Privacy Statement

Last Updated: September 18, 2026

Scope Of This Policy

This privacy statement describes how Esper.io, Inc. (“Esper,” “we,” “our,” or “us”) collects, uses, and discloses personal data in its role as a data controller in connection with our websites, mobile applications, events, and related services that display or reference this statement. Collectively, these are referred to as our “services” throughout this privacy statement. This statement does not apply to any services that display or reference a different privacy statement.

Esper’s device management products and services are designed for and provided to businesses and other organizations, not individual consumers. In the course of providing those services, we may process personal data of consumers or end-users at the direction of our enterprise customers. When we do, we act as a “service provider” or “data processor” on behalf of those organizations and do not control or bear responsibility for their privacy practices.

This Policy does not apply to personal data that we process as a service provider or data processor on behalf of our enterprise customers. If you interact with our services through an organization that uses our device management products and services, you should review that organization’s privacy statement. Any questions regarding the organization's processing of your personal data, including requests to exercise privacy rights under applicable law, should be directed to that organization.

For information about how we process data, including location-based data, when delivering our device management products and services, as well as our data retention and deletion practices, please see our Data Processing Addendum found here: www.esper.io/dpa.

California “Notice at Collection”: California consumers can find specific disclosures, including “Notice at Collection” details, by clicking here.

Personal Data We Collect

The personal data we collect depends on how you interact with us, the services you use, and the choices you make.

We collect information about you from different sources and in various ways when you use our services, including information you provide directly, information collected automatically, information from third-party data sources, and data we infer or generate from other data.

Information you provide directly. We collect personal data you provide to us. For example:

  • Name and contact information. We collect name and contact details such as email address, postal address, and phone number.
  • Communications, content and files. We collect the content and communications you provide to us; for example, we collect and retain your communications (and any content you provide in connection with your communications) when you send us email messages, contact us by phone, or communicate with us via chatbots available on our websites, such as our  AI Device Fleet Strategist chatbot.

Information we collect automatically. When you use our services, we collect some information automatically. For example:

  • Identifiers and device information. When you visit our websites, our web servers automatically log your Internet Protocol (IP) address and information about your device, including device identifiers (such as MAC address); device type; and your device’s operating system, browser, and other software including type, version, language, settings, and configuration. As further described in the “Cookies, Mobile IDs, and Similar Technologies” section below, our websites and online services store and retrieve cookie identifiers, mobile IDs, and other data.
  • Usage data. We automatically log your activity on our websites, apps and connected products, including the URL of the website from which you came to our sites, pages you viewed, how long you spent on a page, access times, and other details about your use of and actions on our website.

Information we obtain from third-party sources. We also obtain the types of information described above from third parties. These third-party sources include, for example:

  • Third-party partners. Third-party applications and services, including social networks you choose to connect with or interact with through our services.
  • Co-branding/marketing partners. Partners with which we offer co-branded services or engage in joint marketing activities.
  • Service providers. Third parties that collect or provide data in connection with work they do on our behalf, for example companies that determine your device’s location based on its IP address.

Information we create or generate. We infer new information from other data we collect, including using automated means to generate information about your likely preferences or other characteristics (“inferences”). For example, we infer your general geographic location (such as city, state, and country) based on your IP address.

When you are asked to provide personal data, you may decline. And you may use web browser or operating system controls to prevent certain types of automatic data collection. But if you choose not to provide or allow information that is necessary for certain services or features, those services or features may not be available or fully functional.

We do not require you to provide nor knowingly collect sensitive personal data.  We ask that you do not provide us with your sensitive personal data, or otherwise include sensitive personal data in your communications with us (for example, via your email or chat communications with us).

We do not knowingly collect personal data from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from children without verification of parental consent, we take steps to remove that personal data from our systems.

Cookies, Mobile IDs, and Similar Technologies

We use cookies, web beacons, mobile analytics and advertising IDs, and similar technologies to operate our websites and online services and to help collect data, including usage data, identifiers, and device information. For additional detail about our use of cookies and similar technologies, see here.

What are cookies and similar technologies?

Cookies are small text files placed by a website and stored by your browser on your device. A cookie can later be read when your browser connects to a web server in the same domain that placed the cookie. The text in a cookie contains a string of numbers and letters that may uniquely identify your device and can contain other information as well. This allows the web server to recognize your browser over time, each time it connects to that web server.

Web beacons are electronic images (also called single-pixel or clear GIFs) that are contained within a website or email. When your browser opens a webpage or email that contains a web beacon, it automatically connects to the web server that hosts the image (typically operated by a third party). This allows that web server to log information about your device and to set and read its own cookies. In the same way, third-party content on our websites (such as embedded videos, plug-ins, or ads) results in your browser connecting to the third-party web server that hosts that content. We also include web beacons in our email messages or newsletters to tell us if you open and act on them.

