ConnectionsConnections
Privacy PolicyTerms of ServiceSupport

Legal

Privacy Policy

Last Updated: September 2026 · How Connections collects, uses, protects, and retains member and visitor data.

Connections ("we," "our," or "us") is a product operated by Connections Global LLC, the data controller for the personal information described here, and respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or participate in our member community.

1. Introduction

Connections ("we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or participate in our member community.

2. Information We Collect

We may collect personal information that you provide directly to us, including:

  • Name, email address, phone number, and mailing address
  • Payment and billing information
  • Professional background and business information
  • Contact records, notes, and relationship data you enter
  • Communications and correspondence with Connections

Automatically Collected Information

When you access our website, we may automatically collect:

  • IP address, approximate location signals, browser, operating system, language, and device information
  • Your device's precise position, only if you have separately switched that on - see “Precise Location and Location-Based Advertising” below
  • Pages visited, time spent on pages, and navigation patterns
  • Referring website and search terms used
  • Cookies and similar tracking technologies

Information From Accounts You Connect

Connecting a Google account is optional. If you connect one, we ask Google only for the specific permissions (“scopes”) the features you use need, and we receive only the data those scopes cover:

  • Your basic Google profile (openid, profile, email): your name, email address, and profile picture, so we can identify and label the connected account.
  • Google Contacts (contacts.readonly): read-only access to the contacts saved in your own Google account. When you run an import, the names, contact details, photos, and any notes saved on those contacts are copied into your own Connections contact records. We do not request or read the “other contacts” scope, so the addresses Gmail auto-saves from people you have emailed once are never read.
  • Google Calendar: the list of your calendars, so you can choose which ones to use; your busy times, so your booking page offers only slots you are actually free for; and permission to create and update the calendar entries for bookings people make with you. We also read the events on your primary calendar to record meetings that have already ended as touches in your own contact history, storing the event title and time but never its description, its location, or the address of an attendee who is not already one of your contacts; to show you, at the moment you ask and without storing the result, people you met with recently who are not yet in your contacts; and to keep a private summary of your own meeting patterns. An attendee who is not already one of your contacts is counted, never named and never stored.

We do not request any Gmail scope, and we do not read your email.

You can remove Connections’ access to your Google account at any time from your Google Account’s third-party access settings, which stops any further reading of your Google data. Information already imported into your Connections account remains in your account until you delete it, and is covered by “Your Rights and Choices” and “Data Retention” below.

Connections’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Those requirements cover information we derive from your Google data as well as the data itself.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our services
  • Process account registration and verify identity
  • Facilitate contact management and relationship workflows
  • Send important account alerts and notifications
  • Process payments and manage billing
  • Respond to inquiries and provide customer support
  • Analyze usage patterns and improve user experience
  • Recommend other Connections services and features based on how you use the platform (first-party only: see "First-Party Service Recommendations" below)
  • Comply with legal obligations and protect our rights

4. Information Sharing and Disclosure

We do not sell your personal information.

Your Public Profile: Publishing a share card makes your MyConnect page, including your name, handle, photo, bio and that card, readable by anyone who has the link. We also list that page in the sitemap we give search engines, so it can appear in search results. We allow AI assistants that cite and link back to read it, and our robots.txt disallows other companies’ AI training crawlers, with two exceptions: Google’s Google-Extended and Amazon’s Amazonbot each use a single token that controls answering and model training together, with no separate training opt-out, so we allow those two rather than remove your page from those assistants entirely. Every other AI training crawler we know of is disallowed. That is about outside crawlers reaching your published page; how Connections itself may use your information is set out in section 20 of our Terms. This applies only to cards you choose to publish: unpublishing your cards takes the page down and removes it from that sitemap. What other members have saved about you in their own contacts is never published this way.

