Privacy Policy
CGE Insights, a service of Pitch Cloud, LLC
Effective Date: August 20, 2026
This Privacy Policy accompanies the CGE Insights Terms of Service and Data Processing Addendum of the same date. Terms defined in the Terms of Service have the same meaning here.
1. Who CGE Insights is, and what this policy covers
CGE Insights is a business-to-business software service operated by Pitch Cloud, LLC. It helps membership organizations understand engagement, identify possible disengagement, decide who to contact, and learn which outreach actions work.
This policy explains how CGE Insights handles information in four different roles:
- Member data. When a Customer uses CGE Insights to track and analyze its Members, the Customer is the controller and CGE Insights is the processor. A controller decides why and how personal data is used. A processor handles it under the controller's instructions.
- CGEInsights.com visitor and prospect data. When CGE Insights operates its tracker on its own public website, CGE Insights is the controller. The people involved are visitors and prospective customers, not Members.
- Customer account, billing, support, and feedback data. CGE Insights is the controller, because it decides how this information is used to operate and support the service.
- Cross-organization pooled learning. CGE Insights is the controller, because it uses protected, non-personal pooled results for its own purpose of improving recommendations across the service.
Definitions. This policy uses the terms defined in the Terms of Service and does not restate them: Customer, Member, Services, and Order Documentation (Terms, section 1), Strategy Advisor (Terms, section 2), and Pooled Summaries (Terms, section 9).
Visitor means a person who visits CGEInsights.com. Prospect means a person or organization that has shown interest in CGE Insights.
2. Information handled for Customers
Website tracker data
A Customer may install the CGE Insights JavaScript tracker on its website. After the visitor gives consent, the tracker may collect:
- Page views and session activity on the Customer's website.
- The page path and hash route.
- A short allow-list of query parameters:
tab,page,view,section,sort,filter, andstep. Other query strings are dropped. - Allowed values, after values that look like email addresses are scrubbed and values longer than 64 characters are dropped as probable tokens.
- The referring domain and first-touch attribution values, including UTM
parameters,
gclid, andfbclid. - A durable random visitor identifier stored in browser
localStorage. - Derived engagement scores and flags.
CGE Insights does not store IP addresses in its application database. An IP address is necessarily used while a request travels over the internet, and CGE Insights' infrastructure providers may retain IP addresses in their own operational and security logs. See section 8.
Member identification
When a Member signs in to the Customer's own member portal, the Customer's site
may call the CGE Insights identify() function with the Member's email address.
This links activity from that browser to the named Member, and the link may
include browsing activity recorded before the Member was identified.
Member roster and enrichment data
A Customer may provide Member data through a CSV upload or a Novi AMS synchronization. The standard roster may include name and email address, membership type and status, join and renewal dates, and engagement history.
CSV enrichment uploads may include additional columns selected by the Customer. CGE Insights does not restrict the content of those additional columns, and does not inspect or validate them. The Customer is responsible for having the right to upload that information and for limiting it to what is needed.
Unless the parties separately agree in writing and applicable law permits the processing, Customers must not upload special-category or similarly sensitive data, including but not limited to health information, religious beliefs, political affiliation, or trade union membership. Customers also must not upload passwords, payment-card data, authentication secrets, or other credentials.
This restriction is a contractual obligation of the Customer and is not represented as a technical control (Terms, section 7). CGE Insights does not inspect, validate, or block the contents of enrichment columns.
3. Tracking and prospect information on CGEInsights.com
CGE Insights also operates its tracker on its own public website. For this tracking, Pitch Cloud, LLC is the controller, and the people involved are visitors and prospective customers, not Members.
After a visitor gives consent, the tracker may collect the same categories
described in section 2 — page views, session activity, reduced URL information,
referring domain, first-touch attribution, a durable random localStorage
identifier, and derived website-engagement information.
CGE Insights uses this as first-party analytics to understand how people reach and use CGEInsights.com. It does not build a cross-site advertising profile and does not provide the identifier to advertising networks.
CGE Insights may also receive information submitted through demo, contact, support, or feedback forms, including name, email address, organization, title, and message.
4. Customer-user, billing, support, and testimonial information
For Customer users, CGE Insights may handle name, email address, role, and authentication identity; authentication through Google, Microsoft, or an email magic link; billing account information, with Stripe holding payment card details; and support requests, feedback, and form submissions.
A feedback form may ask permission to publish a testimonial. CGE Insights publishes a person's name, title, and organization only after that person checks the consent box covering public use.
5. How information is used
- To provide the tracker, roster, identity linking, engagement analysis, recommendations, reports, exports, integrations, notifications, and related functions requested by the Customer.
- To operate Customer accounts, authenticate users, process billing, answer support questions, and receive feedback.
- To understand and respond to interest in CGE Insights, including demo and contact requests.
- To protect accounts and the service, enforce access rules, investigate errors, respond to security events, and record significant operator actions.
- To produce cross-organization pooled learning under the safeguards in section 6.
- To publish a testimonial only with the specific consent described above.
6. Cross-organization pooled learning
CGE Insights uses eligible situation, action, and outcome records from multiple Customers to improve recommendations available across the service. CGE Insights acts as a controller for this separate purpose. This is not processing performed only on one Customer's instructions.
Every one of the following safeguards applies:
- Pooled results contain no personal data and no organization names.
- Records are grouped only by an anonymized situation type and an action type.
- A result is not released unless the group includes at least 50 distinct Members from at least 3 distinct organizations.
- A group below either threshold is discarded, not retained in a weaker or more identifying form.
- Results contain counts and rates only. Together with non-identifying findings, these are the Pooled Summaries defined in section 9 of the Terms.
- CGE Insights staff review findings before they can influence a recommendation.
- One Customer's identifiable data is never shown to another Customer.
6.1 Opt-out, reciprocity, and a Member's separate right to object
All opt-out terms are stated here, in one place.
An authorized Customer administrator may opt out of pooled learning at any time
by contacting privacy@cgeinsights.com. After CGE Insights verifies the
requester, the opt-out takes effect immediately as an account setting and applies
to future eligible records at the next aggregation run.
Participation is reciprocal, which means this: a Customer that stops contributing records also stops receiving Pooled Summaries derived from other organizations. It is a two-way exchange. The Customer continues to receive every analysis and recommendation based on its own data — its dashboard, its outcome history, and its reports are unaffected, because none of them depended on the pool.
Pooled Summaries already created cannot be withdrawn, because they contain counts and rates only, no personal data and no organization names, and cannot be separated by Customer after creation. The 50-Member and 3-organization floors are what make that true: there is nothing to trace back, and therefore nothing to unwind.
A Member may object to pooled learning independently of the Customer. Because
CGE Insights is the controller for this processing rather than the Customer's
processor, a Member's own right to object exists separately from the Customer's
commercial opt-out. A Member may object by contacting privacy@cgeinsights.com
or through their organization. CGE Insights will handle the objection, notify the
Customer, and exclude that Member's records from future aggregation. A
Customer's decision to participate does not decide the question for an individual
Member.
6.2 Lawful basis for pooled learning
Where the GDPR or UK GDPR applies, CGE Insights intends to rely on legitimate interests for the limited Member-linked processing used to create pooled findings, supported by a written Legitimate Interests Assessment covering purpose, necessity, expected benefits, Member expectations, risks, safeguards, and objection handling.
EEA/UK gate. No EEA- or UK-regulated Member data may enter pooled learning until qualified counsel has reviewed and approved that assessment and the related notices and controls.
7. Artificial intelligence and automated decisions
Two features use Google Gemini 2.5-flash: the Strategy Advisor, which drafts recommendations and outreach copy, and the Help Assistant, which answers questions from CGE Insights' own documentation.
Strategy Advisor prompts may include behavioral signals and derived flags. They do not include Member names or email addresses. Prompts are sent at request time. Customer data is not used to train or fine-tune any model.
All statistics and findings are produced by conventional statistical methods in CGE Insights' own code. The AI may explain or phrase a result, but it does not generate the number.
Recommendations are advisory and a human decides whether to act. CGE Insights does not make a solely automated decision that creates legal or similarly significant effects for a Member.
8. Service providers, integrations, and destinations
Supabase — primary database. Holds Member data and Customer account data stored in the service. Processed in US East (Virginia).
Render — backend application hosting. Handles application data processed by backend functions. Processed in US West (Oregon).
Vercel — frontend hosting and the server-side proxy. Handles Customer-user requests, session information, and application data returned through the frontend and proxy. Processed in US East (Washington, D.C.).
