Privacy Policy

Last updated: February 2026

0. Quick Summary

Not a Substitute for the Full Policy

intake.link provides intake forms, document signing, file upload, and payment collection tools used primarily by law firms and organizations ("Tenants"). When individuals submit data through a Tenant's workflows ("End Clients"), intake.link generally processes that data on behalf of the Tenant.

This Privacy Policy explains:

  • what data we collect
  • how we use and share data
  • how cookies and advertising/analytics work
  • how long we retain data
  • your rights depending on where you live

1. Introduction

This Privacy Policy describes how intake.link (the "Service") collects, uses, stores, shares, and protects information when you access or use the Service.

The Service is operated by Concert Capital Management, LLC, a Nevada limited liability company ("Company," "intake.link," "we," "us," or "our").

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, you must not use the Service.

This Privacy Policy should be read together with our Terms of Service, which governs your use of the Service.

2. Interpretation and Definitions

2.1 Interpretation

Words with initial capitalization have meanings defined below. Definitions apply whether the term appears in singular or plural.

2.2 Definitions

For purposes of this Privacy Policy:

  • Account means a unique account created for a Tenant to access the Service.
  • Advertising ID means a resettable identifier associated with a mobile device, such as Apple's IDFA or Google Advertising ID.
  • Business (under CCPA/CPRA) means the entity that determines the purposes and means of processing Personal Information.
  • Company means Concert Capital Management, LLC, a Nevada limited liability company.
  • Consumer (under CCPA/CPRA) means a natural person who is a California resident.
  • Controller (or Data Controller) means the entity that determines the purposes and means of processing Personal Data (as defined by GDPR/UK GDPR and similar laws).
  • Cookies means small files stored on your device that enable certain website features and tracking functionality.
  • Data Subject Request (or DSAR) means a request to exercise privacy rights (e.g., access, deletion, correction).
  • End Client means any individual who submits information through a Tenant's intake forms, signs documents, uploads files, or makes payments via the Service.
  • Personal Data means information relating to an identified or identifiable natural person (terminology commonly used in the GDPR/UK GDPR).
  • Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.
  • Processor (or Data Processor) means an entity that processes Personal Data on behalf of a Controller.
  • Sale (under CCPA/CPRA) generally means selling or disclosing Personal Information for monetary or other valuable consideration (as defined under applicable law).
  • Service means the intake.link websites, applications, dashboards, APIs, and related services.
  • Service Provider (under CCPA/CPRA) means an entity that processes Personal Information on behalf of a Business pursuant to a written contract.
  • Share (under CCPA/CPRA) means disclosure of Personal Information for cross-context behavioral advertising, whether or not for monetary consideration (as defined under applicable law).
  • Subprocessor means a third party engaged by the Company to process Personal Information on our behalf to provide the Service.
  • Tenant means any individual, law firm, or organization that registers for and uses the Service.
  • Tenant Data means all data uploaded, submitted, collected, generated, or otherwise processed through the Service by or on behalf of a Tenant, including End Client submissions.
  • Usage Data means data collected automatically, either generated by the use of the Service or from the Service infrastructure (e.g., page views, feature usage, performance metrics).

3. Scope of This Privacy Policy

This Privacy Policy applies to information collected:

  • through intake.link websites and product dashboards
  • through Tenant accounts and subscription workflows
  • through End Client interactions with Tenant intake forms, signing flows, file uploads, and payment flows
  • through our APIs, documentation, and support interactions

4. Data Roles (Controller vs Processor)

4.1 Tenant Data: We Act as a Processor / Service Provider

When Tenants use intake.link to collect information from End Clients, intake.link generally acts as a Processor (GDPR/UK GDPR terminology) or Service Provider (CCPA/CPRA terminology) with respect to Tenant Data.

In this context:

  • the Tenant is the Controller/Business and determines what data is collected and why
  • the Company processes that Tenant Data only to provide the Service and as instructed/configured by the Tenant

4.2 Tenant Account Data: We Act as a Controller / Business

With respect to:

  • Tenant account information
  • subscription/billing data
  • and certain Usage Data generated to operate and secure the Service

the Company acts as a Controller/Business.

4.3 End Client Requests

If you are an End Client and you want to exercise privacy rights (e.g., access, deletion, correction), you should contact the Tenant directly. Tenants are responsible for responding as Controller/Business.

We will assist Tenants with requests when required by law and contract.

5. Information We Collect

5.1 Tenant Account Information

When you create or administer an Account, we may collect:

  • name
  • email address
  • organization/firm name
  • phone number (optional)
  • billing address
  • payment metadata and subscription status
  • authentication data via Clerk (identity provider)

5.2 Tenant Configuration Data

We collect and store account configuration data such as:

  • firm branding (name, logo, colors)
  • intake form configurations and field definitions
  • document templates and signing workflows
  • payment presets and pricing settings
  • webhook URLs and automation settings
  • notification preferences

5.3 End Client Data (Tenant Data)

When End Clients interact with Tenant workflows, the Service may collect Tenant Data including:

  • form submissions (including any data fields defined by Tenant)
  • e-signature data (signature image, timestamp, IP address, audit trail)
  • payment metadata (transaction confirmation, amount, partial payment details)
  • uploaded files/documents (stored in Vercel Blob)
  • device information and IP addresses

5.4 Automatically Collected Information (Usage Data)

We may automatically collect:

  • IP address (hashed for privacy in logs where feasible)
  • browser type/version
  • operating system
  • device identifiers
  • pages visited and features used
  • timestamps and session duration
  • referrer URL
  • diagnostic/performance data

5.5 Payment Processing Data (Stripe Connect)

Payments are processed through Stripe Connect. The Company operates as the Stripe Connect platform account holder. If Tenants enable payments, a Stripe Custom connected account may be created for that Tenant. Stripe processes payment card data directly; we do not store full credit card numbers; we receive limited payment metadata (e.g., confirmation, amount, last four digits, and transaction identifiers).

5.6 Electronic Signature Data (DocuSeal)

Electronic signatures are processed through DocuSeal, which may collect:

  • signature image
  • signing timestamps
  • IP address
  • audit certificate and completion details

We may store completed document references and audit trail metadata.

6. Cookies, Pixels, and Tracking Technologies

6.1 What We Use

We use:

  • cookies
  • local storage
  • pixels/SDKs (where applicable)
  • log files and similar technologies

6.2 Types of Cookies

We may use:

  • Strictly Necessary Cookies (authentication, security, session management)
  • Functional Cookies (preferences/settings)
  • Analytics Cookies (usage analytics and performance improvements)
  • Advertising Cookies / Pixels (marketing measurement, remarketing, attribution)

6.3 Cookie Controls

You can control cookies through your browser settings. Some features may not function properly if cookies are disabled.

Where required by law, we will use consent mechanisms for certain cookies and provide choices through a cookie banner or preference center.

6.4 Do Not Track

"Do Not Track" (DNT) is a browser setting. We do not currently respond to DNT signals.

7. How We Use Information

We use information we collect to:

  • provide, operate, maintain, and improve the Service
  • authenticate users and manage Accounts
  • process Tenant workflows and deliver Tenant Data to Tenants
  • facilitate electronic signature workflows and completed document access
  • facilitate payment processing and payment status updates
  • send transactional notifications (email/SMS)
  • provide customer support and communicate with users
  • monitor usage for billing and internal analytics
  • secure, debug, and prevent fraud, abuse, and prohibited activity
  • enforce our Terms of Service and other policies
  • comply with legal obligations and respond to lawful requests
  • develop aggregated, anonymized, and/or de-identified analytics and benchmarks

8. Legal Bases for Processing (GDPR/UK GDPR)

Where the GDPR/UK GDPR applies, we process Personal Data under one or more legal bases, including:

  • Contractual necessity (to provide the Service and perform our agreement)
  • Legitimate interests (security, fraud prevention, product improvement)
  • Consent (where required, such as certain cookies or marketing)
  • Legal obligations (tax, accounting, compliance, law enforcement requests)

9. Sharing and Disclosure

We do not sell Personal Information. We may share information as follows:

9.1 Subprocessors / Service Providers

We share data with service providers who help us deliver the Service (see Section 16).

We contractually require subprocessors to protect data and restrict use of data to authorized purposes.

9.2 Tenant-Configured Integrations

Tenants may configure integrations and destinations, including:

  • webhooks to Tenant endpoints
  • Make.com or Zapier workflows
  • CRMs and practice management systems
  • analytics or internal systems

Information is shared per the Tenant's configuration and instructions.

9.3 Payment Processing

We share data with Stripe for payment processing. Stripe's use of data is governed by Stripe's privacy policy.

9.4 Advertising, Remarketing, and Attribution

We may use advertising/analytics partners to:

  • attribute marketing campaigns
  • measure performance
  • run remarketing campaigns to people who have visited intake.link
  • improve marketing effectiveness

Depending on implementation, these parties may set cookies/pixels and receive identifiers (e.g., IP address, cookie IDs, Advertising IDs).

You can opt out using tools provided in Section 12.

9.5 Legal Requirements

We may disclose information when required by law or when we believe disclosure is necessary to:

  • comply with legal process
  • respond to lawful government requests
  • protect rights, property, safety, and security
  • investigate fraud or security incidents
  • enforce Terms of Service

9.6 Business Transfers

Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.

9.7 Aggregated / De-Identified Data

We may use and disclose aggregated or de-identified data for analytics, benchmarks, research, and reporting.

10. Security

10.1 Infrastructure

The Service uses the following infrastructure:

  • Hosting: Vercel (United States)
  • Database: Upstash Redis (encrypted at rest and in transit)
  • File storage: Vercel Blob (encrypted)
  • Authentication: Clerk
  • Payments: Stripe (PCI-DSS compliant)
  • E-signatures: DocuSeal
  • Automations: Make.com (where configured by Tenant)

10.2 Safeguards

We use commercially reasonable safeguards such as:

  • TLS/SSL for data in transit
  • encryption at rest where supported
  • access controls and least-privilege policies
  • audit logging for sensitive operations
  • monitoring and security review procedures

No method of transmission/storage is 100% secure. You use the Service at your own risk.

