Westover Digital Development LLC
Privacy Policy
This Policy explains what information Westover EPR collects, why it is processed, which providers support the service, and the choices available to users.
1. Scope and roles
This Privacy Policy applies to westoverepr.com, readiness assessments, account and workspace features, communications, reports, support, and related Westover EPR services. Westover Digital Development LLC generally acts as the business or controller for public-site, account, sales, billing, security, and service-administration information.
For personal information contained in Customer Data, the Customer organization typically determines why and how that information is processed, and Westover Digital Development LLC processes it to provide the contracted service. A separate data processing agreement may be executed where required.
2. Information we collect
Information you provide
- name, work email, password credentials handled through our authentication provider;
- company, role, contact, readiness-assessment, quote, and onboarding information;
- products, SKUs, packaging, materials, weights, suppliers, sales, and state records;
- uploaded files, evidence, notes, corrections, approvals, and report materials;
- support requests, issue reports, feedback, and communications; and
- billing contacts, accepted quotes, invoices, subscription status, and transaction metadata.
Information collected automatically
- IP address, browser, device, timestamps, requested pages, and referring page;
- authentication, security-verification, session, and access-control events;
- service performance, error, usage, and audit-event metadata; and
- AI execution metadata such as model, operation, timestamps, status, token usage, and hashes.
We do not intentionally collect sensitive consumer information unrelated to packaging-EPR operations. Please do not submit payment-card numbers, passwords, protected health information, or government credentials in uploads or chat.
3. How we use information
- provide, authenticate, secure, maintain, and support the service;
- create readiness reports, quotes, workspaces, review packets, and exports;
- process source documents and prepare unconfirmed AI proposals when authorized;
- perform deterministic calculations and preserve reproducible audit history;
- process billing, prevent fraud, reconcile payments, and maintain accounting records;
- respond to support requests, incidents, and customer communications;
- monitor reliability, enforce policies, and investigate misuse;
- improve workflows using aggregated, de-identified, synthetic, or permissioned feedback; and
- comply with law and establish, exercise, or defend legal rights.
We do not sell Customer Data. We do not use Customer Data to train or fine-tune our own general-purpose AI model. Google states that managed Vertex AI models do not use customer data for model training or fine-tuning without permission; limited provider retention or abuse-monitoring practices may still apply as described in our AI and Data Processing Notice.
4. Cookies and similar technologies
Westover EPR uses technologies necessary for authentication, session continuity, organization selection, security verification, fraud prevention, user preferences, and service operation. Cloudflare Turnstile may process device and network signals to determine whether a request is legitimate. These controls are used for security—not cross-site behavioral advertising.
We do not currently describe optional advertising cookies because the product is not designed around third-party behavioral advertising. If optional analytics or advertising technologies are introduced, this Policy and any required consent controls will be updated before activation.
5. How information is disclosed
We may disclose information to:
- infrastructure and service providers supporting hosting, database, authentication, storage, email, security, AI processing, monitoring, and customer support;
- Stripe and financial providers when billing is enabled;
- authorized users, reviewers, and experts within the Customer-approved scope;
- professional advisers bound by appropriate confidentiality obligations;
- authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud, or enforce agreements; and
- a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice requirements.
Current core providers include Supabase for database, authentication, and private storage; Vercel for application hosting; Google Cloud Vertex AI for approved Gemini operations; Cloudflare for domain and security services; and Stripe for payment processing when enabled. Each provider processes information under its own contractual and privacy terms.
6. AI processing
Public Gemini questions may include the question, bounded product context, and security metadata. Authenticated Gemini features may process organization-scoped status summaries or authorized source documents. The system is designed to avoid sending passwords, signed URLs, unrelated records, or approved legal conclusions to the model.
Gemini results are untrusted proposals or guidance. They cannot approve facts, calculate authoritative totals, make legal determinations, send external messages, or file reports. We retain execution and review metadata needed for auditability, reliability, security, and cost control.
7. Retention
We retain information for the period reasonably necessary to provide the service, preserve reproducible reports and audit history, maintain security, comply with contracts and law, resolve disputes, and support legitimate accounting needs. Retention depends on record type, workspace status, accepted agreements, legal holds, report dependencies, and backup cycles.
Draft or ordinary operational records may be archived or deleted through controlled procedures. Approved and superseded report evidence, audit events, billing records, and records needed to preserve historical reproducibility may be retained longer. Deleted data may remain in encrypted backups until normal backup expiration.
8. Security
We use safeguards designed for the nature of the service, including organization-scoped access controls, server-side authorization, database row-level security, private storage, access logging, role separation, review gates, encryption provided by infrastructure services, and multifactor authentication for supported privileged access.
No security program can guarantee absolute security. Customers must protect credentials, assign roles carefully, limit uploaded data, maintain independent backups of source business records, and promptly report suspected incidents.
9. Your choices and privacy requests
Depending on your location and applicable law, you may request access, correction, deletion, restriction, objection, portability, or information about processing. You may also opt out of nonessential marketing communications. Some requests must be directed to the Customer organization that controls the relevant workspace.
Send requests to compliance@westoverepr.com. We may verify your identity, organization, and authority before responding. We may retain information where required for security, fraud prevention, contracts, legal obligations, disputes, or report reproducibility. We will not discriminate against anyone for exercising an applicable privacy right.
10. International use and children
The service is operated from the United States, and information may be processed in the United States and other locations used by our providers. Customers must not use the service for international personal data unless the required notices, agreements, and transfer protections are in place.
Westover EPR is a business service and is not directed to children under 18. We do not knowingly collect personal information from children.
11. Changes and contact
We may update this Policy as the service, providers, and legal requirements change. The effective date identifies the current version. Material changes will receive additional notice where reasonably required.
Contact: compliance@westoverepr.com. Include your name, organization, account email, request, and the jurisdiction associated with a privacy request.