Privacy Policy
for Contract Hulk.comExecutive Summary — Key Facts at a Glance
This is a summary only and is not meant to enforce or restrict the policy set forth below. Please read the full Policy below for complete details.
We have designed this Policy to be transparent while protecting our legitimate business interests as a U.S.-based provider of employment contract template generation services.
What we collect: Limited personal information you provide (name, email, phone, job title, state, purchase details) plus automatic technical/usage data (IP address, device/browser info, browsing and preview behavior, transaction history).
Why we collect it: To deliver our Services (generate and deliver customized employment contract templates), process payments, provide support, prevent fraud and abuse, enforce our Terms of Service (including competitor restrictions and licensing), protect our intellectual property, comply with law, and improve our platform.
We do NOT:
- We do not sell or share your personal information for third-party marketing or targeted advertising.
- We do not store credit card or full payment card data (handled exclusively by Stripe, our PCI-DSS Level 1 certified processor).
- We do not collect sensitive personal information (SSN, precise geolocation, health data, biometrics, etc.).
- We do not target or comply with GDPR/European privacy laws (Services are for U.S. users only).
We DO keep customer data for as long as necessary — and in many cases indefinitely — to support customer service, legal compliance, tax/accounting requirements, fraud prevention, and especially the enforcement of our Terms of Service and protection of our intellectual property (including retaining generated templates and their unique license numbers, which contain no personal information, to detect unauthorized redistribution).
Cookies & Tracking: Our Website and authorized service providers may use essential cookies and similar technologies for functionality, security, analytics, and marketing attribution. We do not use them for personalized cross-site advertising.
1. Introduction, Scope, and Our Commitment to Transparency
This Privacy Policy ("Policy") describes in detail how ContractHulk.com, operated by Contracts AI LLC ("we," "us," "our," or the "Company"), collects, uses, discloses, protects, retains, and processes personal information in connection with your access to and use of the website located at ContractHulk.com (the "Website") and our automated document generation Services that create employment contract templates based on user-provided job title and U.S. state inputs (collectively, the "Services").
Scope. This Policy applies to all visitors, registered users, customers, purchasers, previewers, and any other individual or entity that interacts with the Website or Services in any way, including those who view template previews, complete purchases, download documents, contact support, or otherwise engage with us.
Acceptance. By accessing, browsing, previewing templates, purchasing, downloading, reading articles or terms, or otherwise using any part of this Website or Services, you acknowledge that you have read, understood, and agree to this Policy in its entirety. If you do not agree, you must immediately cease use of the Services. Your acceptance is evidenced by your continued use and is recorded in our systems consistent with the record-keeping practices described in our Terms of Service ("TOS").
Relationship to Terms of Service. This Policy is incorporated by reference into and forms an integral part of our Terms of Service. In the event of any direct conflict between this Policy and the TOS specifically regarding the collection, use, disclosure, or retention of personal information, this Policy shall control. All other provisions of the TOS (including but not limited to liability limitations, dispute resolution, intellectual property enforcement, competitor restrictions, geographic access rules, and governing law in New York) remain fully applicable and are expressly incorporated herein.
Our Protections. As a business that creates valuable digital intellectual property (employment contract templates), we must retain certain customer and transaction data — including generated documents — to enforce our licensing terms, protect against unauthorized redistribution, detect competitor or malicious access, comply with legal obligations, and defend our rights. We keep customer data for these legitimate purposes, as further detailed throughout this Policy.
Updates. We may update this Policy from time to time. Material changes will be effective upon posting with a new Effective Date. Your continued use after changes constitutes acceptance.
2. Geographic Scope — United States Only — No GDPR Compliance
The Services are intended solely for individuals and entities physically located within the United States of America. We do not target, market to, offer our Services to, or intend to collect or process personal data from persons located in the European Union, European Economic Area, United Kingdom, Switzerland, or any other non-U.S. jurisdiction.
User Representations. By using the Services you represent, warrant, and agree that:
- You are physically located in the United States when accessing or using the Services;
- You are not using VPNs, proxies, or other means to circumvent this geographic restriction;
- You understand we do not comply with the GDPR, UK GDPR, ePrivacy laws, or any similar non-U.S. data protection regulations;
- You will not use the Services if doing so would subject us to foreign regulatory obligations; and
- Access from outside the U.S. is at your sole risk, and we make no warranties of compliance with local laws.
