
Legal · Privacy
Privacy Policy
Effective July 2, 2026
This Privacy Policy explains how Climb Analytics handles information in connection with our website and our analytics platform. It covers visitors to our site and the people who use our product, and it describes how we treat the business data our customers connect.
1. Scope and roles
This policy applies to the Climb Analytics website at climb-analytics.com and to the Climb Analytics application (together, the “Service”), operated by Climb Analytics, LLC, a Georgia limited liability company (“Climb Analytics,” “we,” “us”). Two kinds of information are involved, and our role differs for each:
- Information we collect directly from website visitors and account users (for example, an email you send us or account details). For this information we act as a controller.
- Customer Data that a customer connects from third-party systems such as FieldRoutes, Podium, and Applause and that we process to provide analytics. For this information we act as a processor / service provider on the customer’s behalf, under the customer’s instructions and agreement. If you are an employee, technician, or customer of one of our customers and have questions about that data, please contact that business (the controller) directly.
2. Information we collect
From website visitors
- Contact informationyou choose to give us — for example, when you email us to request a demo (such as your name, email, company, and what you tell us about your business).
- Basic technical/log data that our hosting provider records to deliver and secure the site, such as IP address, browser type, and timestamps.
From product users and customers
- Account information such as name, work email, organization, and role, and authentication data managed by our identity provider.
- Customer Dataingested from the Third-Party Sources a customer connects — for example customer, appointment, payment, subscription, employee, communication, and review records — which we process to produce analytics for that customer.
- Usage data about how the application is used, for security, support, and product improvement.
3. How we use information
- to provide, operate, secure, support, and improve the Service;
- to respond to your inquiries and schedule and conduct demos;
- to produce analytics and reports for the customer whose data we process;
- to create aggregated and de-identified statistics, benchmarks, and market insights (see Section 3a);
- to monitor, prevent, and address fraud, abuse, security, and technical issues;
- to comply with law and enforce our agreements.
We do notsell your personal information, and we do not “share” it for cross-context behavioral advertising. We do not disclose personal information or a customer’s identifiable business data to another operator, broker, or buyer except in the aggregated, de-identified form described below or with that customer’s separate opt-in for the verified marketplace.
3a. Benchmarking, market insights, and the verified marketplace
Aggregated and de-identified insights.We create statistics, benchmarks, and market insights derived in part from Customer Data — for example, to show an operator how it compares to peers, or to describe industry trends. We produce these only in de-identified, aggregated form under a defined standard: outputs reflect a group of operators large enough that no single operator or individual can reasonably be identified, small groups are suppressed (including in thin local markets), we do not attempt to re-identify the data, and recipients are contractually prohibited from doing so. This information is not personal information and is not a “sale” of personal information. For these Aggregated Insights we act as an independent controller/business, separate from our processor role for raw Customer Data. The specific standard we apply — including minimum cohort sizes and re-identification prohibitions — is set out in our Data Processing Addendum.
Verified marketplace (opt-in only).We may offer a program through which an operator can choose to make itself discoverable to vetted brokers or buyers — for example, to explore a sale or financing. An operator’s identity, individual figures, or personal information are disclosed to those third parties only with the operator’s separate, affirmative, and revocable authorization, and only to the extent chosen. Benchmarking participation and marketplace enrollment are distinct choices, and neither is required to use the Service.
Not a financial-incentive program.Benchmarking is a business account setting managed by the customer, and it does not condition the price of, or access to, the Service on any consumer providing personal information. For that reason we do not treat it as a “financial incentive” requiring a separate notice under California law.
We never use Customer Data to train models for the benefit of other customers, or to build generalized products, except in the aggregated, de-identified form described here.
4. How we share information
We share information only as needed to run the Service:
- Service providers / subprocessorsthat host and support the Service under confidentiality and data-protection obligations — for example Microsoft Azure (cloud hosting and data storage), our authentication provider, our error-monitoring provider, and our website host. Each organization’s data is logically isolated from others’.
- Legal and safety— when required by law or to protect rights, safety, or the integrity of the Service.
- Business transfers— in connection with a merger, acquisition, or sale of assets, subject to this policy.
- With your direction— for a customer’s Customer Data, as the customer instructs, including — only with the operator’s separate opt-in — disclosure of the operator’s chosen information to vetted brokers or buyers through the verified marketplace (Section 3a).
- Aggregated / de-identified insights— benchmarks and market insights that do not identify any operator or individual may be provided to other operators and to third parties such as brokers, as described in Section 3a. This is not a sale or sharing of personal information.
We do not otherwise disclose one customer’s identifiable data to another customer, a broker, or any buyer.
5. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and at rest, role-based access controls, single sign-on, and hard logical isolation of each organization’s data. Connections to Third-Party Sources are read-only. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach of personal information occurs, we will notify affected individuals and the appropriate authorities without undue delay where required by applicable law; for Customer Data we notify the affected customer as set out in our Data Processing Addendum.
