Tokenize Privacy Policy

Last updated: September 10, 2026

1. Scope

This Privacy Policy explains how Palindrome Labs, Inc. dba Tokenize ("Tokenize," "we," "us," or "our"), collects, uses, and shares Personal Information when you visit tokenizehq.com or its subdomains, create or administer an account, communicate with us, or otherwise interact with our services (the "Services"). "Personal Information" means information that identifies, relates to, or could reasonably be linked to an identifiable individual.

Tokenize acts as the controller or business for Personal Information that we process for our own purposes, including website, business-contact, account and organization administration, customer-relationship, subscription, billing, payment, tax, fraud-prevention, security, legal-compliance, and optional product-analytics information described in this policy (collectively, "Operational Data"). Operational Data excludes prompts, responses, transcripts, telemetry, source code, files, tool content, and other information that Tokenize processes on a customer's behalf. This policy does not govern data or content that a business customer or its authorized users submit to the Services ("Customer Data"). Tokenize processes Customer Data as a processor, service provider, contractor, or subprocessor on the customer's behalf under our Terms of Use or other customer agreement and our Data Processing and Security Addendum. If you use the Services through your employer or another organization, direct requests concerning Customer Data to that organization.

Where the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance apply, Personal Information is personal data within the meaning of that law. The Swiss-specific provisions in Sections 4, 8, 9, and 10 supplement the other disclosures in this policy.

2. Who We Are

For the Personal Information covered by this policy, the controller or business is:

Palindrome Labs, Inc. dba Tokenize
128 King St, Floor 3
San Francisco, CA 94107, United States

European, United Kingdom, and Swiss representatives

Individuals in the European Economic Area, United Kingdom, or Switzerland may contact Tokenize directly or submit a request through the applicable representative below.

European Union

Instant EU GDPR Representative Limited
Attention: Adam Brogden
Office 2, 12A Lower Main Street
Lucan, Co. Dublin K78 X5P8, Ireland
Email: contact@gdprlocal.com
Website: www.gdprlocal.com
Privacy requests: tokenize.gdprlocal.com/eu

United Kingdom

GDPRLocal Ltd.
Attention: Adam Brogden
1st Floor Front Suite
27-29 North Street
Brighton, England BN1 1EB
Email: contact@gdprlocal.com
Website: www.gdprlocal.com
Privacy requests: tokenize.gdprlocal.com/uk

Switzerland

GDPRLocal Ltd.
Attention: Adam Brogden
Via Luigi Lavizzari 8
Mendrisio, Switzerland
Email: contact@gdprlocal.com
Website: www.gdprlocal.com
Privacy requests: tokenize.gdprlocal.com/swiss

3. Personal Information We Collect

Information you provide

  • Account and profile information: name, work email, phone number, company, role, and similar account details.
  • Authentication information: identifiers and basic profile information provided by an identity provider enabled for your organization.
  • Communications: messages, support requests, feedback, survey responses, and information you choose to share with us.
  • Business, subscription, and billing information: names and contact details for customer administrators, procurement personnel, and billing contacts; selected plans; subscription status; transaction amounts and status; invoices; tax information; and Tokenize account identifiers needed for billing.
  • Payment information: for non-enterprise plans, payment details are submitted directly to Stripe. Tokenize receives limited payment and transaction information from Stripe, such as the payment-method type, partial payment-method details, billing status, and Stripe customer or transaction identifiers. Tokenize does not receive or store full payment-card numbers.

Information we collect automatically

  • Device and network information: IP address, device and browser type, operating system, referring URL, and approximate location derived from an IP address.
  • Service activity: pages viewed, features used, actions taken, session information, and application, security, and diagnostic events.
  • Optional product analytics: if you enable Product Analytics in the authenticated platform, PostHog receives page and feature events, browser and device information, a session identifier, and pseudonymous user and organization identifiers. We do not use PostHog for advertising or cross-site tracking, and we do not send prompts, responses, source code, credentials, or other Customer Data to PostHog.
  • Essential cookies and similar technologies: authentication cookies, local storage, security tokens, consent records, and preferences described in our Cookie Policy.
  • Privacy-focused website analytics: pages viewed, referring websites, browser and device type, country-level location, and aggregated visit and event counts collected without placing analytics cookies or persistent identifiers on your device.
  • Website measurement and company identification: subject to the consent model and choice that apply in your location, Snitcher B.V. uses first-party cookies and browser storage on our public website. Snitcher processes IP address, browser and device characteristics, pages viewed, referring URLs, visit duration, and random device and session identifiers. It uses the IP address to identify the company associated with a visit and derive an approximate location, then provides us with company-level visit information and firmographic data such as company name, industry, and size. We do not use Snitcher to identify individual consumers or for cross-site advertising.

