Privacy Policy
Last updated: March 24, 2026
1. Introduction
HighStrat AI ("HighStrat," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered IT procurement and strategic assessment platform, including our website at highstrat.ai and all related services (collectively, the "Service").
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, job title, department, and organization name when you register.
- Project Data: Project details, descriptions, budgets, and documents you upload for assessment.
- Communications: Messages and queries you submit through our AI assistant and support channels.
- Payment Information: Billing details processed through our third-party payment processor (we do not store full card numbers).
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, and interaction patterns.
- Device Information: Browser type, operating system, IP address, and device identifiers.
- Cookies: Session cookies for authentication and analytics cookies to improve our Service.
2.3 Third-Party Authentication
If you sign in using Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.
3. How We Use Your Information
- Provide, operate, and maintain the Service.
- Process and analyze your uploaded documents using AI to generate assessments and recommendations.
- Personalize your experience and deliver relevant benchmarking data.
- Communicate with you about your account, updates, and support requests.
- Monitor and analyze usage trends to improve the Service.
- Detect, prevent, and address technical issues and security threats.
- Comply with legal obligations.
4. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Service Providers: Cloud hosting (Heroku/AWS), AI processing (OpenAI), analytics, and payment processors that help us operate the Service.
- Within Your Organization: Other members of your organization on the platform may see shared project data based on role permissions.
- Legal Requirements: When required by law, subpoena, or to protect our rights and safety.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
5. Data Security
We implement industry-standard security measures including encryption in transit (TLS/SSL), encryption at rest, JWT-based authentication, role-based access controls, and regular security audits. However, no method of electronic storage or transmission is 100% secure.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data at any time by contacting us. Some data may be retained as required by law or for legitimate business purposes.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Data portability — receive your data in a structured format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at privacy@highstrat.ai.
8. Cookies
We use essential cookies for authentication and session management, and analytics cookies (Google Analytics) to understand how the Service is used. You can control cookie preferences through your browser settings.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
HighStrat AI
Email: privacy@highstrat.ai
Website: www.highstrat.ai
