Privacy Policy
Last updated: February 2026
0. Quick Summary
Not a Substitute for the Full Policy
intake.link provides intake forms, document signing, file upload, and payment collection tools used primarily by law firms and organizations ("Tenants"). When individuals submit data through a Tenant's workflows ("End Clients"), intake.link generally processes that data on behalf of the Tenant.
This Privacy Policy explains:
- what data we collect
- how we use and share data
- how cookies and advertising/analytics work
- how long we retain data
- your rights depending on where you live
1. Introduction
This Privacy Policy describes how intake.link (the "Service") collects, uses, stores, shares, and protects information when you access or use the Service.
The Service is operated by Concert Capital Management, LLC, a Nevada limited liability company ("Company," "intake.link," "we," "us," or "our").
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, you must not use the Service.
This Privacy Policy should be read together with our Terms of Service, which governs your use of the Service.
2. Interpretation and Definitions
2.1 Interpretation
Words with initial capitalization have meanings defined below. Definitions apply whether the term appears in singular or plural.
2.2 Definitions
For purposes of this Privacy Policy:
- Account means a unique account created for a Tenant to access the Service.
- Advertising ID means a resettable identifier associated with a mobile device, such as Apple's IDFA or Google Advertising ID.
- Business (under CCPA/CPRA) means the entity that determines the purposes and means of processing Personal Information.
- Company means Concert Capital Management, LLC, a Nevada limited liability company.
- Consumer (under CCPA/CPRA) means a natural person who is a California resident.
- Controller (or Data Controller) means the entity that determines the purposes and means of processing Personal Data (as defined by GDPR/UK GDPR and similar laws).
- Cookies means small files stored on your device that enable certain website features and tracking functionality.
- Data Subject Request (or DSAR) means a request to exercise privacy rights (e.g., access, deletion, correction).
- End Client means any individual who submits information through a Tenant's intake forms, signs documents, uploads files, or makes payments via the Service.
- Personal Data means information relating to an identified or identifiable natural person (terminology commonly used in the GDPR/UK GDPR).
- Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.
- Processor (or Data Processor) means an entity that processes Personal Data on behalf of a Controller.
- Sale (under CCPA/CPRA) generally means selling or disclosing Personal Information for monetary or other valuable consideration (as defined under applicable law).
- Service means the intake.link websites, applications, dashboards, APIs, and related services.
- Service Provider (under CCPA/CPRA) means an entity that processes Personal Information on behalf of a Business pursuant to a written contract.
- Share (under CCPA/CPRA) means disclosure of Personal Information for cross-context behavioral advertising, whether or not for monetary consideration (as defined under applicable law).
- Subprocessor means a third party engaged by the Company to process Personal Information on our behalf to provide the Service.
- Tenant means any individual, law firm, or organization that registers for and uses the Service.
- Tenant Data means all data uploaded, submitted, collected, generated, or otherwise processed through the Service by or on behalf of a Tenant, including End Client submissions.
- Usage Data means data collected automatically, either generated by the use of the Service or from the Service infrastructure (e.g., page views, feature usage, performance metrics).
3. Scope of This Privacy Policy
This Privacy Policy applies to information collected:
- through intake.link websites and product dashboards
- through Tenant accounts and subscription workflows
- through End Client interactions with Tenant intake forms, signing flows, file uploads, and payment flows
- through our APIs, documentation, and support interactions
4. Data Roles (Controller vs Processor)
4.1 Tenant Data: We Act as a Processor / Service Provider
When Tenants use intake.link to collect information from End Clients, intake.link generally acts as a Processor (GDPR/UK GDPR terminology) or Service Provider (CCPA/CPRA terminology) with respect to Tenant Data.
In this context:
- the Tenant is the Controller/Business and determines what data is collected and why
- the Company processes that Tenant Data only to provide the Service and as instructed/configured by the Tenant
4.2 Tenant Account Data: We Act as a Controller / Business
With respect to:
- Tenant account information
- subscription/billing data
- and certain Usage Data generated to operate and secure the Service
the Company acts as a Controller/Business.
4.3 End Client Requests
If you are an End Client and you want to exercise privacy rights (e.g., access, deletion, correction), you should contact the Tenant directly. Tenants are responsible for responding as Controller/Business.
We will assist Tenants with requests when required by law and contract.