Sources of Personal Information

We collect Personal Information from you, your organization, identity providers that your organization enables, Stripe and other service providers that support our business, your browser or device, and your use of the Services. We may also receive business contact information from public sources, professional networks, event organizers, and referral partners. Snitcher provides company-level information associated with public-website activity and the visitor's network connection.

Tokenize does not intentionally solicit sensitive Personal Information for its own business purposes, such as government identifiers, financial-account numbers, precise geolocation, health or biometric information, or information revealing protected characteristics. Customer Data may contain sensitive information that a customer or its users choose to submit. The customer controls that submission, and Tokenize processes it under the customer agreement and DPA.

4. How We Use Personal Information

We use Personal Information to:

  • provide, administer, secure, and maintain the Services and customer accounts;
  • authenticate users and manage organizations, permissions, and access;
  • prevent fraud, abuse, and security incidents;
  • process payments, administer subscriptions, calculate taxes, issue invoices and refunds, prevent payment fraud, maintain accounting records, and address billing disputes;
  • provide support and communicate about service, billing, security, and account matters;
  • understand feature usage, diagnose errors, and improve the Services;
  • identify and understand business visitors to our public website, measure marketing performance, and conduct business-to-business sales and marketing;
  • send marketing communications where permitted by law and manage communication preferences;
  • comply with law, enforce our agreements, and protect rights and safety; and
  • complete a financing, acquisition, reorganization, or sale of all or part of our business.

Legal bases for European processing

If the EU GDPR or UK GDPR applies, Tokenize relies on the following legal bases:

PurposeLegal basis
Providing accounts, administering customer relationships, support, and service communicationsPerformance of a contract or steps requested before entering into a contract; Tokenize's legitimate interests in operating its business and serving organizational customers
Authentication, fraud prevention, security, logging, and incident responsePerformance of a contract; Tokenize's legitimate interests in protecting the Services, customers, and users; compliance with legal obligations
Billing, tax, accounting, and recordkeepingPerformance of a contract; compliance with legal obligations; Tokenize's legitimate interests in administering its business
Privacy-focused website analyticsTokenize's legitimate interests in understanding aggregate website performance and improving the Site
Website visitor identification, marketing attribution, and related business-to-business outreachConsent when Tokenize presents a consent request; otherwise Tokenize's legitimate interests where law permits, subject to your right to object or opt out
Optional PostHog product analyticsConsent
Security monitoring, error diagnostics, and service improvement that does not rely on optional device analyticsPerformance of a contract; Tokenize's legitimate interests in securing, maintaining, and improving the Services
Marketing communicationsConsent where law requires it; otherwise Tokenize's legitimate interests in marketing business services, subject to your right to object
Legal claims, compliance, and corporate transactionsCompliance with legal obligations; Tokenize's legitimate interests in protecting its rights and completing a corporate transaction

Tokenize considers the nature of the information, the effect on individuals, and the safeguards described in this policy before relying on legitimate interests. You may object to processing based on legitimate interests as described in Section 10.

Processing under Swiss law

Where the FADP applies, we process Personal Information lawfully, in good faith, and proportionately, for purposes disclosed when it is collected or otherwise evident from the circumstances. We apply the FADP's requirements for accuracy, retention, security, and privacy by design and by default. Where processing would otherwise infringe an individual's personality rights, we require a justification permitted by Swiss law, such as consent, an overriding private or public interest, or a legal provision. Where we rely on consent to process sensitive personal data or conduct high-risk profiling, we obtain express consent as required by FADP Article 6(7).

5. How We Share Personal Information

We disclose Personal Information to service providers that support cloud infrastructure, hosting, storage, security, authentication, account administration, consent management, payment processing, subscription administration, tax, analytics, application monitoring, feature management, business communications, productivity, and customer support. PostHog processes the optional product-analytics information described above when you enable Product Analytics in the authenticated platform.

We use Stripe to process payments and administer subscriptions for non-enterprise plans. We provide Stripe only billing contacts, subscription and transaction information, and Tokenize account identifiers needed for billing. Customers submit payment details directly to Stripe. We do not provide Stripe with prompts, responses, transcripts, telemetry, source code, files, credentials, or other Customer Data. Stripe's Privacy Policy describes how Stripe processes information it receives directly.

