Privacy Policy
Version 2026-08-17 · Effective August 17, 2026
This Privacy Policy explains how F&G Enterprise Group LLC, operating PlateReach (“PlateReach,” “we,” “us,” or “our”), collects, uses, discloses, and protects information when people use the PlateReach website, application, and related services.
1. Information we collect
- Account and identity data: name, business email, role, tenant membership, authentication status, profile photo, and account-security information.
- Business profile data: company name, title, business description, phone, website, quote link, business address, and workspace logo.
- Customer Data: prospect records, public business contact information, territory and pipeline data, notes, outreach drafts, follow-ups, feedback, reviews, and tenant settings submitted by authorized users.
- AI and voice data: questions, selected account context, AI outputs, and voice transcripts. PlateReach does not retain raw voice recordings used for transcription in the current product workflow.
- Device and usage data: browser or device type, language, application version, session and security events, notification preferences, installation state, feature interactions, diagnostics, and timestamps.
- Legal records: the Terms and Privacy Policy versions accepted or acknowledged, acceptance time, tenant, user email, locale, and acceptance method.
2. Sources of information
We collect information directly from users and tenant administrators, from use of the service, from authorized integrations and service providers, and from public business sources such as company websites, chambers of commerce, public directories, and other publicly available records. A public source does not guarantee accuracy.
3. How we use information
We use information to provide and secure PlateReach; authenticate users; isolate tenant workspaces; organize prospects and follow-ups; personalize AI-assisted drafts; transcribe user-initiated voice notes; deliver in-app or device notifications; operate the PlateReach Admin CRM; route feedback and internal work; improve reliability and usability; respond to support; enforce our Terms; and comply with law.
4. AI processing
When a user requests an AI feature, PlateReach sends the minimum relevant prompt and selected workspace context to an approved AI provider. Users must review AI outputs. We do not use raw voice recordings as a permanent customer record. The original feedback or note remains separate from any AI summary so the user’s words are not silently replaced.
5. How we disclose information
We may disclose information to infrastructure, authentication, hosting, storage, security, analytics, customer-support, and AI service providers that process information for us; to a tenant owner or authorized users within the same workspace; during a business transaction; to comply with law or protect rights and safety; or with the user’s direction. Current providers may include Supabase, OpenAI, and Cloudflare or their successors.
6. No sale or cross-context behavioral advertising
PlateReach does not currently sell personal information or share it for cross-context behavioral advertising. If this practice changes, we will update this Policy and provide any legally required choices before the change takes effect.
7. Tenant isolation
Each customer workspace is logically separated. A prospect may independently appear in more than one tenant’s database, but one tenant does not receive another tenant’s notes, activities, caller events, ownership, or confidential records. Inbound caller matching begins with the business number called and searches only the corresponding tenant.
8. Retention
We retain information for as long as reasonably necessary to provide the service, maintain business and security records, comply with legal obligations, resolve disputes, and enforce agreements. Retention varies by record type. Tenant owners may request account or Customer Data deletion, subject to backup, security, contractual, and legal-retention requirements.
9. Security
We use safeguards designed to protect information, including authenticated access, multi-factor authentication, tenant-scoped queries, limited administrative permissions, private file storage, and activity controls. No system is perfectly secure, and users must protect their devices and sign-in factors.
10. Choices and privacy rights
Users may update profile information and notification choices inside PlateReach. Depending on location and applicable law, individuals may have rights to know, access, correct, delete, or obtain a copy of personal information, and to limit or object to certain uses. California residents may also have rights under the CCPA, as amended, when it applies. We will not discriminate against a person for exercising an applicable privacy right.
Submit a request through your tenant owner or email franklyn@platereach.com. We may need to verify identity and authority before completing a request.
11. Cookies, device storage, and analytics choices
Required storage. PlateReach uses session technologies, browser storage, and a limited application asset cache for secure sign-in, language, accessibility, workspace selection, installation, voice-consent, and security preferences. These technologies are necessary to provide and protect the service. Blocking them may prevent secure features from working.
Optional analytics. PlateReach sends limited, approved product-use events only when an analytics provider is configured and a user has allowed analytics on that browser and device. Permission alone does not activate or send to an unconfigured provider. Events may include a workspace identifier, app version, language, screen, and saved workflow outcome; this analytics path excludes prospect and customer record content and does not use advertising cookies or session replay. Rejecting analytics does not prevent sign-in or ordinary app use.
Users can change or withdraw this device-level choice at any time through More → Privacy & cookies. Withdrawal stops future optional analytics from that browser; it does not erase events already aggregated. PlateReach does not currently sell personal information or share it for cross-context behavioral advertising.
12. Children
PlateReach is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child provided information.
13. International use
PlateReach is currently operated from the United States. Information may be processed in the United States and other locations where our service providers operate, subject to applicable safeguards.
14. Changes to this Policy
We may update this Policy and will post the current version and effective date. Material changes may require users to acknowledge the new version before continuing. PlateReach stores the acknowledged version and timestamp in its Admin CRM.
15. Contact
Privacy questions and requests may be sent to franklyn@platereach.com.