We may share your information with:

Service Providers: Third-party vendors who assist with payment processing, email delivery, text message (SMS) delivery, hosting and cloud infrastructure, analytics, and the hosted AI model services behind the features described in section 12. These are categories of recipients rather than a list of every individual vendor. Each receives only the information it needs to perform that service: our messaging provider, for example, receives the mobile number and message text needed to send you a message and handles the replies you send back (such as STOP or HELP), but not your opt-in consent records, which stay with us. Some of these vendors also act as independent controllers of the data they handle for their own fraud-prevention, security, and legal-compliance purposes, as set out in their own privacy policies; our payment processor is one.

Legal Requirements: When required by law or to protect our rights and safety.

Business Transfers: If Connections is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of its assets, your information may be transferred to the successor or acquirer as part of that transaction. Any successor will be bound by the commitments in this Privacy Policy with respect to personal information transferred to it, unless and until you are provided notice of a successor privacy policy, except for the restrictions described under “How a transfer interacts with the commitments in this policy” below, which a successor privacy policy does not displace; we will notify you of any change in ownership or material change in how your personal information is used, and will obtain your consent where the law requires it. A transfer of personal information as part of such a transaction is not a "sale" of personal information under applicable law.

Your Own Purchases Across Connections: If you buy from a business that uses Connections to process its payments, the purchase and subscription records that business holds under your verified email may be shown back to you (and only you) inside your Connections account, so you can keep track of what you have signed up for. You can manage these records (including canceling a subscription you bought through Connections) from your Connections account, or manage them directly with the business or through Stripe.

  • No sale of personal data to third-party advertisers.
  • Mobile opt-in data and consent records are not shared with third parties for their own marketing purposes.

While a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of our assets is being evaluated or negotiated, and whether or not it closes, we may disclose personal information to the prospective counterparty and to its legal, financial, and other professional advisers, in each case under written confidentiality obligations that restrict use of the information to evaluating the transaction, and limited to what that evaluation requires.

How a transfer interacts with the commitments in this policy. Where this policy says a category of information is never sold or shared with third parties, or is used only by Connections, a successor described above is not a “third party” for that purpose: it steps into our place as the operator of the service and receives no broader rights in your information than Connections had. The restrictions attached to that information travel with it, including your notice and consent choices, any objection or opt-out you have recorded, suppression state, retention limits, and the deletion duties we owe you or a person who is not a Connections user. This applies to a change of control only, and it does not permit onward sale or sharing by a successor: mobile opt-in data and SMS consent records remain excluded from sharing with any third party, before and after any such transaction, and stored location information remains subject to the opt-in switch and the deletion described in section 18.

Information From a Connected Google Account: If you connect a Google account (for example to import your Google Contacts, or to use your Google Calendar for availability and bookings), the information we receive through those Google scopes, and anything we derive from it, is treated separately in a business transfer. Google’s Limited Use requirements cover derived information as well as the data itself, so we will include it in a merger, acquisition, or sale of assets only after obtaining your explicit prior consent. If you do not consent, it is excluded from that transfer.

5. Data Security

We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

6. Your Rights and Choices

You have the right to access, update, or correct your personal information, request deletion (subject to legal obligations), opt-out of marketing, and disable cookies. To exercise these rights, please contact us at [email protected].

7. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and deliver personalized content. You can control cookies through your browser settings, but disabling cookies may limit certain features of our website.

8. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.

9. Children's Privacy

Our services are intended for adults. We do not knowingly collect information from individuals under 18 years of age.

10. SMS Consent and Mobile Messaging

If you provide your mobile number and expressly consent during account registration or on member forms, we may send account alerts, event reminders, and support notifications by text message. Message frequency varies. Message and data rates may apply.

Mobile data and opt-in consent will not be shared with third parties for marketing purposes.

No mobile information or opt-in consent will be shared with third parties, affiliates, or partners for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Consent to receive SMS messages is not a condition of purchase or membership. You may opt out at any time by replying STOP to any message. Reply HELP for support.

  • Message frequency varies. Message and data rates may apply.
  • Reply STOP to opt out. You will receive one final confirmation message, then no further messages.
  • Reply HELP for assistance or contact [email protected].
  • Mobile opt-in data and consent records are not sold or shared with third parties for their own marketing.

