Hrizn logo
Case StudiesInsightsPricing
Legal

Privacy Policy

How we collect, use, and protect your information

Effective date: February 6, 2026 · Last updated: February 6, 2026

Horizn Inc., d/b/a HRIZN ("HRIZN," "we," "us," or "our") provides a content and marketing platform for dealerships and related businesses. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our website, platform, and related services (the "Services"). We are committed to handling personal and sensitive data in line with applicable law and with the security and transparency you expect from a modern SaaS provider.

1. Information We Collect

1.1 Information You Provide

We collect information you give us when you create an account, subscribe to our Services, request support, or otherwise interact with our platform. This may include name, email address, phone number, job title, organization name, billing and payment information, and any other information you choose to provide.

1.2 Information from Third-Party Integrations (Including Google)

When you connect third-party services to our platform—such as Google Business Profile, Google Analytics (GA4), or Google Search Console—we receive only the data necessary to provide the integrated features (e.g., account and property identifiers, location data, posts, reviews, and analytics). We do not store your Google account password; access is via OAuth 2.0 only. Our use of Google user data is limited to what we disclose in this policy and in our product experience.

1.3 Automatically Collected Information

We collect certain technical and usage data when you use our Services, such as IP address, device and browser type, log data, and how you use the platform. We use this to operate, secure, and improve our Services.

1.4 Aggregated and Anonymized Data

We may collect and aggregate data from the systems you use (e.g., CRM, DMS, inventory feeds) and from third-party partners (e.g., JD Power, OEM build data) to power insights, benchmarking, content generation, and vehicle descriptions. This data is anonymized and cannot be used to identify you, your employees, or your customers individually.

2. How We Use Your Information

2.1 Providing the Services

We use your information to operate, maintain, and deliver the Services—including account management, authentication, support, billing, and the features you use (e.g., content creation, Google Business Profile posting, analytics, and reporting).

2.2 Communications

We may use your contact information to send service-related notices, respond to inquiries, and, where you have opted in, send product updates and marketing. You can opt out of marketing at any time.

2.3 Improvement and Analytics

We use aggregated and anonymized data to analyze usage, improve our Services, develop new features, and provide benchmarking and insights—without identifying individuals.

3. Data Sharing and Disclosure

3.1 Service Providers

We work with trusted vendors for hosting, data storage, analytics, support, and payment processing. These providers are bound by contract to use your information only to perform services for us and to protect it in line with this policy.

3.2 Legal and Safety

We may disclose information where required by law, regulation, legal process, or government request, or to protect the rights, safety, or property of HRIZN, our users, or the public.

3.3 We Do Not Sell Your Personal Data

We do not sell your personally identifiable information. We handle personal data in accordance with applicable privacy laws, including the GDPR and the CCPA, where they apply.

4. Data Protection Mechanisms for Sensitive Data

We protect all data in our care, with additional safeguards for sensitive data such as OAuth tokens and data obtained through Google and other third-party integrations.

4.1 Encryption at Rest

Sensitive credentials—including OAuth refresh tokens for Google Business Profile, Google Analytics (GA4), and Google Search Console—are encrypted at rest using industry-standard encryption. We use AWS KMS (Key Management Service) with AES-GCM encryption and unique initialization vectors so that stored tokens are not stored in plain text and are protected against unauthorized access.

4.2 Encryption in Transit

All data in transit between your devices and our systems, and between our systems and third-party APIs (including Google), is protected using TLS (HTTPS). We do not transmit sensitive data over unencrypted channels.

4.3 No Storage of Third-Party Passwords

For Google and other OAuth-based integrations, we never request or store your account passwords. Access is granted and revoked solely through OAuth 2.0; you can disconnect an integration at any time from within the platform or through your Google account settings.

4.4 Access Control and Infrastructure

Access to systems that store or process sensitive data is restricted to authorized personnel and systems, with credentials and configuration managed through secure, access-controlled environments (e.g., AWS Secrets Manager and parameter stores). Our infrastructure and practices align with standards such as SOC 2, ISO 27001, and GLBA where applicable, and we implement technical and organizational measures to protect against unauthorized access, alteration, disclosure, or destruction of data.

5. Google User Data: Retention and Deletion

If you connect Google services (e.g., Google Business Profile, GA4, or Search Console) to our platform, the following describes how long we retain that data and when we delete it.

5.1 Retention of Google User Data

We retain Google user data only for as long as (1) your organization maintains an active OAuth connection to the relevant Google service, and (2) your organization is an active customer of HRIZN. We retain such data for no more than 30 days beyond what is necessary to operate the connected features while the connection and customer relationship are active. We do not retain Google user data indefinitely after you disconnect or after the customer relationship ends.

5.2 Deletion of Google User Data

When you disconnect a Google integration (e.g., Google Business Profile or Google Analytics) from our platform, we delete the associated connection and the related Google-derived data we hold—including OAuth tokens, location and account metadata, synced posts, reviews, and analytics linkage—in a structured manner so that this data is no longer retained in our systems. We do not use Google user data for purposes other than providing and improving the integrated features described in our product and in this policy. After your customer relationship with HRIZN ends, we do not retain Google user data beyond the retention period described above.

6. General Data Retention and Deletion

6.1 Retention Period

We retain your personal information for as long as needed to provide the Services and fulfill the purposes described in this policy, or as required or permitted by law (e.g., tax, legal, or regulatory obligations).

6.2 Data Export and Deletion Requests

Upon cancellation or termination of the Services, you may request a copy of your data. We will facilitate a secure transfer (e.g., via SFTP, S3, or another agreed, compliant method). We may retain a copy for disaster recovery, relaunch, or anonymized service improvement. You may also request deletion of your data from our systems; data that has already been incorporated into anonymized benchmarking or analytics may remain in aggregated form and is not linked to you.

7. Your Rights

Depending on your location, you may have rights regarding your personal information, including:

• Access and portability: request a copy of your personal data

• Correction: request correction of inaccurate or incomplete information

• Deletion: request deletion of your personal information, subject to legal and operational requirements

• Restriction and objection: restrict or object to certain processing where applicable

• Opt-out of marketing: unsubscribe from marketing communications at any time

To exercise these rights or ask questions about our practices, contact us at privacy@hrizn.io. We will respond in accordance with applicable law. If you are in the EEA or UK, you may also have the right to lodge a complaint with your local data protection authority.

8. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. If changes are material, we may also notify you by email or through the Services. Your continued use of the Services after the effective date of the updated policy constitutes acceptance of the changes. If you do not agree, you should discontinue use and contact us regarding your data.

9. Contact Us

For questions about this Privacy Policy or our data practices:

Horizn Inc., d/b/a HRIZN

Email: privacy@hrizn.io

This Privacy Policy is part of our Terms & Conditions. Please review the full agreement for service terms, intellectual property, and other provisions.

Last updated: February 6, 2026