Reports in PDF · DOCX · Excel · CSV
Legal

Privacy & Cookies Policy

Last updated: June 1, 2026

This Privacy and Cookies Policy (the "Policy") describes how VETT, LLC, dba CrossBeamIP ("VETT," "we," "us," or "our") processes information that identifies, relates to, describes, or could reasonably be linked with an individual or household ("Personal Information") when providing our services. This includes our operation of the websites located at https://www.crossbeamip.ai/ and https://www.crossbeamip.com/ (collectively, the "Sites," "VETT," or "CrossBeamIP"), along with the automated, AI-assisted tools, dashboards, questionnaires, shared report links, and downloadable generated reports ("Reports") made available through them (collectively, the "Services"). Any term not defined in this Policy has the meaning given in our Terms of Use. As used in this Policy, "including" means "including but not limited to."

VETT provides an automated, AI-assisted trademark search and risk-reporting platform. Our Services rely on automated artificial intelligence tools to process questionnaire inputs and generate outputs without human review.

  • This Policy applies to Personal Information collected through the Services.
  • By accessing or using the Services, you accept and consent to the practices described in this Policy.

Reports. As disclosed in our Terms of Use (Section 9) and Subscription Services Agreement (Section 8.6), VETT does not access, retain, store, archive, or maintain any consumer dashboard or any Reports generated therein. Reports are generated dynamically and delivered solely to the Customer's personal dashboard. VETT cannot retrieve, restore, or fulfill any access or portability request for Reports because it does not retain them after generation. The Personal Information rights described in this Policy — including California rights under Section 13 — apply only to Personal Information VETT actually holds, and do not extend to Reports or questionnaire inputs that have been automatically and permanently deleted pursuant to the retention rules in Section 11.

1. Personal Information We Collect and How We Use It

We collect the following categories of Personal Information and use them for the purposes described below.

1.1. Information You Provide Directly

Account Registration and Dashboard Data. When you create an account, we collect identifiers and account information, such as your name, email address, and account credentials, to authenticate you and provide access to the Services.

Questionnaire and Search Data. To run a brand search and generate a Report, we collect the information you enter into the search questionnaire, such as proposed trademark names or phrases, international trademark classes, keywords, and any logo image, stylized mark, or composite mark you choose to upload. We use this information solely to execute your search and generate your Report. The questionnaire is designed to accept trademark-related inputs only, and you must not enter the name, address, contact details, or other Personal Information of third-party clients or any other identifiable individual into questionnaire fields or other input fields. See Section 11 for the automated retention and deletion schedule that applies to questionnaire inputs and Reports.

Payment Information. When you make a purchase, payment is processed through a secure third-party payment processor. We do not collect or store full payment card numbers or full financial credentials. We receive limited transaction-related information necessary to manage your subscription and account access, such as subscription status, plan type, billing status, and the last four digits of a payment card.

Communications. If you contact us, we collect the contact information and any message content you choose to provide to respond to your inquiry, provide support, and maintain business records.

2. Public and Commercial Sources

To generate your Report, the platform automatically retrieves publicly available or commercially available information from official intellectual property and business registries and similar sources, including the USPTO, the WIPO Madrid System, SEC EDGAR, OpenCorporates, and web search results. Publicly available government-record information is not treated as Personal Information where excluded by applicable law. This source data is used to generate your requested Report and is not linked to other users for unrelated purposes.

3. Automatically Collected Information

We collect limited technical information necessary to operate and secure the Services, including IP address, browser type, device or session identifiers, authentication events, and access logs for shared report links. We do not use third-party behavioral analytics, advertising trackers, retargeting scripts, or cross-site marketing cookies. We do not track your activity across unrelated websites. We also use Personal Information to monitor security, prevent fraud and abuse, and apply the security safeguards described in Section 10 (Data Security and Storage).

4. AI Usage and No Model Training

We use third-party AI APIs to perform limited, transactional analysis tasks within a search, such as suggesting trademark classes, interpreting logo design codes, identifying foreign-language equivalents, and summarizing results. We do not use your questionnaire inputs, uploaded logos, or search results to train, fine-tune, or improve our own models, and we contractually require our AI providers not to use that data for model training. Each AI-assisted call within the Services processes your inputs on a one-time, transactional basis only.

5. Categories of Sources

In the preceding 12 months, we have collected Personal Information from the following categories of sources: (a) directly from you, (b) automatically from your device or browser, (c) from payment and communications vendors, and (d) from public or commercial data sources used to generate Reports.

6. How We Disclose Personal Information

We do not sell or share Personal Information for cross-context behavioral advertising, and we have not sold or shared Personal Information in the preceding 12 months. We disclose Personal Information only as reasonably necessary to operate and deliver the Services, including to the following categories of recipients:

  • Cloud hosting, database, and storage providers
  • AI service providers that perform limited transactional analysis
  • Search and registry access providers
  • Payment processors
  • Email and transactional communications providers
  • Professional advisors, auditors, and service providers supporting security, compliance, and operations
  • Government authorities, courts, regulators, or other parties when required by law or necessary to protect rights, safety, or security

In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, Personal Information may be transferred as part of that transaction.

