Privacy Policy
Last updated: August 10, 2026
This Privacy Policy explains how Black Heron Enterprise LLC collects, uses, shares, and protects personal information in connection with greenLightScore. Expand any section below to read the full text.
Key points at a glance:
greenLightScore outputs are informational only — not financial, investment, legal, tax, or advertising advice, and not a guarantee of commercial success.
We do not sell personal information.
Do not submit sensitive personal information or third-party confidential data.
1. Introduction
This Privacy Policy explains how Black Heron Enterprise LLC ("Black Heron," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with the greenLightScore website (www.greenLightScore.com) and related services (collectively, the "Service"). greenLightScore is a product of Black Heron Enterprise LLC.
By accessing or using greenLightScore, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
Important disclaimer: greenLightScore outputs (including greenLightScores, projections, and recommendations) are informational only. They are not financial, investment, legal, tax, or advertising advice, and they are not a guarantee of commercial success.
2. Company and Controller Information
The data controller responsible for your personal information is:
Black Heron Enterprise LLC
30 N Gould St., STE 7000
Sheridan, Wyoming 82801, USA
Email: office@greenLightScore.com
Phone: +1 (307) 414 8400
3. Scope
This Privacy Policy applies to all users of greenLightScore worldwide, including visitors to our website, registered account holders, paying subscribers, and anyone who submits product information for analysis. It applies to information collected through the Service, our marketing communications, and support channels.
Where this Policy refers to "Business Customer" or "Consumer," those terms have the meanings given in our Terms of Service, Section 3.
This Policy does not apply to third-party websites, applications, or services that we do not own or control, even if they are linked from the Service.
4. Personal Information We Collect
We collect the following categories of personal information:
a. Account information — Email address, password (hashed), display name, authentication tokens, and account preferences.
b. Billing information — Subscription tier, billing status, transaction history, and payment identifiers. Card details are handled directly by our payment processor (Stripe) and are never stored on our servers.
c. Product analysis inputs — Product name, category, target platform, cost of goods sold (COGS), selling price, ad budget, and any additional context you submit for analysis.
d. Usage and device data — IP address, browser type, operating system, referring URLs, pages viewed, time spent, and interaction events. IP addresses are used for rate limiting anonymous usage (one free report per IP address).
e. Cookies and similar technologies — Session cookies, authentication cookies, and analytics identifiers. See Section 12 for details.
f. Support communications — Emails, messages, and any information you provide when contacting our support team.
g. Marketing preferences — Your opt-in/opt-out status for marketing emails and product updates.
h. Third-party data — If you sign in with a third-party provider (e.g., Google), we receive your email address and basic profile information as authorized by that provider.
5. Sensitive Personal Information
We do not intentionally collect sensitive personal information such as government identifiers, precise geolocation, health data, biometric data, racial or ethnic origin, religious beliefs, sexual orientation, or trade union membership.
Do not submit sensitive personal information through product analysis inputs or support channels. If you inadvertently submit sensitive information, contact us and we will delete it.
6. How We Use Personal Information
We use personal information for the following purposes:
a. Provide the Service — Create and manage your account, process product analyses, generate greenLightScores and reports, and deliver results.
b. Billing and subscription management — Process payments, manage subscription tiers, send invoices and receipts, and handle refunds or disputes.
c. Improve and develop the Service — Analyze usage patterns, debug issues, monitor performance, and develop new features. Aggregated and anonymized data may be used for product research.
d. Security and fraud prevention — Detect and prevent abuse, enforce rate limits, protect against unauthorized access, and comply with legal obligations.
e. Communications — Send transactional emails (receipts, password resets, account notifications) and, with your consent, marketing updates.
f. Legal compliance — Comply with applicable laws, respond to lawful requests from authorities, and enforce our Terms.
7. Legal Bases for Processing Under GDPR
If you are located in the EU, EEA, UK, or Switzerland, we rely on the following legal bases:
Account creation and Service delivery — Contract (Art. 6(1)(b))
Billing and payment processing — Contract / Legal obligation (Art. 6(1)(b), (c))
Security, fraud prevention, rate limiting — Legitimate interests (Art. 6(1)(f))
Marketing emails — Consent (Art. 6(1)(a))
Analytics and product improvement — Legitimate interests (Art. 6(1)(f))
Legal compliance — Legal obligation (Art. 6(1)(c))
8. Automated Analysis and AI Disclaimer
greenLightScore uses automated systems, including large language models and statistical models, to generate greenLightScores, market analyses, and recommendations. These outputs are algorithmically produced and reflect probabilistic estimates based on the inputs you provide and publicly available data.
greenLightScore outputs are informational only. They are not financial, investment, legal, tax, or advertising advice, and they are not a guarantee of commercial success. You are solely responsible for business decisions you make based on these outputs.
