Legal and privacy

Data Protection and Privacy Policy

Effective and last updated: August 3, 2026

Epic Global Inc. ("Epic Global," "we," "us," or "our") respects privacy and is committed to protecting and handling personal information responsibly. This Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our websites, use products or services that link to this Policy, communicate with us, or authorize a connection to a third-party platform or service.

This Policy describes our general practices. A contract, data processing addendum, product-specific notice, or authorization screen may provide additional or more specific terms. If we process personal information solely on behalf of a business customer, that customer controls the information and its instructions govern our processing.

1. Scope

This Policy applies to:

  • our corporate website at epicglobalinc.com and related pages or subdomains that link to this Policy;
  • Epic Global software products, customer portals, and business services that link to this Policy;
  • marketplace, ecommerce, advertising, analytics, asset-management, and operational services we provide;
  • integrations that a customer or authorized user connects to our services, including marketplaces, social and advertising platforms, identity providers, accounting systems, human-resources systems, and other business applications;
  • job applicants, candidates, contractors, and others who participate in recruiting or employment-related processes; and
  • communications, support requests, assessments, events, and other interactions with Epic Global.

This Policy does not govern a third party's independent privacy practices. Third-party services remain subject to their own privacy policies and terms.

2. Personal Information We Collect

The information we collect depends on how you interact with us and which services or integrations you use.

Information you provide

  • Contact and identity information: name, business email address, telephone number, job title, company, account identifiers, and authentication or profile information.
  • Business and operational information: marketplace accounts, catalogs, SKUs, listings, inventory, pricing, advertising, forecasts, budgets, approvals, assets, software subscriptions, vendors, contracts, and other information submitted for an assessment or service.
  • Transaction and billing information: billing contact details, plan or entitlement information, invoices, payment status, and transaction records. Payment-card details may be collected directly by a payment processor rather than by Epic Global.
  • Communications: messages, meeting information, support requests, survey responses, and records of correspondence.
  • Applicant and recruiting information: resumes, employment and education history, professional qualifications, references, work-authorization information, compensation expectations, interview notes, and other information provided during a recruiting process.
  • Files and content: documents, images, product information, creative materials, reports, or other content you choose to upload or provide.

Please do not provide sensitive personal information unless it is necessary for an authorized business purpose and you have the right to provide it.

Information from connected platforms and APIs

When an authorized user connects a third-party account, we may receive information allowed by that platform and by the permissions selected by the user, including:

  • platform account identifiers, profile information, business or shop information, and authorized-user details;
  • product catalogs, listings, inventory, pricing, orders, returns, shipping or fulfillment information, and customer-service information;
  • advertising accounts, campaigns, spend, performance, audience or attribution metrics, and reporting data;
  • content, post or video metadata, engagement and performance metrics, comments or interaction settings, and publishing status;
  • access tokens, refresh tokens, authorization scopes, token expiration information, webhook events, and integration logs; and
  • other information specifically described on the authorization screen or in applicable product documentation.

The exact information received is limited by the third-party permissions granted and the features enabled.

Information collected automatically

  • IP address, browser type, device type, operating system, language, and approximate location derived from IP address;
  • pages, features, links, and content viewed; timestamps; referring pages; campaign parameters; and interactions with forms or calls to action;
  • session identifiers, account activity, audit events, error logs, and security events; and
  • cookie, pixel, local-storage, and similar technology identifiers.

3. Sources of Personal Information

We may collect personal information:

  • directly from you;
  • from your employer, customer, account administrator, or another authorized user;
  • from platforms and applications you authorize us to connect to;
  • from service providers, business partners, and public business sources; and
  • automatically through our websites, software, logs, cookies, pixels, and similar technologies.

4. How We Use Personal Information

We use personal information to:

  • provide, configure, secure, support, and improve our websites, software, integrations, and services;
  • authenticate users, manage accounts and workspaces, enforce permissions, and maintain audit records;
  • operate authorized marketplace, ecommerce, content, advertising, analytics, asset, procurement, finance, and workflow functions;
  • synchronize data, prepare reports and recommendations, monitor performance, and automate requested business processes;
  • process transactions, administer plans and entitlements, and maintain business and financial records;
  • communicate about services, respond to requests, schedule meetings, deliver notices, and provide customer support;
  • measure website and campaign performance and improve our marketing and customer experience;
  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of law or contract;
  • comply with legal obligations, resolve disputes, enforce agreements, and protect rights and safety; and
  • create aggregated or deidentified information that does not reasonably identify an individual.

We do not use personal information for materially different purposes without providing appropriate notice or obtaining consent when required.

We may use automated tools to generate analyses, recommendations, classifications, or workflow suggestions. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about an individual without meaningful human review.

