POLICY ACTIVE
/
VERSION 1.0
/
US JURISDICTION
/
ALLENTOWN, PA
Legal · Privacy Policy
How we handle your data.
This Privacy Policy explains what information Intrusive Robotics LLC collects from visitors, customers, and partners; why we collect it; how we use, share, and protect it; and the choices you have about it. We’ve written it to be read, not skimmed.
Effective Date · May 18, 2026 · Last Updated · May 18, 2026
Our Commitments
What you can expect from us.
- We collect only the information we need to operate the business, support our customers, and meet our legal obligations.
- We do not sell your personal information, and we do not share it with advertisers or data brokers.
- We are transparent about which third-party services receive your data and what they receive.
- We apply industry-standard administrative, technical, and physical safeguards to protect your information, and we tell you promptly if those safeguards fail.
Contents
- Scope & Definitions
- Information We Collect
- How We Collect Information
- How We Use Information
- Why We Are Permitted To Use It
- How We Share Information
- Third-Party Service Providers
- Cookies & Tracking Technologies
- Support Tickets & RMA Data
- Export Control Compliance
- Data Retention
- Information Security
- Breach Notification
- Your Rights & Choices
- International Visitors
- Children's Privacy
- Third-Party Sites & Links
- Changes To This Policy
- Contact Us
SECTION 01
Scope & Definitions
This Privacy Policy applies to Intrusive Robotics LLC (“Intrusive Robotics,” “we,” “us,” or “our”), a Pennsylvania limited liability company headquartered in Allentown, Pennsylvania. It governs information we collect through our website at intrusiverobotics.com, our product documentation portals, our online store and customer accounts, our technical support and Return Merchandise Authorization (RMA) channels, and any direct communications you have with us by email or web form (collectively, the Services).
By using the Services or providing information to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with how we handle information, please do not use the Services or provide information to us.
Personal Information
Information that identifies, relates to, or could reasonably be linked to a specific individual or household.
Service Provider
A third party we engage to perform services on our behalf (for example, payment processing, shipping, or email delivery).
RMA
Return Merchandise Authorization — our process for handling product returns, warranty claims, and repairs.
Aggregated Data
Data that has been combined or de-identified such that it can no longer reasonably be linked to a specific individual.
SECTION 02
Information We Collect
We collect the categories of information described below. We have organized this section by source so you can quickly see what we collect and when.
Information you provide directly
- Identity and contact information — name, email address, phone number, company or organization name, job title, shipping address, and billing address.
- Account credentials — username and a salted, hashed representation of your password if you create a customer account, along with any account preferences you set.
- Order information — items purchased, order quantities, order history, shipping selections, gift messages or notes, and any correspondence about your order.
- Payment information — payment is processed by our PCI-compliant third-party payment processor. We do not store full payment card numbers, security codes, or magnetic stripe data on our systems. We retain only the card brand, last four digits, expiration month and year, and a transaction reference for reconciliation, support, and accounting purposes.
- Support and RMA information — serial numbers, hardware revisions, firmware versions, descriptions of the issue, photographs, video, log files, telemetry data, return shipping information, and any other diagnostic information you choose to share.
- Communications — the content of emails, support tickets, web-form submissions, and any other messages you send us, including attachments.
- Marketing preferences — your subscription status for newsletters, product updates, and launch announcements.
Information collected automatically
- Device and connection data — IP address, browser type and version, operating system, device type, screen size, language settings, time zone, and referring URL.
- Usage data — pages viewed, time spent on pages, links clicked, search terms used on our site, scroll depth, and timestamps.
- Cookies and similar technologies — see Section 08 for full detail.
Information from third parties
- Payment processors may return transaction status, fraud-screening signals, and the limited card details described above.
- Shipping carriers may return tracking events, delivery confirmations, and address-correction information.
- Export-control screening services may return screening results for billing and shipping addresses (see Section 10).
- Analytics providers may return aggregated reporting on how visitors use the Services.
SECTION 03
How We Collect Information
We collect information when you:
- Visit, browse, or otherwise interact with our website.
- Complete a contact form, subscribe to updates, or request product information.
- Create a customer account or place an order.
