Version 1.0Effective August 29, 2026
Cadrin Privacy Policy · Version 1.0 · Effective [date]
1. Who we are. [Cadrin LLC], Illinois, USA. Contact: hello@getcadrin.com. This policy covers getcadrin.com, app.getcadrin.com, and the Cadrin extension.
2. Information we collect. (a) Account: name, work email, company, password hash, plan, seat assignments. (b) Billing: handled by Stripe; we store customer/subscription identifiers and invoice metadata, never full card numbers. (c) Usage: product analytics (pages, features, searches performed), device/browser data, IP, cookies per our Cookie Policy; session replay in the app with inputs masked. (d) Support: messages you send support@, processed by our ticketing system. (e) User content: pipelines, notes, my-book lists, saved searches. (f) Extension: the company identifier on the page you invoke it on, your device pairing token, and lookups performed — no other page content.
3. The Cadrin dataset. Our product contains information about employers, benefit plans, insurance carriers, and brokers derived from public government records (U.S. DOL Form 5500 filings) and, where enabled, licensed business-contact data about professionals in their business capacity. This information is not collected from you and is processed under our legitimate business purpose of providing market intelligence. Professionals appearing in the dataset may contact privacy@getcadrin.com regarding their business-contact information; see §7.
4. How we use information. Provide and secure the Service; process payments; send transactional messages (auth, receipts, alerts you configure, support); measure and improve the product; prevent fraud and abuse; comply with law. We do not sell your account information and we do not run third-party advertising.
5. Sharing. Only with subprocessors (§8), integration providers you connect (e.g., Salesforce — data you push travels under your instruction), professional advisors, and where required by law or in a business transfer with notice.
6. Retention. Account/user content: life of account + 30 days after deletion request. Billing/tax: 7 years. Security/audit logs: 2 years. Support threads: 3 years. Aggregated/de-identified data may be retained.
7. Your rights. All users: access, export (self-serve JSON/CSV of your content), correction, deletion (≤30 days, subject to §6 retention). California and other applicable states: rights to know, delete, correct, and opt out of sale/sharing — [conditional section: if enrichment "sale" analysis (01 §B5) concludes registration/opt-out duties apply, insert Do-Not-Sell mechanism + data-broker disclosures here]. We do not discriminate for exercising rights. Requests: privacy@getcadrin.com.
8. Subprocessors. Supabase (database/auth, US), Vercel (hosting, US), Stripe (payments), Resend (email), Trigger.dev (job processing), Upstash (rate limiting/cache), PostHog (analytics, US cloud), Sentry (error monitoring), [LLM provider(s) — Anthropic/OpenAI via gateway] (AI drafting; content not used to train their models per their business terms), [enrichment provider, if enabled]. Updates posted with 30-day notice.
9. Security. Encryption in transit and at rest, row-level tenant isolation, least-privilege access, audit logging, 2FA on all administrative systems. No method is 100% secure; report concerns to hello@getcadrin.com.
10. Children. Not directed to anyone under 18; we do not knowingly collect children's data.
11. International. Operated from and hosted in the United States; by using the Service you consent to US processing. Not directed to the EU/UK.
12. Changes. Material changes notified in-app/email 14 days before effect; version history available on request.