5. Connected Platforms and API Integrations

If you or your organization authorize an Epic Global service to connect with a third-party platform, application, or API, the following additional terms apply to information received through that connection ("Integration Data"):

  • Authorization and scope: We access Integration Data only after an authorized user or business customer enables the connection. The information available to us depends on the products, scopes, permissions, account settings, and instructions approved for that integration.
  • Types of Integration Data: Depending on the integration, Integration Data may include account and user identifiers, profile or workspace information, business or shop information, catalog and product data, order and fulfillment data, content or media metadata, engagement and performance metrics, advertising or commerce information, accounting or transaction records, identity or employment information, authorization tokens, and integration logs.
  • Purposes: We use Integration Data to provide the requested connection and related services, such as account linking, data synchronization, marketplace or catalog operations, content publishing, identity and access management, usage analysis, reporting, reconciliation, customer support, security, and troubleshooting.
  • User choice and authorized actions: We honor applicable permissions, account settings, privacy options, and provider restrictions. We do not publish content, change third-party records, or perform account actions unless initiated or authorized through the applicable service workflow.
  • Sharing: We do not sell Integration Data. We disclose Integration Data only to the authorized customer, to service providers that help us deliver the integration under appropriate obligations, when directed by an authorized user, or when legally required. Additional provider-specific restrictions may apply.
  • Tokens and security: Access tokens, refresh tokens, API keys, and similar credentials are treated as confidential, protected using reasonable safeguards, and used only for authorized requests.
  • Retention and revocation: We retain Integration Data only for as long as reasonably necessary to provide the authorized service, meet legal obligations, resolve disputes, or maintain security and audit records. An authorized user may revoke access through the connected provider or request disconnection from Epic Global. Following revocation or a verified deletion request, we delete or deidentify Integration Data that is no longer required, subject to legal obligations, fraud-prevention needs, and limited backup cycles.
  • AI-assisted features and model training: We may use vetted artificial-intelligence service providers to process Integration Data or customer content only to perform a customer-requested feature. We do not use, or permit those providers to use, Integration Data, customer content, uploaded files, or personal information to develop, train, or improve generalized or foundation artificial-intelligence or machine-learning models.

Each connected provider processes information under its own privacy policy, terms, and platform rules. Epic Global is not responsible for a provider's independent practices.

Our use and transfer to any other application of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, credit decisions, or generalized model training.

6. Legal Bases for Processing

Where applicable law requires a legal basis, we process personal information based on contract, legitimate interests, consent, legal obligations, or the need to establish, exercise, or defend legal claims and protect people, property, and systems.

You may withdraw consent where processing relies on consent. Withdrawal does not affect processing that occurred before withdrawal.

7. How We Disclose Personal Information

We may disclose personal information to:

  • service providers and processors that provide hosting, cloud infrastructure, analytics, advertising measurement, customer relationship management, communications, payment processing, security, file storage, identity, support, and professional services;
  • connected platforms and business partners when necessary to complete an authorized integration or provide requested services;
  • your organization and authorized users according to workspace membership, roles, permissions, and customer instructions;
  • professional advisers such as attorneys, accountants, auditors, insurers, and consultants;
  • government authorities or other parties when required by law or reasonably necessary to protect rights, safety, systems, users, or the public; and
  • transaction participants in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate protections.

Our website and services may use providers such as Amazon Web Services, Google Analytics and Google Ads, Meta Pixel, LinkedIn Insight, customer relationship management and sales systems such as HubSpot, Cloudflare security services, email and notification providers, identity providers, and other vendors appropriate to the enabled services. Providers may change as our systems evolve.

8. Sales, Sharing, and Targeted Advertising

We do not sell personal information. We use advertising services that may receive online identifiers, device information, approximate location, and website interaction data to measure campaigns and present advertising across websites or services. Applicable law may define these disclosures as "sharing" or processing for "targeted advertising."

You may opt out of sale, sharing, and targeted advertising through Your Privacy Choices, by using Global Privacy Control, or by emailing privacy@epicglobalinc.com. We recognize legally required browser-based opt-out preference signals for the browser or device sending the signal and, where required by applicable law, any associated consumer profile or account known to us. We do not knowingly sell or share the personal information of individuals under 18, and we do not sell sensitive personal information.

9. Cookies and Similar Technologies

We use cookies, pixels, local storage, session storage, and similar technologies for essential operation, authentication, security, preferences, analytics, performance measurement, error diagnosis, lead attribution, advertising measurement, and conversion reporting.

Essential technologies support security, authentication, requested forms, fraud prevention, preferences, and core website operation. We do not load optional Google Analytics and Ads, Meta Pixel, or LinkedIn Insight tracking until a visitor allows analytics and advertising technologies. A visitor may reject those technologies, change the choice through Your Privacy Choices, or use Global Privacy Control. The saved website choice generally remains in that browser for one year.