Google Cloud (Gemini) — AI text generation. Receives Strategy Advisor prompts carrying behavioral signals and derived flags, without Member names or email addresses, and Help Assistant questions with CGE Insights documentation. No region selection exists: the Gemini Developer API is a global endpoint.
Google and Microsoft — Customer-user single sign-on. Receive Customer-user identity and authentication information only. Processed per each provider's own terms.
Resend — transactional email. Receives the recipient email address and message content for magic links, notifications, and form submissions. Processed per the provider's own terms.
Stripe — payments and billing. Receives billing contact and payment information used to process and document charges. Processed per the provider's own terms.
Mailchimp and Mandrill — email engagement and outreach. Receive email engagement data, and a Member's email address and outreach content when a Customer sends outreach through the integration. Processed per the provider's own terms.
Novi AMS — Member roster synchronization. Receives roster fields synchronized between Novi AMS and CGE Insights. Processed per the provider's own terms.
Sentry — application error monitoring. Receives application error and diagnostic information. Automatic personal-data enrichment is disabled and request URLs are scrubbed from breadcrumbs. Processed per the provider's own terms.
cron-job.org — scheduled job triggering. Receives no personal data, only authenticated requests that trigger background work, so no transfer of personal data occurs.
The four regions above are the ones CGE Insights selects, so only CGE can state them. For the remaining providers, processing location is governed by that provider's own published DPA and transfer terms.
Customers may configure outbound webhooks and Slack or Microsoft Teams notifications. Member data then flows to the destination the Customer selected, and the Customer is responsible for that destination, its configuration, and who can access it. Customers may export reports in PDF or CSV, and are responsible for exported copies after download.
9. Consent for website tracking
The tracker stores a durable random identifier in browser localStorage.
LocalStorage is browser storage rather than a traditional cookie, but privacy and
electronic-communications laws may apply to both when information is stored on or
read from a person's device.
CGE Insights uses a consent-required model everywhere, without jurisdiction detection:
- On CGEInsights.com, CGE Insights presents the consent notice and controls whether the tracker activates.
- On a Customer website, the Customer presents the notice and obtains the choice. CGE Insights provides a consent function the Customer's site or consent-management platform calls to grant or withdraw permission.
- Before consent, the tracker does not create the durable identifier and does not send analytics events.
- Before consent, the tracker does request its own settings from CGE Insights. That request tells CGE Insights which website the tracker is running on. It does not identify the visitor, and it stores nothing on the visitor's device. If the request fails, or a browser or network blocks it, the tracker collects nothing.
- CGE Insights honors the Global Privacy Control signal. When a visitor's browser sends that signal, the tracker treats it as a refusal and collects nothing. A browser that does not send the signal is not treated as having agreed to anything; the absence of the signal means only that no choice was expressed that way.
- When consent is withdrawn, the tracker stops future collection and removes the CGE Insights identifier from that browser.
10. Legal bases for CGE-controlled information
Where the GDPR, UK GDPR, or similar law applies, CGE Insights expects to rely on:
- Contract — to create and operate a Customer-user account and provide the subscribed service.
- Consent — for the website tracker and
localStorageidentifier, and to publish a testimonial using a person's name, title, and organization. - Legitimate interests — to secure the service, prevent misuse, maintain records, improve support, respond to prospects, and carry out approved pooled learning where those interests are not outweighed by a person's rights.
- Legal obligation — when records must be kept or disclosed under law.
For Member data processed for a Customer, the Customer selects the lawful basis and provides required notices. CGE Insights handles the data under the Customer's instructions and the DPA.
11. Retention and deletion
CGE Insights keeps information only for the periods described below or as required by law.
- Website tracking events — 24 months from collection.
- Member roster records — for the duration of the Customer's active subscription, unless the Customer deletes them earlier.
- Member-linked outcome history — 24 months from the outcome date, after which Member-linked records are deleted and results may remain only as non-identifying counts and rates.
- Audit logs — 24 months from the action, even if the subscription ends. Entries recording a deletion request remain even when the underlying data is deleted.
- Encrypted unsaved-form drafts — a draft expires 30 minutes after it is written and cannot be read after that. Expired drafts are deleted within 24 hours. Earlier deletion follows restore, discard, or successful submission.
- Customer account and role data — the active subscription plus 24 months.
- Support and feedback records — 24 months after the matter is closed.
- Authentication and session data — the shorter lifecycle needed to operate and secure the session, including idle logout and a hard 12-hour cap.
