Privacy policy

We help companies that sell to Gov & Education manage the public institution procurement lifecycle.

Last updated: September 10, 2026

Starbridge.ai (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, how we share it, and the rights you have regarding your personal data. By using Starbridge.ai or interacting with our services, you agree to the practices described in this Privacy Policy.

1. Information We Collect

We collect the following types of information when you visit our website, interact with our tools, request a demo, subscribe to updates, or engage with our advertising:

a. Information You Provide Directly

  • Name
  • Email address
  • Company name
  • Job title
  • Phone number (optional)
  • Any information submitted through forms, surveys, or chat

b. Information Collected Automatically

When you visit Starbridge.ai, we automatically collect certain data through cookies, pixels, tags, and analytics tools, including:

  • IP address
  • Device information (browser type, operating system)
  • Pages visited, time spent, and referring URLs
  • Click behavior and interaction data
  • Advertising identifiers (e.g., LinkedIn Insight Tag)

c. Information From Third Parties

We may receive additional data from:

  • Advertising partners such as LinkedIn, Meta, or Google
  • Analytics providers
  • CRM integrations or marketing tools
  • Publicly available data sources

2. How We Use Your Information

We use personal information for the following purposes:

  • To provide and improve the Starbridge.ai platform
  • To respond to inquiries and support requests
  • To deliver demos, content, and product updates
  • To personalise your experience on our website
  • To run marketing campaigns, including targeted and retargeted ads
  • To measure campaign performance and website effectiveness
  • To comply with legal obligations

This includes using tracking technologies (like cookies and the LinkedIn Insight Tag) to understand visitor behaviour, show relevant ads, and optimise marketing performance.

2a. Lawful Basis for Processing (GDPR)

Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we rely on the following lawful bases for processing your personal data:

Processing PurposeLawful Basis
Providing and improving the platformPerformance of a contract
Responding to inquiries and support requestsPerformance of a contract / Legitimate interests
Delivering demos, content, and product updatesLegitimate interests
Personalising your website experienceLegitimate interests
Running marketing and retargeted ad campaignsConsent
Measuring campaign performanceLegitimate interests
Complying with legal obligationsLegal obligation
Using cookies and tracking technologies (non-essential)Consent

Where we rely on consent, you have the right to withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us at support@starbridge.ai.

2b. Google User Data

Starbridge’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We access Gmail and Google Drive data only with your consent and only to provide user-facing features (sending and monitoring outreach from your connected mailbox; read-only search of your Drive documents for RFP drafting). We do not use, transfer, or sell Google user data to create, train, or improve any AI/ML models, nor permit third parties to do so; third-party model providers are used under terms prohibiting training on this data, and self-hosted models run in our isolated infrastructure with nothing shared back to the provider. Humans do not access this data except with your permission, for security, or as required by law. It is deleted when you disconnect or on request at support@starbridge.ai.

3. How We Share Information

We do not sell personal data. However, we may share information with:

a. Service Providers

Trusted third-party vendors who help us operate our website, run analytics, process data, send emails, or provide customer support.

b. Advertising & Analytics Partners

Platforms such as:

  • LinkedIn Ads
  • Google Analytics
  • Meta Ads
  • Email marketing or CRM providers

These partners may use data to provide measurement services or targeted advertising.

c. Business Transfers

If Starbridge.ai is part of a merger, acquisition, or asset sale, user data may be transferred as part of the transaction.

d. Legal Compliance

We may disclose information where required by law or to protect our rights and users’ safety.

4. Cookies & Tracking Technologies

Starbridge.ai uses cookies, pixels, and similar tracking tools to:

  • Analyse website usage
  • Improve user experience
  • Deliver personalised ads
  • Measure ad performance

5. Data Security

We implement administrative, technical, and physical safeguards to protect your data from unauthorized access, loss, misuse, or alteration. While no system is completely secure, we continuously update our systems and processes to maintain a high level of protection.

6. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access your personal data
  • Correct inaccurate information
  • Delete your data
  • Opt out of marketing communications
  • Withdraw consent for data processing
  • Request a copy of your data (data portability)
  • Opt out of targeted advertising
  • Object to processing based on legitimate interests
  • Restrict processing of your data

Right to Lodge a Complaint

If you are located in the European Union or United Kingdom, you also have the right to lodge a complaint with your local supervisory authority:

  • EU residents: Contact your national Data Protection Authority (DPA). A full list is available at edpb.europa.eu.
  • UK residents: Contact the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

To exercise any of your rights, contact us at: support@starbridge.ai.

