Privacy Policy
Last Updated: February 1st, 2025
1. Introduction
BOSS Logics, Inc. (“BOSS,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information we collect from you. Personal information refers to any data that identifies you as an individual, including but not limited to your name, email address, phone number, postal address, and payment details, as defined under applicable data protection laws such as the GDPR and CCPA. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our websites, including www.bosslogics.com and www.bosslogics.live, and use our related services (the “Platform”). It also describes your rights and choices regarding your personal data.
By using our Platform, you agree to the terms outlined in this Privacy Policy. If you do not agree, please do not use our Platform.
2. Information We Collect
We collect various types of information to provide and improve our services, including:
a. Personal Information
We collect personally identifiable information such as:
- Name
- Email address
- Birthday
- Anniversary
- Phone number
- Postal address
- Company name (if applicable)
- Payment information (for transactions)
b. Technical & Usage Data
We may collect:
- Device information (IP address, browser type, operating system)
- Usage data (pages visited, time spent, interactions)
- Cookies and tracking technologies
c. Information from Third Parties
We may receive information about you from business partners, service providers, or publicly available sources.
3. How We Collect Information
- Directly from You: When you sign up, fill out forms, upload files or communicate with us.
- Automatically: Through cookies, server logs, and tracking technologies.
- From Third Parties: Such as analytics providers and marketing partners.
4. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our services.
- Process transactions and manage accounts.
- Respond to inquiries and customer support requests.
- Send important notifications about your account and our services.
- Improve security and fraud prevention.
- Comply with legal obligations.
- Personalize user experience and marketing communications (with consent).
5. How We Share Your Information
We do not sell your personal data but may share it in the following cases:
- With service providers assisting with payment processing, hosting, analytics, etc.
- With business partners if relevant to service offerings.
- To comply with legal obligations or respond to legal requests.
- In the event of a business transaction (merger, acquisition, etc.).
- With your consent for specific purposes.
6. Data Security
We implement appropriate technical and organizational measures to protect your data from unauthorized access, use, or disclosure. Security measures include:
- Data encryption (in transit and at rest)
- Access controls and authentication
- Regular security audits and monitoring
- Incident response procedures
In the event of a data breach, we will notify affected users within 72 hours, as required by applicable laws.
7. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy. Upon request, we will delete your data unless retention is required for legal, regulatory, or legitimate business purposes.
Users can request data deletion via security@bosslogics.com.
8. Children’s Privacy
Our services are not intended for individuals under 13 years of age. We do not knowingly collect personal data from children. If we discover that we have inadvertently collected such data, we will take immediate steps to delete it.
If you believe we may have collected information from a minor, please contact us at security@bosslogics.com.
9. International Data Transfers
We may transfer your personal data to servers located outside of your country. We ensure that such transfers comply with data protection laws by implementing:
- Standard contractual clauses (SCCs)
- Data protection agreements (DPAs)
- Additional security safeguards
10. Cookies & Tracking Technologies
We use cookies to enhance your experience. You can manage cookie preferences via our Cookie Preferences tool. We categorize cookies as:
- Essential Cookies (Required for functionality)
- Performance Cookies (Analytics & usage tracking)
- Marketing Cookies (Advertising & personalization)
You can opt-out of non-essential cookies at any time.
11. Your Rights & Choices
Depending on your location, you may have the following rights regarding your data:
- Access & Correction: Request access to or correction of your personal data.
- Deletion: Request the deletion of your data.
- Withdraw Consent: Opt-out of certain processing activities.
- Restrict Processing: Request that we limit how we use your data.
- Data Portability: Obtain a copy of your data in a structured format.
To exercise your rights, contact us at security@bosslogics.com.
12. Automated Decision-Making
We do not use automated decision-making or profiling that significantly affects users. If this changes, we will update this policy accordingly.
13. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding the personal information (“PI”) we collect about you. This section explains those rights, what we collect, why, who we share it with, and how to make a request.
Personal information we collect
In the past 12 months we have collected the following CCPA-defined categories of personal information:
- Identifiers — name, email address, postal address, telephone number, account ID, IP address.
- Commercial information — orders, proposals, products viewed, transaction history.
- Internet or other electronic network activity — server logs, integration usage data, application interaction events.
- Professional or employment-related information — role, organization, position.
- Inferences drawn from the above to support product features (recommendations, sales analytics).
We do not knowingly collect personal information from children under 16. We do not collect Sensitive Personal Information as defined by CPRA §1798.140(ae) (government identifiers, financial-account credentials, precise geolocation, racial or ethnic origin, religion, biometric data, health data, sex-life data) unless explicitly entered by an authorized user for a specific business purpose.
Sources
- Directly from you when you sign up, fill out a form, or contact us.
- From integrations you authorize (e.g., Shopify, FedEx, Mailchimp, Chargebee).
- Automatically from your interaction with our service (server logs, application telemetry, cookies on our marketing site).
Why we use your information
- To provide, operate, and maintain the BOSS Logics services and platforms.
- To process orders, proposals, and other transactions you initiate.
- To communicate with you about your account, security, and the service.
- To send service-related emails and, where you have opted in, marketing communications.
- To monitor security, prevent fraud, and ensure platform reliability.
- To comply with our legal obligations.