Enforcement. We use IP geolocation, behavioral analysis, and other technical measures to monitor and enforce policies. We reserve the right (consistent with TOS Sections 10 and 12) to deny, suspend, or terminate access without notice to anyone we reasonably believe is outside the U.S. or attempting circumvention. This protects our platform and users from regulatory and security risks.
Any references to cookies or tracking technologies are provided solely for U.S. transparency and do not create or imply any consent mechanisms, banners, or granular controls required under European law.
3. Age Restriction — 18+ Only
Our Services are directed exclusively to individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18 (or under 13 under COPPA). If we learn we have collected such information, we will promptly delete it and take steps to prevent recurrence.
Parents or guardians who believe their child under 18 has provided information to us should contact [email protected] immediately with sufficient details for verification and deletion.
By using the Services you represent you are at least 18 and have full legal capacity to enter binding contracts (per TOS Section 11.1).
4. Information We Collect — Detailed Categories, Sources, and Purposes
We practice data minimization: we collect only the personal information that is reasonably necessary for the purposes described in this Policy. Below is a comprehensive disclosure of the categories of personal information we collect or have collected in the preceding 12 months, the sources, the business or commercial purposes, and the categories of recipients (if any). This format is designed to satisfy transparency requirements under the California Consumer Privacy Act (CCPA/CPRA) and similar U.S. state privacy laws.
Categories of Personal Information Collected.
Identifiers
- Examples: Full name, email address, phone number, IP address, device identifiers (where available), account username/reference.
- Sources: Directly from you (forms, purchase checkout, support requests); automatically from your device/browser; from our systems (logs, account creation).
- Purposes: Account creation and management; identity verification; Service delivery (template generation tied to purchaser); transactional communications; fraud prevention and security; geographic restriction enforcement; customer support; marketing (with consent); legal/IP enforcement and TOS compliance.
- Recipients / Third Parties: Stripe (limited for payment verification); AWS (hosting and logging); analytics providers (aggregated); internal personnel on need-to-know basis; law enforcement or legal process when required.
Commercial Information
- Examples: Purchase history, transaction amounts and dates, order/reference numbers, promotional codes used, download history and timestamps, preview activity counts and types.
- Sources: Directly from you during checkout; automatically generated by our systems upon purchase/download/preview.
- Purposes: Fulfill purchases and deliver templates; maintain accurate transaction records; customer support and re-download assistance; analytics and business improvement; tax/accounting compliance; enforcement of licensing terms and detection of unauthorized sharing (we keep all customer transaction data for these purposes).
- Recipients: Stripe (payment confirmation); AWS (storage of records); internal teams; legal counsel or authorities for enforcement actions.
Internet or Other Electronic Network Activity Information
- Examples: Pages visited, time spent, click patterns, navigation paths, scroll depth, session replay and screen interaction recordings (mouse movement, clicks, scrolling, and page navigation, excluding payment card fields), preview behavior (which templates viewed, time in preview mode, number of previews), UTM parameters, referral sources, email interaction data (opens/clicks where technically available).
- Sources: Automatically collected via server logs, pixels, and analytics tools when you use the Website.
- Purposes: Website functionality and performance optimization; fraud and abuse detection (e.g., excessive previewing without purchase per TOS §9.1); security monitoring; analytics and Service improvement; marketing attribution and campaign measurement.
- Recipients: Third-party analytics providers (under contract); AWS; internal teams.
Geolocation Data (Approximate)
- Examples: U.S. state you select for template generation; approximate location derived from IP address (city-level or coarser).
- Sources: You (state selection); automatically from IP address.
- Purposes: Generate jurisdiction-appropriate employment contract templates; enforce U.S.-only geographic access and TOS restrictions; fraud prevention; analytics (aggregated).
- Recipients: Internal systems only (state is used for template logic); IP-derived location used internally for enforcement and analytics.
Professional or Employment-Related Information (Limited)
- Examples: Job title you provide for template generation; any business name or intended use details you voluntarily supply.
- Sources: Directly from you during template generation or purchase.
- Purposes: Customize and deliver the correct employment contract template; improve template library based on popular roles (aggregated, de-identified).
