Privacy Policy
We collect what we need to send you weather alerts, and nothing more. Your name, email, mobile number, and the locations you want monitored — that's it.
We don't sell your information. We don't share it with marketers, data brokers, or anyone outside the people and services that directly help us deliver alerts to you.
We delete your data within 10 days of cancellation. No regulated data (medical, financial, or government identifiers) is collected or stored.
This Privacy Policy describes how Gower Heritage Holdings, LLC ("GHH," "we," "us," or "our") collects, uses, retains, and protects information in connection with AI-EWS-WX, the AI Early Warning System for Weather. By subscribing to or using the Service, you agree to the practices described in this Policy.
1. Information We Collect
We collect only the information necessary to deliver weather alerts to you and operate the Service.
From subscribers directly
- First and last name
- For account identification and message personalization.
- Email address
- For account access, email alerts, and service communications.
- Mobile phone number
- For SMS alert delivery (only if you opt in).
- Organization (optional)
- For reference and customer support context.
- Monitored location addresses
- Physical addresses or coordinates of locations you want weather alerts for. Used solely to determine which alerts apply to you.
- Subscription preferences
- Which types of alerts you want, time windows, and channel choices (email, SMS).
- Consent records
- Timestamps, IP address at consent, browser type, and explicit opt-in confirmations. Used to maintain compliance with TCPA and other regulations.
Automatically collected
When you visit our website or use the subscriber portal, we may automatically collect:
- IP address and approximate geographic region
- Browser type and operating system
- Pages visited and timestamps
- Referring URL (if you arrived from another site)
This information is used for security monitoring, abuse prevention, and basic analytics to improve the Service. We do not use this information for advertising or sell it to third parties.
What we do NOT collect
- No regulated data: We do not collect medical, health, financial account, government identification (Social Security numbers, driver's license numbers), or biometric information.
- No precise location tracking: The Service uses the locations you explicitly add to your account, not your device's real-time location.
- No payment data on our servers: Payments (when applicable) are processed by third-party providers; we do not store credit card numbers or banking information.
2. How We Use Information
We use collected information for the following purposes:
- Service delivery: Sending weather alerts and forecast briefings to your chosen contact methods.
- Account management: Authentication, preference changes, customer support.
- Compliance: Maintaining records of your opt-in consent for TCPA, CAN-SPAM, and other legal requirements.
- Service operations: Monitoring system health, preventing abuse, troubleshooting technical issues.
- Improvement: Analyzing aggregate usage patterns to improve alert accuracy, delivery reliability, and user experience.
We do not use your information for advertising, profiling, or any purpose unrelated to delivering and improving the Service.
3. How We Share Information
We share information only with service providers who help us operate AI-EWS-WX, and only the minimum necessary to fulfill their function.
Service providers
- SMS delivery (Twilio)
- Mobile phone number, message content, delivery status.
- Email delivery (Zoho Mail)
- Email address, message content, delivery status.
- Hosting infrastructure (Cloudflare, EPIX cluster)
- All subscriber data, encrypted in transit and at rest.
- Form processing (Formspree)
- Initial subscription form submissions during temporary onboarding period; will be replaced by direct integration.
These service providers are bound by their own privacy policies and data processing agreements. We require them to use your information only as needed to provide their services to us.
What we do NOT do
- We do not sell your personal information to anyone, ever.
- We do not share your information with marketers, data brokers, or advertising networks.
- We do not allow third parties to use your information for their own marketing purposes.
Legal requirements
We may disclose information if required by law, court order, or government request, or to protect our rights, your safety, or the safety of others. If permitted by law, we will notify you before disclosure.
4. Data Retention
We retain your personal information only as long as necessary to provide the Service.
- Active subscribers: We retain your account information for as long as you maintain an active subscription.
- After cancellation: Within 10 days of cancellation, your personal information (name, email, phone, location addresses) is purged from active systems.
- Compliance records: Opt-in consent records and message delivery logs may be retained for up to 4 years to satisfy TCPA, CAN-SPAM, and other legal record-keeping requirements. These records contain only consent metadata, not active contact information.
- Aggregated and anonymized data: Statistical data that cannot identify you may be retained indefinitely for service improvement purposes.
5. Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Update or correct inaccurate information.
- Deletion: Request deletion of your account and associated personal information.
- Opt-out: Stop SMS alerts (reply STOP), stop email alerts (use unsubscribe link), or cancel your subscription entirely.
- Portability: Request export of your information in a machine-readable format.
To exercise any of these rights, contact support@myonlineciso.com. We will respond within 30 days.
6. Security
We protect your information using commercially reasonable security measures, including:
- TLS encryption for all data transmitted between your browser and our systems
- Encrypted storage of sensitive fields at the database level
- Access controls limiting employee access to subscriber data on a need-to-know basis
- Audit logging of all administrative actions affecting subscriber data
- Regular security monitoring and incident response procedures
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you in accordance with applicable law.
7. Children's Privacy
AI-EWS-WX is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us information, contact us at support@myonlineciso.com and we will promptly delete it.
8. International Users
AI-EWS-WX is operated from the United States and is intended for use within the United States. If you access the Service from outside the U.S., you understand that your information will be processed in the United States, where data protection laws may differ from those in your jurisdiction.
9. Third-Party Links
Our Service may contain links to third-party websites or services (such as the National Weather Service). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them any information.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated by email to active subscribers at least 14 days before they take effect. The "Last updated" date at the top of this Policy reflects the most recent revision.
11. Contact
Questions, requests, or concerns about this Privacy Policy can be directed to:
Privacy Officer — AI-EWS-WX
Email: support@myonlineciso.com
Web: myonlineciso.com