Legal

Privacy Policy

This policy explains what personal information Paradise Innovation Group collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it — wherever you are.

Effective August 24, 2026 · Last updated August 24, 2026

1.About This Policy #

Paradise Innovation Group LLC, a Montana limited liability company ("Paradise Innovation Group", "we", "us") provides a business platform and professional services. This policy describes how we handle personal information across everything we operate: our public websites, the client dashboard, our mobile applications, the payment and invoice pages we host, the websites and platforms we build and run for clients, and our email, SMS and push notifications.

"Personal information" means information that identifies, relates to, describes or could reasonably be linked with an identifiable individual. Where a law we are subject to uses a different term — "personal data" under the GDPR, "personal information" under the CCPA — we mean the same thing.

This policy is incorporated into our Terms of Service. It applies alongside, and does not replace, any separate agreement or data processing agreement we have signed with you.

We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we run no advertising trackers, analytics SDKs, session recorders or advertising pixels on our sites or in our applications. There is nothing in our platform that follows you around the internet.

2.Our Two Roles #

We handle personal information in two distinct capacities, and your rights differ depending on which one applies.

RoleWhen it appliesWhat it means
ControllerInformation about you as our customer, prospect or site visitor — your account, your billing, our communications with you, our security and audit records.We decide why and how it is processed. This policy is our notice to you, and you exercise your rights directly with us.
ProcessorInformation you put into the platform about other people — your clients, employees, contractors, project contacts, invoice recipients, and leads captured by forms on websites we host for you.You decide why and how it is processed; we act on your instructions. Our customer is the controller and their own privacy notice governs. We handle those records for them, not for us.

If you are an individual whose information reached us because a business we serve put it into the platform — for example you received an invoice, a quote, or a message from one of our customers — your relationship is with that business. Ask them to access, correct or delete your information. If you contact us instead, we will forward your request to them and help them respond, but we cannot act on their records without their instruction.

The processor commitments we make to our customers are set out in Your End Customers’ Data.

3.Information We Collect #

What we hold depends on how you use the Services. Not every category applies to every person.

CategoryExamples
Identifiers and contact detailsName, email address, postal address, telephone number, business name, job role, and the account identifier we assign you.
Account informationYour profile, avatar image, account type, approval status, organisation membership and role, onboarding progress, notification preferences and interface theme.
Enquiry and lead informationWhat you tell us in a contact, consultation or enterprise enquiry form: your project description, company size, timeline and requirements, plus the network address and browser identifier of the submission.
Business records you createBusiness entity details, addresses, logos; client and customer records; employee and contractor records; projects, notes, budgets, addresses and schedules; quotes, invoices, line items, taxes and discounts.
Financial and transaction informationSubscription plan and status, billing history, the last four digits and brand of a payment method, invoice totals, payment status, settlement figures, refunds, platform fee amounts, and the identifiers our payment processor assigns. We never receive or store full card numbers, CVV codes or bank credentials.
Domain registration informationThe domain requested and the registrant details required to register it: name, organisation, street address, city, state, postal code, country, telephone number and email address.
Files and uploadsLogos, brand assets, site preview images, brief and inspiration images, change-request attachments, and project documents such as receipts, permits, contracts and site photographs — together with their file names, types and sizes.
CommunicationsEmails and text messages sent through the platform, support correspondence, change requests, notification content, and a record of each message: recipient, subject, a truncated preview, delivery status and provider identifier.
Technical and device informationInternet protocol address, browser and device identifier (user agent), session records, timestamps, pages and features used, error and diagnostic logs, and — for our mobile applications — the operating system and the push notification token for that install.
LocationApproximate location inferred from your network address, at city or region level. We do not collect precise device location.
Platform operations dataFor websites and platforms we host for you: domain and certificate status, network address, resource usage, uptime and change history.
AI interactionsWhat you type into an assistant or chat feature and what it produces in response, together with the session it belonged to.

What we do not collect

  • We do not collect passwords — sign-in uses a single-use emailed link instead.
  • We do not collect full payment card numbers, security codes or bank account credentials; those go directly to our payment processor.
  • We do not collect government identifiers or identity documents. Where our payment processor needs them to verify a business, they are submitted to that processor directly and are never held by us.
  • We do not knowingly collect information from children — see Children’s Privacy.
  • We do not buy personal information from data brokers or list vendors.