How do we and our partners use cookies and similar technologies?

We, and our analytics and advertising partners, use these technologies in our websites, apps, and online services to collect personal data (such as the pages you visit, the links you click on, and similar usage information, identifiers, and device information) when you use our services, including personal data about your online activities over time and across different websites or online services. This data is used to store your preferences and settings, enable you to sign-in, analyze how our websites and apps perform, track your interaction with the site or app, develop inferences, deliver and tailor interest-based advertising, combat fraud, and fulfill other legitimate purposes.

We and/or our partners also share the data we collect or infer with third parties for these purposes. For more information about the third-party analytics and advertising partners that collect personal data on our services, please see the “Our Disclosure of Personal Data” section of this statement.

What controls are available?

There are a range of cookie and related controls available through browsers, mobile operating systems, and elsewhere. See the “Choice and Control of Personal Data” section below for details.

Our Use of Personal Data

We use the personal data we collect for purposes described in this privacy statement or as otherwise disclosed to you. We may carry out these purposes using artificial intelligence (AI) and other automated technologies.

For example, we use personal data for the following purposes:

  • Service delivery and personalization. To provide, administer, and maintain our services, including troubleshooting and improving those services and monitoring and analyzing usage trends, preferences, and other service activity. To understand you and your preferences to personalize and enhance your experience and enjoyment using our services.
  • Business operations. To operate our business, such as billing, accounting, improving our internal operations, securing our systems, detecting fraudulent or illegal activity, and meeting our legal obligations.
  • Product improvement, development, and research. To improve and develop new services or features, and conduct research.
  • Service and support. To provide service and support and respond to your comments, questions, and requests.
  • Communications. To send you information, including confirmations, invoices, technical notices, updates, security alerts, and support and administrative messages.
  • Marketing. To communicate with you about new services, offers, promotions, rewards, contests, upcoming events, and other information about our services and those of our selected partners (see the “Choice and Control” section of this statement for information about how to change your preferences for promotional communications).
  • Advertising. To display advertising to you (see the “Cookies” and “Choice and Control” sections of this statement for information about personalized advertising and your advertising choices).

We combine data we collect from different sources for these purposes, and to give you a more seamless, consistent, and personalized experience.

We may also use personal data to create de-identified data and use de-identified data or otherwise non-personal data for the purposes above or any other purpose permitted by applicable law. We commit that we will maintain de-identified data in its de-identified form without attempting to re-identify such data.

Our Disclosure of Personal Data

We disclose personal data with your consent or as we determine necessary to provide the services you have requested or authorized. In addition, we disclose each of the categories of personal data described above, to the types of third parties and for the business purposes, described below:

  • Public information. Any information that you voluntarily choose to include in a publicly accessible area of the service will be available to anyone who has access to that content, including other users.
  • Service providers. We provide personal data to vendors or agents working on our behalf for the purposes described in this statement. For example, companies we’ve hired to assist in protecting and securing our systems and services may need access to personal data to provide those functions.
  • Corporate transactions. We may disclose personal data as part of a corporate transaction or proceeding such as a merger, financing, acquisition, bankruptcy, dissolution, or a transfer, divestiture, or sale of all or a portion of our business or assets.
  • Legal and law enforcement. We will access, disclose, and preserve personal data when we believe doing so is necessary to comply with applicable law or respond to valid legal processes, including from law enforcement, national security, or other government agencies.
  • Security, safety, and protecting rights. We will disclose personal data if we believe it is necessary to:
    • protect our customers and others, for example to prevent spam or attempts to commit fraud, or to help prevent the loss of life or serious injury of anyone;
    • operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks; or
    • protect the rights or property of ourselves or others, including enforcing our agreements, terms, and policies.
  • Third party analytics and advertising companies, also collect personal data through our website and apps including identifiers and device information (such as cookie IDs, device IDs, and IP address), geolocation data, usage data, and inferences based on and associated with that data, as described in the “Cookies” section of this statement. These third-party vendors may combine this data across multiple sites to improve analytics for their own purpose and others. For example, we use Google Analytics on our website to help us understand how users interact with our website; you can learn how Google collects and uses information at www.google.com/policies/privacy/partners.  While we do not “sell” your personal data in the traditional sense, disclosures to these third parties via cookies or tracking technologies placed on our website may be considered a “sale” or “sharing” of personal information as defined under the laws of California and other U.S. states.
  • Third party integrations. Some of our services also include integrations, references, or links to services provided by third parties whose privacy practices differ from ours. If you provide personal data to any of those third parties, or allow us to share personal data with them, that data is governed by their privacy statements. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Service.

Finally, we may disclose de-identified information in accordance with applicable law.