11. Changes to This Privacy Policy

We reserve the right to update, modify, add to, or remove any part of this Privacy Policy at any time, at our sole discretion. This includes the right to change how we collect, use, share, or retain your information, and to add new data practices or remove existing ones.

When we make changes, we will update the "Last Updated" date at the top of this page. For material changes, we will make reasonable efforts to provide notice, such as posting a prominent notice on our website or sending an email to registered users. However, it is your responsibility to review this Privacy Policy periodically to stay informed of any updates.

Your continued use of our services following the posting of any changes constitutes your acceptance of those changes. If you do not agree to a revised Privacy Policy, you must stop using our services.

12. AI Features and How They Work

Connections includes AI features that process your contacts, notes, and interaction records. We use these technologies in narrowly scoped, account-specific ways.

AI Vault Search and Embeddings

When you save a contact, note, or touch, we generate a numeric "embedding" (vector representation) using Amazon Bedrock Titan Text Embeddings v2. These embeddings are stored alongside your record and are scoped to your account. They are never returned to other customers, are not used to train models for other customers, and are not sold or shared with third parties. We do not send your raw contact text to any third-party large language model unless you explicitly invoke a feature that requires it, in which case the dependency is disclosed in-product before you use it.

Identity Resolution

We run probabilistic and deterministic matchers (E.164 phone, verified email, and a probabilistic name + employer + mutual-contact score) to detect duplicate contacts and to identify when contacts across different accounts refer to the same person. Cross-account matches power warm-introduction path-finding, the single internal person record and the mutual-contact counts described in “Contacts Who Are Not Connections Users” (section 13) below, and the improvement of the matching itself, as described in that section. Names and identifying details are never revealed to another user until both parties opt in.

AI Network Introductions

AI Network uses double-blind, double-opt-in mechanics. When you request an introduction: (1) we surface candidate paths through your contacts; (2) you select a broker, who sees your name and request but not the target's identity at first; (3) the broker can accept, decline, or pass; (4) only after both the broker and the target opt in is the target's name revealed to you. Either side can revoke consent at any time, after which the contact's information is removed from your view. We log each step, including who acted and when, so the introduction's history can be reviewed.

Automated Decision-Making

We do not use solely automated decision-making (without human review) to make decisions that produce legal or similarly significant effects about you. AI suggestions are advisory; you remain the decision-maker.

Data From Connected Google Accounts

If you connect a Google account, we receive only the data covered by the scopes you grant (for example your Google Contacts, or your calendar). We use that data, and anything aggregated or derived from it, only to provide and improve user-facing features inside Connections. The embeddings described above remain scoped to your account. We do not use it to show you advertising, and we never sell it.

Contacts you import from Google are treated like any other contact you save. They are added to your own contact list, and they take part in the identity resolution described above, which can recognize that a contact in your list and a contact in another member’s list refer to the same person. The consent protections described in this section apply to them in exactly the same way; there is no separate path for imported contacts. Apart from the disclosures already described in “Information Sharing and Disclosure” above - service providers who host and operate these features for us, legal requirements, and business transfers - we do not transfer this information to anyone.

13. Contacts Who Are Not Connections Users

Connections is a personal CRM. When you save a contact who has never signed up for Connections, we store the information you provide so you can manage your relationship with that person, and - if you ask us to - we can add to that record from outside business-data providers, as described below.

What we hold, why, how long, and who else sees it

The information held about a non-user is usually a name, the contact details the customer has for you (such as email address, phone number and mailing address), a job title, employer and public professional profile, sometimes a photo, and the notes and interaction records that customer keeps about their dealings with you. It comes from the customer who saved you, and, where that customer ran a lookup on the record, from the outside contact-data providers described below.

We hold it so the customer who saved you can manage their own relationship with you, so that duplicate records for the same person can be recognised and merged as described in “AI Features and How They Work” above, and to keep the service secure and prevent abuse. Where the EU or UK GDPR applies, our legal basis for the parts of this that we decide ourselves is the legitimate interests of Connections and of our customer in keeping an accurate contact book (Article 6(1)(f)), and you can object to that at any time using the address below.

