Third Party Index

Snapshot 64826

Document
Privacy policy
URL
https://commercecx.com/CommerceCX_Privacy_Notice.html
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
60346 bytes
SHA-256 (raw)
02f4b61024325f160e86c10780c2aed5761000d08aed4ce64481c9430926455c
SHA-256 (normalized text)
788b491abdf8a98bffff213c23de0fc19b003e3683519132a7718dea6aa2ef36

Normalized text

Scripts and page chrome removed; this is what change detection compares.

CONTACT + DEMO REQUEST + PARTNERSHIP + OTHER INQUIRY
Interested in solving your problems with CommerceCX? Let's work together – the best partnerships yield the best results.
Thank you for reaching out to CommerceCX! Our commitment goes beyond delivering answers – we're focused on creating real business value for you. With our innovative solutions, services, and products, we're ready for your unique business challenges.
You can expect a CommerceCX team member to be in touch with you soon to further explore how we can drive your success.
Please see our Privacy Policy regarding how we will handle this information.
Reinvent the Buying Experience
Solutions
Customer Relationship Management
Quote to Cash
Configure, Price, Quote
Contract Lifecycle Management
Order to Cash
Billing Management
Industry Verticals
Services
Advisory Services
Implementation Services
Professional Services
Staff Augmentation
Products
ScaleFluidly
PriceCX
OrderCX
OmniCX
MigrationCX
PharmaCX
Insights
Ideas
Case Studies
Company
Partners
Leadership
Careers
Contact
Solutions
Customer Relationship Management
Quote to Cash
Configure, Price, Quote
Contract Lifecycle Management
Order to Cash
Billing Management
Industry Verticals
Services
Advisory Services
Implementation Services
Professional Services
Staff Augmentation
Insights
Ideas
Case Studies
Products
ScaleFluidly
PriceCX
OrderCX
OmniCX
MigrationCX
PharmaCX
Company
Partners
Leadership
Careers
Contact
© CommerceCX
Security
•
Terms
•
Privacy
LinkedIn
•
Twitter
•
Youtube
Reinvent the Buying Experience
Request Follow-Up
US
Connect with us
US
Solutions
Services
Products
Partners
Insights
Company
Effective Date: April 13, 2026 · Last Updated: April 13, 2026
Legal
Privacy Notice
At CommerceCX, we respect your privacy. This notice explains exactly what personal data we collect, why we collect it, and what rights you have over it. Our information security practices are independently audited and ISO 27001 certified.
GDPR — Europe CCPA/CPRA — California, USA DPDP Act 2023 — India
🔒
We Never Sell Your Data
✓
ISO 27001 Certified
EU
GDPR Compliant
CA
CCPA / CPRA Compliant
IN
DPDP Act 2023 Compliant
Contents
Privacy Contact
Questions or rights requests?
privacy@commercecx.com
We respond within 30 days.
Certifications
🏅 ISO 27001 Certified 🔒 SOC 2 Type II
Section 01
Who We Are
CommerceCX, Inc
150 Cornerstone Dr #104, Cary, NC 27519, United States
CommerceCX is a unified commerce platform and CPQ (Configure, Price, Quote) software provider. We help businesses transform their revenue lifecycle through digital transformation, CRM integration, and commerce solutions.
This Privacy Notice applies to personal data collected through our website at commercecx.com, including our contact and inquiry forms.
Data Controller CommerceCX | [email protected] | commercecx.com
For all data protection inquiries, rights requests, or complaints, contact us at [email protected].
Section 02
What Personal Data We Collect
We collect only the personal data you voluntarily provide when submitting an inquiry through our contact form. We do not collect payment data, health data, government IDs, or any sensitive personal data.
Data Category	Specific Fields	How We Get It
Identity Data	First Name, Last Name	You provide it via the contact form
Professional Data	Business Email, Company Name	You provide it via the contact form
Inquiry Data	Project description (free text)	You provide it via the contact form
Technical Data	Cookies, IP address, browser type	Collected after your consent via our cookie consent tool — see Section 9
We do not collect: Payment or financial data, government IDs, health or biometric data, login credentials, or any data from minors under 18.
Section 03
How We Use Your Data & Our Legal Basis
For every purpose for which we process your personal data, we identify a lawful basis as required by GDPR Article 6 and equivalent provisions under CCPA/CPRA and the DPDP Act 2023.
Purpose	Data Used	Legal Basis
Responding to your inquiry	Name, email, company, project description	Legitimate Interest / Pre-contractual steps (Art. 6(1)(b) & (f))
CRM logging & internal routing	Name, email, company	Legitimate Interest (Art. 6(1)(f))
Follow-up communications about our services	Name, email	Legitimate Interest / Consent where required (Art. 6(1)(f) & (a))
Website analytics & improvement	Technical / cookie data	Consent (Art. 6(1)(a))
