Privacy Policy

Threshold PEO Consulting LLC — RAMPD Platform

Effective date: July 13, 2026

Last updated: August 4, 2026

1. Who this policy covers and who we are

This Privacy Policy explains how Threshold PEO Consulting LLC, a Missouri limited liability company (“Threshold,” “we,” “us”) collects, uses, and protects information in connection with the RAMPD sales acceleration platform (the “Service”).

RAMPD is a business-to-business platform used by our customers — sales organizations — and their authorized users (“Reps,” “Managers,” “Owners”). This policy distinguishes between two categories of people:

Our customers and their users — the people who log into RAMPD and use it.

Prospect contacts — individuals whose business contact information our customers load into, or generate within, RAMPD as part of their own sales activity. These individuals do not have RAMPD accounts and typically do not interact with us directly.

For prospect-contact data, we act as a service provider processing information on our customers’ instructions. Our customers determine what prospect data enters the Service and are responsible for having a lawful basis to process it.

The Service is currently offered to customers in the United States only.

2. Information we collect

2.1 Information from customer users (account holders)

When an Owner, Manager, or Rep uses RAMPD, we collect and store:

Identity and account data: full name, email address, assigned role, and organization membership.

Authentication data: credentials are managed by our authentication provider. Passwords are stored only in industry-standard hashed form; we do not store or have access to plaintext passwords.

2.2 Prospect-contact information (loaded or generated by customers)

Our customers use RAMPD to manage their sales pipelines. In doing so, they store business-context information about prospect individuals and companies, which may include: name, job title, business email address, business phone number, professional social profile links, company name and location, and free-text notes entered by the customer’s Reps.

Some of this information is enriched through a third-party data provider (see Section 4) — meaning additional publicly or commercially available business information about a company or contact may be appended.

We process this information on behalf of and at the direction of our customers. We do not independently determine the purposes for which it is used, and we do not sell personal information.

2.3 Email content processed on behalf of customers

Where a customer connects an email account (see Section 4, Google/Microsoft), RAMPD sends outreach messages on the Rep’s behalf and stores a record of what was sent — including subject line, message body, recipient, and send metadata — so the customer has an accurate activity history.

2.4 Engagement and telemetry data

RAMPD is designed to support tracked links in a customer’s outreach. When this capability is enabled and a recipient interacts with such a link, we record limited event data — the fact of the interaction, a timestamp, and coarse device/browser information — to report engagement back to the customer as a sales signal. We do not retain the recipient’s IP address beyond what is transiently necessary for abuse prevention and security. As of the effective date of this policy, this tracked-link capability is not yet active in the production Service.

2.5 Technical and security data

Like most online services, our infrastructure providers automatically process limited technical data (such as request logs) necessary to operate, secure, and troubleshoot the Service.

3. How we use information

We use information to:

Provide, operate, maintain, and secure the Service.

Authenticate users and enforce access controls between customer organizations.

Send outreach and record sales activity at our customers’ direction.

Provide engagement reporting and sales-signal features to the customer that owns the data.

Detect, prevent, and respond to fraud, abuse, and security incidents.

Comply with legal obligations.

De-identified and aggregated data

We may create and use de-identified and/or aggregated information derived from use of the Service to operate, improve, and develop the Service and its methodology and intelligence features. De-identified and aggregated data does not identify any individual or any individual customer and is not re-identified by us.

4. Third parties and subprocessors

We share information only with service providers who process it on our behalf to deliver the Service, under contractual confidentiality and security obligations. Our current subprocessors and their roles:

Supabase — database, authentication, and storage hosting. Touches all stored platform data.

Vercel — application hosting and edge/serverless functions. Touches request handling.

Google (Gmail API) — sending email on a connected Rep’s behalf. Touches email content and connected-account access.

Microsoft (Outlook/Graph) — sending email on a connected Rep’s behalf. Touches email content and connected-account access.

SearchAPI.io — business-data enrichment. Touches company and contact enrichment queries.

Porkbun — domain registration and DNS management. Domain resolution only; no customer data.

4.1 Google and Microsoft connected accounts

When a Rep connects a Google or Microsoft email account, RAMPD accesses only the scopes necessary to send email on their behalf and stores access credentials in encrypted form.

Specifically, RAMPD receives the connected account's email address and the ability to send email from that account (Google scopes: gmail.send and userinfo.email). RAMPD does not request or receive access to read a connected inbox, contacts, calendar, files, or any other Google account data.

RAMPD’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

5. How we protect information

We maintain administrative, technical, and organizational safeguards designed to protect information, including:

Access controls designed to separate each customer organization’s data, enforced at the database level.

Encryption of sensitive credentials (such as connected-email tokens) at rest.

Encryption of data in transit.

Access limited to authorized personnel and processes.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

6. Data retention

We retain information for as long as necessary to provide the Service to our customers, and thereafter as required for legitimate business or legal purposes. Customers control much of the lifecycle of the data they load into the Service. Records deleted within the Service may be retained in deletion-history and backup systems for a period before permanent removal, and certain activity records (such as sales outreach history) are retained for the life of the customer relationship to preserve an accurate account of customer-directed activity.

7. Your choices and rights

Because most prospect-contact data is controlled by our customers, individuals who wish to access, correct, or delete their information should contact the relevant RAMPD customer (the organization that holds their information). We will assist our customers in responding to such requests as required by law.

Account users may update their profile information or request account changes, and any individual may direct privacy questions or requests to us, at privacy@thresholdpeo.com.

8. Children’s privacy

The Service is a business tool not directed to children and is not intended for anyone under 18. We do not knowingly collect information from children.

9. Changes to this policy

We may update this policy from time to time. Material changes will be indicated by updating the “Last updated” date and, where appropriate, providing additional notice.

10. Contact us

Threshold PEO Consulting LLC

c/o Republic Registered Agent INC.

8301 State Line Rd., Ste 220

Kansas City, MO 64114

privacy@thresholdpeo.com