5. Information We Collect
5.1 Tenant Account Information
When you create or administer an Account, we may collect:
- name
- email address
- organization/firm name
- phone number (optional)
- billing address
- payment metadata and subscription status
- authentication data via Clerk (identity provider)
5.2 Tenant Configuration Data
We collect and store account configuration data such as:
- firm branding (name, logo, colors)
- intake form configurations and field definitions
- document templates and signing workflows
- payment presets and pricing settings
- webhook URLs and automation settings
- notification preferences
5.3 End Client Data (Tenant Data)
When End Clients interact with Tenant workflows, the Service may collect Tenant Data including:
- form submissions (including any data fields defined by Tenant)
- e-signature data (signature image, timestamp, IP address, audit trail)
- payment metadata (transaction confirmation, amount, partial payment details)
- uploaded files/documents (stored in Vercel Blob)
- device information and IP addresses
5.4 Automatically Collected Information (Usage Data)
We may automatically collect:
- IP address (hashed for privacy in logs where feasible)
- browser type/version
- operating system
- device identifiers
- pages visited and features used
- timestamps and session duration
- referrer URL
- diagnostic/performance data
5.5 Payment Processing Data (Stripe Connect)
Payments are processed through Stripe Connect. The Company operates as the Stripe Connect platform account holder. If Tenants enable payments, a Stripe Custom connected account may be created for that Tenant. Stripe processes payment card data directly; we do not store full credit card numbers; we receive limited payment metadata (e.g., confirmation, amount, last four digits, and transaction identifiers).
5.6 Electronic Signature Data (DocuSeal)
Electronic signatures are processed through DocuSeal, which may collect:
- signature image
- signing timestamps
- IP address
- audit certificate and completion details
We may store completed document references and audit trail metadata.
6. Cookies, Pixels, and Tracking Technologies
6.1 What We Use
We use:
- cookies
- local storage
- pixels/SDKs (where applicable)
- log files and similar technologies
6.2 Types of Cookies
We may use:
- Strictly Necessary Cookies (authentication, security, session management)
- Functional Cookies (preferences/settings)
- Analytics Cookies (usage analytics and performance improvements)
- Advertising Cookies / Pixels (marketing measurement, remarketing, attribution)
6.3 Cookie Controls
You can control cookies through your browser settings. Some features may not function properly if cookies are disabled.
Where required by law, we will use consent mechanisms for certain cookies and provide choices through a cookie banner or preference center.
6.4 Do Not Track
"Do Not Track" (DNT) is a browser setting. We do not currently respond to DNT signals.
7. How We Use Information
We use information we collect to:
- provide, operate, maintain, and improve the Service
- authenticate users and manage Accounts
- process Tenant workflows and deliver Tenant Data to Tenants
- facilitate electronic signature workflows and completed document access
- facilitate payment processing and payment status updates
- send transactional notifications (email/SMS)
- provide customer support and communicate with users
- monitor usage for billing and internal analytics
- secure, debug, and prevent fraud, abuse, and prohibited activity
- enforce our Terms of Service and other policies
- comply with legal obligations and respond to lawful requests
- develop aggregated, anonymized, and/or de-identified analytics and benchmarks
8. Legal Bases for Processing (GDPR/UK GDPR)
Where the GDPR/UK GDPR applies, we process Personal Data under one or more legal bases, including:
- Contractual necessity (to provide the Service and perform our agreement)
- Legitimate interests (security, fraud prevention, product improvement)
- Consent (where required, such as certain cookies or marketing)
- Legal obligations (tax, accounting, compliance, law enforcement requests)
9. Sharing and Disclosure
We do not sell Personal Information. We may share information as follows:
9.1 Subprocessors / Service Providers
We share data with service providers who help us deliver the Service (see Section 16).
We contractually require subprocessors to protect data and restrict use of data to authorized purposes.
9.2 Tenant-Configured Integrations
Tenants may configure integrations and destinations, including:
- webhooks to Tenant endpoints
- Make.com or Zapier workflows
- CRMs and practice management systems
- analytics or internal systems
Information is shared per the Tenant's configuration and instructions.
9.3 Payment Processing
We share data with Stripe for payment processing. Stripe's use of data is governed by Stripe's privacy policy.
9.4 Advertising, Remarketing, and Attribution
We may use advertising/analytics partners to:
- attribute marketing campaigns
- measure performance
- run remarketing campaigns to people who have visited intake.link
- improve marketing effectiveness
Depending on implementation, these parties may set cookies/pixels and receive identifiers (e.g., IP address, cookie IDs, Advertising IDs).
You can opt out using tools provided in Section 12.
9.5 Legal Requirements
We may disclose information when required by law or when we believe disclosure is necessary to:
- comply with legal process
- respond to lawful government requests
- protect rights, property, safety, and security
- investigate fraud or security incidents
- enforce Terms of Service
9.6 Business Transfers
Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
9.7 Aggregated / De-Identified Data
We may use and disclose aggregated or de-identified data for analytics, benchmarks, research, and reporting.
10. Security
10.1 Infrastructure
The Service uses the following infrastructure:
- Hosting: Vercel (United States)
- Database: Upstash Redis (encrypted at rest and in transit)
- File storage: Vercel Blob (encrypted)
- Authentication: Clerk
- Payments: Stripe (PCI-DSS compliant)
- E-signatures: DocuSeal
- Automations: Make.com (where configured by Tenant)
10.2 Safeguards
We use commercially reasonable safeguards such as:
- TLS/SSL for data in transit
- encryption at rest where supported
- access controls and least-privilege policies
- audit logging for sensitive operations
- monitoring and security review procedures
No method of transmission/storage is 100% secure. You use the Service at your own risk.
10.3 Breach Response
If we become aware of a security incident affecting Personal Information, we will notify impacted Tenants without undue delay consistent with applicable law and contractual obligations.