Legal compliance & dispute resolution	All fields as relevant	Legal Obligation (Art. 6(1)(c))
We do not: Use automated decision-making or profiling. We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
Section 04
Who We Share Your Data With
We share your data only where necessary to operate our business. All third-party service providers are bound by data processing agreements and are prohibited from using your data for their own purposes.
Recipient	Purpose	Safeguard
CRM tools (e.g. HubSpot / Salesforce)	Storing and managing inquiry records	Data Processing Agreement
Email service providers	Delivering responses to your inquiry	Data Processing Agreement
Cloud infrastructure (Oracle OCI)	Hosting our platform and data	DPA + Standard Contractual Clauses
Vimeo	Video hosting on our website	Vimeo Privacy Policy — sets own cookies
Legal / regulatory authorities	Compliance with law only	Disclosed only as legally required
We do not share your data with advertising networks, data brokers, or any party for commercial marketing purposes. A current list of our subprocessors and service providers is available upon request.
Section 05
International Data Transfers
CommerceCX is headquartered in USA. Our cloud infrastructure includes servers in multiple regions including India and the United States. If you are located in the European Economic Area (EEA) or the United Kingdom, your data may be transferred outside those regions.
Where such transfers occur, we ensure appropriate safeguards are in place:
Standard Contractual Clauses (SCCs) approved by the European Commission — for transfers to countries without an EU adequacy decision
Data Processing Agreements (DPAs) — with all vendors and subprocessors
Transfer Impact Assessments — conducted where required under applicable guidance
For transfers involving Indian residents' data, we comply with applicable cross-border transfer requirements under the Digital Personal Data Protection Act, 2023.
Section 06
How Long We Keep Your Data
We do not keep your data longer than necessary. The following retention periods apply:
Data Type	Retention Period
Contact form submissions	Up to 3 years from submission, or the duration of any resulting business relationship, based on business needs and applicable legal requirements — whichever is longer
Email communications	3 years from the date of last communication
Legal / compliance records	As required by applicable law (typically 5–7 years)
Cookie / analytics data	As specified in our cookie settings — typically 13 months
After the applicable retention period, your data is securely deleted or anonymized. You may request early deletion — see Section 7 below.
Section 07
Your Rights
Depending on where you are located, you have the following rights regarding your personal data. We will respond to all valid requests within 30 days (extendable to 90 days for complex requests).
🇪🇺 Rights Under GDPR — Europe / EEA / UK
Right to Access
Request a copy of all personal data we hold about you (Art. 15)
Right to Rectification
Correct inaccurate or incomplete data (Art. 16)
Right to Erasure
Request deletion of your personal data — the "right to be forgotten" (Art. 17)
Right to Portability
Receive your data in a structured, machine-readable format (Art. 20)
Right to Restriction
Ask us to pause processing in certain circumstances (Art. 18)
Right to Object
Object to processing based on legitimate interest or for direct marketing (Art. 21)
Right to Withdraw Consent
Withdraw consent at any time, without affecting prior processing (Art. 7(3))
Right to Complain
Lodge a complaint with your local supervisory authority (e.g., ICO, CNIL, BfDI) (Art. 77)
🇺🇸 Rights Under CCPA / CPRA — California, USA
Right to Know — what categories of personal data we collect and how we use it
Right to Delete — request deletion of your personal data
Right to Correct — correct inaccurate personal information
Right to Opt-Out — we do not sell or share your personal data for cross-context behavioral advertising; no opt-out is currently required, but you may contact us to confirm
Right to Limit — limit use of sensitive personal information (we do not collect any)
Right to Non-Discrimination — we will never penalize you for exercising your rights
Right to Browser Opt-Out — we recognize and honor browser-based opt-out signals, such as Global Privacy Control (GPC), where required by applicable law
California residents: we respond within 45 days, extendable by a further 45 days where necessary.
🇮🇳 Rights Under DPDP Act 2023 — India
Right to Information — know what personal data we process and for what purpose
Right to Correction and Erasure — correct inaccurate data or request deletion when the purpose is fulfilled
Right to Grievance Redressal — raise a grievance with us and receive a timely response
