Privacy Policy

Last Updated: May 19,2026

1. Personal Information We Collect

We collect personal information from the following sources:

1.1 Information you provide to us

  • Business contact details, including your first and last name, business email address, company name, job title, and phone number.
  • Account information, including your account credentials, billing and payment information, the Services you have purchased or expressed interest in, and other information used to administer your account. Payment information is processed by our payment service provider, Stripe, and we do not store full payment card numbers. Stripe processes your information in accordance with its privacy policy at stripe.com/privacy.
  • Communications you exchange with us, including when you contact our sales, support, or other teams with questions, feedback, demo requests, or otherwise. We may record or transcribe sales and support calls with notice.
  • Marketing information, including your preferences for receiving communications from us, the publications and resources you download, and how you engage with our marketing communications and events.
  • Event and webinar information, including registration details and information you share when attending Nostra-hosted or co-hosted events.

1.2 Information from third-party sources

  • Social media information. We maintain pages on platforms such as LinkedIn, X (formerly Twitter), Instagram, TikTok, and YouTube. When you interact with these pages, we may receive information from you or from the platform itself, subject to the platform's privacy practices.
  • Partners and integrations. We may receive information from our integration partners (such as Shopify, BigCommerce, and others) and channel or referral partners when you engage with our Services through them.
  • Marketing and data providers, including firmographic data, contact enrichment, and intent signals about businesses that may be interested in our Services.
  • Publicly available sources, such as professional networking sites and public records.

1.3 Automatic data collection

We and our service providers automatically collect certain information about your device and your interaction with our Services over time, including:

  • Device data, such as operating system, manufacturer and model, browser type, IP address, unique device identifiers, language settings, mobile carrier, and general location (such as city, state, or region inferred from IP address).
  • Usage data, such as pages or screens viewed, time spent, referring and exit pages, browsing and click history, and access times.
  • Performance data, such as site speed measurements and aggregated metrics related to our Services.

We collect this information using cookies, pixels, software development kits (SDKs), server logs, and similar technologies. For more on how to control these, see Section 6 ("Your Privacy Choices") below.

2. How We Use Personal Information

We use personal information for the following purposes:

2.1 To provide and operate our Services

  • Creating and administering your account
  • Providing, hosting, securing, and maintaining the Services
  • Processing transactions and managing billing
  • Communicating with you about your account, transactions, and changes to our Services or policies
  • Responding to your inquiries and providing customer support

2.2 To improve, develop, and analyze our Services

  • Understanding how customers and visitors use our Services
  • Conducting research, analytics, benchmarking, and product development
  • Debugging, identifying bugs and errors, and improving security and performance
  • Creating aggregated, anonymized, or de-identified data that no longer identifies you, which we may use and share for any lawful business purpose

2.3 For marketing and advertising

  • Sending newsletters, product updates, promotions, event invitations, and other marketing communications via email, postal mail, telephone, text message, or other means (subject to your preferences and applicable law)
  • Personalizing our marketing and measuring its effectiveness
  • Running advertising on third-party platforms, including retargeting visitors of our website
  • Tailoring content and recommendations based on your interests

2.4 To use AI and automated tools

We use AI and machine learning tools internally to support functions such as customer support triage, sales operations, content drafting, and product analytics. We do not use customer end-user personal information processed on behalf of our customers to train third-party generative AI models without contractual authorization. Where we use AI tools, we apply reasonable safeguards to protect personal information.

2.5 For compliance, safety, and protection

  • Enforcing our terms, agreements, and policies
  • Complying with legal obligations and responding to lawful requests
  • Detecting, investigating, and preventing fraud, security incidents, abuse, or illegal activity
  • Establishing, exercising, or defending legal claims
  • Protecting the rights, property, safety, and security of Nostra, our users, customers, employees, and the public

2.6 With your consent

We may use your information for other purposes that we describe to you and for which you provide consent, where required by law.

3. How We Disclose Personal Information

We may share personal information with the following categories of recipients:

  • Service providers and vendors who perform services for us, such as cloud hosting and infrastructure, content delivery, communications, analytics, billing and payment processing, fraud and security monitoring, email and event distribution, customer relationship management, and professional consulting.
  • Integration and channel partners, when you choose to connect a Nostra product with a partner platform or use our Services through them.
  • Professional advisors, including lawyers, accountants, auditors, bankers, and insurers, where necessary for their professional services.
  • Government authorities, law enforcement, and other parties, where we believe in good faith that disclosure is necessary or appropriate to comply with applicable law, respond to lawful requests (such as subpoenas or court orders), protect our rights or those of others, or address safety concerns.
  • Acquirers and other participants in business transactions involving a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction (including during negotiations).
  • Affiliates within the Nostra corporate family, for the purposes described in this policy.
  • With your direction or consent, including when you choose to share information publicly or through our Services.