Tenants are responsible for notifying End Clients where legally required.
11. HIPAA / PHI
THE SERVICE IS NOT HIPAA COMPLIANT.
We do not execute Business Associate Agreements (BAAs). Tenants must not use the Service to collect, store, or transmit Protected Health Information (PHI) that requires HIPAA compliance.
12. Marketing, Ads, and Opt-Out Choices
12.1 Email Marketing
You may opt out of marketing emails by using the unsubscribe link or contacting us at inbox@intake.link.
12.2 Cookies / Targeted Advertising
You may be able to opt out of interest-based advertising via:
- Network Advertising Initiative (NAI): opt-out tools
- Digital Advertising Alliance (DAA): opt-out tools
- Your browser cookie settings
12.3 Mobile Advertising IDs
You may limit ad tracking by disabling advertising personalization:
- iOS: Settings → Privacy & Security → Tracking
- Android: Settings → Privacy → Ads
12.4 Global Privacy Control (GPC)
Where required by law, we will treat GPC signals as an opt-out of sale/sharing. We do not sell Personal Information.
13. Retention
We retain data as follows:
- Tenant account data: retained until account deletion, plus 30 days for recovery
- form session data: per Tenant configuration (default: 90 days completed, 30 days incomplete)
- electronic signature records: 7 years
- payment transaction records: 7 years
- audit logs: 1 year
- server logs: 90 days
We may retain information longer if necessary for legal compliance, dispute resolution, fraud/security investigations, or enforcement of agreements. Tenants may request data export or deletion by contacting inbox@intake.link.
14. CCPA/CPRA Disclosures (California)
14.1 Categories of Personal Information Collected
The table below describes categories we may collect.
| Category (CCPA) | Examples | Sources | Purpose |
|---|---|---|---|
| Identifiers | name, email, IP address, device IDs | Tenant, End Client, device | service delivery, security, support |
| Customer Records | billing address, account data | Tenant | billing, account administration |
| Commercial Info | transactions, subscription plan | Tenant/Stripe metadata | billing, fraud prevention |
| Internet Activity | page visits, clicks, features used | device/service logs | analytics, security |
| Geolocation Data | approximate location from IP | device logs | security, fraud prevention |
| Sensitive PI (limited) | login credentials | Tenant | authentication/security |
14.2 Categories Disclosed for Business Purposes
We may disclose Personal Information to:
- subprocessors/service providers
- payment processors (Stripe)
- infrastructure providers (Vercel, Upstash, Clerk)
- e-signature processor (DocuSeal)
- automation providers (Make.com) as configured
14.3 Sale / Sharing
We do not sell Personal Information.
If we engage advertising measurement/remarketing technologies, those may constitute "sharing" under CPRA depending on implementation. Where applicable, you may opt out using controls described above.
14.4 California Rights
California residents may have rights to:
- know/access
- delete
- correct
- opt out of sale/sharing
- limit use of sensitive PI (where applicable)
- non-discrimination
Submit requests via inbox@intake.link.
15. Other U.S. State Privacy Rights
Residents of certain U.S. states (including Colorado, Virginia, Connecticut, Utah, and others) may have rights to:
- access
- deletion
- correction
- data portability
- opt out of targeted advertising (where applicable)
- opt out of profiling in furtherance of decisions with legal/similar significant effects (where applicable)
To exercise these rights, contact inbox@intake.link.
16. Subprocessors
We use the following subprocessors:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosting, CDN, file storage (Vercel Blob) | United States |
| Upstash | Database (Redis) | United States |
| Clerk | Authentication | United States |
| Stripe | Payment processing (Stripe Connect) | United States |
| DocuSeal | Electronic signatures and audit trails | United States |
| Make.com | Automation/webhook workflows (as configured by Tenant) | EU / United States |
We may update subprocessors as needed. Enterprise customers may request notification of changes.
17. International Data Transfers
The Service is hosted in the United States. If you access the Service outside the U.S., your information may be transferred to and processed in the U.S. and other jurisdictions.
Where required by applicable law, we use safeguards such as:
- contractual protections (including Standard Contractual Clauses where applicable)
- vendor contractual commitments
- other legally recognized transfer mechanisms
18. Children's Privacy
The Service is not directed to children under 13 years of age (or 16 in certain jurisdictions). We do not knowingly collect Personal Information from children.
If you believe a child has provided information, contact inbox@intake.link.
19. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for third-party privacy practices.
20. Changes to This Policy
We may update this Privacy Policy periodically. We will post the updated version and revise the "Last updated" date.
For material changes, we may provide additional notice (such as email notification to Tenants). Continued use of the Service constitutes acceptance.
21. Governing Law
This Privacy Policy is governed by the laws of the State of Nevada, without regard to conflicts of law principles, and subject to dispute resolution provisions in our Terms of Service.
22. Contact Us
For privacy questions or to exercise privacy rights:
Concert Capital Management, LLC
Email: inbox@intake.link
We generally respond within 30 days (or sooner where required by law).