- Recipients: Internal processing only. Note: We do not collect personal information about your employees or the end-users of the templates you generate.
Payment Information (Processed by Third Party Only)
- Examples: We receive only confirmation of successful payment, payment method type (e.g., card brand), and last four digits of card for record-keeping and fraud prevention.
- Important: We do not store, process, transmit, or have access to full credit card numbers, CVV, expiration dates, or other sensitive payment card data. All such data is collected, processed, and stored exclusively by our third-party payment processor, Stripe, Inc., which is certified to PCI-DSS Level 1 standards. Stripe handles this under its own privacy policy and our data processing agreement with them.
- Sources: Stripe (limited confirmation data only).
- Purposes: Confirm successful transactions; maintain accurate financial records; prevent fraud.
- Recipients: Stripe (full handling); we receive only minimal confirmation data.
Inferences Drawn from Other Personal Information
- Examples: Usage patterns, preview frequency, purchase propensity, aggregated analytics insights (primarily de-identified or aggregated).
- Sources: Derived from your usage data and transaction history.
- Purposes: Improve Services, detect anomalies/fraud, personalize limited aspects of the user experience (e.g., relevant template suggestions), business analytics.
- Recipients: Internal use primarily; aggregated insights may be shared with analytics providers under contract.
We do NOT collect sensitive personal information as defined under CPRA or analogous state laws, including but not limited to: Social Security numbers, driver's license or state ID numbers, passport numbers, precise geolocation (beyond state-level for template purposes), financial account numbers (beyond the limited last-four and confirmation data above), health or medical information, biometric data, genetic data, information about protected characteristics (race, religion, sexual orientation, etc.), or contents of private communications unrelated to support requests. Job title and state are used solely for template customization and carry no sensitive connotation in this context.
Sources of Personal Information.
- Directly from you (forms, inputs, checkout, support tickets, voluntary disclosures).
- Automatically from your device and browser (logs, cookies/technical identifiers, IP address).
- From our own systems and records (transaction logs, generated documents associated with your account).
- From third parties: Stripe (limited payment confirmation), analytics providers, security tools, and (rarely) public or business records for TOS violation investigations (e.g., competitor status verification per TOS §10.4 and §15).
Data Minimization & Purpose Limitation. We collect and retain personal information only to the extent reasonably necessary for the specific purposes disclosed in this Policy. We do not use personal information for purposes that are incompatible with those disclosed at the time of collection without providing additional notice or obtaining consent where required. We keep customer data where ongoing retention serves the purposes of Service delivery, customer support, legal compliance, accounting/tax obligations, fraud prevention, and — critically — enforcement of our TOS and protection of our intellectual property rights in the generated templates.
5. How We Use Your Personal Information — Detailed Purposes
We use personal information for the following purposes. You acknowledge these uses are necessary and legitimate for operating our business and protecting our rights under the TOS.
Core Service Delivery
- Generate, customize, and deliver employment contract templates using the job title and state you provide.
- Process and fulfill purchases, issue receipts and download links, and grant access to purchased templates.
- Create, authenticate, and manage user accounts and sessions.
Transactional & Service Communications
- All emails and system notifications are triggered by your actions (purchase → immediate receipt + download email; support request → response; password reset you initiate, etc.). We send no unsolicited marketing without consent.
Marketing Communications (Consent-Based)
- Occasional emails about our Services, new templates, discounts, promotions, and related employment contract offerings.
- Consent mechanisms: You join our marketing list only by (a) selecting the marketing opt-in checkbox during checkout, or (b) providing your email address to save the progress of a previewed contract or to request a promotional discount code, each of which is accompanied by a notice that doing so opts you in to promotional emails. You can opt out at any time (see Section 6).
- Frequency is reasonable and not excessive; content is relevant to our Services.
Analytics, Improvement & Personalization (Limited)
- Analyze usage patterns, preview behavior, and purchase trends (often aggregated) to improve the Website, template quality, user experience, and business operations.
- Measure marketing campaign effectiveness via UTM and referral data.
Security, Fraud Prevention, Abuse Detection & Platform Protection
- Detect, investigate, and prevent fraudulent transactions, scraping, excessive previewing without purchase, hacking, DDoS, and other abuse.
