Legal & Compliance · iViu Insights, Inc.

Privacy Policy

We built iViu from the ground up on a single principle: location intelligence should never require collecting personal information. No names. No emails. No phone numbers. No PII. Ever.

EffectiveJanuary 1, 2024 RevisedMay 2026 JurisdictionIllinois, USA StandardsGDPR · CCPA · PIPEDA

This Privacy Policy describes how iViu Insights, Inc. and its affiliate iViuTech, Inc. (collectively, "iViu," "we," "our," or "us") collect, use, and disclose information through our sensor platform, cloud services, partner integrations, and this website (iviuinsights.com and iviutech.com).

Our core product — the iDTag sensor and iPS platform — operates on a privacy-by-design architecture. Sensors detect and analyze RF signal emissions (Wi-Fi probe requests) emitted by wireless devices in the environment. No user action, app installation, or account registration is required or possible.

Our fundamental commitment: iViu does not collect, store, or process any Personally Identifiable Information (PII). We do not collect names, email addresses, phone numbers, home addresses, government IDs, or financial information through our sensor platform.

If you have questions about this policy or want to exercise your privacy rights, contact us at support@iviutech.com.

Section 01

What We Collect

Signal data only — passive RF emissions from nearby wireless devices, processed immediately into anonymous analytics.

Sensor Platform — Signal Data

iDTag sensors passively receive radio-frequency (RF) signals broadcast by nearby wireless devices as part of their normal operation. These include Wi-Fi probe request frames. The following attributes may be observed and processed:

Data Element Description Stored?
Hashed Device Identifier A one-way cryptographic hash derived from the device's RF characteristics. Cannot be reversed to identify the original device or its owner. YES
Signal Strength (RSSI) Received signal strength indicator, used solely for positioning calculations. YES
Frequency / Channel RF channel on which the signal was observed. YES
Timestamp Date and time of detection, used for dwell-time and flow analytics. YES
Sensor ID / Zone Identifier of the iDTag sensor that detected the signal, mapped to a venue zone. YES
Raw MAC Address Never stored. Modern devices use randomized MAC addresses by default; iViu discards any raw hardware address immediately upon receipt. NEVER

Partner & Customer Accounts

When a business partner or enterprise customer creates an account on the iViu platform, we collect the information necessary to provide services:

  • Company name and business contact name
  • Work email address and phone number
  • Billing and payment information (processed by our PCI-compliant payment processor; card numbers are never stored on iViu servers)
  • Account credentials (passwords stored as salted cryptographic hashes)
  • Usage logs and API access records for security and billing purposes

Website Visitors

When you visit iviuinsights.com or iviutech.com, we may collect basic analytics data described in Section 7 (Website & Cookies).

Section 02

What We Never Collect

Our sensors cannot collect PII. This is an architectural guarantee, not a policy preference.

The following categories of data are architecturally impossible to collect through iDTag sensors. This is not a business decision that can change — the sensors have no capability to capture this information.

  • Names, usernames, or screen names
  • Email addresses
  • Phone numbers
  • Home or mailing addresses
  • Government-issued identification numbers (SSN, passport, driver's license)
  • Financial account numbers or payment card information
  • Biometric data (fingerprints, facial geometry, voice patterns)
  • Health or medical information
  • Demographic information (age, gender, race, ethnicity, religion)
  • Political opinions or affiliations
  • Location history outside of the venue where sensors are deployed
  • Device contents, messages, calls, browsing history, or app data
  • Social media identifiers or profiles

iViu's sensor platform detects presence and movement in a physical space. It does not know — and has no mechanism to learn — who you are.

Section 03

How We Use Data

Signal data is used exclusively to produce aggregated, anonymous intelligence for our platform customers.

Sensor Signal Data

Collected signal data is used solely to:

  • Calculate indoor positioning — determining approximate location within a venue to sub-1-meter accuracy
  • Generate foot traffic analytics — aggregated counts, dwell times, flow paths, and zone occupancy reports delivered to venue operators
  • Support SIGINT security functions — detecting anomalous or unauthorized device behavior in critical infrastructure deployments (e.g., utility substations, government facilities)
  • Improve platform accuracy — internal calibration and model training using de-identified aggregate datasets

Signal data is never used for advertising targeting, behavioral profiling of individuals, resale to data brokers, or any purpose beyond the specific service contracted by the deploying partner.

