Privacy Policy

Last updated: August 29, 2026

This policy explains how Taproot Solutions, Inc. ("Taproot," "we," "us") collects, uses, shares, and protects personal information. It applies to taproot.ing and to the outbound communication services we provide to our business partners.

Questions: privacy@taproot.ing.

1. Information we collect

Information about business contacts

We process contact and business information about individuals in the course of providing outbound communication services:

  • Names
  • Phone numbers
  • Email addresses
  • Job titles and employer information
  • Contact preferences, including consent and opt-out records
  • Qualification criteria and related information used to assess relevance
  • Records of communications with us, including call recordings where applicable

Information collected automatically

When you visit taproot.ing, we and our service providers automatically collect technical information including IP address, browser type and settings, device characteristics, operating system, referring URLs, pages viewed, and approximate location derived from IP address. This is collected through server logs and analytics tools.

Sensitive information

We do not collect or process sensitive personal information as defined under applicable privacy laws, including racial or ethnic origin, religious beliefs, health information, biometric identifiers, precise geolocation, or government identification numbers.

2. Where we get your information

We collect personal information from three sources:

  • Directly from you, when you contact us or interact with our website.
  • From lead generation partners, who provide contact information for individuals who have given prior express written consent to be contacted by Taproot Solutions, including by SMS and telephone.
  • Automatically, through server logs and analytics when you visit our website.

3. How we use your information

  • To deliver and facilitate the communication services we provide to our business partners
  • To contact individuals who have consented to receive communications from us
  • To assess whether a contact is relevant to a partner's requirements
  • To respond to inquiries and provide support
  • To send administrative information, including changes to our terms and policies
  • To maintain the security and operation of our systems
  • To comply with legal obligations, including maintaining records of consent

4. Legal bases (EEA and UK)

Where the EU or UK GDPR applies, we rely on the following legal bases:

  • Consent — for sending marketing communications, where consent has been obtained.
  • Performance of a contract — for delivering services to our business partners.
  • Legitimate interests — for operating and securing our systems and improving our services, where those interests are not overridden by your rights.
  • Legal obligations — for retaining consent records and responding to lawful requests.

5. When and with whom we share information

We disclose personal information to the following categories of third parties:

  • Cloud computing services
  • Communication and collaboration tools
  • Data analytics services
  • Data storage service providers
  • Website hosting service providers
  • Sales and marketing tools
  • AI platforms
  • Business partners, for the purpose of delivering the services they have engaged us to provide

Each service provider is bound by a written contract limiting their use of personal information to the purposes we specify.

We may also disclose personal information in connection with a merger, acquisition, financing, or sale of assets, and where required to comply with law or to establish, exercise, or defend legal claims.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

6. SMS and mobile communications

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We send SMS messages only to individuals who have provided prior express written consent. Consent is obtained through our lead generation partners at the point of data capture, where recipients affirmatively agree to receive text messages from Taproot Solutions.

Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe or HELP for assistance. Opting out of SMS does not affect any other communications you may have consented to receive.

7. Cookies and tracking technologies

We use cookies and similar technologies on taproot.ing for essential site functions, security, and analytics. We do not use advertising cookies, retargeting pixels, or social media tracking, and we do not permit third parties to use tracking technologies on our site for advertising purposes.

Most browsers accept cookies by default. You can set your browser to reject or remove cookies, which may affect some site functions.

8. International transfers

We are a United States company with operations in Israel. Personal information we process may be stored and accessed in the United States and Israel, and by service providers in those countries.

Where personal information is transferred out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses, which are incorporated into our agreements with service providers. Copies can be provided on request. Israel is the subject of an adequacy decision by the European Commission.

9. How long we keep information

  • Consent and opt-in records — at least five years, to comply with telecommunications regulations and to evidence consent.
  • Contact and qualification data — for as long as necessary to fulfill the purposes described in this policy.
  • Call recordings — for as long as necessary for the purposes described, and at least five years where the recording evidences consent.
  • Server logs and analytics data — approximately one year.

When we no longer have a legitimate need to process personal information, we delete or anonymize it, or securely isolate it from further processing where deletion is not immediately possible.

10. Security

We maintain appropriate technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and loss. No system can be guaranteed completely secure, and we cannot warrant that our safeguards will never be defeated.

11. Your privacy rights

United States

Depending on your state of residence, you may have the right to:

  • Know whether we process your personal data, and access it
  • Correct inaccuracies
  • Request deletion
  • Obtain a copy of data you provided to us
  • Opt out of targeted advertising, sale of personal data, or profiling with legal or similarly significant effects
  • Not be discriminated against for exercising these rights

These rights currently apply to residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and to residents of other states as their laws take effect.

EEA, UK, Switzerland, and Canada

You may have the right to access, correct, or erase your personal information, to restrict or object to processing, to data portability, and to withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

If you are in the EEA or UK and believe we are processing your information unlawfully, you may complain to your national data protection authority. In the UK this is the Information Commissioner's Office. In Switzerland, the Federal Data Protection and Information Commissioner.

California "Shine the Light"

California residents may request, once a year and free of charge, information about personal information we disclosed to third parties for their direct marketing purposes in the preceding calendar year. Send requests to privacy@taproot.ing.

Exercising your rights

Email privacy@taproot.ing or write to us at the address below. We will verify your identity before acting on a request, and will respond within the period required by applicable law. You may use an authorized agent, who must provide proof of authorization.

If we decline a request, you may appeal by emailing privacy@taproot.ing. We will respond in writing with our reasons. If your appeal is denied, you may complain to your state attorney general.

12. Do Not Track

There is no uniform standard for recognizing or honoring Do Not Track browser signals, and we do not currently respond to them. We will update this policy if a standard is adopted that applies to us.

13. Children

Our services are directed at businesses and are not intended for anyone under 18. We do not knowingly collect information from children. If you believe we hold information about a child, contact privacy@taproot.ing and we will delete it.

14. Changes to this policy

We may update this policy from time to time. The date at the top reflects the most recent version. Material changes will be posted prominently on this page.

15. Contact us

Privacy questions and requests: privacy@taproot.ing

Aviv Ben-Sira is responsible for privacy matters at Taproot Solutions.

Taproot Solutions, Inc.
131 Continental Drive, Suite 305
Newark, DE 19702
United States