We do not sell personal information for monetary consideration. We may "share" or use personal information for cross-context behavioral advertising as those terms are defined under certain U.S. state privacy laws — see Section 7 below for your rights.

4. Cookies and Tracking Technologies

We and our partners use cookies and similar technologies (such as pixels, tags, and SDKs) to operate our website, remember your preferences, analyze traffic, and support marketing. We use the following general categories:

  • Strictly necessary cookies, required for the website to function.
  • Functional cookies, which remember your preferences and choices.
  • Analytics cookies, which help us understand how visitors use our site (including providers such as Google Analytics).
  • Advertising and targeting cookies, which support advertising on third-party platforms (such as Google, LinkedIn, and Meta).

Where required by law, we request your consent before placing non-essential cookies. You can manage your cookie preferences through the cookie banner or settings on our website, and through your browser. See Section 6 for more on your choices.

5. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. The criteria we use to determine retention periods include:

  • The duration of our relationship with you (for example, the life of your account plus a reasonable archival period)
  • Our legal, tax, accounting, and regulatory obligations
  • The need to resolve disputes, enforce agreements, and defend legal claims
  • The sensitivity of the information and the potential risk of unauthorized access or use

When personal information is no longer needed, we delete, anonymize, or otherwise dispose of it using reasonable measures.

6. Your Privacy Choices

6.1 Marketing communications

You can opt out of marketing emails by clicking the "unsubscribe" link in any marketing email we send, or by contacting us at the address in Section 11. You may continue to receive transactional and service-related communications.

6.2 Cookies and online tracking

You can control cookies and similar technologies through:

  • Our cookie banner or preferences center on our website, where available.
  • Your browser settings, which typically allow you to remove or reject cookies. Most browsers accept cookies by default; you can change this in settings. For more information, visit allaboutcookies.org. Browser-specific instructions: Firefox, Chrome, Microsoft Edge, and Safari.
  • Privacy-focused browsers and extensions, such as Brave, Privacy Badger, DuckDuckGo, Ghostery, or uBlock Origin.
  • Google Analytics opt-out, available at tools.google.com/dlpage/gaoptout.

Because these mechanisms are device- and browser-specific, you'll need to apply them on each device and browser you use.

6.3 Do Not Track and Global Privacy Control

Some browsers send "Do Not Track" signals. We do not currently respond to these signals. We do honor recognized Global Privacy Control (GPC) signals as an opt-out of "sale" or "sharing" of personal information where required by applicable U.S. state privacy law.

7. Regional Privacy Disclosures

7.1 U.S. state privacy rights (including California, Virginia, Colorado, Connecticut, Texas, and others)

Depending on your state of residence, you may have rights to:

  • Know what personal information we collect, use, and disclose about you
  • Access a copy of your personal information in a portable format
  • Correct inaccurate personal information
  • Delete personal information we hold about you
  • Opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising
  • Opt out of certain profiling and targeted advertising
  • Limit the use of sensitive personal information (we do not knowingly collect sensitive personal information for purposes that trigger this right)
  • Appeal a denial of your request, where applicable
  • Non-discrimination for exercising your rights

To exercise these rights, contact us at the details in Section 11. We will verify your request using information we already hold about you. You may also use an authorized agent, subject to verification.

8. Data Security

We use a combination of technical, organizational, and physical safeguards designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. These include encryption in transit, access controls, security monitoring, employee training, and vendor due diligence. No security program is perfect, however, and we cannot guarantee the absolute security of your personal information. If you believe you have discovered a security vulnerability, please report it to [email protected].

9. Children

Our Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16 without appropriate consent, we will delete it. If you believe a child has provided us with personal information, please contact us.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date above and, where appropriate, by other means (such as email or a notice on our website). Your continued use of the Services after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices, or if you would like to exercise your privacy rights, please contact us:

Email: [email protected]

Security reports: [email protected]

Mailing address:Nostra, Inc.1162 Broadway, Fl 8New York, NY 10001United States

For EEA/UK residents, you also have the right to lodge a complaint with your local supervisory authority.