Partner Account Data

Business account information is used to:

  • Provision and maintain platform access
  • Process billing and send invoices
  • Provide technical support
  • Send service notifications (maintenance windows, security alerts)
  • Comply with legal obligations

Legal Basis (GDPR)

For persons in the European Economic Area, our legal basis for processing is:

  • Legitimate interest — for sensor signal data, which is inherently anonymous and processed to provide security and analytics services
  • Contract performance — for partner account data necessary to deliver contracted services
  • Legal obligation — where processing is required by applicable law
Section 04

Data Retention

We retain data only as long as necessary for the contracted purpose.

Data Category Retention Period Notes
Raw signal observations 90 days Used for rolling analytics windows; purged on a 90-day cycle
Aggregated analytics reports 13 months rolling Year-over-year comparisons; no individual device linkage
SIGINT event logs Per customer contract (typically 12–36 months) Retained to support security investigations
Partner account records Duration of contract + 7 years Required for financial and legal compliance
Opt-out records Indefinite Maintained to honor opt-out requests permanently
Website analytics 14 months Standard analytics retention window

Upon expiration of the applicable retention period, data is securely deleted or irreversibly anonymized. Customers may request earlier deletion subject to legal hold obligations.

Section 05

Sharing & Disclosure

We do not sell data. We share only what is necessary to operate the platform.

iViu does not sell, rent, or trade personal data or anonymized signal data to third parties for their independent commercial use.

We may share data in the following limited circumstances:

Platform Partners (Venue Operators)

Analytics reports and dashboards are delivered to the venue operator (our direct customer) who has deployed iDTag sensors on their property. These reports contain only aggregated, anonymized metrics — not individual device-level data.

Service Providers

We engage third-party service providers for infrastructure (cloud hosting, CDN), payment processing, email delivery, and support ticketing. These providers act as data processors under contract and may only process data as directed by iViu.

Legal Requirements

We may disclose data when required by law, court order, or valid government request, or when we believe disclosure is necessary to protect the safety, rights, or property of iViu, our customers, or the public. We will notify affected parties where legally permissible.

Business Transfers

In the event of a merger, acquisition, or sale of assets, data may be transferred to the acquiring entity subject to the same commitments in this policy. We will provide notice before data is subject to a materially different privacy policy.

Section 06

Opt-Out

You can opt any device out of iViu detection at any time. Opt-outs are honored permanently.

Although iViu does not collect personally identifiable information, we recognize that some individuals prefer not to have any device signals processed by our platform. We provide a straightforward opt-out mechanism.

How to Opt Out

Submit a device opt-out request through our dedicated opt-out portal:

Once submitted, your device identifier is added to a permanent exclusion list that is propagated to all deployed iDTag sensors. Signals matching the opted-out identifier are discarded without processing. Opt-out records are retained indefinitely so the exclusion persists even after the raw signal data retention window expires.

What Opt-Out Does

  • Prevents future signal observations from being included in any analytics
  • Removes any rolling signal history associated with the opted-out identifier
  • Applies globally across all iViu partner deployments

What Opt-Out Cannot Do

  • Opt-out cannot remove historical data from before the request was submitted where retention periods have not yet expired
  • Opt-out applies to iViu's platform only; devices may still be detected by third-party systems
Section 07

Website & Cookies

Basic analytics for iviuinsights.com and iviutech.com — no advertising trackers.

Analytics

Our websites use privacy-respecting analytics to understand aggregate visitor behavior (page views, referral sources, device type). Analytics data is anonymized and not linked to any individual. We do not use advertising pixels, cross-site tracking scripts, or behavioral profiling tools.

Cookies

Our websites use a small number of cookies:

  • Theme preference — stores your light/dark mode choice in browser localStorage; never transmitted to our servers
  • Session tokens — for authenticated partner portal sessions; expire when you close your browser or log out
  • Analytics — anonymized first-party analytics only; no third-party advertising cookies

You can disable cookies in your browser settings. Disabling cookies will not affect your ability to read public content on our sites; it may affect the functionality of authenticated partner areas.

Contact Forms

If you contact us through the website contact form, we collect your name, email address, company name, and the content of your message solely to respond to your inquiry. This information is not added to any marketing list without explicit consent.

Section 08

GDPR Rights

For individuals in the European Economic Area, United Kingdom, and Switzerland.

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and equivalent local law:

Art. 15

Right of Access

Request a copy of personal data we hold about you and information about how it is processed.