We use Snitcher, operated by Snitcher B.V., to measure business use of our public website, identify the companies that visit, and support marketing attribution and business-to-business outreach. Snitcher receives the website and device information described in Section 3, uses IP addresses to identify companies and approximate location, and aggregates visit information at the company level. We do not provide Snitcher with prompts, responses, transcripts, telemetry, source code, files, credentials, or other Customer Data. Snitcher's Privacy Policy describes its processing practices.

We require providers that process Personal Information on our behalf to protect it and use it only to provide services to Tokenize, subject to applicable law. When a provider processes Personal Information for its own legally permitted purposes, its privacy notice governs that processing.

Some providers also process Customer Data as Tokenize subprocessors. The current list of Customer Data subprocessors appears in our Trust Center. The customer agreement and DPA govern notice, objections, and Tokenize's responsibility for those subprocessors.

We may also disclose Personal Information to:

  • Professional advisers: lawyers, accountants, auditors, and insurers;
  • Authorities and other parties: when law requires disclosure or when disclosure protects rights, safety, or the integrity of the Services;
  • Transaction participants: investors, lenders, acquirers, successors, and their advisers in connection with a financing or corporate transaction; and
  • Parties you direct: a third party when you ask us to disclose information or consent to the disclosure.

We do not sell Personal Information for money. Some U.S. state privacy laws define "sale," "sharing," or "targeted advertising" broadly enough to include disclosures for marketing even when no money changes hands. You may opt out of non-essential website measurement and company identification through Cookie Preferences and may submit other applicable opt-out requests by emailing privacy@tokenizehq.com.

6. Cookies and Similar Technologies

We use essential cookies and similar technologies for authentication, security, preferences, and application delivery.

We use privacy-focused analytics on our public website. This service does not place analytics cookies or persistent identifiers on your device, and we do not use it to identify you or follow you across websites. Where applicable, we process this information based on our legitimate interest in understanding aggregate website performance and improving our website.

We use a consent manager on our public website. It classifies Snitcher as a marketing technology and applies the consent model configured for the visitor's location. For Swiss visitors and others subject to an opt-in model, the website does not load Snitcher before the visitor accepts marketing technologies. In an opt-out location, Snitcher may load until the visitor rejects marketing technologies. You may accept, reject, or customize non-essential technologies and reopen Cookie Preferences to change your choice. Rejecting or withdrawing marketing consent stops future Snitcher collection from that browser.

PostHog product analytics is off by default in our authenticated platform. If you enable it in Settings > Account > Privacy, we use PostHog to understand feature usage and administer product features. We configure PostHog not to record sessions, autocapture page interactions, create advertising profiles, or collect prompts, responses, source code, credentials, or other Customer Data. You may disable Product Analytics at any time in the same setting. Disabling it stops future PostHog collection from that browser and clears the PostHog browser identity stored there.

When you initiate checkout or manage a paid self-service subscription, you may be directed to a Stripe-hosted page. Stripe may use cookies and similar technologies on its payment pages for payment processing, authentication, security, and fraud prevention. We do not use Stripe technologies for advertising, and we do not load a Stripe payment form on the public website before you initiate a payment or billing action.

We also use diagnostic and security technologies needed to monitor errors, maintain performance, and protect the Services. Our Cookie Policy identifies these technologies, their browser-storage duration, and the choices available to you.

7. Data Retention

We retain Personal Information only for as long as reasonably necessary for the purposes described in this policy. We consider the nature and sensitivity of the information, the length of our relationship, security and support needs, and legal, accounting, audit, and dispute-resolution requirements.

Our general retention approach is:

InformationRetention approach
Account and profile informationFor the life of the account or business relationship and afterward as needed for account closure, security, disputes, and legal compliance
Authentication and organization recordsFor the life of the account or organization and afterward as needed for security, audit, and legal compliance
Communications, support requests, and feedbackFor as long as needed to address the communication and maintain appropriate business records
Billing contacts, subscription information, and transaction recordsFor the business relationship and afterward for periods reasonably necessary for payment processing, refunds, disputes, fraud prevention, tax, accounting, audit, and other legal requirements
Device, usage, security, and application logsFor periods appropriate to security, fraud prevention, troubleshooting, analytics, and operation of the Services
Essential cookie and device-storage dataAccording to the applicable authentication, security, preference, or delivery configuration described in the Cookie Policy
Consent and cookie-preference recordsFor as long as needed to apply and demonstrate your current choice, until you change the preference, clear browser storage, or the record expires under the consent-manager configuration
Privacy-focused website analyticsFor as long as needed to understand website trends and operate the analytics service
Snitcher browser identifiers and company-level visit dataBrowser identifiers persist for the periods listed in our Cookie Policy, up to one year. We retain company-level visit reports only as long as reasonably necessary for website measurement, attribution, and business-to-business sales and marketing.
Optional PostHog product analyticsBrowser identifiers persist for up to 365 days after you enable Product Analytics, unless you disable the setting or clear browser storage sooner; related event data is retained only as long as needed for product analytics and service improvement
Marketing preferencesFor as long as needed to honor the preference, including suppression records after an opt-out

When we no longer need Personal Information, we delete or de-identify it, subject to legal holds and limited retention in backups until those backups are overwritten or expire under our retention schedule.

The Data Processing and Security Addendum governs the retention, return, and deletion of Customer Data.

8. Security

We maintain administrative, technical, and organizational safeguards designed to protect Personal Information.

No system is perfectly secure. If a breach affects Personal Information covered by this policy, we will notify affected individuals and authorities as required by law. The DPA governs notice to customers concerning a Security Incident involving Customer Data.

Swiss data security breaches

Where the FADP applies and Tokenize acts as controller, we will notify the Swiss Federal Data Protection and Information Commissioner (FDPIC) as soon as possible after becoming aware of a data security breach likely to result in a high risk to your personality or fundamental rights (FADP Article 24(1)). We will provide the available information promptly and supplement it as necessary. The Swiss notification duty applies separately from any GDPR notification deadline.

We will inform affected individuals when necessary for their protection or when the FDPIC requires it (FADP Article 24(4)). The notice will use understandable language and describe the breach, its consequences and risks, measures taken or proposed, and a contact person. Any restriction, delay, or omission must be permitted by FADP Article 24(5).

For Customer Data subject to the FADP that we process on a customer's behalf, we will notify the affected customer as soon as possible, regardless of our assessment of the risk, under FADP Article 24(3) and the applicable contractual notification terms. The customer remains responsible for its own obligations as controller.

9. International Processing

Tokenize is based in the United States and stores and processes Personal Information in the United States. The United States is the destination country for international transfers into Tokenize's systems. Some service providers process Operational Data in other countries. Snitcher processes public-website tracker data in Frankfurt, Germany.

For transfers from the European Economic Area, United Kingdom, or Switzerland to the United States, Tokenize relies on the applicable Data Privacy Framework while Tokenize's certification for that framework appears as active on the U.S. Department of Commerce Data Privacy Framework List. If a framework does not apply, Tokenize uses the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss-adapted Standard Contractual Clauses, or another lawful safeguard, or suspends the affected transfer. You may request information about the safeguard that applies to your Personal Information by emailing privacy@tokenizehq.com. Tokenize may redact confidential or security-sensitive information from a copy of a transfer agreement.

Swiss international transfers

For Personal Information transferred from Switzerland to Tokenize in the United States, we rely on the Swiss-U.S. DPF while our Swiss-U.S. certification is active and covers the transferred information, as described below. Our certification covers non-HR Personal Information. An EU-U.S. DPF certification alone does not provide a basis for reliance on the Swiss-U.S. DPF.

For other transfers governed by the FADP, we rely on an adequate level of protection under FADP Article 16(1), as recognized in Annex 1 of the Swiss Data Protection Ordinance, or an applicable safeguard under Article 16(2). Where we use standard contractual clauses, they must be recognized for Swiss transfers and include the required Swiss adaptations, including the FDPIC's competence and the rights of individuals in Switzerland. We assess the protection available in the destination country and apply supplementary safeguards where needed. Any reliance on an exception under Article 17 must meet that exception's conditions. If we cannot establish a lawful basis for a transfer, we suspend it.

We will provide information about additional destination countries and the applicable guarantees or exceptions where required by FADP Article 19(4). You may request information about the safeguard applicable to your Personal Information using the contact details above.