We keep a non-user contact record for as long as the customer who saved it keeps it, and after that on the schedule set out in “Data Retention” below. The information is stored in the United States. Apart from the customer who saved you, it is seen by the service providers who host, secure and process data on our instructions, by the outside contact-data providers described below where such a lookup was run, by a successor in a corporate transaction, and where we are required by law or need to protect our rights and safety, each as set out in “Information Sharing and Disclosure” above.

Where the EU or UK GDPR applies to you, you have the same rights we give our own users, including access, rectification, erasure, restriction and objection, and the right to lodge a complaint with your supervisory authority, as set out in “Regional Privacy Rights” below; residents of California and of other U.S. states with broad privacy laws have the rights described in that same section. Write to the address below and we will handle your request whether or not you hold a Connections account.

Where the information about you came from

Most of what we hold about a non-user was entered, imported or synced by the Connections customer who saved you as a contact: typically a name, email address, phone number, employer, job title, and that customer’s own private notes about their dealings with you.

Separately, a customer can ask us to look a contact up with an outside business-data provider, using that customer’s own account and API credentials with that provider. The providers we support today are Apollo, People Data Labs and LinkdAPI, which supply business-contact information drawn from sources that include publicly accessible ones, such as company websites and public professional profiles. A customer can run a lookup for a single contact or across a list of their contacts. When a lookup runs, we send the provider the identifying details that customer already holds about you, which may include your name, email address, phone number and general location, and we store what the provider returns. That can include your full name, job title, employer, professional-profile address, general location, email address (including a personal one, where the provider returns it), phone number, photograph, and the provider’s unedited response. The provider gives us values, not the origin of each value inside its own dataset, so for any individual field we cannot always tell you whether it came from a publicly accessible source. Each provider handles the details we send it under its own privacy policy.

A customer can also ask an AI assistant inside Connections to propose corrections to a contact record. That sends the details already in the record to the AI provider serving the feature, which returns suggestions the customer reviews before any change is applied.

We treat that data with the following commitments:

  • We do not market to non-users using contact data uploaded by our customers.
  • We do not sell non-user contact data, and we do not hand it to third parties so that they can market to you. Apart from the recipients described elsewhere in this policy - the service providers and the AI providers described above, a successor in a corporate transaction, and disclosures required by law - there is one further flow in which a non-user’s details go to an outside company: if a customer has connected their own account with a business-data provider (for example Apollo, People Data Labs, or LinkdAPI) and asks us to look up a contact, we send that provider the details it needs to run the lookup - the contact’s name and, depending on the provider and what we hold, email address, phone number, and location - authenticated with that customer’s own credentials for that provider. What the provider does with that query afterwards is governed by its agreement with that customer, not by this policy. If no such provider account is connected, we send nothing to any of them.
  • We do not use a non-user’s contact details as training material for generative or foundation AI models, and we do not sell or license them for anyone else’s model training. We do use the outcome of duplicate-matching decisions to improve the record-matching model Connections runs across accounts: when a customer confirms or rejects that two records describe the same person, we record the numeric similarity scores behind that decision (for example how closely two names match, and whether two phone numbers are identical) alongside the internal identifiers of the two records, and we periodically retrain that matching model on those scores. Only the numeric scores and the confirm-or-reject outcome are used as training input; no name, email address or phone number is, and the resulting model is a short list of numeric weights from which no contact’s details can be reconstructed. We record the same kind of signal when a customer acts on a suggested match, and may use it the same way.
  • We will honor a verified deletion request from a non-user about their own data within thirty (30) days. If a contact saved by one of our users asks us to delete their record, we remove it even over the uploader’s objection, and we notify the uploader. Verification, removal, and that notification are carried out by our support team as a manual process rather than by an automated self-service tool - email [email protected] and we will handle it. We do keep one thing on purpose: a one-way cryptographic fingerprint (a hash) of the email address, phone number, or social handle you asked us to erase. Our suppression list holds that fingerprint in place of the value itself, and we use it for one purpose only, which is to refuse to build a profile again if the same details are uploaded by anyone in future. It is never used to contact you and never used to enrich anyone’s records, and we keep it for as long as we operate the service, because deleting it would remove the very protection you asked for.

