Legal and privacy
Effective and last updated: August 3, 2026
This Policy describes our general practices. A contract, data processing addendum, product-specific notice, or authorization screen may provide additional or more specific terms. If we process personal information solely on behalf of a business customer, that customer controls the information and its instructions govern our processing.
This Policy applies to:
This Policy does not govern a third party's independent privacy practices. Third-party services remain subject to their own privacy policies and terms.
The information we collect depends on how you interact with us and which services or integrations you use.
Please do not provide sensitive personal information unless it is necessary for an authorized business purpose and you have the right to provide it.
When an authorized user connects a third-party account, we may receive information allowed by that platform and by the permissions selected by the user, including:
The exact information received is limited by the third-party permissions granted and the features enabled.
We may collect personal information:
We use personal information to:
We do not use personal information for materially different purposes without providing appropriate notice or obtaining consent when required.
We may use automated tools to generate analyses, recommendations, classifications, or workflow suggestions. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about an individual without meaningful human review.
If you or your organization authorize an Epic Global service to connect with a third-party platform, application, or API, the following additional terms apply to information received through that connection ("Integration Data"):
Each connected provider processes information under its own privacy policy, terms, and platform rules. Epic Global is not responsible for a provider's independent practices.
Our use and transfer to any other application of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, credit decisions, or generalized model training.
Where applicable law requires a legal basis, we process personal information based on contract, legitimate interests, consent, legal obligations, or the need to establish, exercise, or defend legal claims and protect people, property, and systems.
You may withdraw consent where processing relies on consent. Withdrawal does not affect processing that occurred before withdrawal.
We may disclose personal information to:
Our website and services may use providers such as Amazon Web Services, Google Analytics and Google Ads, Meta Pixel, LinkedIn Insight, customer relationship management and sales systems such as HubSpot, Cloudflare security services, email and notification providers, identity providers, and other vendors appropriate to the enabled services. Providers may change as our systems evolve.
We do not sell personal information. We use advertising services that may receive online identifiers, device information, approximate location, and website interaction data to measure campaigns and present advertising across websites or services. Applicable law may define these disclosures as "sharing" or processing for "targeted advertising."
You may opt out of sale, sharing, and targeted advertising through Your Privacy Choices, by using Global Privacy Control, or by emailing privacy@epicglobalinc.com. We recognize legally required browser-based opt-out preference signals for the browser or device sending the signal and, where required by applicable law, any associated consumer profile or account known to us. We do not knowingly sell or share the personal information of individuals under 18, and we do not sell sensitive personal information.
We use cookies, pixels, local storage, session storage, and similar technologies for essential operation, authentication, security, preferences, analytics, performance measurement, error diagnosis, lead attribution, advertising measurement, and conversion reporting.
Essential technologies support security, authentication, requested forms, fraud prevention, preferences, and core website operation. We do not load optional Google Analytics and Ads, Meta Pixel, or LinkedIn Insight tracking until a visitor allows analytics and advertising technologies. A visitor may reject those technologies, change the choice through Your Privacy Choices, or use Global Privacy Control. The saved website choice generally remains in that browser for one year.
Unless a contract, legal obligation, litigation hold, or product-specific notice requires a different period, our general retention schedule is:
When information is no longer required, we delete, deidentify, or securely isolate it. We maintain limited suppression records when necessary to honor opt-outs and prevent unwanted re-enrollment.
We maintain administrative, technical, and physical safeguards designed to protect personal information. Depending on the service, safeguards may include access controls, role-based permissions, encryption in transit and at rest, audit logging, credential and secret management, network protections, backups, monitoring, vulnerability remediation, and incident-response procedures.
No system can be guaranteed completely secure. You are responsible for protecting your credentials and promptly notifying us of suspected unauthorized access.
Epic Global is based in the United States and may process information in the United States and other countries where we or our service providers operate. Those countries may have privacy laws different from the laws where you live.
For restricted transfers from the European Economic Area, we use the European Commission's Standard Contractual Clauses where required, together with transfer assessments and supplementary safeguards appropriate to the transfer. For restricted transfers from the United Kingdom, we use the United Kingdom International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses where required. We may rely on an applicable adequacy decision or another lawful transfer mechanism when available. You may request information about the relevant safeguard by emailing privacy@epicglobalinc.com.
Depending on your location and subject to applicable exceptions, you may have the right to:
To submit a request, email privacy@epicglobalinc.com with the subject line "Privacy Request" or use our contact form. We may need to verify your identity and authority before completing a request.
We respond within the time required by applicable law, generally within 45 days under applicable U.S. state privacy laws and within one month under European Economic Area or United Kingdom data-protection law. If law permits an extension, we will notify you and explain the reason.
If we deny a request, our response will explain the basis and any appeal right. Where an appeal is available, reply to the denial or email privacy@epicglobalinc.com with the subject line "Privacy Appeal." A person who was not responsible for the original denial will review the appeal.
If Epic Global processes information solely on behalf of your employer or another business customer, please direct your request to that organization first. We will assist the customer as required by our agreement and applicable law. We will not discriminate against you for exercising applicable privacy rights.
During the preceding 12 months, we may have collected identifiers and contact information; customer and commercial records; internet, device, and network activity; approximate geolocation; professional or employment-related information; user-provided content; account credentials; financial information used for authorized business functions; and inferences derived from business or usage information.
We use these categories for the operational, security, support, analytics, advertising, transaction, integration, and legal purposes described in Section 4 and disclose them to the recipients described in Section 7. We do not sell personal information. We may share online identifiers, device and network activity, approximate location, and website interaction data with advertising and analytics providers for targeted advertising as described in Section 8.
We process sensitive personal information only for permitted operational, security, legal, or customer-directed purposes. We do not sell sensitive personal information or use it to infer characteristics about an individual. We limit collection, use, and retention to information reasonably necessary and proportionate to the disclosed purpose.
Applicable state residents may exercise the rights described in Section 13 and opt out through Your Privacy Choices, Global Privacy Control, or privacy@epicglobalinc.com. We do not use personal information to make solely automated decisions that produce legal or similarly significant effects without meaningful human review.
Our websites, software, and business services are not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.
Our services may link to or integrate with third-party websites and services. Their privacy practices are governed by their own notices and agreements. Review those policies before providing information or authorizing a connection.
We may update this Policy to reflect changes in our services, data practices, providers, or legal requirements. We will post the updated Policy and revise the "Last updated" date. When required, we will provide additional notice or obtain consent for material changes.
Questions, concerns, or privacy requests may be directed to:
Epic Global Inc.When contacting us about a privacy right, use the subject line "Privacy Request."