
Privacy Policy
This Privacy Policy describes how 19th Street Ventures, doing business as OpticCPG ("OpticCPG," "we," "us," or "our"), collects, uses, and shares information when you visit our website at [WEBSITE URL] (the "Site"), use the OpticCPG platform and related applications (the "Service"), or otherwise interact with us.
By using the Site or the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the Site or the Service.
1. Who We Are
OpticCPG is a marketing intelligence and business analytics platform for consumer packaged goods (CPG) and direct-to-consumer (DTC) brands. Our customers are businesses. When a business ("Customer") uses the Service, it connects data sources — such as e-commerce platforms, advertising accounts, accounting software, and financial accounts — so that we can provide analytics, reporting, benchmarking, and optimization recommendations.
This Privacy Policy covers both the Site and the Service. Where our Customers use the Service to process information about their own customers, we act as a service provider processing that information on the Customer's behalf and at the Customer's direction.
2. Information We Collect
2.1 Information You Provide Directly
Account information. When you create an account, we collect your name, email address, company name, and authentication credentials. Account creation and authentication are handled through our identity provider.
Business profile and settings. Information you enter into the Service, such as unit economics assumptions, product costs, business targets, and configuration preferences.
Communications. Information you provide when you contact us, request a demo, subscribe to communications, respond to surveys, or otherwise correspond with us.
Payment information. If you purchase a paid subscription, our payment processor collects billing details on our behalf. We do not store full payment card numbers on our systems.
2.2 Information Collected Through Connected Data Sources
When you connect third-party accounts to the Service, we collect information from those accounts with your authorization. Depending on which integrations you enable, this may include:
E-commerce and sales data (e.g., Shopify, Amazon): order history, transaction records, product and SKU data, revenue, fulfillment records, and related order details. Order records may include personal information about your customers, such as names, email addresses, shipping addresses, and purchase details ("End Customer Data").
Advertising data (e.g., Google Ads, Meta Ads, Amazon Ads, TikTok Ads): campaign-level performance data such as spend, impressions, clicks, conversions, and related campaign metadata.
Accounting data (e.g., QuickBooks): general ledger data, invoices, bills, expenses, chart of accounts, and related financial records.
Bank account and financial data (via Plaid): when you choose to link a financial account, we use Plaid Inc. ("Plaid") to access account and transaction information, which may include account balances, transaction history, and account identifiers. By linking a financial account, you grant OpticCPG and Plaid the right to access, transmit, store, and use this information as described in this Privacy Policy and in Plaid's End User Privacy Policy, available at https://plaid.com/legal/#end-user-privacy-policy. We do not receive or store your banking username or password; credentials are provided directly to Plaid.
Authentication tokens. To maintain connections to the services above, we store access tokens, refresh tokens, and related connection metadata. We do not receive or store your passwords for connected third-party services.
We access connected accounts on a read-only basis unless we explicitly tell you otherwise and you approve a specific action.
2.3 Information Collected Automatically
When you visit the Site or use the Service, we and our service providers automatically collect:
Device and usage information: IP address, browser type, operating system, device identifiers, pages viewed, referring URLs, and the dates and times of access.
Cookies and similar technologies: We use cookies and similar technologies for authentication, security, preferences, and analytics. You can control cookies through your browser settings; disabling certain cookies may limit functionality such as staying signed in.
Log data: Server logs, error reports, and diagnostic information generated in the course of operating the Service.
3. How We Use Information
We use the information we collect to:
Provide, operate, maintain, and secure the Site and the Service;
Generate the analytics, dashboards, metrics, reports, forecasts, and recommendations that constitute the Service;
Establish and maintain connections to the third-party data sources you authorize, and refresh data from those sources on a scheduled or on-demand basis;
Process data using automated systems, which may include artificial intelligence and machine learning models, to classify, analyze, summarize, and generate recommendations from your business data;
Create aggregated, anonymized, or de-identified data — including industry benchmarks such as contribution margins, acquisition costs, fulfillment costs, and similar metrics — as described in Section 4;
Communicate with you about your account, the Service, security matters, and, where permitted, products and features we think may interest you (you may opt out of marketing communications at any time);
Monitor and analyze usage to improve and develop the Site and the Service;
Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms; and
Comply with legal obligations and enforce our agreements.
4. Aggregated, De-Identified, and Benchmark Data
We may aggregate, anonymize, or otherwise de-identify information collected through the Service — including sales, advertising, financial, and operational data — so that it no longer identifies you, your business, or any individual. We may use and disclose such aggregated or de-identified data for any lawful purpose, including to produce industry benchmarks, market analyses, and product improvements, and to train and improve our analytical models.
We will not disclose aggregated or benchmark data in a form that identifies your business or that we reasonably believe could be used to re-identify your business's individual data, and we commit to maintaining and using de-identified data only in de-identified form and not attempting to re-identify it, except as permitted by law to test the effectiveness of our de-identification processes.
5. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
Service providers. We share information with vendors that perform services on our behalf, such as cloud hosting and databases, identity and authentication, payment processing, financial data connectivity (Plaid), analytics, email delivery, and AI/model providers used to power features of the Service. These providers are permitted to use the information only to provide services to us and are bound by contractual confidentiality and data-protection obligations.
Connected platforms. When you authorize an integration, information necessarily flows between OpticCPG and that platform (for example, we send API requests containing your account identifiers to retrieve your data). Each platform's own privacy policy and terms govern its handling of your data on its side, including Google, Meta, Amazon, TikTok, Shopify, Intuit (QuickBooks), and Plaid.
Within your organization. Information in your account is visible to other authorized users of your Customer account, according to the access controls in place.
Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, information may be transferred as part of that transaction, subject to reasonable confidentiality protections. We will notify you of any such transaction that materially changes how your information is handled.
Legal requirements. We may disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of OpticCPG, our users, or others.
With your consent. We may share information for other purposes with your consent or at your direction.
6. End Customer Data
Where order, transaction, or similar records that our Customers connect to the Service contain personal information about the Customer's own customers, we process that End Customer Data solely as a service provider on the Customer's behalf: to provide the Service to that Customer, to create aggregated or de-identified data as described in Section 4, and as otherwise permitted by our agreement with the Customer and applicable law. We do not use End Customer Data to market to those individuals, and we do not sell it or share it for cross-context behavioral advertising.
If you are a customer of one of our Customers and have questions about how your information is handled, please contact that business directly. We will assist our Customers in responding to verified privacy-rights requests as required by law.
7. Data Retention
We retain information for as long as your account is active or as needed to provide the Service, and thereafter as necessary to comply with legal obligations, resolve disputes, enforce agreements, and maintain business records. Historical performance data is central to the analytics we provide, so connected-source data is retained for the life of the account by default.
When you disconnect an integration, we stop collecting new data from that source and delete or deactivate the associated access tokens. When you close your account, or upon your verified request, we will delete or de-identify your information within a reasonable period, except where retention is required or permitted by law. Aggregated and de-identified data may be retained indefinitely.
8. Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption of data in transit, access controls, tenant isolation, and secured storage of authentication tokens. Sensitive financial credentials for linked bank accounts are handled by Plaid and are not stored on our systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for the security of the systems you use to access the Service. If we learn of a security incident affecting your information, we will notify you as required by applicable law.
9. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights under applicable US state privacy laws (including the California Consumer Privacy Act as amended by the CPRA, and similar laws in other states):
Right to know / access: to request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom it was disclosed;
Right to deletion: to request that we delete personal information we collected from you, subject to legal exceptions;
Right to correction: to request that we correct inaccurate personal information;
Right to portability: to receive a copy of your personal information in a portable format;
Right to opt out of sale or sharing: we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of; and
Right to non-discrimination: we will not discriminate against you for exercising your rights.
To exercise these rights, contact us at [PRIVACY EMAIL]. We will verify your request using the email address associated with your account or other reasonable verification methods, and respond within the time required by applicable law. You may designate an authorized agent to make a request on your behalf; we may require proof of the agent's authority.
For clarity: most of the data we handle relates to businesses rather than individuals. Where information identifies an individual (such as your name and work email, or End Customer Data), the rights above apply as provided by the applicable law. Requests concerning End Customer Data should be directed to the Customer (the business you transacted with), and we will support that business's response as its service provider.
We do not use or disclose sensitive personal information for purposes other than those permitted under applicable law (such as providing the Service you request), and financial account information collected through Plaid or QuickBooks is used solely to provide the Service.
10. Do Not Track and Opt-Out Preference Signals
Some browsers transmit "Do Not Track" or Global Privacy Control (GPC) signals. Because we do not sell personal information or share it for cross-context behavioral advertising, these signals do not change how the Site or Service operates, but we honor them where applicable law requires.
11. Third-Party Sites and Services
The Site and the Service may contain links to third-party websites and rely on third-party platforms (including Google, Meta, Amazon, TikTok, Shopify, Intuit, and Plaid). We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party service you connect to OpticCPG, including Plaid's End User Privacy Policy at https://plaid.com/legal/#end-user-privacy-policy and Intuit's privacy statement for QuickBooks.
Our use and transfer of information received from Google APIs adheres to the applicable Google API Services User Data Policy, including its Limited Use requirements.
12. Children's Privacy
The Site and the Service are intended for business use by adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us at [PRIVACY EMAIL] and we will delete it.
13. International Users
We are based in the United States, and the Site and Service are operated from and intended for users in the United States. If you access them from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your jurisdiction.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by a prominent notice on the Site or within the Service before the changes take effect, and we will update the "Last updated" date above. Your continued use of the Site or the Service after changes become effective constitutes acceptance of the revised policy.
15. Contact Us
19th Street Ventures, d/b/a OpticCPG Address: 30 N Gold St Ste N Sheridan, WY 82801. Email: team@cpgplaybook.co
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, or wish to exercise your privacy rights, please contact us using the information above.