[Under the Hood] Debating the latest Tech and Tools for your Business

Watch Now

Privacy Policies

Effective Date: July 2026

Supersedes any Privacy Policies that pre-date this. This policy is specific to the North America region.


Introduction

Salted Stone, Inc. ("Salted Stone", "we", "us", or "our") respects the privacy of the people whose information we handle. This policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and what rights you have.

Two different situations are covered here, and they carry different obligations.

The first is information we handle for our own purposes: visitors to www.saltedstone.com, people who contact us or subscribe to our communications, prospective clients, job applicants, and our own personnel. For that information we are a data controller, meaning we decide why and how it is used.

The second is information we access while delivering services to our clients. Salted Stone implements and supports marketing and CRM platforms, principally HubSpot, on behalf of client organizations. That work can involve access to personal information belonging to a client's customers, prospects, or employees. For that information we are a service provider, and a processor under GDPR, acting only on our client's instructions. We do not decide how it is used. Section 1.2 sets out what that means in practice.

If your information was given to one of our clients, that client is the controller of it, and your rights are exercised through them rather than through us. Section 10 explains how we handle requests that reach us directly.

1. Our role

1.1 Where we are the controller

We determine the purposes and means of processing for information collected through our website, our marketing, our sales process, recruitment, and employment.

1.2 Where we are a service provider

Delivering client services does not involve independently processing, storing, or controlling personal information. In practice:

  • Our access to client data is limited to client-directed activity inside client-controlled environments, such as the client's own HubSpot portal.
  • That access is provisioned, governed, and revocable by the client through the platform's administrative controls.
  • The data stays resident in the platform provider's infrastructure. We do not copy it into our own systems, sell it, use it for our own purposes, or keep it beyond the engagement.
  • Our obligations in this role are set out contractually in the Data Protection Agreement we enter into with each client.

2. What we collect as a controller

2.1 Information you provide

  • Name, email address, phone number, and postal address including state, province, ZIP or postal code, and city
  • Company name, job title, and professional details
  • The content of enquiries, messages, and correspondence you send us
  • Marketing and communication preferences
  • Where you apply for a role: your CV, work history, qualifications, and related application materials

2.2 Information collected automatically

We collect information about how our website is accessed and used. That includes IP address, browser type and version, pages visited, date and time of visit, time spent on pages, unique device identifiers, referring source, and other diagnostic data.

2.3 Cookies and similar technologies

We use cookies and similar technologies, including beacons, tags, and scripts, to operate the website, remember your preferences, support security, and analyze usage.

Cookies are small data files stored on your device. You can set your browser to refuse them or to notify you when one is set, though parts of the website may not work properly if you do. The categories we use are session cookies to operate the site, preference cookies to remember your settings, security cookies, and analytics and marketing cookies to understand usage and measure how our marketing performs.

Where the law requires consent before non-essential cookies are set, we obtain it, and you can withdraw it at any time through the cookie controls on our website.

2.4 What we do not collect

We do not seek special categories of personal information, and we ask that you not send it to us. This covers information about health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic or biometric data, and sexual orientation, along with government identification numbers and payment card details.

3. How we use information, and our legal bases

Where GDPR or similar law applies, we rely on the following legal bases.

Purpose Legal basis
Operating, maintaining, and securing our website Legitimate interests
Responding to enquiries and providing support Legitimate interests, or performance of a contract
Delivering contracted services to clients Performance of a contract
Sending marketing communications Consent, or legitimate interests where permitted
Analyzing website usage to improve our services Legitimate interests, or consent where required for cookies
Recruitment and evaluating applications Legitimate interests, or consent
Meeting legal, tax, and regulatory obligations Legal obligation
Establishing, exercising, or defending legal claims Legitimate interests

Put more plainly: we use information to run and maintain our services, tell you about changes, respond when you contact us, understand how the website is performing, and meet obligations the law places on us.

We do not sell personal information, and we do not share it for cross-context behavioral advertising as California law defines those terms.

4. Automated decision-making

We do not use personal information to make automated decisions producing legal effects or otherwise significantly affecting individuals, and we do not conduct profiling of that nature for ourselves or on behalf of clients.

We do use AI and large language model tools in our work. Where those tools touch client information, they are subject to the controls in our Security Policy, including the requirement that the provider does not train models on submitted business data.

5. Service providers and subprocessors

We engage third parties to help deliver and analyze our services. They may access personal information only to perform work on our behalf, and are contractually obligated not to disclose it or use it for any other purpose.

Our principal providers:

Provider Purpose
HubSpot CRM, marketing automation, and website hosting, both for Salted Stone and as the platform on which client services are delivered
Google Workspace Email, document storage, and collaboration

We maintain a register of the subprocessors used in client delivery, recording each provider's purpose, the categories of data it may access, and its security certifications. It is available to clients on request. Clients are informed before we add or replace a subprocessor with access to their data.