Data Privacy Framework

Palindrome Labs, Inc. dba Tokenize participates in and complies with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF") as set forth by the U.S. Department of Commerce. The U.S. Department of Commerce lists Tokenize as an active participant under all three frameworks for non-HR Personal Information. Tokenize has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles for non-HR Personal Information received from the European Economic Area and the United Kingdom and Gibraltar in reliance on the EU-U.S. DPF and the UK Extension. Tokenize has certified that it adheres to the Swiss-U.S. DPF Principles for non-HR Personal Information received from Switzerland in reliance on the Swiss-U.S. DPF. Tokenize relies on a framework as a transfer mechanism only while its certification for that framework appears as active. If this policy conflicts with the EU-U.S. DPF Principles or Swiss-U.S. DPF Principles, the applicable Principles govern. Learn more through the Data Privacy Framework program and view our certification on the Data Privacy Framework List.

Section 5 identifies the types and, where appropriate, the identities of third parties to which Tokenize discloses Personal Information and the purposes of those disclosures. Tokenize remains responsible under the Data Privacy Framework Principles for Personal Information it transfers to a third party acting as an agent on its behalf unless Tokenize proves that it was not responsible for the event giving rise to the damage. Tokenize may disclose Personal Information in response to lawful requests by public authorities, including to meet national-security or law-enforcement requirements.

EU, UK, and Swiss individuals may exercise the access and choice rights described below for Personal Information covered by the applicable Data Privacy Framework. You may also contact us to opt out of a disclosure of covered Personal Information to a non-agent third party or a use for a purpose materially different from the purposes described when the information was collected. Tokenize obtains affirmative express consent before disclosing sensitive Personal Information to a non-agent third party or using it for a materially different purpose when the Data Privacy Framework Principles require consent.

In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Tokenize commits to resolve DPF Principles-related complaints about our collection and use of Personal Information. EU, UK, and Swiss individuals with inquiries or complaints concerning Personal Information received in reliance on the applicable Data Privacy Framework should first contact Tokenize at privacy@tokenizehq.com. Tokenize will acknowledge and respond to the complaint within 45 days.

Tokenize commits to refer unresolved complaints concerning our handling of non-HR Personal Information received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, or the Swiss-U.S. DPF to JAMS, an alternative dispute-resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint, or if Tokenize has not addressed the complaint to your satisfaction, visit JAMS Data Privacy Framework Dispute Resolution for more information or to file a complaint. JAMS provides these services at no cost to you.

The Federal Trade Commission has jurisdiction over Tokenize's compliance with the Data Privacy Framework Principles. Under the conditions described in Annex I to the Principles, you may invoke binding arbitration after exhausting the other recourse mechanisms available under the applicable framework.

10. Your Privacy Rights

Depending on where you live and subject to applicable law, you may have the right to:

  • access or know about Personal Information we process about you;
  • correct inaccurate Personal Information;
  • delete Personal Information;
  • receive a portable copy of Personal Information;
  • opt out of certain processing, including a sale, sharing, or targeted advertising where applicable;
  • withdraw consent where processing relies on consent; and
  • exercise your rights without unlawful discrimination.

If the EU GDPR or UK GDPR applies, you may also have the right to restrict processing, object to processing based on legitimate interests or direct marketing, and lodge a complaint with the supervisory authority in the country where you live or work or where you believe a violation occurred. If the FADP applies, you may request information about our processing, ask us to correct or delete Personal Information, object to processing, request data delivery or transfer where the statutory conditions apply, and contact the Swiss Federal Data Protection and Information Commissioner. Withdrawing consent does not affect processing that occurred before withdrawal.

To submit a request, email privacy@tokenizehq.com or use the applicable representative portal in Section 2. You may change public-website marketing consent through Cookie Preferences. You may withdraw consent for PostHog product analytics through Settings > Account > Privacy in the authenticated platform. We may request information needed to verify your identity or authority. We will respond within the period required by law.

If we deny a request, we will explain why. Where applicable law provides an appeal right, email privacy@tokenizehq.com with the subject line "Privacy Request Appeal" and identify the request you want us to reconsider.

Swiss access requests and concerns

Where the FADP applies, you may ask whether we process your Personal Information and request the information needed to understand the processing and exercise your rights. This includes the purposes, retention period or criteria, available source information, recipients, and relevant destination countries and transfer safeguards. Subject to statutory conditions and exceptions, you may also seek correction, deletion or destruction, restriction of unlawful processing or disclosure, and data delivery or transfer.