- Open a technical support ticket, request an RMA, or contact us about warranty service.
- Email us directly or reply to our messages.
- Communicate with us through professional channels such as LinkedIn or via partner referrals.
SECTION 04
How We Use Information
We use the information we collect for the following purposes.
- To operate the business — process orders, fulfill and ship products, issue invoices and receipts, manage returns and warranty claims, and maintain customer accounts.
- To provide technical support — diagnose hardware and firmware issues, respond to support tickets, process RMAs, and complete repairs.
- To communicate with you — respond to inquiries, send transactional messages (order confirmations, shipping notifications, RMA status updates, security alerts, and similar service communications), and, with your consent, share product updates, firmware releases, and launch announcements.
- To improve our products and Services — analyze how visitors use the Services, evaluate the effectiveness of our documentation, and use aggregated or de-identified support data to inform product improvements.
- To comply with legal obligations — including US tax and accounting requirements, export-control regulations, and other applicable laws.
- To protect our business, customers, and the public — detect, investigate, and prevent fraud, abuse, security incidents, and other unlawful activity, and to enforce our terms of service and other agreements.
We do not sell your personal information, and we do not use it for cross-context behavioral advertising.
SECTION 05
Why We Are Permitted To Use It
We process personal information when we have a lawful basis to do so. Depending on the activity, we rely on one or more of the following:
- Performance of a contract — to provide the products and services you have ordered or requested.
- Legitimate interests — to operate, secure, and improve the Services in ways that do not override your rights and reasonable expectations.
- Consent — for activities that require it, such as marketing emails. You may withdraw consent at any time.
- Legal obligation — to comply with tax, accounting, export-control, and other applicable laws.
SECTION 06
How We Share Information
We share personal information only as described below.
- Service providers — companies that help us operate the business, including our website host, email delivery provider, payment processor, shipping carriers, analytics provider, customer-support tooling, and accounting software. These providers are bound by contractual obligations to use your information only to provide their services to us and to apply appropriate safeguards. A non-exhaustive list of categories appears in Section 07.
- Shipping carriers — we provide carriers (such as USPS, UPS, FedEx, and DHL) with the name, address, phone number, and order details needed to deliver your order and provide tracking.
- Component manufacturers, suppliers, and authorized distributors — when a support case or RMA requires escalation to a component vendor or contract manufacturer for failure analysis or warranty processing, we may share relevant technical information. We limit the personal information we share to what is necessary, and we use anonymized or aggregated data where practical.
- Professional advisors — our attorneys, accountants, auditors, and insurers, who are subject to professional duties of confidentiality.
- Law enforcement and other authorities — when required by law, valid legal process (such as a subpoena, court order, or warrant), or where we believe in good faith that disclosure is necessary to protect our rights, the safety of any person, or the integrity of the Services. Where lawful and reasonable, we will notify the affected user.
- Corporate transactions — in connection with a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will require any successor entity to honor this Privacy Policy or to provide notice of any material changes.
- With your consent or at your direction — in any other case where you have specifically authorized disclosure.
SECTION 07
Third-Party Service Providers
The following categories of service providers may process personal information on our behalf. Each is bound by a written agreement that limits their use of the information to providing services to us. Specific vendors may change from time to time; we update this list when material changes occur.
Category
Purpose
Website & hosting
Hosting our website, securing connections, and serving content.
Payment processing
Authorizing, capturing, and reconciling payments under PCI-DSS.
Shipping & logistics
Generating labels, calculating rates, and delivering orders.
Email delivery
Sending transactional and (with consent) marketing email.
Customer support & CRM
Managing support tickets, RMA cases, and customer correspondence.
Analytics
Understanding aggregate visitor behavior to improve the Services.
Accounting & tax
Bookkeeping, invoicing, and tax compliance.
Export-control screening
Screening orders against US sanctions and restricted-party lists.
SECTION 08
Cookies & Tracking Technologies
We use cookies, local storage, tracking pixels, and similar technologies to operate the Services, remember your preferences, and understand how visitors use the site.
- Strictly necessary — required for core site functionality such as authenticated sessions, shopping carts, checkout, and basic security. These cannot be disabled without breaking the Services.