Choice and Control of Personal Data

We provide a variety of ways for you to control the personal data we hold about you, including choices about how we use that data. More information about these choices and controls is provided below. In some jurisdictions, the controls and choices above may be enforceable as rights under applicable laws. In particular, see the sections “European Data Protection Rights”  and “California Privacy Rights.

How to exercise your rights and choices over your personal data. In addition to the controls detailed below, you can send us a request to exercise your rights or these choices by using the contact methods described at the bottom of this privacy statement.

You may also designate, in writing or through a power of attorney, an authorized agent to make requests on your behalf to exercise your rights over your personal data. Before accepting such a request from an agent, we may require the agent to provide proof you have authorized it to act on your behalf, and we may need you to verify your identity directly with us.

To honor a request that we provide, correct, or delete specific pieces of personal data about you, we may need to verify your identity to the degree of certainty required by law. Accordingly, we may request that you provide additional information in order to complete your request.

In some cases, we may decline to honor your request. For example, we may decline requests where granting the request would be prohibited by law, could adversely affect the privacy or other rights of another person, would reveal a trade secret or other confidential information, or would interfere with a legal or business obligation that requires retention or use of the data. Further, in some cases, we may decline a request where we are unable to verify you as the person to whom the data relates, the request is unreasonable or excessive, or where otherwise permitted by applicable law.

If you receive a response from us informing you that we have declined your request, in whole or in part, you may have a right to appeal that decision under applicable law, in which case you may submit your appeal using the contact method described at the bottom of this privacy statement.

Communications preferences. You can choose whether to receive promotional communications from us by email, SMS, and telephone. If you receive promotional email or SMS messages from us and would like to stop, you can do so by following the directions in that message or by contacting us as described in the “Contact Us” section below. If you receive a sales call from us, you can ask to be placed on our do-not-call list. These choices do not apply to certain informational communications such as mandatory service communications.

Targeted advertising. To opt-out from or otherwise control targeted advertising, you can use the browser or platform controls described below. These choices may be specific to the device or browser you are using. If you access our services from other devices or browsers, take these actions from those devices or browsers to ensure your choices apply to the data collected when you use them.

Data sales. While we do not sell personal data in the traditional sense, some privacy laws define “sale” broadly to include some of the disclosures described in the “Our Disclosure of Personal Data” section above. To opt-out from such data “sales” please complete the form found here: https://trust.esper.io/your-data.

Browser or platform controls.

  • Cookie controls. Most web browsers are set to accept cookies by default. If you prefer, you can go to your browser settings to learn how to delete or reject cookies. If you choose to delete or reject cookies, this could affect certain features or services of our website. If you choose to delete cookies, settings and preferences controlled by those cookies, including advertising preferences, may be deleted and may need to be recreated.
  • [Reference to Cookie Banner Placeholder]
  • Global Privacy Control. Some browsers and browser extensions support the “Global Privacy Control” (GPC) or similar controls that can send a signal to the websites you visit indicating your choice to opt-out from certain types of data processing, including data sales and/or targeted advertising, as specified by applicable law. When we detect such a signal, we will make reasonable efforts to respect your choices indicated by a GPC setting or similar control that is recognized by regulation or otherwise widely acknowledged as a valid opt-out preference signal.
  • Do Not Track. Some browsers include a "Do Not Track" (DNT) setting that can send a signal to the websites you visit indicating you do not wish to be tracked. Unlike the GPC described above, there is not a common understanding of how to interpret the DNT signal; therefore, our websites do not respond to browser DNT signals. Instead, you can use the range of other tools to control data collection and use, including the GPC and cookie controls described above.

Email web beacons. Most email clients have settings that allow you to prevent the automatic downloading of images, including web beacons, and the automatic connection to the web servers that host those images.

European Data Protection Rights

If the processing of personal data about you is subject to European Union data protection law, you have certain rights with respect to that data:

  • You can request access to, and rectification or erasure of, personal data;
  • If any automated processing of personal data is based on your consent or a contract with you, you have a right to transfer or receive a copy of the personal data in a usable and portable format;
  • If the processing of personal data is based on your consent, you can withdraw consent for future processing at any time;
  • You can object to, or obtain a restriction of, the processing of personal data under certain circumstances; and
  • For residents of France, you can send us specific instructions regarding the use of your data after your death.

To make such requests, please use the contact information at the bottom of this statement. When we are processing data on behalf of another party that is the “data controller,” you should direct your request to that party. You also have the right to lodge a complaint with a supervisory authority, but we encourage you to first contact us with any questions or concerns.

We rely on different lawful bases for collecting and processing personal data about you, for example, with your consent and/or as necessary to provide the services you use, operate our business, meet our contractual and legal obligations, protect the security of our systems and our customers, or fulfil other legitimate interests in accordance with applicable law.

