Privacy notice
Effective September 24, 2026
Information collected
When you request a territory review, PermitOrigin collects the information you submit, including your name, work email, company, role, branch footprint, material focus, and decision criteria. If a pilot is accepted, PermitOrigin also collects the territory criteria, record grading, commercial outcomes, support communications, and billing records needed to operate and evaluate the pilot.
How information is used
The information is used to evaluate pilot fit, assess territory coverage, respond to your request, prepare a relevant sample, operate an accepted pilot, improve record quality, protect the service, and maintain required business records. PermitOrigin does not sell form-submission information.
Service providers
Netlify provides site hosting and form processing. Spaceship and Spacemail provide domain and business-email services. An accepted pilot may use separately licensed data and operational providers identified in the applicable order or service documentation. Access is limited to people and providers that need the information for these purposes.
Retention and requests
Unaccepted territory-review submissions are deleted or anonymized within 90 days unless retention is required for security, dispute, or legal purposes. Accepted pilot reports, criteria, grading, and outcome records are retained for the pilot and up to 12 months after it ends, then deleted or anonymized unless the parties agree otherwise in writing. Billing records may be retained for the period required by applicable accounting and tax law. You may request access, correction, or deletion by emailing privacy@permitorigin.com.
Public-record information
PermitOrigin may evaluate public permit records and licensed data sources. A public permit does not establish purchase intent, supplier preference, or consent to automated outreach. Pilot users are responsible for reviewing records and following applicable communication laws and policies.
Security
PermitOrigin uses access controls, encrypted transport, limited data collection, source restrictions, and documented incident and credential-rotation procedures. No system can guarantee absolute security. Security reports may be sent to security@permitorigin.com.
Changes
This notice may be updated as the service and its providers change. The effective date above identifies the current version.
Contact
Privacy questions may be sent to privacy@permitorigin.com. Service and support questions may be sent to support@permitorigin.com.