10. Data Retention

Unless a contract, legal obligation, litigation hold, or product-specific notice requires a different period, our general retention schedule is:

  • Customer accounts, workspace administration, and contract records: for the customer relationship and up to seven years afterward.
  • Billing, transaction, tax, and accounting records: seven years from the applicable transaction or reporting period.
  • Customer content and Integration Data: while the account or authorized connection remains active. After termination, disconnection, or a verified deletion request, active-system data is deleted or deidentified within 30 days unless the customer contract specifies a different period; protected backup copies expire within 90 days.
  • Security, access, and audit records: generally one to ten years, depending on the service, customer configuration, investigation needs, and contractual or compliance requirements.
  • Support records: three years after the support matter closes.
  • Marketing and business-development records: until opt-out or two years after the last meaningful interaction, whichever occurs first, except for suppression records.
  • Applicant and recruiting records: two years after the applicable recruiting process, unless law requires a different period.

When information is no longer required, we delete, deidentify, or securely isolate it. We maintain limited suppression records when necessary to honor opt-outs and prevent unwanted re-enrollment.

11. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information. Depending on the service, safeguards may include access controls, role-based permissions, encryption in transit and at rest, audit logging, credential and secret management, network protections, backups, monitoring, vulnerability remediation, and incident-response procedures.

No system can be guaranteed completely secure. You are responsible for protecting your credentials and promptly notifying us of suspected unauthorized access.

12. International Data Transfers

Epic Global is based in the United States and may process information in the United States and other countries where we or our service providers operate. Those countries may have privacy laws different from the laws where you live.

For restricted transfers from the European Economic Area, we use the European Commission's Standard Contractual Clauses where required, together with transfer assessments and supplementary safeguards appropriate to the transfer. For restricted transfers from the United Kingdom, we use the United Kingdom International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses where required. We may rely on an applicable adequacy decision or another lawful transfer mechanism when available. You may request information about the relevant safeguard by emailing privacy@epicglobalinc.com.

13. Your Privacy Rights

Depending on your location and subject to applicable exceptions, you may have the right to:

  • request access to or a copy of personal information;
  • request correction of inaccurate personal information;
  • request deletion of personal information;
  • request restriction of or object to certain processing;
  • receive certain information in a portable format;
  • withdraw consent;
  • opt out of certain sales, sharing, targeted advertising, or profiling;
  • appeal a denial of a privacy request where applicable; and
  • lodge a complaint with a data-protection authority.

To submit a request, email privacy@epicglobalinc.com with the subject line "Privacy Request" or use our contact form. We may need to verify your identity and authority before completing a request.

We respond within the time required by applicable law, generally within 45 days under applicable U.S. state privacy laws and within one month under European Economic Area or United Kingdom data-protection law. If law permits an extension, we will notify you and explain the reason.

If we deny a request, our response will explain the basis and any appeal right. Where an appeal is available, reply to the denial or email privacy@epicglobalinc.com with the subject line "Privacy Appeal." A person who was not responsible for the original denial will review the appeal.

If Epic Global processes information solely on behalf of your employer or another business customer, please direct your request to that organization first. We will assist the customer as required by our agreement and applicable law. We will not discriminate against you for exercising applicable privacy rights.

14. United States State Privacy Disclosures

During the preceding 12 months, we may have collected identifiers and contact information; customer and commercial records; internet, device, and network activity; approximate geolocation; professional or employment-related information; user-provided content; account credentials; financial information used for authorized business functions; and inferences derived from business or usage information.

We use these categories for the operational, security, support, analytics, advertising, transaction, integration, and legal purposes described in Section 4 and disclose them to the recipients described in Section 7. We do not sell personal information. We may share online identifiers, device and network activity, approximate location, and website interaction data with advertising and analytics providers for targeted advertising as described in Section 8.

We process sensitive personal information only for permitted operational, security, legal, or customer-directed purposes. We do not sell sensitive personal information or use it to infer characteristics about an individual. We limit collection, use, and retention to information reasonably necessary and proportionate to the disclosed purpose.

Applicable state residents may exercise the rights described in Section 13 and opt out through Your Privacy Choices, Global Privacy Control, or privacy@epicglobalinc.com. We do not use personal information to make solely automated decisions that produce legal or similarly significant effects without meaningful human review.

15. Children's Privacy

Our websites, software, and business services are not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.

16. Third-Party Websites and Services

Our services may link to or integrate with third-party websites and services. Their privacy practices are governed by their own notices and agreements. Review those policies before providing information or authorizing a connection.

17. Changes to This Policy

We may update this Policy to reflect changes in our services, data practices, providers, or legal requirements. We will post the updated Policy and revise the "Last updated" date. When required, we will provide additional notice or obtain consent for material changes.

18. Contact Us

Questions, concerns, or privacy requests may be directed to:

Epic Global Inc.
Attn: Privacy
333 S 520 W Ste 250
Lindon, UT 84042
United States
Email: privacy@epicglobalinc.com
Website: epicglobalinc.com/contact

When contacting us about a privacy right, use the subject line "Privacy Request."