- Prospect and contact-form data — 24 months after the last meaningful interaction.
- Testimonial consent records — 24 months after the testimonial is removed.
- Billing and transaction records — a target of 7 years, subject to applicable tax and recordkeeping requirements.
Deletion after a subscription ends
Both cases run from the same trigger the Terms use: the effective date of a notified termination (Terms, section 19).
- Voluntary cancellation. A self-service Customer cancels through account settings (Refund Policy, section 12). CGE Insights retains Customer-controlled Member records, tracking events, enrichment data, Member-linked outcome history, and related content for 30 days from the effective date of that cancellation.
- Involuntary termination or payment lapse. A failed payment, expired payment method, past-due status, or other billing-status change does not by itself begin the deletion period. The 30 days begin only when CGE Insights sends a written termination notice identifying the termination and deletion dates. This matches the Terms, which state that suspension is not termination and that a missed payment or expired card does not by itself terminate an account.
During that window, an authorized Customer administrator may request an operator-fulfilled export of available Customer data. This is a manual process. There is no self-service full-account export. Panel-level CSV exports and Reports Builder exports do not represent a complete export of Customer or Member data.
At the end of the 30 days, CGE Insights deletes Member records, tracking events, enrichment data, Member-linked outcome history, and related content from active systems. Audit logs remain for their separate 24-month period, and non-identifying Pooled Summaries may remain.
A limit on deletion that Customers must know about
Deleting a Member from CGE Insights does not remove that Member from the Customer's own association management system. Where a Customer runs a scheduled Novi AMS synchronization, a Member deleted in CGE Insights may be re-created by the next synchronization unless the Customer also removes or suppresses them at source. CGE Insights states this plainly rather than describing an erasure it cannot keep.
Backups
CGE Insights makes no backup-retention or restoration commitment in this policy. Backup behavior across its infrastructure providers has not been established or tested by CGE Insights, and a stated retention period would describe a schedule that does not yet exist.
12. Testimonials and withdrawal of consent
A person may withdraw testimonial consent at any time by contacting
privacy@cgeinsights.com. After verification, CGE Insights removes the
testimonial from CGE-controlled digital channels within five business days.
Copies already printed, downloaded, cached, or held by an unrelated third party
may not be immediately removable.
CGE Insights retains the consent and withdrawal record for 24 months after removal, to document that the testimonial was authorized and the withdrawal handled.
13. Privacy rights and requests
Member requests. Members should submit privacy requests to their membership organization. If CGE Insights receives a request relating to Member data, it will promptly forward or refer it to the applicable Customer and will not independently fulfill it unless instructed by the Customer or required by law. The exception is a Member objection to pooled learning under section 6.1, where CGE Insights is the controller and handles the objection itself.
Customer requests for assistance. An authorized Customer administrator may
request assistance with access, correction, export, restriction, or deletion at
privacy@cgeinsights.com. CGE Insights verifies the Customer account and the
requesting user before acting. CGE Insights acknowledges the request within two
business days, begins the requested technical action promptly, and agrees a
completion timeline with the Customer based on the scope of the request.
Requests about CGE-controlled information. These may be submitted to
privacy@cgeinsights.com. CGE Insights verifies identity and responds within the
period required by applicable law.
Denials and appeals. If CGE Insights denies a request involving information it controls, it provides a written reason. The requester may appeal; CGE Insights uses a different reviewer when practical and responds within 45 days or any shorter period required by law.
CGE Insights retains an audit record of a request and its handling even when the underlying personal data has been deleted.
14. Security
CGE Insights currently uses the following safeguards:
- All database access is server-side. There is no browser-side database client.
- Row-level security is enabled on database tables with no browser policies, making them service-role only.
- The browser does not call the backend directly. A server-side proxy holds a shared secret, and the public site key is not treated as a credential.
- Third-party credentials and webhook URLs are encrypted at rest using Fernet encryption.
- Sessions use idle logout and a hard 12-hour cap.
- Unsaved form drafts are encrypted on the server and limited by a field allow-list.
- Webhook payloads are signed with an HMAC.
- Outbound webhook, Slack, and Microsoft Teams destinations are host-restricted and protected against server-side request forgery.
- Significant operator actions are recorded in audit logs.
- Ingest accepts events only for registered sites; an unrecognized site key is rejected before any database write.
No security program eliminates all risk. Customers must protect their own accounts, choose appropriate destinations, and notify CGE Insights of suspected misuse.
