Privacy Policy
Effective Date: February 7, 2026
Last Updated: April 8, 2026
Fixture, Inc. ("Fixture," "we," "us," or "our") provides a customer relationship management platform, including https://fixture.app, our web app, APIs, browser extension, and related services (collectively, the "Services").
This Privacy Policy explains what we collect, how we use it, when we share it, and your choices.
1. Scope and Roles
This policy applies to:
- Customers who use Fixture
- Individuals whose data our Customers store in Fixture
- Visitors to fixture.app or sites that use Fixture tracking/forms
When Customers use Fixture to manage their CRM data, we generally act as a processor/service provider and the Customer acts as the controller/business.
When we process data for our own operations (for example, account administration, security, support, and compliance), we act as a controller.
2. Information We Collect
We collect and process categories of information such as:
- Account and workspace information (for example, name, email, profile details, workspace membership)
- CRM data that Customers choose to store (for example, people, companies, leads, deals, notes, and activity data)
- Website and form data processed for Customers (for example, visitor identifiers, page/form interaction data, submission metadata)
- Cookie and similar technology data (for example, session identifiers, persistent visitor identifiers, referrer information, geolocation, and related attribution or identity-resolution data)
- Browser extension capture data from supported sources when a user chooses to capture data
- AI assistant conversation data (prompts, responses, and conversation history)
- Operational and diagnostic data (for example, product usage, performance, and error data)
These are high-level categories and examples, not an exhaustive list.
3. How We Use Information
We use information to:
- Provide and operate the Services
- Authenticate users and enforce workspace access controls
- Process Customer data according to Customer instructions
- Support and improve product performance, reliability, and security
- Provide and improve AI assistant features
- Support visitor identification, attribution, audience enrichment, marketing measurement, and related outreach workflows
- Communicate with users about service and security matters
- Comply with legal obligations and enforce agreements
4. How We Share Information
We do not sell personal information for money.
We may share information:
- With service providers/subprocessors that support the Services
- With marketing, analytics, attribution, and visitor-identification partners that help us understand website usage, identify business visitors, enrich records, or support outreach and campaign measurement
- At Customer direction, when we act as processor/service provider
- For legal, security, fraud-prevention, or rights-protection reasons
- In connection with a merger, acquisition, or other business transfer
Depending on the tool, configuration, and jurisdiction, some of this processing may be considered "sharing" for cross-context behavioral advertising or targeted advertising under applicable law.
5. Cookies and Similar Technologies
We use cookies and similar technologies for functions such as:
- Authentication and session management
- Workspace selection and user preferences
- Visitor identification and form/tracking functionality
- Attribution, audience measurement, and business-visitor recognition
- Consent management where required
Some of these technologies are set by us or by vendors acting on our behalf, including first-party cookies used to recognize returning visitors, maintain sessions, store referral information, and support identity-resolution functionality.
You can control cookies through your browser settings and, where available, through our cookie banner or consent manager. Disabling some cookies may affect functionality.
6. Visitor Identification and Marketing
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout. You also have the option to opt out of the collection of your personal data in compliance with GDPR by visiting https://www.rb2b.com/rb2b-gdpr-opt-out.
7. AI Features
If you use our AI assistant, we process conversation content and related context to provide responses.
This may involve sending relevant request data to model providers that support this feature.
8. Data Retention
We retain data as long as needed to provide the Services, satisfy legal obligations, resolve disputes, and protect the Services.
In general:
- Account/workspace data is retained while active, plus a reasonable period for legal and operational needs
- Customer CRM/tracking/forms data is retained until deleted by the Customer or required to be retained by law
- Logs and diagnostics are retained according to operational and security needs
9. Security
We use technical and organizational safeguards designed to protect personal information, including encryption in transit, access controls, and security monitoring.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
10. International Data Transfers
Fixture is based in the United States. Data may be processed in the U.S. and other countries where we or our service providers operate.
Where required, we use appropriate safeguards for international data transfers.
11. Your Rights and Choices
Depending on where you live, you may have rights such as access, correction, deletion, portability, restriction, objection, withdrawal of consent, and opting out of certain sales, sharing, or targeted advertising.
To submit a privacy request, email privacy@fixture.app.
If your data is controlled by one of our Customers, please contact that Customer first. We will assist Customers with requests as required by law and contract.
Global Privacy Control (GPC)
Where required by applicable law, we will process legally recognized browser-based opt-out preference signals, such as Global Privacy Control, as requests to opt out of relevant sale, sharing, or targeted-advertising activities for the browser or device that sent the signal.
12. Children's Privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice by updating this page and, where appropriate, by email or in-product notice.
14. Contact and DPA
Fixture, Inc.
2261 Market St, STE 46126
San Francisco, CA 94114
Email: privacy@fixture.app
Customers that need a Data Processing Agreement (DPA) or current subprocessor information can request it at the same email address.