Who we share it with
We share personal information only with service providers who help us operate the platform, under written contracts that prohibit them from using your data for their own purposes. Our service providers include:
- Google Cloud Platform (hosting, storage, infrastructure)
- Twilio (SMS delivery)
- Mailchimp (email marketing — only with your opt-in)
- Chargebee (subscription billing)
- FedEx and other shipping carriers (label generation, tracking)
- Sentry (error monitoring)
- Google Analytics (first-party site analytics)
- Shopify and other authorized integration partners (product, inventory, and order sync)
We may also share information when required by law, in response to valid legal process, or to protect the rights, property, or safety of BOSS Logics, our customers, or the public.
Sale or sharing of personal information
We do not sell your personal information for monetary or other valuable consideration.
We do not share your personal information for cross-context behavioral advertising. Our marketing pages use Google Analytics to understand site usage; Google Signals (the feature that would feed analytics data into Google’s advertising graph) is disabled, so analytics data is not used to target advertising across other websites or apps.
Global Privacy Control (GPC)
If your browser sends the Sec-GPC: 1 signal (Global Privacy Control), we treat it as a verified opt-out request from any sale or sharing of your personal information and record the preference against your account (when authenticated) or session. You do not need to take any additional action.
How long we keep it
We retain personal information for as long as your account is active, plus any additional period required by tax, audit, or other legal obligations. Specific retention schedules are documented internally and enforced via automated purge jobs. When personal information is no longer needed, we delete or de-identify it.
Your California rights
As a California resident, you have the right to:
- Know what personal information we have collected about you, the sources, the purposes, and the third parties we have shared it with, going back at least 12 months.
- Access a copy of the specific pieces of personal information we hold about you (data portability).
- Delete personal information we have collected from you, subject to certain legal exceptions.
- Correct inaccurate personal information we hold about you.
- Opt out of the sale or sharing of personal information (we do not sell or share, but the right is preserved).
- Limit the use of Sensitive Personal Information to the limited purposes permitted by CPRA.
- Be free from retaliation for exercising any of these rights — we will not deny you service, charge a different price, or provide a different level of quality because you exercised a privacy right.
How to submit a request
To exercise any of these rights, contact our Data Protection Officer:
- Email dpo@bosslogics.com with “Privacy Request — California” in the subject line.
Verification. Before we fulfill a request, we will verify your identity using information already on file — typically your account email plus confirmation of recent account activity. We may ask for additional information if needed to match you to the account.
Authorized agents. You may use an authorized agent to make a request on your behalf. The agent must provide written, signed authorization from you, and we may still ask you to verify your own identity directly with us before fulfilling the request.
Response time. We will acknowledge your request within 10 business days and respond substantively within 45 days. If we need more time, we will let you know and may extend the response window by an additional 45 days, for a total of 90 days, as permitted by CPRA.
14. European Privacy Rights (GDPR / UK GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent local laws give you specific rights regarding your personal data.
Legal basis for processing
We process your personal data on one or more of the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the BOSS Logics Live service you signed up for, fulfill orders, and operate your account.
- Consent (Art. 6(1)(a)) — for optional marketing communications and analytics where you have explicitly opted in. You may withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — for security monitoring, fraud prevention, service improvement, and operating our business. We balance these interests against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, anti-fraud, and other applicable laws.
Your rights
You have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectify inaccurate or incomplete data (Art. 16).
- Erasure / “right to be forgotten” (Art. 17), subject to lawful exceptions.
- Restrict processing in certain circumstances (Art. 18).
- Data portability — receive your data in a structured, machine-readable format and transmit it to another controller (Art. 20).
- Object to processing based on our legitimate interests, including profiling (Art. 21).
- Withdraw consent at any time where consent is the basis for processing (Art. 7(3)). Withdrawal does not affect the lawfulness of processing before withdrawal.
- Lodge a complaint with the data protection supervisory authority in your country of residence (e.g., the ICO in the UK, CNIL in France, BfDI in Germany). A list of EU authorities is available at edpb.europa.eu.
International data transfers
BOSS Logics Live is hosted on Google Cloud Platform infrastructure in the United States. When your personal data is transferred from the EEA, UK, or Switzerland to the US, we rely on:
- Standard Contractual Clauses approved by the European Commission and the UK ICO, as included in our agreements with Google Cloud and other US-based service providers.
- Supplementary measures including encryption in transit and at rest, role-based access controls, and audit logging.
A copy of the Standard Contractual Clauses is available on request from our Data Protection Officer.
How to exercise your rights
Email dpo@bosslogics.com with “Privacy Request — GDPR” in the subject line. We will respond within 30 days, with the option to extend by an additional 60 days for complex or numerous requests, in line with Art. 12(3).
You do not have to pay a fee to make a request. We may charge a reasonable fee or refuse to act on requests that are manifestly unfounded or excessive.
Automated decision-making
We do not use solely automated decision-making (including profiling) that produces legal or similarly significant effects on you, as defined in Art. 22.
15. Policy Updates
We may update this Privacy Policy periodically. If we make material changes, we will notify users via email or a notice on our website.
16. Contact Us
For any privacy-related inquiries, please contact:
Data Protection Officer
BOSS Logics, Inc.
📧 Email: security@bosslogics.com
📍 Address: 1230 Avenue of Americas, 16th Floor, New York, New York 10020
Last updated: February 1, 2024