Please do not put sensitive personal information into the platform. It is built for ordinary business records. Do not enter or upload government identifiers, financial account credentials, health or medical information, biometric data, precise geolocation, or information about a person’s racial or ethnic origin, religion, sexual orientation, union membership or criminal record. We do not want it, we do not need it, and the Services are not designed to protect it.

4.Where We Get It #

  • Directly from you — when you fill in a form, create an account, buy a subscription or domain, upload a file, send a message, submit a change request or brief, or contact us.
  • From your device, automatically — network address, browser and device identifier, session and diagnostic records, generated as you use the Services.
  • From our customers — where a business we serve enters your details into their account, or where a form on a website we host for them submits an enquiry.
  • From our service providers — payment, delivery and registration status from our payment processor, message providers and registrar.
  • From public and business sources — publicly available business information such as a trading name, published business contact details or a public website, used to prepare a proposal or a demonstration site for a business we would like to work with.

5.How We Use Information #

  • Provide the Services — create and run your account, build and host your platform, generate and deliver quotes and invoices, take payments, register domains, store your files and run the features you use.
  • Authenticate you — send sign-in links, maintain your session, and keep your account secure.
  • Take and reconcile payments — bill subscriptions and one-off charges, route invoice payments, calculate and record fees, and handle refunds and disputes.
  • Communicate with you — service notices, receipts, billing and security alerts, change-request updates, support replies, and in-app, email, SMS and push notifications about activity in your account.
  • Support you — investigate and resolve the problems you report, which may require looking at the records involved.
  • Keep records and prove what happened — maintain an audit trail of messages sent, sign-ins, and significant actions, so that a question about whether a client was contacted, or whether an account signed in, can be answered.
  • Secure the Services — detect, prevent and investigate fraud, abuse, unauthorised access and attacks; apply rate limits; and enforce our Terms.
  • Improve the Services — understand which features are used and where they fail, diagnose errors, and plan what to build. We use operational and aggregate information for this, not profiling of individuals.
  • Market our services — send information about what we offer to business contacts and existing customers, and prepare proposals and demonstration sites. You can opt out at any time.
  • Comply with law — meet tax, accounting, sanctions, consumer protection and record-keeping obligations, respond to lawful requests, and establish, exercise or defend legal claims.

We do not use your business records, your client lists, your documents or your AI inputs to train machine learning models, and we do not disclose them to any third party for that purpose.

7.Cookies and Similar Technologies #

We use a small number of cookies, all of them necessary for the site to work. We do not use advertising, analytics, profiling or tracking cookies, and we do not embed third-party tag managers, pixels or product-analytics scripts.

CookiePurposeTypeLifetime
Session cookieKeeps you signed in after you use a sign-in link, and protects requests against cross-site forgery.Strictly necessaryUntil the session expires or you sign out
Theme preferenceRemembers the colour theme you chose so the page renders correctly on the server before it loads.FunctionalUp to 1 year
Selected businessRemembers which of your business entities you are currently working in, so pages open on the right one.FunctionalUp to 1 year
Payment processor cookiesSet by our payment processor within its own checkout and billing components, for fraud prevention and to make payment work.Strictly necessary (third party)Set by that provider

Our mobile applications use equivalent local device storage for the same purposes, and store a push notification token for the install if you enable notifications.

You can block or delete cookies in your browser settings, but the strictly necessary ones cannot be refused without breaking sign-in and payment. Because we run no advertising or analytics cookies, there is nothing here for a consent banner to ask about and no behavioural profile to opt out of.

Do Not Track and Global Privacy Control

We do not track users across third-party websites, so a Do Not Track or Global Privacy Control signal has nothing to change in how we behave. We honour opt-out preference signals to the extent any law requires, and we treat them as a valid opt-out request where applicable.

8.Who We Share Information With #

We share personal information only as described here. Each provider receives the minimum needed to perform its function and is bound by contract to protect it and to use it only for that purpose.

