TerrierTerrier

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how Terrier Corp. ("Terrier," "we," "us," "our") collects, uses, stores, protects, and discloses information when you use our SaaS spend-optimization platform (the "Service").

1. Information We Collect

Google Workspace Directory Data

With your explicit authorization through Google OAuth, we access read-only directory information including:

  • User accounts, email addresses, and group memberships
  • License assignments and seat allocations
  • Last-activity timestamps and login signals

Scope limitation: We request only the minimum OAuth scopes necessary to identify inactive licenses, ghost seats, and departed staff. We do not request email body access or Calendar data.

Financial Transaction Data (Plaid)

When you connect corporate cards through Plaid Inc., we receive transaction metadata only:

  • Merchant name, category, amount, and transaction date
  • Recurring charge patterns and billing cycles

We never receive: cardholder names, full card numbers, PIN data, or customer payment information.

Account Data

You provide: Your name, work email, organization details, company size, and industry.

Implicit Data

  • IP address and browser type (for security and fraud prevention)
  • Service usage logs (features accessed, audit frequency, time zones)
  • Support communications (tickets, emails, chat transcripts)

2. How We Use Your Data

What We Do With Your Data

  • Identify unused software licenses and redundant subscriptions
  • Flag ghost seats (billing for departed employees)
  • Detect unauthorized or shadow IT spend
  • Generate audit reports and savings recommendations
  • Send optional nudges (Slack, Teams, email) to your team
  • Operate, maintain, secure, and improve the Service

What We Never Do

  • We do not sell your data to vendors, competitors, or third parties
  • We do not benchmark your spend against other companies
  • We do not use your data for advertising or marketing purposes
  • We do not monetize your data in any form
  • We do not use Google Workspace data to train AI models on your company's emails or directory
  • We do not access email bodies, calendar events, or file contents in Google Drive

3. Data Security & Retention

Security: All data encrypted in transit (TLS 1.2+) and at rest (AES-256). Access restricted to authorized personnel. We follow SOC 2 security principles.

Retention: Audit data retained 24 months after account closure. Transaction metadata: 12 months. Upon termination, you have 30 days to export your data; after that, all data is deleted within 7 days from live systems and 90 days from backups.

4. Legal Basis & Regulated Industries

We process your data under consent, legitimate interest, contractual necessity, and legal obligation. For law firms and accounting firms, your use must comply with state bar ethics rules. We maintain audit trails for compliance records and never benchmark your spend against competitors.

For staffing agencies, employment data is processed only for billing waste identification, not employment decisions. We do not discriminate based on protected characteristics.

5. Your Privacy Rights

Depending on your location, you have rights including: access to your data, correction, deletion, portability, and objection to processing.

For EU/UK: GDPR rights including right to erasure and right to lodge complaints with Supervisory Authorities.

For California: CCPA/CPRA rights including right to know, delete, and opt-out of sales (we do not sell data).

To exercise these rights: Contact us at privacy@terrier.io or legal@terrier.io with "Privacy Request" in the subject line. We will respond within 30 days.

6. Google API & Third Parties

Terrier's use of Google APIs adheres to the Google API Services User Data Policy. We do not combine Google data with other sources, transfer to third parties (except Plaid for spend reconciliation), or train AI models on customer-specific data.

We also integrate with Plaid, Slack, Microsoft Teams, and Gmail. Your use is also governed by their privacy policies. You may revoke access anytime.

7. Data Breach Notification

In the event of a confirmed data breach, we will notify affected users without unreasonable delay, and no later than 72 hours, as required by GDPR and most state laws. For EU/UK residents, we will notify your relevant Supervisory Authority simultaneously.

8. Contact Us

For privacy questions, rights requests, or concerns:

We will respond to inquiries within 5 business days with an acknowledgment and within 30 days with a substantive response.

Last updated: June 2026 · Terrier Corp. · legal@terrier.io