Legal
Privacy Policy
Last Updated: June 2, 2026
Gintex AI is committed to protecting your privacy. This policy describes how we handle personal information collected through our website and services.
Table of Contents
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Information
- 4. User Accounts and Authentication
- 5. Cookies and Tracking Technologies
- 6. Third-Party Services and Integrations
- 7. Data Sharing and Disclosure
- 8. Data Retention
- 9. Data Security
- 10. Your Rights
- 11. Children's Privacy
- 12. International Data Transfers
- 13. Contact Information
- 14. Policy Updates
1. Introduction
Gintex AI ("Gintex", "we", "us", or "our") operates the website located at www.gintex.ai (the "Site") and provides brand perception intelligence, AI visibility analysis, GeoRepute market audits, and related strategic advisory services (collectively, the "Services").
This Privacy Policy explains what information we collect from visitors and clients, why we collect it, how it is used and protected, and what rights you have with respect to that information. By accessing or using the Site, you agree to the practices described in this policy.
If you have questions or wish to exercise any of your rights, please contact us at the address listed in Section 13.
2. Information We Collect
We collect information in the following ways:
2.1 Information You Provide Directly
- Contact Form: When you submit an inquiry through our contact page, we collect your name, email address, company name (optional), the subject category of your inquiry, and the message body.
- Newsletter Sign-Up: When you subscribe to our intelligence newsletter, we collect your email address.
- Consultation Requests: When you book a consultation via our "Book a Consultation" call-to-action, we collect contact details necessary to schedule and conduct that session.
- Admin Account Registration: Authorized staff members who access the administrative CMS provide their email address and password. This information is used solely for internal platform management.
2.2 Information Collected Automatically
- Server Logs: Our hosting infrastructure (Vercel) automatically records standard web server log data, including your IP address, browser type, operating system, referring URL, pages visited, and timestamps. These logs are used for security monitoring and infrastructure management.
- LocalStorage: We store a single key (
gintex-theme) in your browser's local storage to remember your light/dark mode preference. This data never leaves your device and is not transmitted to our servers.
2.3 Information We Do Not Collect
We do not collect payment card numbers, social security numbers, government-issued identification, or sensitive health data. We do not currently use third-party behavioral analytics or advertising tracking pixels.
3. How We Use Information
We use the information collected for the following purposes:
- Responding to inquiries: To review, process, and reply to messages submitted via our contact form.
- Service delivery: To schedule and conduct consultations, deliver intelligence reports, and fulfill any contracted advisory engagement.
- Newsletter communications: To send you intelligence updates, industry insights, and product announcements if you have opted in. You may unsubscribe at any time.
- Platform administration: To authenticate authorized administrators and manage our internal blog CMS powered by Supabase.
- AI content generation (internal): Our admin CMS uses the OpenAI GPT-4o and Anthropic Claude APIs to generate draft blog articles from editorial prompts provided by our staff. No visitor data is passed to these APIs.
- Security and fraud prevention: To monitor for abuse, unauthorized access, or other harmful activities.
- Legal compliance: To comply with applicable laws, regulations, or enforceable governmental requests.
- Improving our Site: To understand how visitors navigate and use the Site so we can improve content and user experience.
4. User Accounts and Authentication
The Site does not offer public user account registration. Account access is restricted to authorized Gintex AI administrators and editors only.
Admin accounts are authenticated via Supabase Auth using email and password credentials. Passwords are hashed and stored securely by Supabase and are never accessible to Gintex staff in plain text.
Authentication sessions are managed server-side using secure HTTP cookies issued by Supabase. These cookies are essential for maintaining admin sessions and are not used for marketing or tracking purposes.
6. Third-Party Services and Integrations
We share data with the following categories of third-party service providers, each operating under their own privacy policies:
- Supabase (database & authentication): Our PostgreSQL database and authentication layer is hosted on Supabase. Contact form submissions and admin credentials are stored in Supabase-managed infrastructure. Supabase is SOC 2 Type II certified. Privacy policy: supabase.com/privacy.
