Effective date: March 19, 2026
Pathbound ("we", "us", "our") operates the Pathbound platform (app.pathbound.ai), the Pathbound website (pathbound.ai), the Pathbound Tracker service, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Services.
We serve as both a data controller (for data we collect about our own users and website visitors) and a data processor (for data our customers process through our platform). This policy covers our controller activities. Our processing activities on behalf of customers are governed by our Data Processing Agreement (DPA).
When you create a Pathbound account, we collect:
When our customers use the Pathbound platform, they may upload or generate data including contact records, company records, event data, and enrichment data. We process this data on behalf of our customers per their instructions. Our customers are the data controllers for this data and are responsible for ensuring they have a lawful basis for its collection and processing.
Our customers may deploy the Pathbound Tracker on their websites. When deployed, the tracker collects information about visitors to our customers' websites, including:
Our customers are the data controllers for tracker data collected on their websites. We process this data as a processor on their behalf. Customers are responsible for implementing appropriate consent mechanisms before deploying the tracker and for disclosing the tracker's data collection in their own privacy policies.
We use Google Tag Manager and Google Analytics on our own websites (pathbound.ai, docs.pathbound.ai) to understand how visitors interact with our sites. This may collect:
These analytics tools use cookies, which we load only after obtaining your consent where required by applicable law.
Pathbound uses third-party AI providers (including Anthropic, OpenAI, Google, and Mistral) to power AI agent features. Customers can use Pathbound's built-in AI or bring their own API key (BYOK). When AI features are used:
We integrate with third-party data providers (such as Apollo.io) to enrich contact and company records. When enrichment is used, we may send identifiers (such as email addresses or company domains) to these providers and receive additional business information in return, such as job titles, company size, industry, and publicly available professional information.
We use the information we collect to:
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data based on the following legal grounds:
We share personal data with the following categories of third parties:
We use third-party service providers to help operate our Services. These sub-processors process data on our behalf and are contractually bound to protect your data. Our current sub-processors include:
When our customers connect third-party integrations (such as HubSpot, Intercom, Pipedrive, Slack, or Gmail), data flows between Pathbound and those services are governed by the customer's instructions and the respective integration provider's terms.
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Pathbound, our users, or others.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
access_token | Authentication (JWT session) | Session | Essential |
__Host-csrf | CSRF protection | Session | Essential |
pathbound_visitor_id | Visitor identification (Tracker) | 365 days | Functional |
pathbound_session_id | Session tracking (Tracker) | 1 day | Functional |
Google Tag Manager and Google Analytics may set their own cookies on our website. These are loaded only with your consent where required by applicable law.
The Pathbound Tracker uses device fingerprinting (a hashed combination of browser, screen, and device signals) to recognize returning visitors. This technique does not use cookies but creates a statistical identifier based on device characteristics. Where required by applicable law, our customers must obtain consent before the tracker collects fingerprint data.
The Pathbound Tracker honors a pathbound_dnt=1 cookie. When this cookie is present, the tracker will not collect any data. Customers implementing the tracker can use this mechanism to respect visitor opt-out preferences.
If you are in the EEA or UK, you have the right to:
If you are a California resident, you have the right to:
We do not sell personal information as defined by the CCPA. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA). If you are an end-user of a Pathbound customer's website (i.e., your data was collected via the Pathbound Tracker), please direct your request to that customer, who is the data controller for your information.
Pathbound is based in the United States. If you are accessing our Services from the EEA, UK, or other regions with data transfer restrictions, your data will be transferred to and processed in the United States.
We rely on the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), and other legally approved transfer mechanisms to ensure adequate protection for international data transfers.
We implement industry-standard security measures to protect your data, including:
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to [email protected].
Our Services are not directed to individuals under 16. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. For significant changes affecting how we process your data, we will provide additional notice (such as email notification for account holders).
If you have questions about this Privacy Policy or our data practices, contact us at: