Microsoft, Microsoft 365, Outlook, SharePoint, OneDrive, Microsoft Teams, Microsoft Graph, Azure, and Entra are trademarks of the Microsoft group of companies. ImpressionsDirect360 is an independent provider and is not affiliated with, sponsored by, or endorsed by Microsoft.
Last Updated: September 11, 2026
IMPRESSIONSDIRECT360 LLC ("ImpressionsDirect360", "we", "us", or "our") provides domain, website, email, QR and link, payment, and managed Microsoft 365 services. This notice explains what information those services actually collect, why we use it, and the choices available to you.
This is a notice, not a request for blanket consent. Where consent is legally required for a particular use, we ask for it at that use. Account creation separately requires acceptance of our Terms of Service.
Managed Microsoft 365 customers: sections 1–8 describe how we handle your account with us. Where we administer your own Microsoft 365 tenant, we are handling your data on your behalf, and the Data Processing Addendum at the end of this page sets out that arrangement.
We collect the information needed to provide the product you choose:
We use personal information to perform our agreement with you, operate and secure the service, comply with legal obligations, and pursue legitimate operational interests that do not override your rights. In particular, we use it to:
We disclose information to vendors only for the functions described in our dated, public subprocessor list. That list identifies Microsoft, Google Cloud/Firebase, Vercel, Stripe, Tucows/OpenSRS, Resend, and the AI providers currently used, along with the data category and processing location we can state.
No platform advertising tracking. As of September 11, 2026, our marketing pages do not load TikTok Pixel, Google Analytics, Google AdSense, Meta Pixel, or another third-party advertising tracker, and our checkout and payment systems do not report conversion events to TikTok. We do not sell personal information or share it for cross-context behavioural advertising. A prior TikTok marketing and conversion configuration was disabled on that date; contact the Privacy Officer if you want information about data associated with an earlier visit.
Limited first-party checkout measurement. Our branded domain storefront records a small set of session-scoped steps—search results, cart, contact, review, and confirmed purchase-complete views—so we can find where checkout is confusing. We do not send these events to an advertising network, store the searched domain in the event, or retain the browser session identifier; the server stores only a one-way session hash. The measurement is skipped when the browser sends Global Privacy Control or Do Not Track. These operational measurement records do not currently have an automatic deletion timer; you may request deletion as described below.
Customer-controlled tags on short links. A paying customer may configure a Meta Pixel or Google tag on a branded short-link redirect. Those tags do not load until the visitor affirmatively chooses "Allow analytics" on a neutral interstitial. "Continue without" reaches the same destination without loading a tag, and a Global Privacy Control signal bypasses the tag automatically. The customer controls the tag account and receives its provider analytics; we require that customer to provide any additional notice or consent the law requires.
We may also disclose information when you direct us to, as part of a business transfer, to protect customers or the service from fraud and security threats, or when required by a valid subpoena, court order, or other legal process. We review government requests for legal validity and disclose only what the request requires.
We use first-party cookies and browser storage needed for sign-in, fraud prevention, saved-cart state, interface preferences, OAuth and multi-factor-authentication state, and other requested features. A password-protected QR code or short link uses a one-hour, HTTP-only unlock token; the password itself is not written to the browser cookie. Referral codes remain in the URL for the requested journey and are not turned into a long-lived affiliate cookie.
Our marketing pages do not currently use optional advertising or analytics cookies. The limited domain-checkout measurement described above uses session storage rather than a cookie and respects Global Privacy Control and Do Not Track. The customer-controlled short-link tags described in section 4 load only after the visitor chooses to allow them for that visit.
We keep account and product records while the account or product is active and afterward only as reasonably needed for security, support, tax, accounting, dispute, and legal obligations. Domain registration and transaction records may be retained for registry, contractual, fraud-prevention, and legal requirements. Recovery Vault copies follow the retention shown with that product and are deleted when coverage expires.
QR, short-link, campaign, and related analytics records remain until you delete the campaign or account, subject to required backups and legal records; there is not currently an automatic deletion timer for those records. Managed Microsoft 365 operational records follow the separate addendum below. You can ask us to delete your account or specific records, and we will explain any information we must retain and why.
Depending on where you live, you may ask to access, correct, delete, or receive a copy of personal information we control, and may appeal a denied request or use an authorised agent. Email legal@impressionsdirect360.com. We verify requests before acting and will respond within the period the applicable law requires.
You may unsubscribe from marketing email without stopping service, security, receipt, registry-verification, or renewal messages. We do not currently sell personal information or share it for cross-context behavioural advertising, so there is no sale or sharing to opt out of. We honour Global Privacy Control for the optional customer tags described in section 4 and do not discriminate against anyone for exercising a privacy right.
We use encrypted transport, access controls, recent-authentication checks for sensitive actions, audit records, and provider secret stores appropriate to the service. Card data is entered directly into Stripe. No internet service can promise absolute security, and we do not claim a security certification we have not earned. Report a suspected account or privacy incident to the contacts below.
ImpressionsDirect360 Legal Dept.
Attn: Privacy Officer
701 Market St Ste 110 #2008
Saint Louis, MO 63101-1824, US
legal@impressionsdirect360.com·support@impressionsdirect360.comThe services are for adults and businesses and are not directed to children under 13. Account holders must be at least 18 and authorised to act for any business they enter. If we learn that we collected a child's personal information in violation of applicable law, we will delete it.
We operate from the United States. Our vendors may process information in the United States and the other locations identified on the subprocessor page. If you use the service from another country, you are responsible for ensuring the service is appropriate for your use; legally required transfer protections continue to apply.
We will update the date at the top when this notice changes. For a material change to how we use personal information, we will provide a prominent in-product notice or email before or when the change becomes effective, as appropriate. A privacy notice describes our practices; continued use is not treated as consent where the law requires a separate affirmative choice.
Addendum A · Added August 23, 2026 · Reviewed September 11, 2026
This addendum applies to customers of our managed Microsoft 365 service — the service in which we administer a Microsoft 365 tenant that belongs to you. It describes how we handle the content inside that tenant. Sections 1–10 above continue to apply to your ImpressionsDirect360 account, billing, saved projects, and product records. Where the two disagree about tenant content, this addendum is the one that governs.
This is not legal advice.
This addendum was written in-house and published so you can review it. It has not been drafted or reviewed by an attorney, and nobody here is one. Have your own counsel review it before you rely on it or sign anything that references it. If your counsel needs a change, tell us — we would rather negotiate the wording than have you assume it.
For everything inside your Microsoft 365 tenant, you are the data controller and IMPRESSIONSDIRECT360 LLC is a processor acting on your behalf. You decide what data exists, who may see it, and how long it is kept. We do not sell your tenant content, share it for advertising, or use it to train models. We do keep operational records derived from it — details our automations extract from the mail they handle — because that is how the service runs and bills; section 6 sets out exactly what those records contain and where they sit.
We act only on your documented instructions, which are:
If we believe an instruction would break the law, we will say so before acting on it rather than quietly carrying it out. For your ImpressionsDirect360 account, billing records, saved projects, and product records, we are the controller and the sections above apply instead.
You buy and hold your own Microsoft 365 licences, in your own name. We do not resell Microsoft licences today — the tenant, the subscription, and the billing relationship with Microsoft are all yours.
Only what the automations and support you asked for actually touch:
The data subjects are your own staff and the people who correspond with them. You nominate the mailboxes, sites, and calendars the automations run against, and that is what they are configured to touch. Be clear about what that limit is: it is a setting in our configuration, not a boundary Microsoft enforces on us. The permissions our application actually holds are tenant-wide. Section 5 says how wide, and what you can do in your own tenant to narrow it.
The permission set is not negotiated per customer. There is one multitenant application with one fixed set of Microsoft Graph application permissions — Mail.ReadWrite, Mail.Send, Calendars.Read, Sites.ReadWrite.All, and User.Read.All — and every customer consents to the same five. Microsoft shows them to your administrator on its own consent screen before anything is approved. The permission list on our Microsoft 365 security page lists these same five. If the two ever differ, this page is the one to believe — and the Microsoft consent screen in your own tenant beats us both.
We do not ask for special categories of personal data and the service is not designed around them. We cannot stop such data arriving in a mailbox we process, so if it routinely will, raise it with us before onboarding — see the certification note in section 5.
Your tenant content is processed to deliver the automations and the support you configured, and to keep the operational and billing records that running them produces — described in section 6. We do not sell it, rent it, or share it for advertising, and we do not use it to train models — ours or anyone else's.