- Enforce geographic restrictions and competitor exclusion policies (TOS §§10, 12, 15).
- Monitor for malicious behavior or TOS violations.
Intellectual Property Protection, Licensing Enforcement & Legal Compliance (Why We Keep All Customer Data)
- Retain purchaser information, transaction records, download logs, preview activity, and copies of generated templates for as long as necessary — and often indefinitely — to:
- Enforce our licensing terms and pursue remedies (including liquidated damages) against unauthorized redistribution or sharing (TOS §§10.3, 13.13, 23.3);
- Detect and investigate competitor access or misuse of our templates (TOS §§10, 15);
- Utilize the unique license number embedded in each generated document, which is used solely to identify the licensed purchaser in cases of unauthorized redistribution and contains no personal information beyond the license reference (TOS §§13.9, 13.13, 23.4);
- Defend against legal claims, respond to disputes, and protect our intellectual property rights in the proprietary System and templates (TOS §7, §16, §23);
- Comply with tax, accounting, record-keeping, and other legal obligations;
- Maintain audit trails for completed transactions and customer service history.
- We keep all customer data because digital products like ours are easily copied and redistributed. Retention is a reasonable and necessary business practice to protect the substantial investment we make in creating high-quality, jurisdiction-specific employment contract templates. This is expressly authorized and required by our TOS.
Other Legitimate Purposes
- Respond to valid legal process, court orders, subpoenas, or government requests.
- Establish, exercise, or defend legal claims (including in arbitration per TOS §24).
- Any other purpose disclosed to you at collection or for which you provide consent.
Phone Number Use. We may use the phone number you provide to confirm your identity, to contact you regarding your purchase, delivery, or a support issue, and, with your consent where required by law, for occasional promotional communications from our company only. We do not share your phone number with third parties for their marketing. You may opt out of promotional phone communications at any time by contacting [email protected].
No Automated Decision-Making or Profiling with Significant Effects. We do not use personal information for automated decision-making or profiling that produces legal effects or similarly significant effects concerning you. Template generation is a straightforward rules-based process using your explicit inputs (job title + state) to select and populate the appropriate template. It does not involve AI profiling of you personally.
6. Email Communications, Marketing Consent, and Opt-Out Rights
Every email sent by our systems is the direct result of your action on the Website/Services or is sent with your prior affirmative consent.
Marketing Consent at Checkout. During checkout you may opt in to receive occasional marketing and promotional emails from us about our Services, discounts, new offerings, and similar employment contract products by selecting the marketing opt-in checkbox. This consent is recorded with your purchase details (time-stamped, name, email, phone, reference number) per TOS §4.2. If you do not select the checkbox, you will receive only transactional and service emails, except as described in Section 6.3.
Marketing Consent from Saved Progress and Promo Code Requests. If you provide your email address to save the progress of a previewed contract, or to request a promotional discount code, you are opting in to receive promotional emails from us. A notice to this effect is displayed next to the email entry box at the time you provide your email address. You may opt out at any time as described in Section 6.4.
Easy Opt-Out. Every marketing email contains a prominent "Unsubscribe" link. You may also email [email protected] with "Unsubscribe" in the subject line. We honor requests promptly (within 10 business days or as required by CAN-SPAM). Opting out affects only marketing emails; transactional, security, support, and service emails necessary to fulfill our agreement with you cannot be opted out of.
CAN-SPAM Compliance. We fully comply with the CAN-SPAM Act. Marketing emails include accurate sender information, clear subject lines, our contact details, and a functioning unsubscribe mechanism. We do not send to purchased/rented lists.
7. Data Sharing and Disclosure — We Do Not Sell or Share Your Information
No Sale or Sharing. We do not sell, rent, trade, or share your personal information with third parties for their own marketing or advertising. We do not "SELL" or "SHARE" personal information as defined under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, or similar state laws. We do not engage in targeted advertising or cross-context behavioral advertising. We have not done so in the preceding 12 months.
Limited Sharing with Service Providers Only. We share personal information only with trusted third-party service providers and subprocessors that perform functions on our behalf under written contracts requiring them to:
- Use data solely for our authorized purposes;
- Maintain strong confidentiality and security protections;
- Not use or disclose data for their own purposes or further share it except as necessary to perform their services;
- Delete or return data upon termination of the relationship (subject to legal retention needs).