Art. 16

Right to Rectification

Request correction of inaccurate personal data.

Art. 17

Right to Erasure

Request deletion of personal data where there is no compelling reason for continued processing.

Art. 18

Right to Restriction

Request restriction of processing in certain circumstances.

Art. 20

Right to Portability

Receive your personal data in a structured, machine-readable format.

Art. 21

Right to Object

Object to processing based on legitimate interests, including for analytics purposes.

To exercise any of these rights, contact us at support@iviutech.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK or the relevant EEA data protection authority).

Note on sensor data: Because sensor data is processed anonymously with no link to any identifiable individual, it does not constitute personal data under GDPR. There is no data held that can be attributed to you by name, email, or other identifier. The opt-out mechanism in Section 6 provides a practical means of exclusion.

Section 09

CCPA Rights

For California residents under the California Consumer Privacy Act.

California residents have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know — request disclosure of the categories and specific pieces of personal information collected about you, the purposes for collection, and the categories of third parties with whom it has been shared
  • Right to Delete — request deletion of personal information we have collected, subject to certain exceptions
  • Right to Correct — request correction of inaccurate personal information
  • Right to Opt Out of Sale or Sharing — iViu does not sell or share personal information for cross-context behavioral advertising. No opt-out of sale is needed.
  • Right to Limit Use of Sensitive Personal Information — iViu does not collect sensitive personal information as defined by the CPRA
  • Right of Non-Discrimination — we will not discriminate against you for exercising your privacy rights

To submit a CCPA request, contact us at support@iviutech.com or call us at the number on the About page. We will verify your identity before processing requests and respond within 45 days, with a possible 45-day extension where permitted.

Do Not Sell or Share My Personal Information: iViu does not sell personal information and does not share it for cross-context behavioral advertising. If this policy changes, we will provide at least 30 days' advance notice and update this page with a "Do Not Sell or Share" link before any such activity begins.

Section 10

Children's Privacy

Our platform and websites are not directed at children under 13.

The iViu platform and websites are intended for business and enterprise use and are not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information through our website contact form or partner portal, we will delete that information promptly.

As noted throughout this policy, our sensor platform does not collect personally identifiable information from any individual — regardless of age.

If you believe a child under 13 has provided us personal information, please contact us at support@iviutech.com.

Section 11

Security

Defense-grade security practices for a platform trusted at critical infrastructure sites.

iViu implements industry-standard and beyond-standard security measures appropriate to the sensitive nature of the environments in which our platform is deployed, including government facilities, utility substations, financial institutions, and major retail and gaming properties.

  • All data in transit is encrypted using TLS 1.2 or higher
  • Data at rest is encrypted using AES-256
  • Sensor-to-cloud communications use mutual TLS with certificate pinning
  • Access to production systems is restricted by role-based access control (RBAC) with multi-factor authentication
  • Partner portal sessions use short-lived tokens; credentials are stored as salted hashes (bcrypt)
  • Penetration testing and security audits are conducted on a regular basis
  • Our incident response plan includes mandatory breach notification as required by applicable law

In the event of a security incident involving personal data, we will notify affected parties and, where required, regulatory authorities within the timeframes mandated by applicable law (72 hours under GDPR; as promptly as feasible under applicable US state law).

Section 12

Changes to This Policy

We will notify you of material changes before they take effect.

We may update this Privacy Policy from time to time. The "Revised" date at the top of this page reflects the date of the most recent changes.

For material changes — changes that expand the types of data collected, alter how data is used, or affect your rights — we will provide at least 30 days' advance notice by posting a prominent notice on our websites and, where we have your contact information, by email.

Continued use of the iViu platform or our websites after the effective date of a revised policy constitutes acceptance of the updated terms to the extent permitted by law.

Section 13

Contact

Reach our privacy team directly. We respond within 5 business days.

For privacy-related inquiries, rights requests, or concerns, please contact:

iViu Insights, Inc. — Privacy Team
Email: support@iviutech.com
Mailing Address: iViu Insights, Inc., Burr Ridge, Illinois, USA
Opt-Out Portal: optout.iviuinsights.com

For general business inquiries, visit our Company page or use the contact form on the main site.

Privacy by Design

Built to protect.
From the ground up.

Our architecture ensures privacy is not a feature we added — it's the foundation everything else is built on. No configuration required.

Request a Briefing View Architecture Opt Out a Device