7. Data Retention

We retain personal data only as long as necessary to provide services, comply with legal obligations, or support business operations. When data is no longer needed, we securely delete or anonymise it.

8. International Data Transfers

If you are located outside the United States, please note that your data may be processed in countries that may have different data protection laws.

Where we transfer personal data from the European Economic Area (EEA) or the United Kingdom to countries that have not received an adequacy decision from the European Commission or the UK Secretary of State, we ensure appropriate safeguards are in place. These safeguards include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, as applicable
  • Other approved transfer mechanisms under applicable law

You may request a copy of the relevant safeguards by contacting us at support@starbridge.ai.

9. Children’s Privacy

Starbridge.ai is not intended for individuals under 16. We do not knowingly collect data from children. If we discover such data was collected, we will delete it promptly.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Changes will be reflected with a revised “Last updated” date at the top of this page.

11. Starbridge Browser Extension

This section applies to Starbridge: Intelligence for Public Sector Sales, our Chrome browser extension, and supplements the policy above. Where this section conflicts with the general policy, this section controls for data handled by the extension. The website advertising and retargeting practices described elsewhere in this policy do not apply to extension data.

Information We Collect

Tab URLs and Account Detection

The extension reads tab URLs when tabs are activated or finish loading and when the extension starts. This can include tabs that load in the background. It processes the hostname, origin, and path locally and stores recent URL components and cached account-detection results in your browser.

While you are signed in, automatic detection sends the website hostname or the organization identifier from a LinkedIn company, school, or showcase URL to Starbridge to search for a matching public-sector account. These requests can occur even when no account matches, while the side panel is closed, and when the floating Starbridge tab is hidden. The account-detection request does not send the full page URL, query string, or fragment. Detection uses URL information; it does not extract or upload the text of the webpages you visit.

Account and Authentication Data

We process your account information, including your name, email address, user identifier, organization identifier and name, and account or organization role. Auth0 (Okta) handles sign-in and issues access and refresh tokens. The extension stores these tokens locally to maintain your session, sends access tokens to authenticate requests to Starbridge, and sends refresh tokens to Auth0 to renew your session.

Research, AI Chat, and CRM Features

When you search for accounts, view contacts, or use AI chat, Starbridge processes the search terms, selected account and contact identifiers, chat messages, relevant account context, generated responses, conversation identifiers, and feedback needed for those features. Chat messages and relevant context may be sent through our backend to the AI providers listed below to generate responses. Conversations and responses are stored to support conversation history.

If your organization has connected a CRM and you use the extension’s CRM features, Starbridge processes connection identifiers, account and contact records, and synchronization status. When you request a synchronization, the relevant records are transferred to the connected CRM selected for that operation.

Usage and Diagnostics

We collect a persistent device identifier, extension version, browser and device information, session information, product-interaction events, and error reports. Network requests also disclose an IP address to the receiving service. Interaction events include opening the extension, viewing an account or account tab, and giving feedback on or copying a chat response. When you are signed in, analytics can associate these events with your email address, user identifier, organization identifier and name, and role.

When you copy an AI response using the chat’s copy control, the analytics event includes the response text and its conversation and message identifiers. Where session replay is enabled, PostHog may record interactions within the extension’s side panel to help diagnose usability and reliability issues. The recorder is configured to mask input values and displayed text; this masking does not apply to response text sent separately in a copy event.

Local URL handling and storage, device identification, feature-configuration requests, and diagnostic processing can occur before you sign in. Usage analytics starts when you open the side panel. Signing in enables authenticated account lookups and associates usage with your account.

How We Use and Handle Extension Data

The extension’s single purpose is to provide public-sector sales intelligence in your browser, including account detection, account and contact research, related AI assistance, and connected CRM workflows. We use extension data to provide these features, authenticate you, maintain your settings and conversation history, and secure, maintain, and measure the performance and reliability of the extension.

Requests carrying extension data to Starbridge and the service providers below use encrypted HTTPS/TLS connections. Access to account features is authenticated. We apply the security safeguards described in Section 5 to extension data stored in our systems.