6. Data retention
We keep each category of information only as long as needed for the purposes described here:
- Contact informationfrom website inquiries — until you ask us to delete it or it is no longer needed for follow-up, whichever is sooner.
- Account information— for the life of the account and a short wind-down period after it closes.
- Customer Data— for the term of the customer’s subscription; on termination we delete or de-identify it within a commercially reasonable wind-down period, except where retention is required by law.
- Security and usage logs— for a limited period consistent with security and operational needs.
- Aggregated / de-identified insights— because they no longer identify anyone, may be retained after termination.
We may retain information longer where required to comply with law, resolve disputes, or enforce our agreements.
7. Your rights and choices
Depending on where you live, you may have some or all of the following rights over personal information we hold about you as a controller/business: to know or access the information and how we use it; to correct inaccuracies; to delete it; to receive a portable copy; to opt outof any “sale,” “sharing,” or targeted advertising and of certain profiling; to limit the use of sensitive information; and to object to or restrict certain processing. As explained below, we do not sell or share personal information for cross-context behavioral advertising.
How to exercise your rights. Use our Your Privacy Choices page, or email privacy@climb-analytics.comwith “Privacy Request” and the right you want to exercise. When your request reaches us we record it, verify your identity before acting, may ask for information to confirm it, and respond generally within 45 days— extendable where the law permits and we tell you why. You may use an authorized agentto submit a request; we may require the agent’s proof of authority and verification of your identity. We will not discriminate against you for exercising your rights, and you may appeal a decision by replying to our response. If we process your information as a processor on a customer’s behalf (Customer Data), please direct your request to that business (the controller); we will assist them as required.
7a. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended, gives you the rights described in Section 7. In the preceding 12 months, we have collected the following categoriesof personal information, from the sources and for the purposes described in Sections 2–3: identifiers (such as name and email); commercial information; professional or employment-related information; internet or network activity (such as log data); and, within Customer Data, categories that a customer may connect. We disclose personal information to service providers/contractors for the business purposes in Section 4.
- No sale or sharing.We do not “sell” personal information and do not “share” it for cross-context behavioral advertising, as those terms are defined under California law. Because we do not, there is no “Do Not Sell or Share My Personal Information” action to take — but you may still contact us to confirm.
- Sensitive personal information.In our own (controller) collection we do not use or disclose sensitive personal information for purposes that would require offering a “Limit the Use of My Sensitive Personal Information” choice. Any sensitive information that reaches us inside Customer Datais handled only as a processor on the customer’s instructions (Section 1), not for our own purposes.
- Rights. You may request to know/access, delete, and correct your personal information, and to opt out of any sale/share (which we do not do), as described in Section 7.
7b. Other U.S. state privacy rights
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, and a growing number of others — have rights that may include access, correction, deletion, portability, and opting out of targeted advertising, sale, and certain profiling. We honor these rights consistent with each applicable law. To exercise them, use the method in Section 7. Where a law provides an appeal process, you may appeal our decision by replying to our response.
7c. Europe, the United Kingdom, and legal bases (GDPR)
Where the EU or UK GDPR applies, we process personal information on one or more of these legal bases: performance of a contract with you; our legitimate interests in operating, securing, and improving the Service (balanced against your rights); compliance with a legal obligation; and, where required, your consent. For Customer Data, we act as a processoron the customer’s instructions.
You have the rights in Section 7, and additionally the right to withdraw consent at any time (without affecting prior processing) and to lodge a complaint with your supervisory authority. We rely on appropriate safeguards for international transfers as described in Section 9. If we are required to designate an EU or UK representative, we will identify one here.
8. Cookies and tracking
Our marketing website uses strictly-necessary cookies and, only with your consent, privacy-friendly anonymous analytics; it does not use advertising or cross-site tracking cookies, and we do not sell or share information for targeted advertising. The application uses cookies necessary for authentication and session management. You can accept or reject optional cookies from our banner and change your choice anytime via “Cookie preferences” in the footer. For full detail on the categories we use and how we treat Global Privacy Control signals, see our Cookie Policy.
9. International data transfers
We operate in the United States, and information may be processed in the United States or other countries where we or our service providers operate, which may have different data-protection laws than your own. Where required for transfers of personal data out of the EEA, UK, or Switzerland, we use an appropriate safeguard, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), together with supplementary measures where needed.
10. Children
The Service is for businesses and is not directed to children under 16, and we do not knowingly collect their personal information.
11. Changes to this policy
We may update this policy from time to time. We will change the effective date above and, where appropriate, provide additional notice. Your continued use of the Service after an update takes effect constitutes acceptance.
12. Contact
For privacy questions or requests, contact us at privacy@climb-analytics.comwith “Privacy” in the subject line.
Questions? Contact us at privacy@climb-analytics.com.