15. Personal data breach notices
CGE Insights will notify an affected Customer without undue delay after becoming aware of a personal data breach involving Customer personal data, and aims to provide an initial notice within 48 hours of becoming aware, even when the investigation is incomplete.
"Aware" means CGE Insights has a reasonable degree of certainty that a security incident has occurred and has compromised Customer personal data. An automated alert, an unconfirmed report, or an initial indication does not by itself establish awareness. CGE Insights will investigate promptly and will not delay confirmation in order to postpone notification.
The initial notice will include, to the extent known: the nature of the breach; the categories and approximate number of affected people and records; likely consequences; measures taken or proposed; a contact for follow-up; and information the Customer may reasonably need to assess its own notification duties. Information may be provided in phases.
Notices go by email to the Customer's designated security contact, which the Customer must provide and keep current. If none is available, CGE Insights may notify the account administrator or another known organizational contact.
CGE Insights requires sub-processors to notify it of breaches affecting Customer personal data and to cooperate as needed for CGE Insights to meet these obligations.
16. International processing and transfers
CGE Insights contracts only with Customers established in the United States at launch. Those Customers may have Members or website visitors located in the EEA, the United Kingdom, Switzerland, or elsewhere.
The four services CGE Insights selects regions for all process in the United States, as stated in section 8. Other providers process according to their own published terms and may process in other locations.
Where a restricted international transfer requires a legal mechanism, CGE Insights intends to rely on the applicable provider DPA, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or another lawful mechanism.
The pooled-learning gate in section 6.2 applies separately.
17. Sub-processor changes
The sub-processors listed in the applicable DPA are approved as of that agreement's effective date.
Before authorizing a new or replacement sub-processor, CGE Insights will give at least 30 days' advance notice by email to the Customer's designated legal, privacy, security, or account-administrator contact.
CGE Insights maintains the current list in its public Trust Center. The Trust Center is the public record, but posting there does not replace the required email notice.
A Customer may object during the notice period on reasonable data-protection or security grounds, explaining the specific concern. The parties will work in good faith to resolve it. If a valid objection cannot be resolved before the new sub-processor begins processing, the Customer may terminate the affected service without an early-termination penalty, subject to the applicable agreement.
CGE Insights may make an emergency sub-processor change without 30 days' notice when reasonably necessary to protect the service, respond to a security incident, avoid a material service interruption, or comply with law, and will notify affected Customers as soon as reasonably practical with the reason for the shortened notice.
18. Practices CGE Insights does not use
- CGE Insights does not sell or rent personal data.
- CGE Insights does not use advertising networks, advertising pixels, or cross-site advertising identifiers.
- CGE Insights does not use Customer data to train or fine-tune an AI model.
- CGE Insights does not share one Customer's identifiable data with another Customer.
- CGE Insights does not use third-party analytics on the authenticated Customer dashboard.
CGE Insights does operate its own first-party tracker on its public marketing website, as described in sections 3 and 9.
19. Changes to this policy
The effective date is the date this policy is first published. CGE Insights maintains archived versions or a change log.
CGE Insights may update this policy as needed. Most updates are routine: a clearer description, more detail about something the service already does, or a correction. A routine update takes effect when it is posted here, and no email is sent for it.
Some changes come with an email. CGE Insights emails Customer administrators at least 30 days before the change takes effect when the update accompanies either of the following:
- a substantial change to the services CGE Insights provides, or
- a change to the Terms of Service that materially affects the Customer.
A change required by law comes with an email even when it is small. Where a law, a regulator, or a court requires a change to this policy, CGE Insights notifies Customer administrators on the timeline that requirement allows. This applies whether the change is large or minor, and it takes precedence over the routine-update rule above.
Urgent changes. A change needed to protect the service, respond to a security incident, or comply with an immediate legal obligation may take effect before the notice period ends. CGE Insights notifies affected Customers as soon as reasonably practical and states why the notice was shortened.
However a change reaches you, it is also recorded. The Trust Center lists every version of this policy with its date and which sections changed. When you next sign in after a change, CGE Insights shows a notice in the application linking to the document that changed.
20. Contact
Privacy questions and requests: privacy@cgeinsights.com
Security reports and breach follow-up: security@cgeinsights.com
Pitch Cloud, LLC · 1012 W. Eldorado Pkwy, Unit 501, Little Elm, TX 75068