6. International transfers

Your information may be transferred to and held on systems outside your state, province, or country, where data protection law may differ from your own. If you are outside the United States and provide information to us, it is transferred to the United States and processed there.

Where personal information leaves the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards. These include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the transfer mechanisms our platform providers operate.

7. How long we keep information

We retain personal information only as long as the purposes in this policy require, or as long as the law requires.

  • Enquiry and correspondence records: as long as needed to handle the matter, and for a reasonable period afterward
  • Marketing contact records: until you unsubscribe or withdraw consent, or until the record becomes inactive under our data hygiene practices
  • Website analytics: according to the retention settings of the tools we use
  • Recruitment records: for the duration of the process, and afterward only where permitted and relevant
  • Client engagement records: for the term of the engagement, and any period required for legal, tax, or contractual purposes

In our service provider role we do not retain client personal information beyond the term of the engagement. On written request, and absent an overriding legal retention obligation, we delete or anonymize client data in our possession and confirm completion to the client.

8. Security

We maintain appropriate technical and organizational measures for the nature of our services. Our Security Policy at www.saltedstone.com/security-policy-2026 describes them.

Client data resides within enterprise platforms rather than on Salted Stone infrastructure, so encryption, physical security, network protection, and infrastructure resilience for that data are provided by those platform providers under their own independently certified security programs. HubSpot publishes its certifications and controls at legal.hubspot.com/security.

The security of your information matters to us. No method of internet transmission or electronic storage is completely secure, however, and while we use commercially reasonable means to protect personal information, we cannot guarantee absolute security.

9. Data breach notification

If we become aware of a security incident involving unauthorized access to, disclosure of, alteration of, or destruction of personal information within systems we control, we act without undue delay to investigate and contain it.

Where the affected information belongs to a client, we notify that client within 72 hours of becoming aware of the incident, consistent with our Data Protection Agreement, and assist in investigation and mitigation. Responsibility for notifying affected individuals or regulators rests with the client as controller, unless the law independently requires us to do so.

Where we are the controller of the affected information, we notify the relevant supervisory authority and affected individuals as the law requires.

10. Your rights

Depending on where you live, you may have the following rights over information for which we are the controller.

Under GDPR and similar laws:

  • Access. Confirmation of whether we hold information about you, and a copy of it.
  • Rectification. Correction of inaccurate or incomplete information.
  • Erasure. Deletion, where no overriding basis for keeping it exists.
  • Restriction. Limits on how we use your information in certain circumstances.
  • Portability. A copy of information you provided to us, in a structured, commonly used, machine-readable format.
  • Objection. Objection to processing based on legitimate interests, and objection at any time to processing for direct marketing.
  • Withdrawal of consent. Withdrawal at any time where we rely on consent, without affecting the lawfulness of earlier processing.
  • Complaint. A complaint to your local supervisory authority.

Under the CCPA and CPRA, California residents may:

  • Know what categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we share it with
  • Request deletion of personal information we have collected
  • Request correction of inaccurate personal information
  • Opt out of the sale or sharing of personal information. We do not sell or share personal information as California law defines those terms
  • Limit the use of sensitive personal information. We do not seek to collect it
  • Receive equal service and price for exercising any of these rights

Making a request

Contact privacy@saltedstone.com. We acknowledge requests and respond within the period the law requires, ordinarily one month under GDPR and 45 days under California law. We may need to verify your identity first, and we use information provided for verification only for that purpose. You may use an authorized agent where the law permits.

If your information was given to one of our clients

Where we access your information as a service provider, the client is the controller and your rights are exercised through them. If you contact us directly about such information, we refer your request to that client without undue delay and assist them in responding. We do not act on those requests independently.

11. Disclosure for legal reasons

We may disclose personal information where we believe in good faith that doing so is necessary to comply with a legal obligation, to protect or defend our rights or property, to investigate possible wrongdoing connected to our services, to protect the personal safety of users or the public, or to protect against legal liability.

We may also disclose information in connection with a merger, acquisition, financing, or sale of assets, and will take reasonable steps to see that it remains protected.

12. Links to other sites

Our website contains links to sites we do not operate. Following one takes you to that party's site, and we encourage you to read the privacy policy of every site you visit. We have no control over, and take no responsibility for, the content or privacy practices of third-party sites.

13. Children's privacy

Our services are not directed to anyone under 18, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has given us personal information, contact us and we will take steps to remove it.

14. Changes to this policy

We may update this policy. Updates are posted on this page with a revised effective date and version above. Where changes are material, we give notice by email or by a prominent notice on the website before they take effect. We encourage you to review the policy periodically.

15. Contact us

Questions, requests, or complaints about this policy or our handling of personal information:

Our Privacy Officer is reachable at privacy@saltedstone.com.