Privacy Policy
Steeple Systems, Inc.
Effective: July 15, 2026
Last updated: July 15, 2026
Steeple Systems, Inc. ("Steeple," "we," "us") builds marketing software for destination marketing organizations. This policy explains what we collect, why, and what you can do about it. It covers steeple.systems and the Steeple application.
If you are a customer under a signed services agreement, that agreement controls where it conflicts with this policy.
1. Who we are
Steeple Systems, Inc.
A Delaware corporation
Contact: chad@steeple.systems
For privacy questions, data requests, or anything in this policy, email chad@steeple.systems. A person reads that address.
2. What we collect
Information you give us.
- Name, email address, and organization when you book a demo, create an account, or contact us.
- Your destination's website URL and related public information when you request an evaluation.
- Billing and contact details when you become a customer.
- Anything you send us directly.
Information from your organization's connected accounts.
If you connect third-party services to Steeple, we access data from those services on your behalf and only for the purposes you authorize:
- Google Search Console, Google Analytics 4, and YouTube Analytics (via Google OAuth): search performance, site traffic, and video performance data for properties you control.
- Meta platforms: page and content performance data for accounts you connect.
We access this data to produce your marketing work and reporting. We do not use it to train general-purpose models, and we do not sell it. You can disconnect any integration at any time, which revokes our access going forward.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Information about the destination.
Steeple maintains a knowledge base about your destination: attractions, events, brand voice, partner relationships, published content, and the decisions your team makes as it reviews and approves work. Some of this is drawn from public sources. Some comes from you.
Information collected automatically.
- Log data: IP address, browser type, pages viewed, timestamps.
- Error and performance data, so we can find and fix problems.
- Cookies and similar technologies (see Section 7).
What we don't collect.
We do not knowingly collect information from anyone under 16. We do not collect sensitive personal information as defined under applicable law, and we ask you not to send it to us.
3. Why we process it
We process personal information to:
- Provide the service and produce your work.
- Communicate with you about your account, the service, and things we think you should know.
- Bill you and keep financial records.
- Secure the service and investigate misuse.
- Improve the service.
- Comply with law.
Where GDPR applies, our legal bases are: performance of a contract (providing the service), legitimate interests (security, improvement, communicating with business contacts), consent (marketing email, non-essential cookies), and legal obligation (records, tax).
4. How we use AI
Steeple uses large language models to produce drafts, analysis, and recommendations. Some of that processing happens through Anthropic's API.
Two commitments:
Your data is not used to train third-party models. We use Anthropic's API under commercial terms that do not permit training on our inputs or outputs.
Nothing publishes without a human. Steeple does not publish content on your behalf without an authorized person at your organization approving it. This is enforced in the product, not by policy alone.
5. Who we share it with
We do not sell personal information. We share it in four situations:
Service providers. Companies that run parts of our infrastructure, bound by contract to handle data only on our instructions. As of the effective date:
| Provider | Purpose |
|---|---|
| Vercel | Application hosting |
| Neon | Database |
| Clerk | Authentication |
| Anthropic | Model inference |
| Cloudflare | Storage and network |
| Resend | Transactional email |
| Stripe | Payments |
| Sentry | Error monitoring |
| Loops | Marketing email |
| Calendly | Demo scheduling |
| Google Workspace | Business email and documents |
This list changes as our infrastructure changes. Email us for the current version.
Your organization. If you use Steeple through your employer, your organization's administrators can see your account and the work you do in it.
Legal. When required by law, subpoena, or valid government request, or to protect rights and safety. If we receive a request for your data and we are legally permitted to tell you, we will.
Business transfer. If Steeple is acquired or merges, information may transfer. Any acquirer remains bound by this policy or gives you notice before changing it.
6. Your data, and getting it back
You own your destination's content. Content, facts, and approved work in your Steeple knowledge base belong to your organization, not to us.
You can take it with you. At any time, and at the end of a subscription for any reason, we will provide an export of your organization's content in a usable format. We do not hold your content hostage to renewal.
Public records. Many of our customers are public or quasi-public bodies subject to open-records laws. Nothing in our arrangement prevents you from meeting those obligations, and we will help you respond to a records request against material held in Steeple.
7. Cookies
We use cookies and similar technologies to keep you signed in, remember preferences, and understand how the site is used. Essential cookies are required for the service to function. Non-essential cookies are used only with your consent where consent is required.
You can control cookies through your browser. Blocking essential cookies will break parts of the service.
Embedded third-party tools on our site, including our scheduling widget, may set their own cookies under their own policies.
8. Your rights
Everyone. You can ask us to access, correct, or delete your personal information, and you can unsubscribe from marketing email using the link in any marketing message. Transactional messages about your account are not marketing.
GDPR (European Economic Area, UK, Switzerland). You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. You may lodge a complaint with your national supervisory authority. Where we transfer personal data outside the EEA, we rely on Standard Contractual Clauses or another lawful transfer mechanism. Customers subject to GDPR may request a Data Processing Addendum.
California. You have the right to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined under the CCPA. We will not discriminate against you for exercising your rights.
To exercise any right, email chad@steeple.systems. We will verify your identity before acting and respond within the time the law requires.
9. Security
We use encryption in transit and at rest, access controls, authentication through a dedicated identity provider, and monitoring. OAuth tokens for connected accounts are stored encrypted and used only for the purposes you authorized.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any required authority as the law requires and without undue delay.
10. Retention
We keep personal information as long as your account is active and as long afterward as we need it for legal, tax, accounting, and dispute-resolution purposes. Prospect and marketing contact information is kept until you ask us to remove it or until it goes stale.
When we no longer need information, we delete it or de-identify it.
11. International
Steeple is operated from the United States. If you use the service from outside the United States, your information will be transferred to and processed in the United States, where privacy laws differ from those in your country. Where required, we use appropriate safeguards for those transfers.
12. Changes
We will update this policy as the service changes. If we make a material change, we will notify account holders by email or in the product before it takes effect. The "last updated" date at the top always reflects the current version.
13. Contact
Steeple Systems, Inc.
chad@steeple.systems
Questions, requests, and complaints all go to the same address.