Matching records across accounts

If two customers have each saved the same person, our matching system can recognise that both records describe one individual and keep a single internal person record for them, so that person is not held as two unrelated strangers. Separately, we count across accounts how many customers hold any given pair of people in common. That count is stored on its own, with no record of which customers they are, and a pair held by only one customer is never stored at all. It is used inside our introductions feature to suggest other members you may already know.

Two limits here are enforced in the software, not only promised. A person who does not hold a Connections account is never offered in those suggestions. And where we show two members how many connections they have in common, we show only the number: the names of the people in common are never sent out of our database.

These commitments have one exception, and it is the same one that applies to member data: if Connections is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of its assets, of the kind described under “Business Transfers” in section 4, non-user contact records may pass to the successor or acquirer as part of that transaction. Such a transfer is not a “sale” of personal information under applicable law, and a successor does not receive these records as a third party free to use them for its own purposes: we will require any successor to take them subject to the commitments in this section, including the removal right described in this section, and that requirement is not displaced by a successor adopting its own privacy policy. Separately, the service providers and legal requirements described in section 4 apply to non-user contact records as they do to member data.

We do not send each person an individual privacy notice when a customer saves their details. In most cases the only route we would have to reach you is the very contact information we are being asked not to use for our own purposes, and writing to every person in every customer’s address book would involve disproportionate effort. Article 14 of the EU and UK GDPR allows that where we instead take appropriate measures to protect you, including by making this information publicly available. This section is that public notice, it applies to every non-user record we hold, and we keep it current.

If you are the data subject of contact information uploaded to Connections by another user and would like that record removed, email [email protected] with the subject “Contact removal request” and we will verify and process the request.

14. Transactional Invite Emails

When you choose to invite a contact to Connections, you may opt in to having Connections send a single transactional invite email to that contact on your behalf. We only do this with your explicit, unchecked-by-default consent for each send. The email:

  • Is sent from [email protected], not from your address.
  • Has a subject line that clearly identifies Connections as the sender.
  • Identifies you by name as the person who triggered the send.
  • Includes a clear footer disclosing that the email was sent by Connections at your request, with a one-click "unsubscribe forever" link that permanently suppresses future invite emails to that address from any Connections user.
  • Is never sent more than once per recipient per sender without the recipient's affirmative action.

We do not, and will not, send emails that impersonate you, that appear to originate from your email address, or that mimic ongoing email conversations.