We normally answer Swiss access requests free of charge within 30 days. If we cannot provide the information within that period, we will inform you within the 30 days, explain the reason, and tell you when to expect our response. Any refusal, restriction, delay, or fee must be permitted by the FADP, and we will explain the applicable reason.

You may contact us or our Swiss representative in Section 2 about your request or concerns. You may also raise data-protection concerns with the FDPIC through its contact page at https://www.edoeb.admin.ch/en/contact-2 and seek judicial remedies where available under Swiss law.

Automated decision-making

Tokenize does not use Personal Information covered by this policy to make a decision based solely on automated processing that produces legal effects or similarly significant effects for an individual. The Services may produce recommendations and classifications for business customers, but the customer controls decisions made from those Outputs.

California disclosures

The table below describes the categories of Personal Information that we may collect, the sources, our purposes, and the recipients. We do not collect every example from every individual.

CCPA categoryExamplesSourcesPurposesRecipients
IdentifiersName, work email, phone number, IP address, account identifiers, and online identifiersYou, your organization, an enabled identity provider, your device, public sources, professional networks, event organizers, referral partners, and service providers such as SnitcherAccounts, authentication, security, support, communications, company identification, attribution, and business-to-business marketingHosting, identity, security, application, communications, support, analytics, and company-identification providers
Cal. Civ. Code § 1798.80(e) informationName, phone number, business contact details, billing address, and partial payment-method detailsYou, your organization, Stripe, public sources, professional networks, event organizers, or referral partnersAccount administration, payment processing, support, and business communicationsProviders supporting those functions, payment providers, and professional advisers
Commercial informationSelected plan, subscription status, transaction amounts and status, invoices, refunds, and billing historyYou, your organization, Stripe, and use of the ServicesPayment processing, subscription administration, tax, accounting, fraud prevention, refunds, and billing supportPayment, billing, tax, accounting, fraud-prevention, and support providers
Internet or electronic-network activityDevice information, referring URLs, pages viewed, feature activity, and application or security logsBrowsers, devices, use of the Services, and service providers such as SnitcherOperation, security, troubleshooting, analytics, improvement, company identification, attribution, and business-to-business marketingHosting, infrastructure, analytics, monitoring, security, application, and company-identification providers
Approximate geolocationGeneral location derived from an IP addressDevice or network connection and service providers such as SnitcherSecurity, fraud prevention, analytics, service operation, company identification, attribution, and business-to-business marketingHosting, security, analytics, and company-identification providers
Professional or employment informationCompany, role, business contact information, professional profile, business relationship, and firmographic informationYou, your organization, an identity provider, public sources, professional networks, event organizers, referral partners, or Snitcher for company-level firmographic informationAccount administration, support, company identification, attribution, and business communicationsIdentity, productivity, communications, support, and company-identification providers
InferencesAn association between public-website activity and a company or business interestPublic-website activity and company-identification providers such as SnitcherCompany identification, attribution, and business-to-business marketingAnalytics, communications, and company-identification providers

We have not sold Personal Information for money in the preceding 12 months. Snitcher processes identifiers, Internet or electronic-network activity, and approximate geolocation to produce company-level visit information and related inferences. You may opt out of this non-essential processing through Cookie Preferences or by emailing privacy@tokenizehq.com. We do not knowingly sell or share the Personal Information of consumers under 16.

11. Marketing Communications

We may use company-level visit information from Snitcher and business contact information from other sources to send product news or conduct business-to-business outreach as permitted by law. Marketing emails include an unsubscribe mechanism. You may stop future Snitcher collection through Cookie Preferences. An opt-out does not affect service, security, billing, support, or other transactional communications.

12. Children

The Terms of Use require users of the public Site to be at least 18. The separate references in this Policy to children under 13 and consumers under 16 address privacy-law requirements and do not change the Site eligibility rule.

The Services are a business product intended for organizations and their personnel. They are not directed to children, and we do not knowingly collect Personal Information from anyone under 13. Contact privacy@tokenizehq.com if you believe a child has provided Personal Information to us.

13. Third-Party Links

The Services may link to third-party sites and tools that we do not control. Their privacy policies govern their practices.

14. Changes to This Policy

We may update this policy as our practices or legal obligations change. We will post the revised version with a new "Last updated" date and provide any additional notice required by law. Where law requires consent before materially different processing, we will obtain it before beginning that processing.

15. Contact Us

Palindrome Labs, Inc. dba Tokenize
128 King St, Floor 3
San Francisco, CA 94107, United States
privacy@tokenizehq.com