Current categories include:
- Stripe, Inc. — Exclusive handler of all payment card data (PCI-DSS Level 1). We receive only minimal confirmation data. This is an internal integration required to enable payments on our Website.
- Amazon Web Services (AWS) — Cloud hosting, storage (including generated documents), databases, logging, and email delivery (SES). Data is stored primarily in U.S. regions.
- Analytics & Performance Providers — Third-party tools for usage analytics, performance monitoring, and marketing attribution (may use cookies/pixels under our contractual control; data primarily aggregated).
- Security & Operational Tools — Fraud detection, abuse monitoring, DDoS protection, and customer support platforms (as needed).
Subprocessor List. Upon verified request we will provide a current list of our material subprocessors and the services they perform.
Legal, Safety & Enforcement Disclosures. We may disclose personal information (including retained generated templates and tracking data) when we have a good-faith belief it is necessary to:
- Comply with law, regulation, court order, subpoena, or valid legal process;
- Protect our rights, property, safety, or legitimate interests (or those of our users or the public);
- Investigate, prevent, or respond to fraud, security incidents, TOS violations (including competitor access and template redistribution), or threats to the platform;
- Enforce our TOS, licensing agreements, and intellectual property rights (we may share evidence with authorities, in arbitration, or court proceedings);
- Complete a business transfer (merger, acquisition, etc.) with appropriate protections.
No Other Sharing. We do not share with competitors, data brokers, or unrelated parties. We do not facilitate real-time bidding or advertising ecosystems.
International Data Transfers. Personal information is primarily stored and processed in the United States. When we engage subprocessors that may access data from outside the U.S., we use appropriate safeguards such as Standard Contractual Clauses (or equivalent) and contractual requirements to protect the data consistent with U.S. privacy expectations. Because we do not target non-U.S. users, GDPR transfer rules do not apply.
8. Cookies, Tracking Technologies, and Automated Data Collection
General Statement. Our Website and the authorized third-party service providers we use (for hosting, payment processing, analytics, security, and marketing attribution) may use cookies, web beacons, pixels, local storage, server logs, and similar tracking technologies. The specific technologies in use may change over time as we add, remove, or update service providers; this section describes the categories of technologies we may deploy and the purposes for which they are used.
Why We (and Our Providers) May Use These Technologies
- Essential / Strictly Necessary: To enable core functionality such as maintaining login sessions, preserving preview state during your visit, processing purchases, load balancing, basic security (e.g., CSRF protection), and remembering basic preferences. These are required for the Website to work properly.
- Analytics & Performance: To understand how users interact with the site (pages viewed, time spent, navigation, preview behavior), identify performance issues, and improve the Services. Data is often aggregated.
- Session Replay & Screen Interaction Recording: To record how visitors interact with our pages (such as mouse movement, clicks, scrolling, and page navigation) so we can diagnose usability problems, detect abuse, and improve the Website. These recordings exclude payment card fields, which are handled exclusively inside Stripe's checkout.
- Marketing Attribution & Campaign Measurement: To track the effectiveness of our promotional efforts using UTM parameters and referral data (no cross-site retargeting or personalized advertising).
- Security & Fraud Prevention: To detect suspicious activity, enforce geographic restrictions, and protect the platform.
What We Do NOT Do with Tracking Technologies
- We do not sell or share data collected via these technologies for third-party targeted advertising.
Your Controls. Most browsers allow you to block or delete cookies. Disabling essential cookies will likely impair core functionality (login, purchases, previews). Some browsers send "Do Not Track" (DNT) or Global Privacy Control (GPC) signals. We honor GPC signals for any sale/sharing opt-out to the extent technically feasible (even though we do not sell or share). We currently do not alter our practices in response to DNT signals due to the lack of a uniform standard.
More Information. For details on specific technologies in active use on the live site, contact [email protected]. We will provide reasonable information upon request. This Policy is written for U.S. users and does not include European-style cookie consent banners or granular opt-in mechanisms.