These automated processes do not produce legal effects concerning you or similarly significantly affect you within the meaning of GDPR Article 22. Where required, you may request human review by contacting us.
9. AI and Product Input Data
Product analysis inputs you submit are transmitted to third-party AI providers (currently Anthropic) for processing. These providers act as our sub-processors and are contractually restricted from using your data to train their models or for any purpose other than delivering results back to us.
We do not send your personal account information (email, billing data) to AI providers alongside your product inputs.
Do not submit third-party confidential information, trade secrets, or protected intellectual property that you are not authorized to disclose. You are responsible for the content you submit.
10. How We Share Personal Information
We share personal information only as described below:
a. Service providers (sub-processors) — Infrastructure (Supabase, Cloudflare), payment processing (Stripe), email delivery, AI processing (Anthropic), and analytics providers, each bound by data processing agreements.
b. Legal and regulatory disclosures — When required by law, subpoena, court order, or to protect our rights, users, or the public.
c. Business transfers — In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality safeguards and continued protection under this Policy.
d. With your consent — Any other sharing that you explicitly authorize.
e. Aggregated, de-identified, derived, and benchmark data — We may create and share Aggregated Data, De-identified Data, Derived Data, and Benchmark Data, as described in Section 24 below, which cannot reasonably be used to identify you.
11. Sale, Sharing, and Targeted Advertising
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. We do not use your data to serve you targeted ads on third-party platforms.
12. Cookies and Tracking Technologies
We use the following categories of cookies and similar technologies:
a. Strictly necessary — Authentication, session management, security, and load balancing. Cannot be disabled.
b. Functional — Remember your preferences (e.g., UI settings). Optional.
c. Analytics — Aggregated usage metrics (Plausible, Google Analytics). Analytics data is not used for advertising.
d. Advertising — We do not use advertising or cross-site tracking cookies.
You can control cookies through your browser settings. Disabling strictly necessary cookies may break the Service.
13. Data Retention
We retain personal information only as long as needed for the purposes described:
Account data — Until account deletion + 30 days backup
Reports (Vault) — Until you delete them, or until account deletion
Billing records — 7 years (tax/accounting law)
Support communications — 3 years from last contact
IP address (rate limiting) — 30 days
Analytics (aggregated) — Up to 26 months
Marketing preferences — Until you unsubscribe
14. Data Security
We implement industry-standard technical and organizational measures, including:
Encryption in transit (TLS 1.2+) and at rest.
Row-level security in our database so users can only access their own data.
Hashed passwords and secure authentication tokens.
Access controls, least-privilege permissions, and audit logging.
Regular security reviews and dependency updates.
No system is completely secure. If we become aware of a breach affecting your personal information, we will notify you and applicable regulators as required by law.
15. International Data Transfers
We are based in the United States, and our sub-processors may operate globally. If you access the Service from outside the US, your data will be transferred to and processed in the US and other countries.
For transfers from the EU/EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) and equivalent safeguards approved by the European Commission and UK ICO.
16. Your Privacy Rights
Subject to applicable law, you have rights regarding your personal information, including:
Access — request a copy of the data we hold about you.
Correction — request correction of inaccurate data.
Deletion — request erasure of your data.
Portability — receive your data in a structured, machine-readable format.
Restriction — request restricted processing.
Objection — object to processing based on legitimate interests.
Withdraw consent — for processing based on consent.
To exercise any of these rights, email office@greenLightScore.com. We will respond within the timeframes required by applicable law.
17. EU / EEA / UK / Swiss Rights
If you are located in the EU, EEA, UK, or Switzerland, you have the rights described in Section 16 under the GDPR and UK GDPR. You also have the right to lodge a complaint with your local data protection authority.
For UK residents, the supervisory authority is the Information Commissioner's Office (ICO).
18. US State Privacy Rights
Residents of California, Colorado, Connecticut, Virginia, Utah, and other US states with comprehensive privacy laws may have rights including access, deletion, correction, portability, and the right to opt out of targeted advertising or the sale of personal information.
As described in Section 11, we do not sell personal information and do not engage in targeted advertising.
To exercise any state privacy right, email office@greenLightScore.com. You may also designate an authorized agent to submit requests on your behalf.
19. California Privacy Notice (CCPA / CPRA)
California residents have specific rights under the CCPA/CPRA.