Right to Nominate — nominate another person to exercise your rights on your behalf
Grievance Officer (India — DPDP Act 2023) CommerceCX Grievance Officer | [email protected]
We acknowledge all grievances within 72 hours and resolve them within 30 days.
How to Exercise Your Rights
Email us at [email protected] with the subject line "Privacy Rights Request".
Please include: your full name, the email address you used to contact us, and a description of your request. We may verify your identity before processing.
Section 08
How We Protect Your Data
🏅 ISO 27001 Certified CommerceCX is certified to ISO 27001 — the internationally recognized standard for information security management. Our security controls are independently audited by an accredited certification body, giving you assurance that we meet rigorous, verified security standards.
In addition to our ISO 27001 certification, we implement the following technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction:
ISO 27001 certified — independently audited information security management system (ISMS)
Encryption of data in transit using TLS / HTTPS
Encryption of data at rest
Role-based access controls — only authorized personnel can access personal data
Audit logging — access to personal data is logged and monitored
Regular security assessments and vulnerability scanning
Formal incident response and business continuity procedures
Data Processing Agreements with all vendors and subprocessors
Annual internal security reviews and risk assessments
Breach Notification In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (as required by GDPR) and inform affected individuals without undue delay where legally required. Our incident response procedures are documented and tested as part of our ISO 27001 certified ISMS.
Section 09
Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies. A cookie is a small text file placed on your device that helps us operate our website and understand how it is used. You can control your cookie preferences at any time using our cookie consent tool.
Cookie Categories
Strictly Necessary Always active — cannot be disabled
Cookie	Purpose	Duration
Session cookies	Ensure the website functions correctly and securely	Session (deleted when browser closes)
Analytics Requires your consent
Cookie	Purpose	Duration
Analytics cookies (e.g. Google Analytics)	Help us understand how visitors use our site — pages visited, time spent, traffic sources	Up to 13 months
Marketing Requires your consent
Cookie	Purpose	Duration
Marketing / retargeting cookies	Used to show relevant content and track campaign performance	Up to 90 days
Third-Party Set by external services
Provider	Purpose	Their Privacy Policy
Vimeo	Video playback on our website — Vimeo sets its own cookies when the player loads	vimeo.com/privacy
Managing Your Cookie Preferences
When you first visit our website, you will be shown a cookie consent banner where you can:
Accept All — allow all categories of cookies
Reject Non-Essential — allow only strictly necessary cookies
Manage Preferences — choose which categories to allow
You can change your preferences at any time by clicking the cookie settings link in our website footer, or by adjusting your browser settings. Note that disabling certain cookies may affect website functionality.
EU / EEA Visitors In accordance with GDPR, we will not set non-essential cookies without your explicit consent. Browsing our website does not constitute consent to cookies.
Section 10
Children's Data
Our services are not directed at individuals under the under the age of 16 (or the applicable minimum age under local law). We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected] and we will delete it promptly.
Section 11
Changes to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will:
Update the Last Updated date at the top of this page
Notify you by email where we hold your contact details
Post a notice on our website for significant changes
We encourage you to review this Privacy Notice periodically to stay informed about how we protect your data.
Section 12
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Notice or how we handle your personal data, please reach out:
CommerceCX — Privacy & Data Protection Email: [email protected] | Website: commercecx.com
Supervisory Authorities
EU / EEA users: You have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu
UK users: You may contact the Information Commissioner's Office (ICO) at ico.org.uk
Indian users: You may raise a grievance with our Grievance Officer (see Section 7) or contact the Data Protection Board of India once operational.
Reinvent the Buying Experience
Reinvent the Buying Experience
Home
Insights
Company
Solutions
Services
Products
© CommerceCX
Security
•
Terms
•
Privacy
•
LinkedIn
•
Twitter
•
Youtube