This Privacy Policy explains how AspirePro LLC (“AspirePro LLC”, “we”, “us”) collects, uses, and protects information in connection with the AspirePro platform and the aspirepro.io website (together, the “Services”).
1. Who we are#
AspirePro is a professional services automation platform operated by AspirePro LLC, a limited liability company organized under the laws of Minnesota, United States. This policy applies to the aspirepro.io marketing website and to the AspirePro application.
Where AspirePro is used by an organization (a “Customer”), that organization decides what data its team enters and is the controller of that data; AspirePro LLC processes it as a processor (or “service provider” under U.S. state privacy laws) on the Customer’s behalf and under its instructions. For data we collect for our own purposes — such as account registration, billing, website visits, and inquiries — AspirePro LLC is the controller. A Customer’s use of the Services is also governed by its agreement with us, including our standard Data Processing Addendum (a countersigned copy is available on request).
2. Information we collect#
Information you provide#
- Account and organization data — names, email addresses, organization details, and credentials used to create and sign in to an organization.
- Customer content — the records your organization creates in the app, such as companies, contacts, deals, projects, tickets, time entries, invoices, HR records, knowledge articles, meeting notes, and files. Customer content may include personal information about your organization’s own clients and contacts; your organization is responsible for having a lawful basis to submit it.
- Contact and inquiry data — information you submit through our website forms, such as your name, email, company, and message.
- Scheduling and portal data — when your organization shares a public booking page, survey, or client-portal access, the people who use those pages submit information (such as a name, email, meeting time, or survey response) that is stored in that organization.
- Billing data — subscription plan, billing contact, and seat counts. Payment card details are entered directly with our payment processor (Stripe) and are never stored on our servers.
Information collected automatically#
- Usage and device data — IP address, browser type, pages viewed, and actions taken, used to operate, secure, and improve the Services.
- Cookies and similar technologies — used to keep you signed in, remember preferences, and protect against abuse. See Cookies below.
Information from connected services#
If your organization connects third-party accounts (for example Microsoft 365, Google Workspace, HubSpot, QuickBooks Online, or Stripe), we receive the data those integrations are authorized to share — such as calendar events, email messages you choose to sync or send, CRM records, or accounting records. See Connected services below.
3. How we use information#
- To provide, maintain, and secure the Services and your organization.
- To authenticate users, enforce permissions, and prevent fraud and abuse.
- To process subscriptions, seats, and payments.
- To respond to inquiries, provide support, and send service-related messages.
- To understand usage and improve the reliability and features of the Services.
- To comply with legal obligations and enforce our agreements.
We do not sell personal information, we do not use it for third-party advertising, and we do not use Customer content to train AI models — ours or anyone else’s.
4. AI features#
AspirePro includes an in-app assistant (“Prox”) that can read your organization data and take actions on your behalf, subject to your permissions and with confirmation before any change. To generate responses, relevant context from your organization may be sent to our AI model provider — xAI, the maker of Grok — for processing. Under xAI’s enterprise API terms, that content is processed solely to return a response and is not used to train their models. AI features respect the same role-based access controls as the rest of the platform — Prox can never show a user data their own permissions would not allow, and can never take an action they could not take themselves.
Your organization can also connect AI tools of its own choosing through AspirePro’s built-in MCP server. A connected tool authenticates with a scoped token and operates under the connecting user’s permissions; data it retrieves is then handled by your chosen AI provider under your organization’s agreement with that provider.
5. Meeting recordings & transcription#
If your organization enables the Notetaker module and connects a meeting-recording service of its choice (AspirePro does not supply the recording bot itself), a visible bot can join meetings from a connected calendar to record audio, produce transcripts, and generate summaries and action items. Recordings and transcripts are stored in your organization and follow its sharing settings; meeting owners control access, and organization administrators cannot silently override a meeting’s privacy settings.
Consent is your organization’s responsibility. Laws on recording conversations vary — some jurisdictions require the consent of every participant. The Customer and its users are responsible for providing any required notices and obtaining any required consents before recording a meeting. Where a third-party transcription or AI provider is used to process a recording, it does so on our behalf, under contract, and does not use the content to train its models.
6. Connected services (Google, Microsoft & others)#
Integrations are optional and connected by your organization or by individual users. We access only the scopes you authorize, use that data solely to provide the feature you connected it for (for example calendar sync, sending email from your own mailbox, meeting scheduling, or two-way CRM sync), and never sell it or use it for advertising. You can disconnect an integration at any time from the app, and you can also revoke access from the third party’s own security settings.
Google user data. AspirePro’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used to train AI models, never sold, and never used for advertising; humans do not read it except with your explicit permission, where required for security or legal compliance, or where it has been aggregated and anonymized.
Microsoft data. Data received through Microsoft 365 integrations (calendar, mail, and sign-in) is handled the same way: accessed only per the permissions granted, used only to provide the connected feature, and subject to your organization’s own Microsoft 365 policies.
7. How we share information#
We share information only as needed to run the Services:
- Service providers (sub-processors) — vendors that process data under contract on our behalf. Our core sub-processors are: DigitalOcean (cloud hosting and databases, US), Amazon Web Services (encrypted backup storage, US), Stripe (payments and billing, US), Cloudflare (network security and bot protection, US), SMTP2GO (transactional email delivery), and xAI (AI processing for Prox, US). With your consent, our marketing website also uses Google Analytics and Microsoft Clarity for website analytics (see Cookies). We will provide a current list on request.