Provider categoryWhat they receiveWhy
Payment processingName, email, billing details, payment method (collected by them, not us), transaction amounts and identifiers; and for businesses accepting payments, the identity and business verification information they require.To take subscription payments, process invoice payments into your own account, verify businesses, manage payouts, and prevent fraud.
Object storageThe files you upload and their metadata.To store logos, documents, images and attachments.
Email deliveryRecipient address, sender, subject and message content.To deliver sign-in links, notifications, invoices, quotes and correspondence.
SMS deliveryRecipient telephone number and message content.To deliver text notifications and documents you choose to send by SMS.
Push notification servicesDevice push token and notification content.To deliver notifications to our mobile applications through Apple and Google’s notification services.
Domain registrar and registriesThe domain and the registrant contact details you supplied.To register and manage domains. Some details may be published — see Domain Registration and WHOIS.
Certificate authorityDomain names only.To issue TLS certificates for the platforms we host. Issued certificates are published in public certificate transparency logs, which is inherent to how TLS works.
Hosting and infrastructureWhatever passes through or is stored by the Services.To run the servers, database and network the platform operates on.
AI processingThe text you submit to an assistant feature.To generate a response — see AI Features.
Professional advisersOnly what is necessary for the matter.Accountants, auditors, insurers and lawyers, under a duty of confidence.

Other disclosures

  • Between you and the business you deal with — if you pay an invoice or submit an enquiry, the business named on the document receives your information, because they are who you are dealing with.
  • With your direction — where you ask us to send something to someone, or to connect a third-party service.
  • For legal reasons — where we believe in good faith that disclosure is required by law, legal process, or a lawful request from a public authority; or is necessary to investigate suspected fraud or abuse, to protect the rights, property or safety of any person, or to establish, exercise or defend legal claims. Where we may lawfully do so, we will tell you first.
  • In a business transfer — see Business Transfers.

We will name the specific providers in each category on request. Write to oink@paradiseinnovation.group.

9.We Do Not Sell or Share Your Information #

We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding twelve months — and we do not do so now. We have no advertising relationships, we run no advertising or analytics trackers, and we do not disclose personal information to data brokers or advertising networks. We do not knowingly sell or share the personal information of anyone under 16.

Disclosures to the service providers listed above are made for a business purpose under contracts that prohibit them from retaining, using or disclosing the information for any other purpose. They are not sales, and they are not sharing for advertising.

We also do not offer any financial incentive or price difference in exchange for personal information.

10.Payment Information #

Payments are handled by our payment processor. Card and bank details are collected inside components hosted by that processor and are transmitted directly to it. We never receive full card numbers, security codes or bank credentials, and none of it passes through or is stored on our systems.

What we hold is the record of the transaction: amounts, currency, status, payment method type and last four digits, timestamps, fee and settlement figures, refunds, and the identifiers the processor assigns. We need this to bill you, to show a business what it earned, to reconcile, and to meet our tax and accounting obligations.

If you set up a business to accept payments, the identity and business verification our processor requires — which can include government identifiers and identity documents — is collected by that processor directly through its own hosted flow. We see only whether verification is outstanding, in progress or complete, and which categories of information the processor is still asking for.

The payment processor is an independent controller of the information it collects for fraud prevention, regulatory compliance and its own legal obligations, and its own privacy policy governs that use.

12.Domain Registration and WHOIS #

To register a domain we must give the registrar and the registry the registrant details you provide: name, organisation, address, telephone number and email address. This is required by ICANN and the relevant registry, and we cannot register a domain without it.

Some or all of those details may be published in public WHOIS or RDAP directories, or disclosed to third parties with a legitimate interest, in accordance with registry policy and the privacy protections the registrar applies. Registration data may also be escrowed with a third-party data escrow agent as ICANN requires.

Registrant details must be accurate — a registry may suspend or cancel a domain registered with false information. Ask us if you want to know what protections apply to a particular domain before you buy it.

13.Email, SMS and Push Notifications #

Service messages

While you have an account we send messages you cannot opt out of: sign-in links, receipts, billing and security notices, and updates about activity in your account. These are part of the Services.

Marketing

Marketing messages carry an unsubscribe link, and you can opt out at any time by using it or by writing to us. Opting out of marketing does not stop service messages. We do not need consent to send business-to-business marketing where the law permits it on the basis of legitimate interests, but you can object regardless and we will stop.

Text messages

If you give us a mobile number we may text you about your account. Reply STOP to opt out, HELP for help. Message and data rates may apply. We do not share mobile numbers or SMS consent with third parties for their own marketing.

Push notifications

If you allow notifications in one of our mobile applications, we store a push token identifying that install and the account it belongs to, refreshed each time the application launches. Tokens are deleted when you sign out and when the notification service reports one as no longer valid. Turn notifications off in your device settings at any time.