The AI paths, precisely. Qwen 3.8 Max is used only to create and refine websites through Vercel AI Gateway, and those calls require zero-data-retention-capable routing. The storefront assistant, logo prompts, and content tools use Google's Gemini API on Google's paid tier. A prompt is processed by the provider assigned to that feature and its response is returned to you. We keep no extra copy of the prompt beyond the customer records you choose to save and the operational record described in section 6.
Every AI action is metered per customer, because your plan includes a monthly allowance. Metering records that an action ran, for which customer, and its size for cost attribution — it is a billing record, not a copy of what the action was about.
The vendors that can touch your data on our behalf are listed, with what reaches each one and where they process it, at /trust/subprocessors. That page is the live list — we keep it current rather than restating a copy here that could drift out of date, and it carries the date it was last reviewed.
We use no subprocessor that is not on that page. When we add one, the page is updated. If you object to a new subprocessor, email support@impressionsdirect360.com and we will explain what it does and offer an alternative where one exists. Where none exists, you can cancel. Cancel anytime — your plan stays active until the end of the period you've paid for. Paid periods are ordinarily non-refundable; legal and billing-error exceptions apply.
Described as they are today, not as a wish list:
What we do not have. We hold no SOC 2 report, no ISO 27001 certification, and no HIPAA attestation, and we have not been audited by a third party. Card payments are handled by Stripe, so card data never reaches our servers; that is Stripe's compliance, not ours. Our subprocessors hold certifications of their own — those are theirs, and we do not present them as ours.
Granular delegated administration (GDAP) is not what is in place today. GDAP is created through Microsoft Partner Center and our reseller enrolment has not completed, so we will not describe our access as delegated administration until it is true. Today it is the application consent described above: it has no built-in expiry date, and it ends when you revoke it.
The row-by-row version, including which vendor handles which category, is on the security page.
Your content. Mail bodies and documents live in your tenant and we hold no copy of them, so there is nothing of that kind for us to return at the end. We do not delete them. The single exception is an automation you configured to archive or delete on your own retention policy, with your sign-off; that acts on your instruction, not ours.
What we do hold is not nothing. The operational records in section 6 contain details extracted from your mail, and those are on our side. You can ask us for a copy of them, and you can ask us to delete them.
When the service ends. You revoke the application's consent in your own admin center and our access stops immediately; scheduled automations stop with it. Your tenant, licences, mail, files, and anything an automation filed for you are all unaffected and stay exactly where they are.
How long we keep our operational records. We keep them while your account is open, and afterwards where we still need them — billing, tax, and accounting records, and the automation record itself. There is no automated deletion schedule for any of it today. Nothing expires these records on a timer; they stay until somebody deletes them, and we are not going to claim a retention clock we do not run. Ask us what we hold about your account and we will send you a copy, delete what we are able to delete, and say plainly what we have to keep and why.
Your automation record. Email support@impressionsdirect360.com and we will send you the record of what our automations did in your tenant over the period you name. For access by a person here rather than by an automation, the record is Microsoft's audit log in your own tenant, not ours — see section 5.
Rights requests. If someone exercises a data protection right — access, correction, deletion, export — and you need our help, email support@impressionsdirect360.com. Because the mail and files sit in your own tenant, you can often action a request yourself with Microsoft's tools faster than we can; where you cannot, we will help you find, export, correct, or delete it. The extracted details in our own operational records are ours to search, not yours — tell us the request covers those too and we will include them. As a processor we answer to you, not to your staff or your customers directly, so we will refer a request that reaches us straight to you unless you ask us to handle it. Requests are worked during our support hours, Monday–Friday, 9:00 AM – 6:00 PM Central, under the response target for your plan.
Breach notification. If we become aware of a personal data breach affecting your tenant data, we will notify you without undue delay with what we know at the time: what happened, which of your data was involved as far as we can tell, what we have done, what we are still doing, and anything we need from you. If the picture is incomplete we will say so rather than wait for a tidy story, and we will follow up as it changes.
We do not quote a fixed notification clock in hours, because we do not yet run the round-the-clock monitoring that would let us honour one. How to report a suspected incident to us, and what we do in the first hours, is on /trust/incident-response.
IMPRESSIONSDIRECT360 LLC
A Missouri limited liability company
701 Market St Ste 110 #2008
Saint Louis, MO 63101-1824
Support hours: Monday–Friday, 9:00 AM – 6:00 PM Central