Privacy Policy
Effective Date: March 15, 2026
At VisitThree, we consider data privacy a fundamental building block of trust with our developer community and enterprise clients. This Privacy Policy details out what data we collect, how it is secured, and the ephemeral nature of our core edge computing processes. By accessing our developer APIs, platform dashboards, or web utilities, you accept the practices prescribed in this policy.
1. Information We Collect
We limit data collection exclusively to what is strictly necessary to operate a globally distributed API platform.
- Account Data: Information you explicitly provide to us when establishing an authentication key, such as your email address, name, billing details, and company organization identifiers.
- Analytical Telemetry: Anonymized logging data generated when requests hit our network edge. This includes IP addresses, request latency matrices, user-agent headers, and geographic regions. We leverage this telemetry purely to balance loads across our distributed clusters and prevent abuse.
2. Processing of Tool Payloads (Ephemeral Computation)
We exclusively use the information we collect to provide, maintain, and securely scale our API services. This includes processing edge-computed transactions, rendering SaaS outputs, and protecting our infrastructure against DDoS threats. We analyze aggregated, anonymous webhook behaviors to continually decrease API latency.
CRITICAL: Any payloads submitted directly via our programmatic suite (e.g., generating PDFs via the Resume Builder API, parsing JSON structures, formatting Base64 strings) are processed ephemerally in memory at the edge. VisitThree does not persist developer tool submission payloads on long-term storage unless explicitly intended by the API configuration (e.g., opting-in to persistent caching).
3. Cookies & Session Management
VisitThree utilizes cookies and encrypted JSON Web Tokens (JWTs) strictly to securely authenticate developers into the dashboard and safely manage payment sessions. We do not embed third-party marketing trackers or ad-retargeting scripts into your logged-in dashboard experience.
4. Data Sharing & Sub-processors
We do not, and will not, sell your personal information or your API footprint data.
We share data exclusively with trusted third-party cloud infrastructure providers (Sub-processors) required to operate our platform (such as Vercel, AWS, or Stripe). These sub-processors are legally bound by strict Data Processing Agreements (DPAs) guaranteeing they maintain confidentiality and utilize standard security protocols such as AES-256 encryption.
5. Data Retention & Deletion
We retain your Account Data only for as long as your account remains active. If you elect to delete your account via the VisitThree Dashboard, all associated API keys, billing associations, and PII are permanently purged from our primary databases within 30 days. Analytical telemetry is retained in an anonymized, aggregated format indefinitely for historical traffic baselining.
6. Contacting the Security Team
Protecting your integration workflow is our core priority. If you represent an enterprise client and require standard compliance documentation (DPA, SOC2 reports, penetration test summaries), or if you wish to report a security vulnerability, please contact us at [email protected].