Our record of what was sent

We record every message the platform sends — the recipient, the channel, the subject, a truncated preview of the content, the delivery status and the provider’s identifier — including failures. That record exists so that a dispute about whether someone was told something can be answered, and so that a message that silently failed can be found. It is retained as described in How Long We Keep It.

14.AI Features #

Where the platform offers an assistant or chat feature, what you type is sent to a language model to generate a response, along with the conversation it belongs to.

  • Your inputs and outputs are not used to train models, by us or by anyone else, and are not disclosed to any third party for that purpose.
  • We may retain conversations to provide the feature, to diagnose problems and to prevent abuse.
  • Where a feature is delivered through a third-party model provider rather than infrastructure we operate, that provider processes the input as our service provider under contract. We will identify the provider on request.
  • Do not enter sensitive personal information, credentials, payment details or anything you are not permitted to disclose into an AI feature.

AI output can be wrong. The limits on relying on it are set out in AI Features in our Terms.

15.How We Protect Information #

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption in transit using TLS across our sites, applications and interfaces, and encryption of data at rest by our infrastructure providers.
  • Passwordless authentication with single-use, expiring sign-in links — there is no password for anyone to guess, reuse or leak.
  • Session records that capture the network address and device of each sign-in, so unfamiliar access can be identified, and the ability to revoke sessions.
  • Access controls that scope every record to the business entity it belongs to, so one customer cannot reach another’s data.
  • Manual approval of new accounts before platform access is granted.
  • Rate limiting and abuse controls on public endpoints and forms.
  • An audit trail of messages sent, sign-ins and significant actions, including the network address and device behind them.
  • Segregation of payment credentials, which never enter our systems.
  • Least-privilege administrative access, kept to the small number of people who need it, with their actions recorded.
  • Regular dependency and security patching of the platforms we run.

No system is perfectly secure. We cannot guarantee the security of information transmitted to us or held by us, and we cannot protect an account whose email inbox has been compromised — a sign-in link sent there is a working credential. Keep your email account secure, and tell us immediately if you suspect a problem.

If a breach affecting your personal information occurs, we will notify you and the relevant supervisory authorities where the law requires, without undue delay. Report a suspected vulnerability or incident to oink@paradiseinnovation.group.

16.How Long We Keep It #

We keep personal information for as long as we need it for the purpose it was collected, and then for as long as we are required or reasonably need to keep it for legal, tax, accounting, security or dispute-resolution purposes. In practice:

InformationHow long
Account and profileFor as long as your account is open, and for a limited period afterwards so that you can reactivate. Deleted or anonymised after that, subject to the rows below.
Business records you createdFor as long as your account is open. On termination, available for export for 30 days, then deleted on the schedule described in our Terms.
Financial, invoice and transaction recordsAt least seven years from the transaction, as tax and accounting law requires. These are not deleted on request.
Audit records of messages sent, sign-ins and significant actionsRetained long-term as our record of what the platform did and when. Deleting an account removes the link to it but not the underlying event record — that is the point of an audit trail.
Enquiry and lead informationUp to 24 months from your last interaction with us, unless you become a customer or ask us to delete it sooner.
Uploaded filesUntil you delete them or your account closes. The record that a file existed, its size and who uploaded it is kept afterwards for storage accounting and cleanup.
Domain registration recordsFor the life of the registration and afterwards as the registrar, registry and ICANN require.
Push notification tokensUntil you sign out, disable notifications, or the notification service reports the token as invalid — whichever comes first.
Session recordsUntil the session expires or is revoked; the audit record of the sign-in is retained as above.
Support correspondenceUp to 3 years from the last message in the thread.
BackupsOperational backups are rotated and overwritten on a rolling schedule. Information deleted from the live system may persist in a backup until that copy is overwritten.

Where we hold information as a processor for one of our customers, they set the retention period through their use of the platform, and we delete it on their instruction or in accordance with the schedule above.

17.International Transfers #

We are based in Paradise Valley, Montana, United States, and our infrastructure and service providers are located in the United States and Europe. If you are outside those places, using the Services involves transferring your information to them, where privacy laws may differ from those in your country.

Where we transfer personal information out of the European Economic Area, the United Kingdom or Switzerland, we rely on an appropriate safeguard — usually the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, and supplementary measures where the circumstances of the transfer require them. Where a provider is certified under an approved framework, we may rely on that instead.