9. Data Retention — We Keep All Customer Data as Needed for Legitimate Purposes
General Retention Philosophy. We keep all customer data for as long as it is reasonably necessary to fulfill the purposes outlined in this Policy, provide the Services, comply with legal obligations, resolve disputes, enforce our agreements (especially the TOS), prevent fraud and abuse, and protect our intellectual property and business interests. In many cases — particularly for transaction records, purchaser information, and generated templates — this means indefinite or very long-term retention.
Specific Retention Practices
- Account and Contact Information (name, email, phone): Retained while the account is active and for a reasonable period thereafter to support customer service, potential re-activation, or enforcement needs.
- Transaction, Purchase, Preview, and Download Records: Retained indefinitely or for the maximum period permitted or required by law. These records are essential for accurate financial reporting, tax compliance, audit trails, customer service history, and — most importantly — enforcement of our licensing terms and detection of unauthorized template redistribution.
- Generated Employment Contract Templates and Associated Data: Retained solely for licensing enforcement, intellectual property protection, and legal defense purposes as authorized in TOS Section 16. Retention may continue indefinitely while there remains a need to monitor for or respond to unauthorized use, competitor access, or IP violations. These retained files contain a unique license number used solely to identify the licensed purchaser in cases of unauthorized redistribution; the license number contains no personal information beyond the license reference.
- Analytics, Usage Logs, and Technical Data: Retained for as long as useful for security, fraud prevention, performance improvement, and business analytics (typically 1–3+ years for raw logs; longer for aggregated insights or security purposes).
- Marketing Consent and Opt-Out Records: Retained as long as necessary to demonstrate CAN-SPAM compliance and to honor suppression requests.
- Legal Hold or Dispute-Related Data: Retained for the full duration of any investigation, claim, arbitration, litigation, regulatory proceeding, or appeal, plus any additional period required.
What Happens If You Request Deletion or Close Your Account? You may request deletion of your personal information (see Section 11). However, we may retain certain information even after such a request where:
- Retention is necessary to complete a transaction or provide Services you requested;
- It is required or permitted by law, regulation, or legal process;
- It is needed to protect against fraud, abuse, or security threats;
- It is necessary to enforce our TOS, licensing terms, or intellectual property rights (including retained generated templates and tracking data);
- It is needed for tax, accounting, or other legitimate business record-keeping.
De-identified or aggregated data may be retained indefinitely. You acknowledge and agree that our retention practices — including keeping customer data and generated templates for enforcement purposes — are reasonable and necessary given the nature of digital products and the risks of unauthorized copying described in the TOS.
Secure Deletion. When data is no longer needed and no legal or enforcement retention obligation applies, we securely delete, destroy, or irreversibly de-identify it using industry-standard methods.
10. Data Security — Reasonable Safeguards and No Absolute Guarantees
Our Security Measures. We implement and maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, or destruction. These include:
- Encryption of data in transit (TLS/SSL) and at rest where feasible and appropriate;
- No storage of full credit card data by us — all payment card processing is handled exclusively by Stripe under PCI-DSS Level 1 certification;
- Role-based access controls, least-privilege principles, multi-factor authentication where appropriate, and strict internal access policies;
- Secure cloud infrastructure via AWS with appropriate network segmentation, monitoring, and logging;
- Regular vulnerability assessments, penetration testing, security monitoring, and incident response procedures;
- Employee and contractor confidentiality agreements, background checks where appropriate, and ongoing training on data protection and security;
- Secure development practices and change management.
No Absolute Security. Despite our reasonable efforts, no security measure is 100% effective, and transmission over the Internet and electronic storage inherently carry risks of unauthorized access. We cannot and do not guarantee absolute security. You provide personal information at your own risk. We are not liable for breaches that occur despite our reasonable safeguards, except to the extent required by applicable law.
Data Breach Notification. In the event of a confirmed or reasonably suspected breach involving personal information, we will:
- Investigate promptly and take reasonable containment and mitigation steps;
- Notify affected individuals and relevant U.S. authorities as required by applicable state and federal breach notification laws (generally without unreasonable delay, with timing and content varying by state);
- Provide details on the nature of the incident, categories of information involved (e.g., contact info, transaction records, or — in rare cases — limited retained template data), steps we are taking, and recommended protective actions for you (e.g., monitor accounts, change passwords, consider credit monitoring);
- Comply with any additional requirements (e.g., notification to credit bureaus or offers of identity protection services when appropriate).