10.3 Breach Response

If we become aware of a security incident affecting Personal Information, we will notify impacted Tenants without undue delay consistent with applicable law and contractual obligations.

Tenants are responsible for notifying End Clients where legally required.

11. HIPAA / PHI

THE SERVICE IS NOT HIPAA COMPLIANT.

We do not execute Business Associate Agreements (BAAs). Tenants must not use the Service to collect, store, or transmit Protected Health Information (PHI) that requires HIPAA compliance.

12. Marketing, Ads, and Opt-Out Choices

12.1 Email Marketing

You may opt out of marketing emails by using the unsubscribe link or contacting us at inbox@intake.link.

12.2 Cookies / Targeted Advertising

You may be able to opt out of interest-based advertising via:

  • Network Advertising Initiative (NAI): opt-out tools
  • Digital Advertising Alliance (DAA): opt-out tools
  • Your browser cookie settings

12.3 Mobile Advertising IDs

You may limit ad tracking by disabling advertising personalization:

  • iOS: Settings → Privacy & Security → Tracking
  • Android: Settings → Privacy → Ads

12.4 Global Privacy Control (GPC)

Where required by law, we will treat GPC signals as an opt-out of sale/sharing. We do not sell Personal Information.

13. Retention

We retain data as follows:

  • Tenant account data: retained until account deletion, plus 30 days for recovery
  • form session data: per Tenant configuration (default: 90 days completed, 30 days incomplete)
  • electronic signature records: 7 years
  • payment transaction records: 7 years
  • audit logs: 1 year
  • server logs: 90 days

We may retain information longer if necessary for legal compliance, dispute resolution, fraud/security investigations, or enforcement of agreements. Tenants may request data export or deletion by contacting inbox@intake.link.

14. CCPA/CPRA Disclosures (California)

14.1 Categories of Personal Information Collected

The table below describes categories we may collect.

Category (CCPA)ExamplesSourcesPurpose
Identifiersname, email, IP address, device IDsTenant, End Client, deviceservice delivery, security, support
Customer Recordsbilling address, account dataTenantbilling, account administration
Commercial Infotransactions, subscription planTenant/Stripe metadatabilling, fraud prevention
Internet Activitypage visits, clicks, features useddevice/service logsanalytics, security
Geolocation Dataapproximate location from IPdevice logssecurity, fraud prevention
Sensitive PI (limited)login credentialsTenantauthentication/security

14.2 Categories Disclosed for Business Purposes

We may disclose Personal Information to:

  • subprocessors/service providers
  • payment processors (Stripe)
  • infrastructure providers (Vercel, Upstash, Clerk)
  • e-signature processor (DocuSeal)
  • automation providers (Make.com) as configured

14.3 Sale / Sharing

We do not sell Personal Information.

If we engage advertising measurement/remarketing technologies, those may constitute "sharing" under CPRA depending on implementation. Where applicable, you may opt out using controls described above.

14.4 California Rights

California residents may have rights to:

  • know/access
  • delete
  • correct
  • opt out of sale/sharing
  • limit use of sensitive PI (where applicable)
  • non-discrimination

Submit requests via inbox@intake.link.

15. Other U.S. State Privacy Rights

Residents of certain U.S. states (including Colorado, Virginia, Connecticut, Utah, and others) may have rights to:

  • access
  • deletion
  • correction
  • data portability
  • opt out of targeted advertising (where applicable)
  • opt out of profiling in furtherance of decisions with legal/similar significant effects (where applicable)

To exercise these rights, contact inbox@intake.link.

16. Subprocessors

We use the following subprocessors:

ProviderPurposeLocation
VercelHosting, CDN, file storage (Vercel Blob)United States
UpstashDatabase (Redis)United States
ClerkAuthenticationUnited States
StripePayment processing (Stripe Connect)United States
DocuSealElectronic signatures and audit trailsUnited States
Make.comAutomation/webhook workflows (as configured by Tenant)EU / United States

We may update subprocessors as needed. Enterprise customers may request notification of changes.

17. International Data Transfers

The Service is hosted in the United States. If you access the Service outside the U.S., your information may be transferred to and processed in the U.S. and other jurisdictions.

Where required by applicable law, we use safeguards such as:

  • contractual protections (including Standard Contractual Clauses where applicable)
  • vendor contractual commitments
  • other legally recognized transfer mechanisms

18. Children's Privacy

The Service is not directed to children under 13 years of age (or 16 in certain jurisdictions). We do not knowingly collect Personal Information from children.

If you believe a child has provided information, contact inbox@intake.link.

19. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for third-party privacy practices.

20. Changes to This Policy

We may update this Privacy Policy periodically. We will post the updated version and revise the "Last updated" date.

For material changes, we may provide additional notice (such as email notification to Tenants). Continued use of the Service constitutes acceptance.

21. Governing Law

This Privacy Policy is governed by the laws of the State of Nevada, without regard to conflicts of law principles, and subject to dispute resolution provisions in our Terms of Service.

22. Contact Us

For privacy questions or to exercise privacy rights:

Concert Capital Management, LLC
Email: inbox@intake.link

We generally respond within 30 days (or sooner where required by law).