Write to oink@paradiseinnovation.group for a copy of the safeguards applying to a particular transfer.

18.Your Privacy Rights #

Subject to the law that applies to you, you may have the right to:

  • Know and access — be told what personal information we hold about you, where it came from, why we have it, and who we have disclosed it to, and receive a copy.
  • Correct — have inaccurate or incomplete information put right.
  • Delete — have your personal information erased, subject to the records we are required to keep.
  • Port — receive the information you gave us in a portable, machine-readable format, and have it sent to another provider where technically feasible.
  • Object and restrict — object to processing based on our legitimate interests, object to direct marketing at any time, or ask us to restrict processing while a dispute is resolved.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.
  • Opt out — of the sale or sharing of personal information, of targeted advertising, and of profiling with legal or similarly significant effects. None of these apply to us: we do none of them.
  • Non-discrimination — not be treated differently for exercising a privacy right. We will not deny you service, change your price, or give you a lesser experience because you exercised one.
  • Complain — lodge a complaint with your data protection authority.

How to exercise a right

Write to oink@paradiseinnovation.group and tell us what you would like us to do. Requests are free unless they are manifestly unfounded or excessive. We will acknowledge within 10 business days and respond within 45 days, extending by a further 45 days where the request is complex — and within one month where the GDPR or UK GDPR applies, extendable by two further months.

We must verify who you are before acting, in proportion to the sensitivity of what is asked. Usually we do that by confirming control of the email address on the account; for a deletion or a request covering sensitive records we may ask for more. We will not create an account or collect extra information solely to verify a request.

An authorised agent may make a request for you if they provide written permission signed by you, and we may still contact you directly to confirm it. A parent or guardian may act for a minor.

If we decline a request we will tell you why. Where the law provides an appeal — as several US state laws do — you may appeal by replying to our decision, and we will respond within the period that law allows and tell you how to contact your attorney general or supervisory authority if you remain dissatisfied.

If your information is in the platform because one of our customers put it there, ask them. We hold those records as their processor and cannot change or delete them without their instruction — see Our Two Roles. Tell us anyway and we will pass the request on and help them answer it.

19.United States State Privacy Rights #

This section applies if you are a resident of a US state with a comprehensive consumer privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. We are based in Montana and comply with the Montana Consumer Data Privacy Act as well as the laws of the states our customers are in.

The rights in Your Privacy Rights are the rights these laws give you, and the process described there is how to exercise them.

California notice at collection

For the purposes of the California Consumer Privacy Act, as amended, the categories of personal information we have collected in the preceding twelve months, and the statutory categories they fall under, are:

CCPA categoryCollectedBusiness purposeDisclosed to
Identifiers (name, email, postal address, phone, IP address, account ID)YesProviding and securing the Services, billing, communications, legal compliancePayment, email, SMS, hosting and storage providers; registrar
Customer records (contact and financial details under Cal. Civ. Code § 1798.80)YesBilling, invoicing, business records, tax and accountingPayment and hosting providers; professional advisers
Commercial information (purchases, subscriptions, transactions)YesProviding the Services, billing, reconciliation, supportPayment and hosting providers
Internet and network activity (usage, session and diagnostic records)YesSecurity, fraud prevention, debugging, service improvementHosting provider
Geolocation (approximate, from IP address)YesSecurity and fraud preventionHosting provider
Audio, electronic or visual information (files and images you upload)YesProviding the ServicesStorage provider
Professional or employment information (role, employer, employee records you create)YesProviding the ServicesHosting provider
InferencesNo
Sensitive personal informationNo — we do not collect it and ask you not to submit it
Biometric information, education records, precise geolocationNo

We disclosed each collected category to service providers for the business purposes shown. We sold no personal information and shared none for cross-context behavioural advertising — see We Do Not Sell or Share Your Information. Because we collect no sensitive personal information, the right to limit its use does not arise.

California residents may also request, once a year and free of charge, information about disclosures to third parties for their own direct marketing purposes under California’s "Shine the Light" law. We make no such disclosures.

Nevada

Nevada residents may direct us not to sell certain personal information. We do not sell personal information, but you may still submit a request to the address above and we will record it.

