NicklOne legal
Privacy policy.
How NicklOne collects, uses, discloses, retains, and protects Personal Information through our website, platform, account registration, sales, support, and customer-authorized integrations.
·1. Scope and our role
This Privacy Policy explains how NicklOne collects, uses, discloses, retains, and protects Personal Information through the NicklOne website, software platform, account-registration process, sales process, support services, and customer-authorized integrations (collectively, the "Services"). NicklOne is operated by Pyro Mart, Inc. d/b/a NicklOne ("NicklOne," "we," "us," or "our"). This Privacy Policy is a notice of our information practices and is not intended to serve as consent where applicable law requires separate consent.
NicklOne may act in different roles. We act as a business or controller when we collect information directly from website visitors, prospects, trial users, business contacts, and account administrators. We generally act as a service provider or processor when a business customer uses NicklOne to process information about its customers, vendors, employees, contractors, or other contacts ("Customer Data"). In that case, the customer controls the Customer Data and is responsible for its own privacy notices, lawful basis, and instructions. NicklOne processes identifiable Customer Data only to provide, configure, secure, maintain, and support the Services, comply with documented customer instructions, and perform other activities permitted by the applicable customer agreement. We may use aggregated or de-identified information to improve and develop the Services as described below.
If you are a customer, vendor, employee, contractor, or consumer of one of our business customers, please contact that customer first regarding Personal Information it controls. This Privacy Policy does not replace a customer's own privacy notice. It applies to a customer-branded website or mobile application only if that service expressly links to this Privacy Policy and identifies NicklOne as the responsible business or controller.
When an authorized user creates a NicklOne account, the user may be asked to acknowledge receipt of this Privacy Policy. Separate consent will be requested where required for a particular processing activity.
2. Information we collect
Depending on how you interact with us, we may collect the following categories of Personal Information:
- Contact and account information, such as name, business email address, telephone number, company, job title, username, password stored in protected form, authentication and session information, and account-administration details.
- Sales, trial, and support information, such as products sold, business model, locations, current systems, workflow needs, communications, support requests, feedback, and documents or files voluntarily provided to us.
- Customer operational data, such as product catalogs, SKUs, pricing, suppliers, purchase orders, inventory, fulfillment records, sales orders, customer and vendor records, returns, invoices, payment status, shipment information, service history, and related business records. Depending on the modules a customer enables, Customer Data may also include workforce and performance information such as employee identity, role, goals, sales activity, performance measurements, manager notes, commissions, bonuses, and calculated compensation.
- Integration data received from connected services that a customer authorizes, including data received through APIs, OAuth permissions, access and refresh tokens, webhooks, secure file transfers, imports, exports, or other approved connection methods. We may store integration credentials or tokens needed to maintain an authorized connection.
- Technical and usage information, such as IP address, browser and device information, device or push-notification identifiers where applicable, pages or features used, referral source, timestamps, diagnostics, log data, and security events.
- Feature-specific information, where enabled, such as user instructions and content submitted to AI-enabled features, files or images intentionally uploaded to support or product features, and location information voluntarily provided for an address or location-based workflow.
- Communications information, such as emails, support tickets, chat messages, call notes, survey responses, and, where we provide the notice required by law, call recordings or transcripts.
We obtain this information directly from you or the customer you represent; automatically through use of the website or Services; or from a connected service at a customer's direction. Users may create and manage account credentials through designated secure account interfaces, and customer administrators may provide integration credentials through designated configuration interfaces. We do not ask users to send passwords, authentication codes, integration secrets, or full payment-card numbers through marketing, sales, or support forms or ordinary email.
3. Connected services and integrations
A customer may connect NicklOne with third-party systems, including accounting and ERP platforms, ecommerce stores, marketplaces, warehouse and fulfillment systems, CRM tools, carriers, payment providers, point-of-sale systems, data feeds, file-storage services, and other business applications. A connection may use customer-authorized OAuth, API tokens, secure credentials, webhooks, file transfers, or imports.
NicklOne processes the data the customer authorizes and that is reasonably necessary and proportionate for the enabled workflow. Depending on the connection, this may include account, contact, product, supplier, inventory, order, shipment, invoice, payment-status, transaction, pricing, or configuration data. The applicable authorization flow, integration settings, or documentation will describe, or provide a means to review, the access requested.
