteria we use to determine retention periods include:

  • Account information: retained for the duration of your account or business relationship and for a reasonable period afterward to support service inquiries, fraud prevention, and legal claims.
  • Transaction and billing records: retained as needed to comply with tax, accounting, and audit requirements.
  • Website analytics and cookie data: retained in accordance with our analytics configuration.
  • Customer support records: retained to support follow-up inquiries and quality assurance.
  • Job applicant records: retained for the period required by applicable law and our internal recruiting policies.

When we no longer need your personal information, we will securely destroy, delete, or anonymize it, unless we are legally required to retain it.

Your marketing choices

You can opt out of our use of your personal information for marketing purposes, or withdraw your prior consent, by the methods described below. After we receive your request, your consent will be withdrawn; however, please allow a reasonable processing period, and you may continue to receive communications scheduled before your request was received.

To stop receiving promotional email communications, you may click the “Unsubscribe” link in any promotional email or contact us at support@gridavate.com. Even if you opt out of marketing communications, we may still send you non-marketing communications, such as messages about an existing business relationship, transactional notices, and updates to this Privacy Policy or our Terms and Conditions.

Your state privacy rights

This section provides additional information for residents of U.S. states whose laws may provide rights regarding personal information that Gridavate collects directly from them, as described in “Scope and application of this Privacy Policy” above.

Important note about loan-related information

Most personal information Gridavate processes in connection with consumer loan verification and validation is processed on behalf of, and under contract with, lenders and financial institutions. That information is generally subject to the federal Gramm-Leach-Bliley Act (GLBA) and its implementing regulations, and is exempt from the state consumer privacy laws described in this section. In addition, Gridavate acts as a service provider or processor for that information, not as a business or controller. If you have questions or wish to exercise rights regarding loan-related personal information, please contact the lender or financial institution that holds your account.

The rights described below apply only to personal information that Gridavate collects directly from you and that is not otherwise exempt under applicable law.

California residents

If you reside in California, the California Consumer Privacy Act of 2018, as amended (CCPA), may provide you with the following rights regarding personal information that is not exempt under the CCPA:

  • To know what categories of personal information we have collected, the sources of that information, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it;
  • To request the specific pieces of personal information we have collected about you;
  • To request the deletion of your personal information, subject to certain exceptions;
  • To correct inaccurate personal information we maintain about you;
  • To opt out of the “sale” or “sharing” of your personal information, as those terms are defined under the CCPA;
  • To limit our use and disclosure of “sensitive personal information,” as defined under the CCPA; and
  • To be free from unlawful discrimination for exercising your CCPA rights.

To exercise your CCPA rights, please email us at support@gridavate.com or call us at 833-817-5485.

Categories of personal information under California law

For purposes of the CCPA, the categories of personal information we have collected from individuals covered by this Privacy Policy in the preceding twelve (12) months are:

  • Identifiers (such as name, business email address, business phone number, username, IP address, and online identifiers);
  • California Customer Records Act categories (such as name, employer, job title, and contact information);
  • Commercial information (such as records of demonstrations requested and products or services considered or purchased);
  • Internet or other electronic network activity information (such as browsing and interaction data on our websites);
  • Audio, electronic, visual, or similar information (such as recordings of sales and customer support calls);
  • Professional or employment-related information (such as employer, job title, work history, and, for job applicants, background check results obtained through our background check provider);
  • Education information (for job applicants only); and
  • Inferences drawn from the above categories.

We collect this information from the sources, and use and disclose it for the purposes, described elsewhere in this Privacy Policy. We disclose these categories of personal information to the categories of recipients described in the “How we disclose personal information” section above.

Payment information. When you pay for our Services, payment card and bank account information is collected and processed by our third-party payment processor, not by Gridavate. Gridavate does not store full payment card numbers or bank account numbers on its own systems.

Sensitive personal information. Of the categories defined as “sensitive personal information” under the CCPA, we collect only account log-in credentials (username and password) used to authenticate access to your account. We use this information only for the purposes specified in CCPA Regulation § 7027(m), including providing the Services you have requested, authenticating users, and detecting and preventing security incidents. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit its use under the CCPA.

We do not knowingly collect other categories of sensitive personal information, including Social Security numbers, driver’s license numbers, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, the contents of mail or messages, biometric or genetic data, or information about health, sex life, or sexual orientation.

We do not sell personal information and do not knowingly share it for cross-context behavioral advertising.

Other state residents

If you are a United States resident, you may, subject to applicable law and verification of your identity, request to access, correct, delete, or obtain a portable copy of personal information we have collected directly from you; opt out of any sale, sharing, or targeted advertising; limit our use of sensitive personal information; and appeal a denial of your request. To exercise these rights, contact us using the information in the 'Contact us' section.

Appeals

If we decline to take action on a request you submit under applicable state privacy law, you may appeal our decision by contacting us using the information in the “Contact us” section below. We will respond to your appeal in accordance with applicable law.

How to exercise your rights

To exercise any of the rights described in this section, please contact us using any of the methods listed in the “Contact us” section below. We will respond to verifiable requests within the time period required by applicable law (generally 45 days, subject to extension where permitted).

To protect your information, we will take reasonable steps to verify your identity before responding to a request, which may include asking you to confirm information we already have. We will not use information collected for verification for any other purpose.

You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide written proof of authorization (such as a signed permission letter or power of attorney) and may require you to verify your identity directly with us.

How we protect personal information

We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use.

Despite our efforts, no organization can fully eliminate security risks or guarantee the security of personal information. Unauthorized access, hardware or software failure, and other factors may compromise the security of information at any time.

Third-party use of cookies and tracking technologies

Some content or applications on our websites may be served by third parties, including analytics providers and content providers. These third parties may use cookies, web beacons, or similar technologies to collect information about your interaction with our Services. The information they collect may be associated with personal information, or may be used to collect information about your online activities over time and across different websites and online services.

We do not control how third parties use information collected through their technologies. If you have questions about a particular third-party tool or provider, you should contact that provider directly. For information about opting out of certain forms of online advertising, you may visit https://thenai.org/.

Location and data processing

Gridavate is headquartered in the United States, and our Services are operated in the United States. Personal information will be stored and processed on servers located in the United States and may be transferred to or accessed from other countries. Those countries may not provide the same level of data protection as the laws in your country of residence. By using our Services, you understand that your personal information may be transferred to, stored, and processed in the United States.

Updates to this Privacy Policy

Gridavate may amend this Privacy Policy from time to time. If we make material changes, we will notify you by posting a prominent notice on our website or by other means as required by applicable law before the changes take effect. We encourage you to review this Privacy Policy periodically. The date this Privacy Policy was last updated is noted at the bottom of this page.

Children’s privacy

Our Services are intended for business users 18+ and not directed to minors. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take reasonable steps to delete it.

Contact us

You may contact us as follows with questions about this Privacy Policy or to exercise any of the rights described above:

Email: privacy@gridavate.com

Phone: 833-817-5485

Address: Gridavate, LLC, 2025 Zumbehl Road #82, St. Charles, Missouri 63303

 

Date Last Updated: July 2026

© 2026 Gridavate, LLC. All rights reserved.