PRIVACY

Privacy Policy

Effective September 13, 2026

This Privacy Policy explains how Commonset, Inc. ("Commonset," "we," "us," or "our") collects, uses, discloses, retains, and protects information when people visit our websites, create or use a Commonset account, participate in a pilot, request a demo, or use the Commonset service.

Customer agreements may contain additional terms governing customer data. Where a negotiated agreement applies, it controls to the extent stated in that agreement.

1. Information we collect

Account and identity information

We collect names, email addresses, organization information, account identifiers, authentication-provider identifiers, organization and team membership, and administrative roles needed to provide and secure the service.

Customer capability data

Depending on product configuration, customers may provide or connect capability content such as skills, instructions, prompts, metadata, versions, ownership, provenance, review information, access settings, provider-specific fields, and related files. Commonset processes that content to provide and secure the service and as otherwise agreed with the customer.

Connected service information

When a customer connects an AI platform, source repository, identity service, or other supported integration, Commonset processes provider configuration, external account or resource identifiers, synchronization metadata, and credentials or tokens supplied for the connection. Commonset uses connection credentials to perform authorized operations with the selected provider.

Billing and commercial information

For paid or contracted services, Commonset processes billing contact information, plan and subscription status, seat counts, contract dates, and references to records maintained by a billing or payment provider. Commonset's product data model does not store payment card or bank account numbers.

Usage and operational data

We collect service activity such as logins, capability and version actions, review and approval events, distribution and synchronization activity, provider connection status, audit events, feature usage, errors, performance information, and security-relevant events. We design operational telemetry to avoid collecting raw capability content unless it is needed for the requested feature or to operate and protect the service.

Website, demo, and communications information

When a visitor allows optional website analytics, Commonset collects limited website activity as described in the Cookies and analytics section below. We also collect information that people choose to provide through demo requests, support requests, design-partner conversations, feedback, surveys, and other communications.

2. How we use information

We use information to provide, maintain, secure, and improve Commonset; authenticate users and enforce organization and access boundaries; store, version, review, govern, distribute, or synchronize capabilities as requested; operate integrations with AI providers and other connected services; administer customer relationships, subscriptions, and billing; provide usage, adoption, audit, and administrative visibility; troubleshoot incidents and prevent abuse or security threats; communicate about the service, pilots, support, and material product or legal changes; understand product and public-site usage where permitted; comply with legal obligations; and enforce agreements.

3. How we disclose information

Commonset may disclose information to service providers and subprocessors that we select to help host, store, secure, authenticate, communicate, analyze, bill, or operate the service, subject to appropriate contractual and security obligations.

Commonset may also send information to AI or platform providers when a customer intentionally connects, imports from, publishes to, synchronizes with, or otherwise directs Commonset to use that provider. These customer-directed providers are a distinct processing boundary from Commonset-selected service providers, and copies sent to them may be governed by the customer's relationship with that provider.

We may also disclose information at a customer's direction or with appropriate authorization; when required or appropriate for legal, security, fraud-prevention, or rights-protection reasons; or in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, subject to applicable protections.

Commonset does not sell customer capability content as a data product.

4. Customer content and service roles

For many enterprise service data flows, the customer determines why and how employee or organizational data is used, while Commonset processes that data to provide the service. For other activities, such as operating our public website, managing our own accounts and business relationships, or responding to direct inquiries, Commonset may determine the purposes of processing itself.

The exact legal role may depend on the context, applicable law, and any agreement between Commonset and the customer.

5. Cookies and analytics

Commonset uses limited Google Analytics 4 (GA4) measurement on the public marketing website to understand basic traffic and engagement. Website analytics is separate from operational, security, audit, and product telemetry used to provide and protect the Commonset service.

Commonset does not load the Google Analytics tag unless a visitor chooses Accept analytics. Before that choice, Commonset's GA4 integration does not send website analytics data to Google. Visitors can reject analytics without losing access to the public website and can later change their choice through Cookie settings.

Analytics configuration

Commonset uses Google Analytics 4 on the public marketing website. Measurement is limited to page views and scroll activity. Google Signals, user-provided data collection, granular location and device data collection, advertising personalization, and automatic measurement of outbound clicks, site searches, video engagement, file downloads, and form interactions are disabled.

Page locations and referrers are reduced to origin plus path so query strings and fragments are not intentionally included. Commonset does not intentionally attach Commonset user IDs, organization IDs, capability IDs or capability content, provider configuration, credentials, security evidence, search terms, or demo-form fields to website analytics events.

After a visitor who has allowed analytics submits a demo request, Commonset records a parameter-free generate_lead event without attaching the visitor's demo-form fields.

Your analytics choice

Commonset stores a versioned first-party preference cookie for up to 180 days to remember whether analytics was accepted or rejected. The preference cookie is used to honor that choice and does not itself enable Google Analytics.

Google Analytics cookies created by Commonset's configuration are scoped to the public marketing host rather than the authenticated Commonset application. When a visitor rejects analytics, Commonset stops loading the Google Analytics tag on future page views and clears Google Analytics cookies under Commonset's control. Optional marketing analytics is not used on the authenticated Commonset application or customer capability surfaces.

6. Retention and deletion

Commonset keeps information for as long as reasonably necessary to provide and secure the service, maintain appropriate governance and audit records, comply with contractual and legal obligations, resolve disputes, prevent fraud or abuse, and enforce agreements.

Retention periods vary by information type and purpose. When information is no longer required, Commonset deletes, de-identifies, or otherwise disposes of it under applicable retention and deletion procedures.

Certain minimized records may be kept for limited periods when needed for security, auditability, fraud prevention, legal compliance, or the integrity of governance decisions. Information in backups may remain until those backups age out under the applicable backup lifecycle.

Copies sent to a customer-directed provider may remain subject to the customer's relationship with that provider and the provider's own retention practices.

7. Security

Commonset uses administrative, technical, and organizational safeguards designed to protect information, including tenant-aware access controls, secure authentication, encryption in transit, appropriate encryption at rest, logging, and least-privilege practices. No method of transmission, storage, or system operation can guarantee absolute security.

Additional information about our current technical posture is available on the Security and trust page.

8. International data transfers

Commonset and its service providers may process information in countries other than the country where the information was originally collected. Cross-border processing is subject to applicable law, customer agreements, and any transfer safeguards required for the relevant processing relationship.

9. Privacy rights

Depending on where a person lives, applicable law may provide rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. Requests may be sent to privacy@commonset.ai.

When Commonset processes personal information on behalf of an employer or other customer, the customer may be responsible for responding to the request. In those cases, we may direct the requester to the relevant customer and assist that customer as required by applicable law or agreement.

10. Children

Commonset is intended for business and organizational use by adults. The Commonset service and user accounts are not intended for people under 18, and Commonset does not knowingly offer the service to children. If we learn that personal information was collected through the service from a person under 18 contrary to this policy, we will take appropriate steps to address that information.

11. Changes to this policy

We may update this Privacy Policy as the service evolves. When we make material changes, we will communicate them as appropriate and update the effective date above.

12. Contact

Privacy questions and requests may be sent to privacy@commonset.ai.

Commonset, Inc.
1111 Oakfield Dr Ste 115 PMB 3184
Brandon, FL 33511
United States