Customers may request that NicklOne disconnect an integration at any time. Customer administrators may also revoke NicklOne access through the connected provider where available. Connected third parties operate under their own terms and privacy notices; NicklOne is not responsible for their independent practices, availability, or security.
4. How we use information
We use Personal Information to:
- Provide, configure, maintain, secure, and support NicklOne;
- Create and administer customer accounts and authorized user access;
- Enable customer-authorized integrations, imports, exports, and workflows;
- Respond to trial requests, sales inquiries, support requests, and other communications;
- Diagnose issues, prevent fraud, detect misuse, and protect the integrity of our services;
- Improve and develop NicklOne using aggregated or de-identified information, and maintain the quality and reliability of customer-authorized features;
- Send service-related, security, account, billing, and, where permitted, marketing communications; and
- Meet legal obligations, enforce agreements, and protect rights, safety, property, and systems.
Where applicable law requires a legal basis, we process Personal Information to perform a contract, take steps requested before entering a contract, comply with law, pursue legitimate interests such as operating, securing, and improving the Services where those interests do not override individual rights, or with consent. Where we rely on consent, it may be withdrawn as permitted by law.
5. AI and automated features
NicklOne may offer AI-enabled or automated features that summarize information, identify patterns, suggest workflows, forecast operational needs, or assist users in navigating the platform. When a customer enables such a feature, relevant Customer Data and user instructions may be processed by NicklOne and approved AI service providers solely to provide, secure, evaluate, and support that feature, subject to the applicable customer agreement and provider safeguards. Outputs are advisory and may be incomplete or inaccurate. They are not legal, tax, accounting, medical, safety, or other professional advice.
Customers remain responsible for reviewing and approving decisions or actions affecting inventory, pricing, orders, invoices, payments, workforce matters, customer service, or other material business operations. NicklOne does not use identifiable Customer Data to train generalized or cross-customer AI models without the customer's prior written authorization. Customer-specific configuration, retrieval, evaluation, or processing performed to provide an enabled feature is not generalized model training. Information about applicable AI subprocessors and material retention settings is available on request or in the applicable service documentation.
6. How we disclose information
We may disclose Personal Information to service providers and subprocessors that help us host, store, secure, monitor, operate, support, communicate about, or improve NicklOne; provide customer-authorized AI features; deliver communications; or manage business relationships; to a customer's authorized users and customer-authorized connected services; to professional advisers, auditors, insurers, or business partners where the disclosure is reasonably necessary and subject to appropriate confidentiality or data-protection obligations; to authorities or other parties when required by law or necessary to protect rights, safety, or security; and to an actual or prospective buyer, successor, investor, lender, or affiliate in connection with a merger, financing, acquisition, restructuring, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell Personal Information or share it for cross-context behavioral advertising. We do not disclose Customer Data to third parties for their independent marketing purposes.
7. Service providers and subprocessors
The following providers support the NicklOne website and commercial operations as of the Effective Date. NicklOne also uses service providers and subprocessors for platform hosting, data storage and backup, security and monitoring, email and support, and customer-authorized AI or other product features where applicable. This schedule does not list customer-selected connected services, which vary by customer and workflow.
| Service provider | Purpose |
|---|---|
| Cloudflare | Website and application hosting, security, performance, and website form-record storage. |
| AgentMail | Operational delivery of website request notifications to the NicklOne team. |
| Google Analytics | Consent-based website traffic measurement and lead-attribution reporting. Trial-request field values are not sent to Analytics. |
| Pipedrive | Sales and business-relationship management for prospective and current customers. |
We may replace or add service providers as our business changes. An updated subprocessor list is available by request to support@nicklone.com. Where required by contract, we will provide customers notice of material subprocessor changes.
Customer-selected connected services operate under the customer's direction and their own terms and privacy notices. NicklOne-selected providers that process Personal Information on our behalf are subject to contractual privacy, confidentiality, and security obligations appropriate to the services they provide.