- Integrations you enable — when your organization connects a third-party product (for example HubSpot or QuickBooks), data is exchanged with that product at your direction, under its own terms and privacy policy.
- Within your organization — Customer content is visible to other authorized users of the same organization, according to the permissions your administrators configure.
- Legal and safety — where required by law, or to protect the rights, property, or safety of AspirePro LLC, our customers, or others.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
8. Data storage, security & isolation#
Each organization is provisioned with its own dedicated database, so one Customer’s data is not co-mingled with another’s. We protect information using measures that include encryption of data in transit (TLS), encrypted backups, role-based access controls, optional two-factor authentication for organization users (and mandatory multi-factor authentication for our own platform administrators), and comprehensive audit logging of actions taken in the app.
No method of transmission or storage is completely secure, but we work continually to protect your information. If we become aware of a security breach affecting your personal information, we will notify affected Customers without undue delay and in accordance with applicable law.
9. Data retention#
We retain Customer content for as long as an organization is active and as needed to provide the Services. When an organization is closed, we delete or de-identify Customer content within a commercially reasonable period (generally within 90 days), unless we are required to retain it to comply with legal obligations, resolve disputes, or enforce our agreements. Encrypted backups are kept on a rolling basis and are automatically overwritten within approximately 30 days.
10. Your rights & choices#
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. If your data lives in an organization’s AspirePro account, please direct your request to that organization — it controls that data, and we will assist it as a processor. For data we control, you can exercise your rights by contacting us at support@aspirepro.io. We may need to verify your identity before acting on a request, and we will not discriminate against you for exercising your rights.
11. California privacy rights#
This section supplements the rest of this policy for California residents, per the California Consumer Privacy Act as amended (“CCPA”). In the preceding 12 months we have collected the categories of personal information described in Section 2: identifiers (such as name and email), commercial information (such as subscription details), internet activity (such as usage data), professional information (such as employer and title), and any personal information contained in Customer content, which we process as a service provider.
- We do not sell personal information and do not “share” it for cross-context behavioral advertising, and we have not done either in the preceding 12 months.
- We collect and use sensitive personal information (such as sign-in credentials) only to provide the Services.
- California residents may exercise rights to know, access, correct, delete, and port their personal information, and to non-discrimination, by emailing support@aspirepro.io. You may use an authorized agent; we will verify the request as the law allows.
12. European & UK privacy rights#
Where the EU or UK General Data Protection Regulation applies to data we control, our legal bases are: performance of a contract (providing the Services you or your organization signed up for), legitimate interests (securing and improving the Services, preventing abuse, and responding to business inquiries), legal obligation (such as tax and accounting requirements), and consent where we ask for it. You may have the rights to access, rectify, erase, restrict, or object to processing, and to data portability, and you may lodge a complaint with your local supervisory authority. Where we transfer personal data out of the EEA, UK, or Switzerland, we use appropriate safeguards such as standard contractual clauses.
13. Cookies#
We use the following categories of cookies:
- Session & security (strictly necessary) — a per-organization session cookie and a CSRF token keep you signed in and protect requests; Cloudflare may set cookies as part of verifying that a visitor is human.
- Preferences (functional) — cookies remembering your appearance (light or dark) and sidebar state.
- Analytics (marketing website only) — On aspirepro.io we use Google Analytics (cookies beginning with _ga) to measure site traffic, and Microsoft Clarity (cookies beginning with _clck and _clsk) to understand how visitors use the site through aggregated interaction data such as heatmaps and session replays. Clarity runs only if you allow it, wherever you are. Google Analytics depends on where you visit from: in the European Economic Area, the United Kingdom and Switzerland (or when we cannot tell where you are) it sets no cookie until you accept via our cookie banner, and until then receives only cookieless, non-identifying pings (Google Consent Mode); everywhere else it runs by default, the banner tells you so, and one click turns it off. If your browser sends a Global Privacy Control signal we treat that as “off” everywhere and show no banner. You can change your choice at any time using the “Cookie settings” link in the footer — turning analytics off stops both tools and expires their cookies.
- Cookieless traffic measurement (marketing website only) — Cloudflare Web Analytics counts page views, referrers, countries and page-speed measurements without cookies or fingerprinting, so it needs no consent.
The AspirePro application itself contains no third-party analytics or session-replay tools — these run only on the public marketing website. You can also control cookies through your browser settings, though disabling necessary cookies may prevent you from signing in. We do not use cross-site advertising trackers.
14. International transfers#
We operate primarily in the United States. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers operate, which may have different data-protection laws than your jurisdiction. We protect transferred data as described in this policy.
15. Children’s privacy#
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children; if you believe a child has provided us personal information, contact us and we will delete it.
16. Changes to this policy#
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice (such as an email to organization owners). Your continued use of the Services after an update means you accept the revised policy.
17. Contact us#
AspirePro LLC — if you have questions about this policy or our privacy practices, contact us at support@aspirepro.io.