- Preference — remember non-essential choices such as language, currency, or layout preferences.
- Analytics — help us understand which pages are visited and how the site performs in aggregate. We do not use analytics cookies to build advertising profiles or to track you across unrelated websites.
Most browsers allow you to view, manage, or delete cookies through their settings. Blocking strictly necessary cookies may prevent parts of the Services from working correctly. Where supported by our analytics providers, we honor Do Not Track and Global Privacy Control browser signals.
SECTION 09
Support Tickets & RMA Data
Technical support and RMA processing require additional information beyond what is needed for a typical website visit. When you open a ticket or request an RMA, we may collect:
- Product serial numbers, hardware revisions, and firmware versions.
- A description of the problem, operating conditions, and environment.
- Photographs, video, oscilloscope captures, log files, telemetry, or other diagnostic data you choose to share.
- Return shipping information and proof of purchase, where applicable.
We use this information to diagnose the issue, process the return or repair, fulfill warranty obligations, and conduct internal failure analysis and quality tracking. Anonymized diagnostic data may be retained for engineering analysis after the case is closed. Photographs, video, and customer-identifying details are not used for marketing without separate, explicit consent.
SECTION 10
Export Control Compliance
Some of our products are subject to US export-control laws, including the Export Administration Regulations (EAR) and applicable sanctions administered by the Office of Foreign Assets Control (OFAC). To comply with these laws, we screen orders against US restricted-party and sanctioned-party lists. This screening involves transmitting your name, billing address, and shipping address to a third-party screening service. We may decline or hold orders that present a potential export-control concern and may share information with US government agencies when required by law.
SECTION 11
Data Retention
We keep personal information only as long as we need it for the purposes described in this Privacy Policy, or longer if required by law. Specific retention practices include:
- Order, billing, and tax records — retained for at least seven (7) years to comply with US federal and state tax and accounting requirements.
- Support and RMA records — retained for the warranty life of the product plus a reasonable period for quality tracking and failure analysis, typically no less than five (5) years from case closure.
- Account information — retained while your account is active. Inactive accounts may be deleted or anonymized after an extended period of inactivity. You may request deletion at any time, subject to the legal-hold exceptions described in Section 14.
- Marketing communications — retained until you unsubscribe or otherwise withdraw consent, after which we retain a minimal record (typically an email-address hash) to honor your opt-out.
- Web server and access logs — retained for up to ninety (90) days for security and operational diagnostics, after which they are deleted or anonymized.
- Aggregated and de-identified data — may be retained indefinitely, as it can no longer reasonably be linked to you.
SECTION 12
Information Security
We maintain an information-security program designed to protect personal information against unauthorized access, disclosure, alteration, and loss. Our safeguards include the following categories of controls.
Technical controls
- Encryption in transit — all traffic between your browser and our Services is encrypted using TLS 1.2 or higher. HTTP Strict Transport Security (HSTS) is enforced on production domains.
- Encryption at rest — customer records, support tickets, and order data are stored on systems that encrypt data at rest using industry-standard algorithms.
- Credential protection — account passwords are never stored in plaintext. We store only salted, one-way cryptographic hashes using a modern password-hashing function.
- Payment-card isolation — full card data never touches our servers. Payment fields are tokenized by our PCI-DSS-compliant payment processor, and only non-sensitive references (last four digits, card brand, expiration, transaction ID) are retained on our side.
- Network and endpoint security — production systems sit behind hardened network boundaries with managed firewalls, DDoS protection, and intrusion-detection logging. Administrative endpoints require up-to-date operating systems, full-disk encryption, and endpoint protection.
- Patch and vulnerability management — we apply security updates to operating systems, application frameworks, and dependencies on a routine schedule, with expedited remediation for critical vulnerabilities.
- Backups — production data is backed up on a regular schedule, with backups encrypted and access-controlled. Restoration procedures are tested periodically.
Administrative controls
- Access control — access to personal information is limited to authorized personnel with a documented need, governed by role-based permissions and the principle of least privilege.
- Multi-factor authentication — multi-factor authentication is required for administrative access to systems that store personal information, including our website backend, payment processor, email provider, and CRM.