Categories of personal information collected in the last 12 months:
Identifiers (email, IP) — Yes
Commercial information (subscription, transactions) — Yes
Internet/network activity (usage, cookies) — Yes
Geolocation (from IP; not precise) — Yes (coarse)
Sensory / biometric — No
Sensitive personal information — No
Sources and purposes:
Directly from you — Deliver the Service, billing, support
Automatically (cookies, logs) — Security, analytics, rate limiting
Third-party sign-in (Google) — Account creation
Sale/sharing: We have not sold or shared personal information in the past 12 months and do not do so.
California residents may exercise access, deletion, correction, and non-discrimination rights by emailing office@greenLightScore.com.
20. Children's Privacy
greenLightScore is not directed to children under 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it. Parents or guardians may contact us to request deletion.
21. Marketing Communications
We send marketing emails only if you have opted in. You can unsubscribe at any time using the link in any marketing email or by emailing office@greenLightScore.com. Transactional emails (receipts, password resets, security notices) are not marketing and cannot be unsubscribed from while you have an active account.
22. Do Not Track and Global Privacy Control
We honor Global Privacy Control (GPC) signals from your browser as an opt-out of any sale or sharing of personal information. Because we do not sell or share personal information, GPC has no additional effect on our processing. We do not currently respond to legacy "Do Not Track" browser headers.
23. User Responsibilities
You are responsible for:
Keeping your account credentials secure and confidential.
Ensuring the information you submit is accurate and lawful.
Not submitting sensitive personal information (see Section 5).
Not submitting third-party confidential or protected information (see Section 9).
Complying with applicable laws when using outputs from the Service.
24. Aggregated, De-identified, Derived, and Benchmark Data
We treat your product analysis inputs as confidential to your account. Only you and authorized Black Heron personnel, bound by confidentiality obligations, can access your individual reports and raw inputs.
We may combine your Customer Content and data generated through your use of the Service with information from other customers and lawful sources to create Derived Data and Benchmark Data — statistical, aggregated, de-identified, or anonymized information such as category-level launch rates, average margins, or scoring trends — provided this information does not disclose your raw inputs or reasonably identify you.
If you are a Business Customer: we may use properly aggregated or de-identified Derived Data and Benchmark Data to provide comparative scoring, develop and improve greenLightScore, analyze commercial trends, produce reports and industry statistics, conduct research, market the Service using aggregate findings, and develop generalized insights and other Black Heron products and services.
If you are a Consumer: we use your Customer Content to provide the Service to you, and we may use properly anonymized or aggregated information from your use of the Service for statistical analysis, benchmarking, security, and Service improvement only as described in this Section. We will obtain your separate consent before using your data for any additional purpose not described here.
As between you and Black Heron, you retain ownership of your original Customer Content. Black Heron owns the Aggregated Data, De-identified Data, Derived Data, and Benchmark Data that we create.
We do not publicly disclose your raw product inputs or identify you as the source of any particular data point. Where a benchmark population is too small or structured in a way that could reasonably permit your identification, we will suppress, combine, generalize, delay, or decline to publish it.
We do not use your product inputs to train third-party AI models. Our AI sub-processors (see Section 9) are contractually restricted from training on your data.
Full terms governing this data use are set out in our Terms of Service, Section 25 (Aggregated, De-identified, Derived, and Benchmark Data).
25. Data Processing Addendum
Business customers subject to GDPR or similar laws may request a Data Processing Addendum (DPA) by emailing office@greenLightScore.com. The DPA supplements this Policy for customers who require one.
26. Third-Party Services
The Service relies on the following key third-party providers:
Supabase — database, authentication, and storage.
Cloudflare — hosting, CDN, and edge compute.
Stripe — payment processing.
Anthropic — AI analysis processing.
Plausible / Google Analytics — aggregated usage analytics.
Each provider's own privacy policy governs its handling of data. Links may be provided from the Service; we are not responsible for third-party privacy practices outside of our contractual sub-processor obligations.
27. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice on the Service before the changes take effect. The "Last updated" date at the top always reflects the most recent revision.
28. Contact Us
Entity: Black Heron Enterprise LLC
Address: 30 N Gould St., STE 7000, Sheridan, Wyoming 82801, USA
Email: office@greenLightScore.com
Phone: +1 (307) 414 8400
29. Summary of Key Privacy Points
We collect only what we need to run greenLightScore: account, billing, product inputs, and basic usage data.
We do not sell personal information and do not run targeted advertising.
Product inputs are processed by AI sub-processors under contract; they cannot train on your data.
greenLightScore outputs are informational only — not financial, investment, legal, tax, or advertising advice, and not a guarantee of commercial success.
Do not submit sensitive personal information or third-party confidential data.
You have rights to access, correct, delete, and export your data — email office@greenLightScore.com.
Data is encrypted in transit and at rest, with row-level security isolating each account.
Section 24 describes how we use aggregated and de-identified data, including differences between Business Customer and Consumer treatment.