15. Data Retention

  • Active account data: retained for as long as your account is active, unless a shorter period applies to a particular category. Some categories run on their own clock while your account is still open, and are deleted or stop being used when that clock runs out - this includes the attributes we derive about you in our intelligence graph, described next.
  • Intelligence graph facts (per category): when we record a fact about a person in the relationship and identity graph that powers connections, matching, and suggestions, we stamp that fact with its own expiry at the moment it is written. By category: account identity facts about an account holder (name, email) 3,650 days; payment and subscription records (plan, lifetime value, connector earnings, introduction bid refunds) 2,555 days (seven years); connection records built from events and co-attendance, marketplace and deal interest, shared workspaces, conversations, donations, referrals, calendar invitations, and course enrolments 1,095 days; answers you submit (question answers, event-registration answers, form answers, stated goals) 730 days; marketing attribution and the summaries we derive about a relationship (touch counts, tie strength, relationship types, introduction activity, mutual-contact overlap, meeting history) 395 days; and saved location on the 13-month schedule described in “Precise Location and Location-Based Advertising” below. A small number of older field types we no longer collect (for example a stored handle, avatar, biography, or payment-processor customer identifier) keep the same clocks for as long as any such record still exists. Each period runs from the moment the fact is recorded, so a fact can expire well before your account does; deleting your account or making a verified erasure request ends it sooner.
  • Facts that stop being used rather than being deleted: some of what we hold about you in those same records - your job title, your employer, and your employment history - expires 365 days after we record it. When it expires, and also when you object to our using your information for a particular purpose, we stop using the affected facts instead of deleting them: they are marked unusable, are no longer used for search or matching, and the search embeddings built from them are deleted. The underlying value stays stored, and we still disclose it to you if you ask us for a copy of what we hold. It is deleted outright when you delete your account or ask us to erase you.
  • Record of what we ingested (kept after the value is removed): separately from each fact in our relationship graph, we keep a record of the ingestion itself: which person it concerned, which field it was, which part of Connections supplied it and the specific source it came from, the lawful basis and consent it was recorded under, and when it was asserted and when it expires. When we delete a fact at the end of its retention period, we also erase that fact’s value from this record and stamp the date of the erasure, but we keep the surrounding record of the processing, because it is what lets us show how your data was handled and answer a later correction, complaint, audit, or regulatory request. Facts that we stop using rather than delete at the end of their period keep their entry in this record until they are deleted or erased. We have not set a fixed maximum period for this record; the criterion we apply is that we keep it only for as long as we may need it to demonstrate how we handled your data. We delete the record outright when you delete your account or when you ask us to erase you.
  • Activity and usage records: our default for records of things that happened - pages viewed and actions taken, device and browser information, errors, messages sent, payment attempts, and consents given or withdrawn - is to keep them for as long as we operate the service rather than delete them on a fixed timer, because they are our record of what the service did and we rely on them for security, abuse and fraud prevention, dispute resolution, billing and tax records, and understanding how the product is used. We keep them only for those purposes, and where a shorter period applies we say so in this policy (for example backups, and precise location, which is kept for at most 13 months). If you have an account, the activity records linked to you are erased or de-identified when you delete it, on the schedule described below. Activity records collected from visitors who never create an account are not linked to a name or an account and are kept on the same basis; you can ask us to delete information we hold about you as described in “Your Rights and Choices.”
  • Processing and integrity records: several of the records we keep to show the system worked correctly are deleted by a scheduled sweep once their window ends: delivery receipts for graph updates, after 30 days; graph parity and delivery-health runs, after 90 days; completed or failed document-processing jobs and superseded document versions, after 30 days; proposed facts once their review has concluded, after 90 days; and correction requests, 30 days after they are resolved. Affinity signals, which we use to rank what we suggest to you, expire 180 days after the interaction they describe. Other audit and integrity records, including access logs, are kept for longer as described elsewhere in this section.
  • After account deletion: when you request deletion we end your sessions immediately and lock the account, and your data then enters a thirty (30) day waiting period before erasure begins. During that period the account is inaccessible and nothing has yet been erased. Once the waiting period ends, our scheduled erasure run deletes your personal data across Connections services, normally completing within a further thirty (30) days; if one of our services is temporarily unavailable, its copy of your data is retried on later runs until the erasure is complete. The following are excepted: (a) records we must retain by law (such as tax records), (b) audit logs of intro consent and security events, retained in pseudonymized form for as long as needed for security, abuse-prevention, and dispute-resolution purposes, (c) backups, which expire on their own rotation cycle of no more than ninety (90) days, and (d) content you created or collected (such as your notes, touches, saved contact records, and responses submitted to your forms), which we retain only in a de-identified form that is no longer linked to your identity or to the person it described, as described below.
  • Non-user contact records: deleted when the contact is removed by the user or when we receive a verified removal request from the non-user. When the account that saved them is deleted, we irreversibly de-identify these records (removing the contact’s name, email, phone, notes, and other identifying details) in the same erasure run that deletes that account, so that what remains no longer identifies that person.
  • Aggregated, de-identified data: may be created, used, and retained indefinitely for security, fraud prevention, research, product development, benchmarking, and the platform analytics and industry insights we build, always in a form that does not identify any individual.