We maintain an incident response plan and will act in good faith to protect affected individuals.
11. Your Privacy Rights and How to Exercise Them
Your Rights (U.S. State Privacy Laws). Depending on your state of residence and applicable law (including CCPA/CPRA for California residents and substantially similar laws in Virginia, Colorado, Connecticut, Utah, and other states), you may have some or all of the following rights:
- Right to know what personal information we collect, use, disclose, and the purposes;
- Right to access / obtain a copy of the specific pieces of personal information we hold about you;
- Right to delete personal information (subject to important exceptions noted in Section 9);
- Right to correct inaccurate or incomplete personal information;
- Right to opt out of any "sale" or "sharing" of personal information or targeted advertising (we engage in none);
- Right to limit use of sensitive personal information (we collect none for such purposes);
- Right to data portability (where technically feasible);
- Right to non-discrimination for exercising your rights;
- Right to opt out of marketing emails (easy unsubscribe as described in Section 6).
How to Submit a Request. Email a verifiable request to [email protected]. Include:
- Your full name and the email/phone associated with your account or purchases;
- A clear description of the request (e.g., "Access request — California resident" or "Deletion request");
- Any details that help us locate your information (approximate purchase date, reference number, etc.).
Verification. We will verify your identity to a reasonable degree of certainty before processing (matching details from our records, confirmation via recent purchase email, or additional verification in sensitive cases). Authorized agents must provide proof of authorization; we may require direct confirmation from you.
Response Timeframes. We acknowledge requests and respond within the timeframes required by applicable law (typically 45 days, extendable once by 45 days with notice). If we cannot verify or must deny a request (e.g., because data is retained for legal/IP enforcement), we will explain why and provide any available appeal process.
No Fee for Reasonable Requests. We do not charge fees for verifiable requests unless they are manifestly unfounded, excessive, or repetitive.
Shine the Light (CA Civil Code §1798.83). We do not share personal information with third parties for their direct marketing purposes. California residents may request information about any such sharing that occurred in the prior year by contacting us at the email above.
Global Privacy Control (GPC). We honor GPC signals for opt-out of sale/sharing to the extent technically feasible.
12. Additional State Privacy Rights
Residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and any other U.S. state with an applicable comprehensive privacy law have rights substantially similar to those in Section 11. We will honor applicable requests and provide required notices and mechanisms. Specify your state of residence when submitting a request. We monitor evolving state privacy laws and update this Policy as needed.
13. Third-Party Links and Services
The Website may contain links to third-party sites or services (e.g., Stripe checkout pages). This Policy does not apply to them. We are not responsible for their privacy practices, security, or content. Review their policies before providing information. Interactions with third-party services are at your own risk.
14. Changes to This Privacy Policy
We may update this Policy at any time to reflect changes in our practices, Services, legal requirements, or business needs. Material changes take effect upon posting with an updated Effective Date and/or version number. Where appropriate we may provide additional notice (email to registered users or prominent site notice). Your continued use after changes constitutes acceptance. Review this Policy periodically.
15. Contact Us
For all privacy questions, concerns, complaints, data subject requests, or to exercise your rights:
[email protected] (for all privacy and legal matters)
Contracts AI LLC
ContractHulk.com
We respond to general inquiries within seven (7) business days. Formal rights requests are handled per applicable legal timeframes and verification requirements.
16. Relationship to Terms of Service, Governing Law, and Miscellaneous
This Policy is part of and incorporated into the TOS. The TOS governs overall use of the Services, liability, disputes, intellectual property, enforcement mechanisms, liquidated damages for violations, and New York governing law. In case of conflict on privacy-specific matters, this Policy controls; otherwise the TOS controls.
This Policy is governed by the laws of the State of New York, USA (consistent with TOS §25), without regard to conflict of law principles. Disputes are resolved per the arbitration and dispute resolution provisions in TOS §24, except where privacy laws mandate specific consumer processes.
If any provision is held invalid or unenforceable, the remainder continues in full force (per TOS §26).
We reserve all rights not expressly granted. Nothing creates third-party beneficiary rights except as required by applicable privacy law for data subject requests. You agree to attempt informal resolution via the contact methods above before formal claims, consistent with TOS §24.1.
Effective as of July 5, 2026 — Version 2.1