- Vendor due diligence — we evaluate the security and privacy practices of service providers before engagement and require written contracts that obligate them to protect the information we share with them.
- Personnel training — staff with access to personal information receive privacy and security training appropriate to their role and refresh that training periodically.
- Confidentiality obligations — employees, contractors, and service providers are bound by written confidentiality obligations covering customer information.
- Incident response — we maintain a written incident-response procedure covering detection, containment, eradication, recovery, notification, and post-incident review.
Physical controls
- Facility security — physical access to our operating premises and to any on-site computing equipment is controlled and monitored.
- Hosted infrastructure — production systems are hosted in data centers operated by reputable providers that maintain recognized security certifications (such as SOC 2, ISO 27001, or equivalent).
- Media handling — storage media that contained personal information is securely wiped or physically destroyed before disposal.
No system is perfectly secure. While we use commercially reasonable measures appropriate to the sensitivity of the information we hold, we cannot guarantee absolute security. You can help protect your account by using a strong, unique password, enabling any multi-factor authentication options we offer, keeping your devices and browsers up to date, and contacting us immediately if you suspect unauthorized access.
SECTION 13
Breach Notification
If we determine that an incident has compromised the security, confidentiality, or integrity of personal information we hold, we will:
- Investigate and contain the incident.
- Notify affected users without unreasonable delay where required by law or where we believe notice is otherwise appropriate, using the contact information on file.
- Notify regulators, law-enforcement authorities, and other parties as required by applicable law.
- Provide a clear description of what happened, what information was involved (to the extent we can responsibly disclose it), the steps we have taken, and recommended steps you can take.
SECTION 14
Your Rights & Choices
You have a number of choices regarding the personal information we hold about you. To exercise any of the rights below, contact us using the information in Section 19. We will respond within the time required by applicable law and will not discriminate against you for exercising any right described here.
- Access — request confirmation of whether we hold personal information about you and a copy of that information.
- Correction — request that we correct information that is inaccurate or incomplete.
- Deletion — request that we delete personal information we hold about you. We may retain information we are legally required or permitted to keep, including for tax, accounting, warranty, security, fraud-prevention, or legal-hold purposes.
- Portability — request a copy of certain information in a portable, machine-readable format.
- Opt out of marketing — unsubscribe from marketing email at any time using the link included in each message, by adjusting your account preferences, or by contacting us. You will continue to receive non-marketing messages related to your orders, support cases, security, and account.
- Cookie controls — adjust browser settings to block or delete cookies, and use opt-out tools provided by analytics vendors.
- Authorized agents — where permitted by law, you may use an authorized agent to submit requests on your behalf. We may require verification of the agent's authority and your identity.
We may need to verify your identity before fulfilling a request, typically by matching information you provide with information we already hold.
SECTION 15
International Visitors
The Services are operated from the United States and are intended for users in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data-protection laws may differ from those of your country. By using the Services, you consent to that transfer and processing.
SECTION 16
Children's Privacy
The Services are not directed to children under thirteen (13), and we do not knowingly collect personal information from children under thirteen. If you are under eighteen (18), please do not provide us with personal information without the involvement of a parent or guardian. If you believe a child under thirteen has provided personal information to us, please contact us and we will take prompt steps to delete it.
SECTION 17
Third-Party Sites & Links
The Services may contain links to third-party websites, social-media platforms, datasheets, documentation hosted by component manufacturers, and other resources operated by parties we do not control. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
SECTION 18
Changes To This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the Effective Date and Last Updated dates at the top of this page and, where appropriate, provide additional notice (for example, by email or a prominent notice on the Services). Your continued use of the Services after a change takes effect constitutes acceptance of the updated Privacy Policy.
SECTION 19
Contact Us
If you have questions about this Privacy Policy, wish to exercise any of the rights described in Section 14, or want to report a concern about how we handle personal information, please contact us.
Privacy Contact
Intrusive Robotics LLC
Allentown, Pennsylvania, USA
© 2026 · Intrusive Robotics LLC · Allentown, PA
Designed Here · Built Here · Flown Here