7. Business and Commercial Purposes

We collect, use, and disclose Personal Information for the following business and commercial purposes: providing the Services; authenticating users; generating Reports; processing payments; responding to inquiries; sending transactional, billing, and administrative communications; maintaining records; preventing fraud and abuse; monitoring security; debugging, repairing, and improving service functionality; enforcing contractual terms; and complying with legal obligations.

8. Marketing

We may send promotional emails about VETT, CrossBeamIP, the Services, or product updates. You may opt out of promotional emails at any time using the unsubscribe link in the message or by contacting us. Opting out will not affect transactional or administrative messages, such as account, billing, or security notices.

We maintain professional social media profiles, such as LinkedIn. The privacy policies of the relevant platforms govern interactions with those profiles. We do not deploy social media tracking pixels or retargeting scripts on the Sites.

9. Cookies and Similar Technologies

We use only strictly necessary cookies and similar technologies required to authenticate users, maintain sessions, process account status, and support secure payment-related workflows. We do not use analytics, advertising, targeting, or tracking cookies or pixels. You can block cookies through your browser settings, but doing so may prevent you from logging in and using the Services.

10. Data Security and Storage

We use reasonable administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, and destruction. These measures include using cloud infrastructure providers that support encryption in transit and at rest. No method of internet transmission or electronic storage is completely secure, and absolute security cannot be guaranteed.

Account Access. Access to your account requires both a password and a time-limited code sent to your phone (multi-factor authentication). After a period of inactivity, you are automatically signed out. We provide backup codes you can use if you lose access to your phone. If our systems detect a configuration problem, they are designed to deny access by default rather than allow it.

Access to Reports. Only account members can see Reports associated with the account. Before we display a Report, our system checks that it belongs to your account, and our database enforces that rule independently as an additional safeguard. As noted throughout this Policy and our Terms of Use and Subscription Agreement, VETT does not retain copies of Reports and cannot access any Report independently of the account holder.

Sharing Reports. When you choose to share a Report, we generate a long, hard-to-guess link (URL). You may choose to protect a shared Report with a password. We store that password in an encrypted or hashed form, not in plain text or in a notification email. You may set a date for a shared link to expire and may turn off a link at any time, including after someone has already accessed it. We limit repeated password-guessing attempts. Shared files are delivered through a private channel.

Payments. Your payment information is entered directly on Stripe, a trusted third-party payment processor. We never have access to your payment details, either to view or store them.

Encryption and Data Handling. We use encryption to protect your data in transit (when it travels between your browser and our servers) and at rest (while it is stored on our systems). Encryption makes raw files unreadable to unauthorized parties. Encrypted data is readable only by parties who have the appropriate keys. Reports are stored in areas that are walled off from, and not indexed by, public search engines. We apply web security safeguards, including treating all user-supplied input as plain text rather than as executable commands. We verify that uploaded files are legitimate images of an appropriate size.

Internal Safeguards. We store sensitive credentials, such as passwords and encryption keys, in a secure vault and not in application code. Automated background tasks (for example, processes that remove expired links) use their own credentials and permissions. For critical security functions, such as password hashing, we rely on widely used, industry-standard components rather than custom-built cryptography.

Storage. The Services are intended for users in the United States, and Personal Information is processed and stored in the U.S. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law.

11. Retention

We retain Personal Information only for as long as reasonably necessary for the purposes described in this Policy, as disclosed at or before collection, or as required by law. Retention periods may vary by category of information.

Reports and Search Materials — Strict Automated Retention Rules.

For Reports and related search materials, the platform applies the following automated retention rules, which are non-negotiable features of the platform architecture:

  • Time limit: Each Report, including questionnaire inputs, uploaded logo files, and search results, is automatically and permanently deleted ten (10) days after the Report is run, regardless of whether it has been downloaded.
  • Volume limit: Each account retains a maximum of twenty-five (25) of the most recent Reports. Running a new search above that limit automatically and permanently deletes the oldest Report, even if it is less than ten (10) days old.
  • Recovery: Deleted Reports cannot be recovered. VETT does not retain any copy of deleted Reports and cannot fulfill access, portability, or retrieval requests for Reports that have been deleted, or that were never stored by VETT in the first place.
  • Customer responsibility: You are solely responsible for downloading and saving Reports before deletion occurs. See our Terms of Use (Section 9) and Subscription Agreement (Section 8.6) for your full download obligations.

Account, Billing, and Compliance Data. We may retain limited account, billing, legal-compliance, fraud-prevention, and security-log information for longer where reasonably necessary to comply with law, resolve disputes, enforce agreements, and protect the Services.