- Vercel (hosting & edge network): Our Site is deployed on Vercel's global infrastructure, which processes server-side requests and may log IP addresses and request metadata for infrastructure purposes. Privacy policy: vercel.com/legal/privacy-policy.
- OpenAI (AI content generation — internal only): Our staff use OpenAI's GPT-4o model to generate draft editorial content within our admin CMS. Only staff-provided text prompts are sent to OpenAI; no visitor personal data is included. Privacy policy: openai.com/policies/privacy-policy.
- Anthropic (AI content generation — internal only): Similarly, we use Anthropic's Claude model for content drafting in our admin CMS. No visitor data is transmitted. Privacy policy: anthropic.com/privacy.
- Social sharing networks: Blog articles include share buttons for LinkedIn, Facebook, and X (Twitter). Clicking these buttons redirects you to the respective platform, which may set its own cookies and collect data per its own privacy policy. We do not load tracking scripts from these platforms on page load.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We may share information in the following limited circumstances:
- Service providers: With the vetted third parties listed in Section 6, strictly to deliver the services they provide to us.
- Legal obligations: When required by law, court order, or government authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: In connection with a merger, acquisition, or sale of all or a portion of our assets, in which case we will provide notice and require the successor entity to honor this Privacy Policy.
- With your consent: For any other purpose with your explicit prior consent.
8. Data Retention
We retain personal data only as long as necessary:
- Contact form submissions: Retained in our database for up to 24 months to allow follow-up and record-keeping, after which they are deleted unless an active client relationship exists.
- Newsletter emails: Retained until you unsubscribe, after which your email is removed within 30 days.
- Admin session data: Session tokens expire automatically in accordance with Supabase's default session management policies.
- Server logs: Retained by Vercel for up to 30 days for infrastructure and security purposes.
- AI generation logs: Internal logs recording prompt tokens and generation cost metadata are retained for operational analytics and are not linked to visitor personal data.
9. Data Security
We implement industry-standard security measures to protect your information:
- All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
- Database access is restricted via role-based access controls enforced by Supabase Row Level Security (RLS) policies.
- Admin passwords are hashed using bcrypt via Supabase Auth and are never stored in plain text.
- API keys for OpenAI and Anthropic are stored as server-side environment variables and are never exposed to the browser.
- Our Supabase service role key is stored exclusively on the server and never included in client-side code.
Despite these measures, no method of electronic transmission or storage is 100% secure. If you believe your information has been compromised, please contact us immediately at the address in Section 13.
10. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention obligations.
- Objection: Object to certain processing activities, including direct marketing.
- Restriction: Request that we limit the processing of your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format (where technically feasible).
- Withdraw consent: Where processing is based on consent (e.g., newsletter), withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please email us at Hello@gintex.ai. We will respond within 30 days. We may need to verify your identity before processing your request.
11. Children's Privacy
The Site and Services are directed to business professionals and are not intended for children under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us and we will delete it promptly.
12. International Data Transfers
Gintex AI operates globally. Your information may be transferred to, stored, and processed in countries outside your country of residence, including the United States, where our hosting provider (Vercel) and database provider (Supabase) maintain infrastructure.
When transferring data from the European Economic Area (EEA) or the United Kingdom, we rely on appropriate legal mechanisms including Standard Contractual Clauses (SCCs) or the adequacy decisions recognized by the relevant supervisory authorities. Our sub-processors (Vercel and Supabase) are also subject to applicable transfer safeguards.
13. Contact Information
For privacy-related inquiries, requests, or complaints, please contact:
Gintex AIPrivacy Team
Email: Hello@gintex.ai
Website: www.gintex.ai
14. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last Updated" date at the top of this page will always reflect the most recent revision.
For material changes, we will provide a prominent notice on the Site or contact you directly if we hold your email address. Your continued use of the Site after changes take effect constitutes acceptance of the revised policy.
Have questions about this policy or how we handle your data?
Contact Us