8. Sensitive and restricted data
NicklOne processes account passwords in protected form, authentication and session information, and customer-authorized integration credentials as necessary to operate the Services. Unless we expressly agree otherwise in a written customer agreement or feature-specific notice, NicklOne is not designed for storing or processing full payment-card information, Social Security numbers, passport or driver's-license numbers, protected health information, genetic or biometric information, or other highly sensitive information. A customer remains responsible for determining whether its intended use is appropriate for its industry, data, and legal obligations and for preventing users from submitting restricted information through free-form fields or uploads.
Where a customer uses an approved payment provider, NicklOne may receive limited billing, token, payment-status, or transaction metadata; it does not intentionally collect or store full payment-card numbers. If a NicklOne feature requests device location, the feature will provide contextual notice and request device permission where required; location will be used for the disclosed feature, such as selecting a delivery or service address.
10. Retention and security
We retain each category of Personal Information only for as long as reasonably necessary and proportionate to the purposes described in this Policy. The period depends on factors including the duration of the customer or business relationship, account and integration status, applicable contractual commitments, backup and disaster-recovery cycles, security and fraud-prevention needs, legal or accounting requirements, and applicable limitation periods. Customer Data retention, deletion, and export rights are governed by the applicable customer agreement. When deletion is required, information may remain in restricted backups until overwritten under the applicable backup schedule, unless earlier deletion is legally required or technically feasible. We may retain aggregated or de-identified information where permitted by law and will not attempt to reidentify it except to test or validate the de-identification process as permitted by law.
Current category-specific retention criteria and periods are documented in NicklOne's internal retention schedule and, where required, in an applicable notice at collection or customer agreement.
We maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, loss, alteration, misuse, or disclosure. No system can guarantee absolute security. If we determine that a security incident requires notice under applicable law or contract, we will investigate and provide notice as required.
11. Privacy rights and choices
Depending on your location, the applicable law, and our role in processing your Personal Information, you may have rights to request access, correction, deletion, a portable copy, restriction of or objection to certain processing, withdrawal of consent where consent applies, and opt-out of marketing communications. These rights may be subject to exceptions and verification requirements.
California residents may have rights to know, correct, and delete Personal Information, to receive information about our collection and disclosure practices, and to opt out of the sale or sharing of Personal Information where applicable. NicklOne does not sell Personal Information or share it for cross-context behavioral advertising as those terms are defined by California law. We will not discriminate or retaliate against an individual for exercising applicable privacy rights. If applicable law provides a right to appeal and we deny a privacy request, you may appeal by replying to our response with the subject line "Privacy Appeal."
To make a request, email support@nicklone.com with the subject line "Privacy Request." Include your name, organization, email address, relationship to NicklOne or a NicklOne customer, and request. You may use an authorized agent where applicable law permits. We may request information reasonably necessary to verify identity or authority and will not require creation of a new account solely to submit a request. If we process the information for a customer, we may refer the request to that customer and assist the customer as required by our agreement and applicable law.
12. International transfers
NicklOne operates from the United States. Personal Information may be processed in the United States and other locations where NicklOne or its service providers operate. Where required by law, we will use an appropriate transfer mechanism or contractual safeguard and provide information about how to obtain a copy of the applicable safeguards. For customers that require a data processing addendum, the applicable customer agreement or addendum will control.
13. Children's privacy
NicklOne's website and business-administration platform are intended for business users and are not directed to children under 13. We do not knowingly collect Personal Information directly from children under 13. If we learn that we collected such information in circumstances governed by children's privacy law, we will take appropriate steps to delete it. A business customer that uses NicklOne in connection with a consumer-facing service remains responsible for age eligibility, parental notice or consent, and other children's privacy obligations applicable to that service unless a written agreement expressly provides otherwise.
14. Changes to this policy
We may update this Privacy Policy as our business, services, integrations, or legal obligations change. We will post the updated policy and revise the Effective Date. Where required, we will provide additional notice of material changes.
15. Contact
For privacy questions, data requests, or integration-disconnection requests, contact:
Pyro Mart, Inc. d/b/a NicklOne99 East Dedham Street, Suite 320
Boston, MA 02118, United States
Email: support@nicklone.com
Sales: sales@nicklone.com