16. Regional Privacy Rights

European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

If you are located in the EEA, UK, or Switzerland, you have rights of access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your supervisory authority under Articles 15–22 of the GDPR (and UK equivalents). Our legal bases for processing are: contract (to provide the service), legitimate interests (security, fraud prevention, product improvement under the double-opt-in framework), consent (for optional features), and legal obligation. Connections is operated from the United States. The personal information you provide is processed and stored on infrastructure located in the United States, and the service providers we use for hosting, payment processing, message delivery, and AI processing receive it there. Where required, we rely on Standard Contractual Clauses for international transfers from the EEA / UK / Switzerland to the United States. If you are in the EEA, UK, or Switzerland and would like to know what safeguards apply to a particular transfer, contact us at [email protected].

California (CCPA / CPRA)

California residents have the right to know, delete, correct, and opt out of "sale" and "sharing" of personal information. Connections does not engage in either. You may designate an authorized agent to make requests on your behalf and have the right not to be discriminated against for exercising your rights.

Other U.S. States

Residents of Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Minnesota, and other states with general privacy laws have the right to confirm whether we process their personal data and to access it, to correct it, to delete it, to obtain a copy in a portable format, and to opt out of the sale of personal data, of targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects.

All three of those opt-outs are already our default position. We do not sell personal data. We do not conduct targeted advertising as these laws define it, meaning advertising selected on the basis of your activity over time across websites or apps that we do not operate. Two first-party choices sit alongside that, and both are off until you switch them on yourself: “Targeting” in your privacy settings, which lets us use what you do inside Connections’ own services to choose which of our own products and offers we show you, and the location setting described in section 18, which adds the area you are in. Neither shows you anyone else’s advertising, and switching the location setting off both stops that use and deletes what we stored. And, as described in section 12, we do not profile you in furtherance of decisions that produce legal or similarly significant effects.

We honor these rights for residents of any U.S. state with a general privacy law, whether or not that law’s own thresholds reach a company our size. Submit requests to [email protected].

Sensitive Personal Information

U.S. state privacy laws treat certain categories of information as sensitive. These include health, disability, pregnancy and mental health; political affiliation and how you vote; religion; trade union membership; race and ethnic origin; genetic and biometric data; sex life, sexual orientation and gender identity; precise geolocation; and the credentials that give access to an account.

Apart from the two described next, and apart from anything sensitive you choose to record yourself in your own notes, files and contact records, as described at the end of this subsection, we do not collect or derive information in those categories. Our intelligence graph, the system that derives and stores facts about people, refuses them: it discards an attribute whose name or whose value falls into one of those categories, on every path that can write to it, so when a feature reads a note or a document and proposes a fact of that kind, the proposal is dropped instead of saved. We do not use information in those categories to profile you or your contacts, to target advertising, or to train AI models.

Two of those categories are unavoidable parts of running the service. The credentials that sign you in are held only to authenticate you and to keep your account secure, and are used for nothing else. Precise geolocation is stored, and used for anything beyond filling in an address you asked for at that moment, only if you switch it on yourself, and only as described in “Precise Location and Location-Based Advertising”; the switch described there is also how you exercise your right to limit the use of your sensitive personal information.

What you write or upload yourself is different: your notes, files and contact records are your own content and stay in your account under your control. If you choose to record something sensitive there, we do not use it to build a profile, and you can edit or delete it at any time.

Oregon and Minnesota: the specific third parties

If you live in Oregon or Minnesota, you may ask us for a list of the specific third parties, not merely the categories of third party, to which we have disclosed personal information, and we will provide it. Email [email protected] with the subject “Third party disclosure list”. Because we do not sell personal information and do not share it for cross-context advertising, that list is short: it names the service providers described in “Information Sharing and Disclosure” above, the payment processor and the business involved in any purchase you made through Connections, any successor in a business transfer described in that section, any prospective counterparty and its professional advisers in a transaction being evaluated as described in that section, any outside contact-data provider to which we sent your details on a lookup run by a customer who holds you as a contact, as described in section 13, and any disclosure we were legally compelled to make.