Who We Share Extension Data With

The following providers process extension data to deliver the functions described above. The data each receives depends on the feature you use:

  • Auth0 (Okta) — sign-in, account authentication, and session renewal.
  • Google Cloud, including Firebase and Firestore — hosting, data storage, authentication for Firebase-backed features, and synchronization of account, conversation, and integration data.
  • Amplitude — product-usage analytics, including device and account identifiers, email address, organization information, interaction events, and copied AI response text. The extension uses Amplitude’s EU endpoint.
  • PostHog — product-usage analytics, error reporting, and session replay where enabled, including device and account identifiers, email address, organization information, interaction events, diagnostic information, and copied AI response text. The extension uses PostHog’s US endpoint.
  • LaunchDarkly — feature configuration, using user and organization identifiers, user type, organization type, and feature-evaluation information.
  • Anthropic and OpenAI — AI processing through Starbridge’s backend, including prompts, relevant conversation and account context, and generated responses, depending on the configured model and fallback provider.
  • Your organization’s connected CRM provider — the account and contact records and synchronization information needed for the CRM operations you request.

Where Extension Data Is Stored

On your device, the extension uses browser storage for access and refresh tokens, the device identifier, your selected organization and display preferences, recent tab URL components, and a cache of checked hostnames and account-detection results. Analytics and authentication libraries may also store session state in the extension’s browser storage.

Data sent to Starbridge is processed and stored on our cloud infrastructure. The service providers listed above process and store the data needed for their respective functions in their systems. Extension data may be processed in the United States and other countries; Amplitude analytics uses the EU endpoint and PostHog uses the US endpoint. The international-transfer safeguards described in Section 8 apply.

Retention and Deletion

Local account-detection results are treated as stale after one hour for lookups with no matching account or six hours for matching results. Stale records are removed during subsequent cache activity and may remain stored longer when the extension is inactive. Other local settings and identifiers remain until they are updated or removed. Signing out removes the extension’s stored access and refresh tokens, but does not automatically erase its detection cache, analytics identifiers, or data already sent to Starbridge or its providers.

We retain server-side account, research, conversation, and integration data for as long as needed to provide your account features and history. We retain analytics and diagnostic data for as long as needed to maintain and measure the extension’s functionality, investigate errors or security incidents, and meet applicable legal obligations. Retention depends on the type of data, the service purpose, account status, and applicable deletion requests and legal requirements. When data is no longer needed, we delete or anonymize it as described in Section 7.

Removing the extension clears its Chrome local storage; it does not delete data already held by Starbridge, analytics providers, or a connected CRM. You can request access to, correction of, or deletion of your extension data, or withdraw consent where processing relies on consent, by contacting support@starbridge.ai. Requests concerning records already transferred to your organization’s CRM may also need to be directed to your CRM administrator.

Your Controls

You can sign out to stop authenticated account lookups. Hiding the floating Starbridge tab changes its visibility only and does not stop background account detection or telemetry. To stop all further processing by the extension, disable or remove it through Chrome’s extension settings. Disabling the extension does not itself delete previously stored data.

Limited Use of Extension Data

Starbridge’s use and transfer of data collected through the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell extension data, use or transfer it for advertising, provide it to data brokers, use it for creditworthiness or lending decisions, or use it for purposes unrelated to the extension’s single purpose.

We limit transfers to those needed to provide or support the disclosed features, comply with law, or protect against fraud or abuse. A transfer as part of a merger, acquisition, or asset sale requires your explicit prior consent. Human access to extension user data is limited to your explicit consent to read specific data, security investigations, legal requirements, or aggregated and anonymized data used for internal operations.

12. Contact Us

If you have questions or requests regarding this Privacy Policy or how we handle data, contact us at:

Starbridge.ai
Email: support@starbridge.ai
Starbridge Inc, 169 Madison Ave, STE 11217, New York, New York 10016

13. EU & UK GDPR Representatives

Pursuant to Article 27 of the GDPR and Article 27 of the UK GDPR, Starbridge.ai has designated the following representatives for individuals in the European Union and United Kingdom respectively. These representatives can be contacted on all issues relating to the processing of personal data and the exercise of data subject rights.

EU Representative

Ria Pardeep
Email: ria@workstreet.com
c/o Workstreet
Bahnhofstraße 8
30159 Hanover
Germany

UK Representative

Rebecca Sham
Email: rebecca@workstreet.com
c/o Workstreet
Abbey House
83 Princes Street
Edinburgh
EH2 2ER
Scotland, United Kingdom

Ready to give your SLED team real leverage?

Let’s talk about how Starbridge can build a qualified pipeline for your current team — without adding headcount.

Book a demo