California Privacy Rights

If you are a California resident and the processing of personal information about you is subject to the California Consumer Privacy Act (CCPA), you may have certain rights with respect to that information.

Notice at Collection. At or before the time of collection, you have a right to receive notice of our practices, including the categories of personal information and sensitive personal information to be collected (if any), the purposes for which such information is collected or used, whether such information is sold or shared, and how long such information is retained. You can find those details in this statement by clicking on the above links.

Right to Know. You have a right to request that we disclose to you the personal information we have collected about you. You also have a right to request additional information about our collection, use, disclosure, or sale of such personal information. Note that we have provided much of this information in this privacy statement.

Rights to Request Correction or Deletion. You also have rights to request that we correct inaccurate personal information and that we delete personal information under certain circumstances, subject to a number of exceptions.

Right to Opt-Out / “Do Not Sell or Share My Personal Information”. You have a right to opt-out from future “sales” or “sharing” of personal information as those terms are defined by the CCPA. Note that the CCPA defines “sell,” “share,” and “personal information” very broadly, and some of our data disclosures described in this privacy statement may be considered a “sale” or “sharing” under those definitions. In particular, we may let advertising and analytics providers collect identifiers (IP addresses, cookie IDs, and mobile IDs), usage (or “activity”) data (browsing, clicks, app usage), and device information, through our sites and apps when you use our online services, but do not “sell” or “share” any other types of personal data. We do not sell or share (nor do we knowingly collect) sensitive personal data or the personal data of minors. If you do not wish for us or our partners to “sell” or “share” personal information relating to your visits to our sites, you can make your request by completing the form found here: https://trust.esper.io/your-data. If you opt-out using these choices, we will not disclose or make available such personal information in ways that are considered a “sale” or “sharing” under the CCPA. However, we will continue to make available to our partners (acting as our service providers) some personal information to help us perform advertising-related functions. Further, using these choices will not opt you out of the use of previously “sold” or “shared” personal information or stop all interest-based advertising.

Right to Limit Use and Disclosure of Sensitive Personal Information. You have a right to limit our use of sensitive personal information for any purposes other than to provide the services or goods you request or as otherwise permitted by law. Note that we do not use sensitive personal information for any such additional purposes.

Right not to be Discriminated Against. Finally, you have a right to not be discriminated against for exercising these rights set out in the CCPA.

Additionally, under California Civil Code section 1798.83, also known as the “Shine the Light” law, California residents who have provided personal information to a business with which the individual has established a business relationship for personal, family, or household purposes (“California Customers”) may request information about whether the business has disclosed personal information to any third parties for the third parties’ direct marketing purposes. Please be aware that we do not disclose personal information to any third parties for their direct marketing purposes as defined by this law.

Retention of Personal Data

We retain personal data for as long as necessary to provide the services and fulfill the transactions you have requested, comply with our legal obligations, resolve disputes, enforce our agreements, and for other legitimate and lawful business purposes. Because these needs can vary for different data types in the context of different services, actual retention periods can vary significantly based on criteria such as user expectations or consent, the sensitivity of the data, the availability of automated controls that enable users to delete data, and our legal or contractual obligations.

Location of Personal Data

The personal data we collect may be stored and processed in your country or region, or in any other country where we or our affiliates, subsidiaries, or service providers process data, some of which may have laws that offer different levels of data protection than the country in which you reside. Currently, we primarily use data centers in the United States. The storage location(s) are chosen to operate efficiently and improve performance. We take steps to process and protect personal data as described in this statement wherever the data is located.

Location of Processing European Personal Data. We transfer personal data from the European Economic Area (EEA), United Kingdom (UK), and Switzerland to other countries, some of which have not been determined by the European Commission to have an adequate level of data protection. When we do so, we use legal mechanisms, including contracts, to help ensure your rights and protections. To learn more about the European Commission’s decisions on the adequacy of personal data protections, please visit: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en.

Security of Personal Data

We take reasonable and appropriate steps to help protect personal data from unauthorized access, use, disclosure, alteration, and destruction. Please be aware that no security measures are perfect or impenetrable.  We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards.

To help us protect personal data, we request that you use a strong password and never share your password with anyone or use the same password with other sites or accounts.

Changes to This Privacy Statement

We will update this privacy statement when necessary to reflect changes in our services, how we use personal data, or the applicable law. When we post changes to the statement, we will revise the "Last Updated" date at the top of the statement. If we make material changes to the statement, we will provide notice and take any additional actions regarding such changes as may be required by law (e.g. obtaining consent or providing an opportunity to withdraw consent or otherwise opt-out).

How to Contact Us

If you have a privacy concern, complaint, or a question for us, please contact us at privacy@esper.io or 425-394-6107.

Our address is 3600 136th Pl SE # 210, Bellevue, WA 98006.