20.EEA, UK and Swiss Rights #

If you are in the European Economic Area, the United Kingdom or Switzerland, the GDPR, UK GDPR or Swiss FADP applies to our processing of your personal information as a controller. The legal bases we rely on are in Legal Bases for Processing, and your rights and how to exercise them are in Your Privacy Rights.

You have the right to lodge a complaint with your local supervisory authority — in the United Kingdom, the Information Commissioner’s Office; in the EEA, the authority in your country of residence, work or the alleged infringement; in Switzerland, the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.

We have not appointed an Article 27 representative. If you believe one is required for our processing of your information, write to oink@paradiseinnovation.group and we will deal with your request directly and review the position.

Providing personal information is generally necessary to enter into and perform our contract with you. If you do not provide it, we may be unable to provide the Services.

21.Canada, Australia and Elsewhere #

Canada. We handle personal information in accordance with PIPEDA and applicable provincial legislation. You may access and correct your personal information, and withdraw consent subject to legal and contractual restrictions, by writing to us. You may complain to the Office of the Privacy Commissioner of Canada.

Australia and New Zealand. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 and, in New Zealand, the Privacy Act 2020. You may request access to and correction of your personal information, and complain to us, to the Office of the Australian Information Commissioner, or to the New Zealand Privacy Commissioner.

Everywhere else. Wherever you are, you may write to us with a privacy request and we will handle it in accordance with this policy and any law that applies to you. We do not require you to be in a particular country to ask.

22.Children’s Privacy #

The Services are for business use and are not directed to children. We do not knowingly collect personal information from anyone under 18, and you must be 18 to hold an account.

If you believe a child has provided us with personal information, write to oink@paradiseinnovation.group and we will delete it promptly. We do not knowingly sell or share the personal information of anyone under 16 — and we do not sell or share anyone’s.

23.Automated Decision-Making #

We do not make decisions producing legal or similarly significant effects about you by automated means without human involvement. Account approval is a manual decision made by a person. Domain registration is performed by a person. Rate limiting and abuse controls are automated but affect access to a request, not your rights, and can always be reviewed by a person.

Our payment processor performs automated fraud scoring and identity verification as part of its own service, and may decline a transaction or restrict an account on that basis. Those decisions are theirs, not ours, and their privacy policy explains how to contest one.

We do not profile individuals for marketing, and we do not use personal information to build behavioural or predictive profiles.

24.Third-Party Sites and Client Websites #

Our sites and the Services link to sites we do not run. We are not responsible for their content or their privacy practices, and this policy does not apply to them. Read their policies before giving them information.

Websites and applications we build and host for our customers are our customers’ own. When you use one — for example by submitting an enquiry form on a contractor’s website we host — the business that operates the site is the controller of what you submit, and its privacy notice governs. We receive and process that information as its service provider: typically the name, email address, telephone number, the services requested, any comment, your marketing preference, and the network address and browser identifier of the submission, which we store and forward to the business by email and text message.

To access, correct or delete something you submitted to one of those sites, contact the business that operates it. Tell us as well and we will forward your request.

25.Business Transfers #

If we are involved in a merger, acquisition, financing, reorganisation, bankruptcy or sale of all or part of our business, personal information may be disclosed to the counterparty and its advisers as part of due diligence, and may be transferred as one of the assets. Any recipient will be bound to honour this policy in respect of information transferred to it, or to give you notice and a choice before materially changing how it is handled.

26.Changes to This Policy #

We may update this policy as the Services change or the law does. When we do, we will change the effective date at the top of this page. Where a change materially affects how we handle personal information we already hold, we will give you notice by email or through the platform before it takes effect, and obtain your consent where the law requires it.

Continuing to use the Services after the new policy takes effect means you accept it. We keep prior versions and will provide one on request.

27.Contact Us #

Paradise Innovation Group LLC is the controller of the personal information described in this policy where we act as a controller. We are located in Paradise Valley, Montana, United States.

For any privacy question, request or complaint — including access, correction, deletion, portability, objection, opting out, or an appeal against a decision we have made — write to oink@paradiseinnovation.group. A postal address for formal notices is available on request.

We take complaints seriously and will investigate and respond. If you are not satisfied with our response, you may contact your data protection authority, attorney general or privacy commissioner, as described in the sections above.

Questions about this document? Write to oink@paradiseinnovation.group.

© 2026 Paradise Innovation Group. This document is provided for your information and does not constitute legal advice.