Appealing a Decision

If we decline a request you made under a U.S. state privacy law, we will tell you why within the time that law allows, and you may appeal. Reply to our response, or email [email protected] with the subject “Privacy request appeal”. A person reviews every appeal, never an automated process, and we will write back with our decision and the reasons for it within forty-five (45) days, and in every case within the deadline your state’s law sets. If we deny the appeal, that response will also give you a way to submit a complaint to your state Attorney General.

17. First-Party Service Recommendations

Connections is a family of first-party services operated by Connections Global LLC (for example: events, payments, notes, calendars, bookings, and email signatures). We may analyze how you use Connections (such as the features you use and the actions you take) to suggest other Connections services and features that may be useful to you (for example, suggesting our email-signature tools if you regularly share your contact details by hand).

  • These suggestions are generated and shown entirely inside Connections, and the usage signals behind them are used only to recommend Connections' own services to you.
  • Recommendation signals are never sold, never shared with third parties, and never used for third-party advertising.
  • Recommendation signals are not made available to any advertising system or advertiser, including advertisers who use Connections' own advertising surfaces. A suggestion is a first-party product notice shown only to you; no advertiser can target you based on these signals.
  • Suggestions are advisory only. You can dismiss any suggestion, and a dismissed suggestion is suppressed.
  • The signals behind suggestions are personal information under this policy: they receive the same security protections, are covered by your rights in "Your Rights and Choices," and are deleted on the schedule described in "Data Retention."

18. Precise Location and Location-Based Advertising

Connections can fill in an address for you from your device's own position, and - separately, and only if you turn it on - can keep the area you are in. These are two different things and we keep them apart on purpose.

Using your position without keeping it

Wherever we ask for an address, there is a “Use my location” button. Your browser asks your permission, we exchange the coordinates for an address, and we show it to you to confirm before anything is filled in. If you have not turned on the setting described below, that is the whole transaction: we keep nothing about where you were. Pressing the button is not consent to being tracked, and you can use it as often as you like.

Saving where you are, and what we use it for

If you switch on “Save where you are, and use it for our own ads” in Cookie settings, we record the area you are in when you use that button, and we use it to make what we show you relevant to where you live - including advertising for Connections' own products and services. We record an approximate position (rounded to roughly 110 metres), your city, region, postal code and country, when it was observed, and how accurate your device said it was. We do not record a continuous history of your movements and we do not track you in the background.

This is opt-in only, and never bundled

Our legal basis is your consent, and nothing else - not legitimate interest, in any country. The setting is off by default everywhere in the world, and accepting cookies as a whole does not switch it on: “Accept all” deliberately leaves it off, because a single blanket button is not specific consent for information this sensitive. The only way it is ever on is if you opened Cookie settings and turned that one switch on yourself. Each decision is recorded against your account, so you and we can both see what you actually chose and when.

Turning it off

Open Cookie settings from the bottom of any page and switch it off. It takes one click - the same one click that turned it on - and it both stops any future use and deletes the location information we had stored. You do not need to contact us, give a reason, or change anything else. If you are in California, this is also how you exercise your right to Limit the Use of My Sensitive Personal Information: precise geolocation is “sensitive personal information” under the CPRA, and that switch is the control. You may also email [email protected] if you would rather we did it for you.

Who else sees it

No advertiser, ad network or data broker. Location information is never sold, never shared with other advertisers, ad networks or data brokers, and is never used for advertising by anyone other than Connections on our own services. It is not used to let other members find you, and it is not part of anything you publish. Like everything else we hold, it is seen by the service providers who host, secure and process data on our instructions, and it may be disclosed in a corporate transaction, or where we are required by law or need to protect our rights and safety, each as set out in “Information Sharing and Disclosure” above. Location we have stored is kept for at most 13 months and then deleted, and it is deleted sooner if you switch the setting off or delete your account.

Privacy PolicyTerms of ServiceSupportCookie settingsContact
© 2026 Connections Global LLC · Connections. All rights reserved.