12. Your Rights

Subject to applicable law and verification, you may request access to, correction of, or deletion of Personal Information associated with your account. You may also update certain account information directly through your dashboard.

Important limitation: Because the system automatically and irreversibly deletes search data after the retention periods described in Section 11, rights of access, correction, or deletion do not extend to questionnaire inputs, uploaded logos, and Reports that have already been permanently purged. Additionally, because VETT does not retain or possess Reports after generation, VETT cannot fulfill any access or portability request for Reports, regardless of whether they have been deleted.

13. California Privacy Rights

This Section applies only to California residents and supplements the rest of this Policy.

Categories of Personal Information Collected. In the preceding 12 months, depending on how you use the Services, we have collected the following categories of Personal Information:

  • Identifiers, such as name, email address, IP address, online identifiers, and account credentials
  • Customer records or similar account information, such as billing contact details and subscription information
  • Commercial information, such as plan type, purchase history, subscription status, and transaction metadata
  • Internet or other electronic network activity information, such as browser type, session data, log data, and authentication events
  • User-provided content, such as questionnaire responses, uploaded logo files, and support communications
  • Professional or business-related information, to the extent included in account or billing details

We do not knowingly collect or use sensitive personal information for purposes other than those permitted by California law, such as providing the Services, processing payments, detecting security incidents, preventing fraud, and maintaining service quality.

13.1. Categories of Sources. We collect Personal Information from the following categories of sources: directly from you; automatically from your device or browser; from vendors that support billing and communications; and from public or commercial sources used to generate Reports.

13.2. Purposes. We collect and use Personal Information for the business and commercial purposes described in Section 7.

13.3. Disclosure for Business Purposes. In the preceding 12 months, we have disclosed the categories of Personal Information listed above to service providers and contractors that provide hosting, storage, analytics-free operational infrastructure, AI processing, payment processing, communications, security, and compliance support. We do not sell Personal Information, and we do not share Personal Information for cross-context behavioral advertising.

13.4. California Rights. California residents may have the following rights, subject to applicable exceptions:

  • The right to know the categories and specific pieces of Personal Information collected about them
  • The right to know the categories of sources, purposes of collection, and categories of recipients
  • The right to request deletion of Personal Information collected from them
  • The right to request correction of inaccurate Personal Information
  • The right to opt out of sale or sharing of Personal Information, though VETT does not sell or share Personal Information as defined under California law
  • The right to limit the use and disclosure of sensitive personal information, though VETT does not use sensitive personal information beyond permitted purposes
  • The right not to receive discriminatory treatment for exercising privacy rights

Important limitation on Reports. California privacy rights — including the right to access, portability, correction, and deletion — apply only to Personal Information VETT actually holds. Because VETT does not retain or possess Reports or questionnaire inputs at any time after generation (and such data is subject to automatic permanent deletion within ten (10) days), these rights do not and cannot extend to Reports or search inputs already deleted, or to Reports VETT never stored. This is not a denial of rights — it is a factual statement about what VETT possesses.

13.5. Exercising Rights; Verification; Authorized Agents. To exercise privacy rights, contact us at customer-service@crossbeamip.com. We may need to verify your identity before fulfilling a request, such as by matching the request to your account information or by requiring confirmation from the email address associated with your account. We may request limited additional information solely for verification purposes.

You may designate an authorized agent to submit a request on your behalf. We may require proof of the agent's authority and may also require you to verify your identity directly with us.

13.6. Appeal / Additional Information. If we deny a request, we may explain the basis for the denial to the extent required by law. Certain information may be retained where necessary to comply with legal obligations, complete transactions, detect security incidents, protect against fraudulent or illegal activity, or exercise or defend legal claims.

14. Children's Privacy

The Services are intended for professional, business-to-business use and are not directed to minors. We do not knowingly collect Personal Information from individuals under 18. We do not knowingly sell or share the Personal Information of consumers under 16.

15. Third-Party Sites and Sources

The Services may reference or link to third-party websites, registries, and platforms. Those third parties operate under their own terms and privacy policies, and VETT is not responsible for their independent privacy practices.

16. Changes to This Policy

We may update this Policy from time to time. The latest version will be posted on the Sites and reflected by the Effective Date above. If changes are material, notice may be provided by email or by prominent notice on the Sites. Your continued use of the Services after the effective date of any updated Policy constitutes your acceptance of the changes.

17. Contact Us

If you have questions about this Policy or wish to exercise privacy rights, contact:

Email: customer-service@crossbeamip.com

VETT, LLC dba CrossBeamIP, 309 Pine Avenue, Suite 236, Long Beach, CA 90802

VETT, LLC dba CrossBeamIP, is a California limited liability company and a woman-owned technology company. Nothing in this Policy establishes an attorney-client relationship between VETT, LLC, and any user of the Services.