BIG Intelligence Nexus — Privacy Policy

Effective date: July 17, 2026 Last updated: July 17, 2026

BIG INTELLIGENCE AI, LLC, a Michigan limited liability company ("BIG Intelligence," "we," "us," or "our"), operates the Nexus platform at https://truthgap.bigintelligenceai.com (the "Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use it, who processes it on our behalf, and the choices you have.

If you have a question about this Policy or want to exercise any of your rights, email us at support@bigintelligenceai.com.

1. What we collect

1.1 Information you give us

  • Email address — used as your account identifier for passwordless sign-in and to send you invoices and Report-delivery messages.
  • First name — captured at sign-up so we can render "Welcome back, [Name]" on the site.
  • Purchase details — the vehicles you buy Reports for, the invoice number, the amount, whether the transaction consumed a free credit, and any redeemed credits' history.
  • Support correspondence — anything you send to support@bigintelligenceai.com.
  • Dealer-lead information (when you opt in to a dealer-matching form) — the phone number and ZIP code you provide, and the vehicle you selected, so we can prioritize dealer matches. Phone is required in our "Find Your Next Car" (Tier 3) flow and optional in our lower-friction dealer-interest form.

1.2 Information from Stripe (our payment processor)

When you complete a paid purchase, Stripe processes the transaction. Stripe returns limited data that we store on the payment record:

  • Card last four digits, card brand, and card expiration month/year;
  • Billing name, billing email, and the billing address (line, city, state, ZIP, country) that Stripe returns to us for the transaction;
  • The customer name entered at checkout;
  • Stripe session, payment intent, and customer identifiers; and invoice number, amount, currency, and status.

We do not receive or store your full card number, card verification value (CVV), or bank credentials. Card data is handled by Stripe under Stripe's own privacy notice at stripe.com/privacy. For payment processing purposes, Stripe acts as an independent controller of the data it collects at checkout; we act as an independent controller of the limited payment metadata Stripe returns to us.

1.3 Information we generate as you use the Service

  • Session tokens — random opaque tokens issued after email verification and stored in a browser cookie (nexus_session) to keep you signed in. A companion cookie (nexus_name) stores your first name for personalization only.
  • Search / view history — when you visit a vehicle page, comparison, or segment page, we record the vehicle slug, the vehicle name, the page type ("vehicle_page," "compare," or "segment"), and a timestamp, along with your session token and — if you are signed in — your email. We use this to render your "Recently Viewed" list on your account page and to understand product usage.
  • Server logs and analytics — routine web-server metadata that may include IP address, browser user-agent string, referring URL, timestamps, and error diagnostics used to operate and secure the Service.

1.4 Cookies

We use a small number of first-party cookies:

  • `nexus_session` — session token; required for sign-in and to persist your entitlements. Cookie lifetime is up to 365 days; it is cleared when you sign out.
  • `nexus_name` — your first name for on-site personalization.
  • Hosting/security telemetry cookies used by our hosting provider (Vercel) for load-balancing, session pinning, and abuse detection.

We do not currently deploy third-party advertising cookies, retargeting pixels, or cross-site tracking pixels. If that changes, this Policy will be updated and, where required by law, we will present a cookie-consent notice before the new cookies are set.

2. Why we use this information

We process personal information to:

  • Deliver the Service you asked for — verify your email, sign you in, take payment, deliver your PDF Reports, send invoices and confirmations, and provide support;
  • Enforce entitlements — check that a signed download link belongs to a valid paid or credit-based session, and that a purchased Report is delivered to the right customer;
  • Prevent fraud and abuse — detect duplicate charges, unusual purchase patterns, and misuse of free credits;
  • Improve the Service — understand which vehicles are viewed and where the product needs work;
  • Comply with law — respond to lawful requests, keep required records, and defend our legal rights.

3. Who processes information on our behalf

We use a small set of vetted service providers ("processors") to run the Service. Each receives only the data it needs to perform its role and is bound by its own contractual and legal privacy obligations. If you sign up or purchase, your data may be processed by:

  • Vercel — application hosting for the Next.js website and API routes. Vercel also provides Vercel Blob, which stores your Report PDFs and issues expiring signed download URLs.
  • Neon — Postgres database hosting for account, session, purchase, and search-history records.
  • Stripe — payment processing. Stripe acts as an independent controller (see Section 1.2).
  • Resend — transactional email delivery (email verification codes, invoices, Report-delivery messages, and support-related notifications).

We do not sell your personal information. We do not share your personal information with third parties for their own marketing purposes.

We may disclose information without your prior consent if we believe in good faith that disclosure is required to comply with legal process, enforce our Terms of Service, protect the safety of any person, or defend against legal liability.

If we are ever involved in a merger, acquisition, financing due diligence, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to the acquirer's commitment to honor the material terms of this Policy.

4. How Report PDFs are delivered and stored

Your purchased PDFs are stored in Vercel Blob. When you buy a Report or exercise a free credit, we mint a signed download link that expires 24 hours after issuance and email it to you through Resend. You can log into your account at any time to re-generate a fresh 24-hour link. The signed link itself carries the token that authorizes the download; keep it private.

5. Data retention

We keep personal information only as long as we need it for the purposes described above, or as required by law.

  • Account and session records — retained while the session is active (session cookie lifetime is up to 365 days) and for a reasonable audit window after expiry.
  • Purchase records (invoice, amount, card last-4 and brand, billing address, Stripe identifiers) — retained for seven (7) years for accounting, tax, chargeback-defense, and audit purposes.
  • Search / view history — retained on a rolling basis to support the "Recently Viewed" feature and product analytics.
  • Support correspondence — retained for a reasonable period after resolution.
  • Server logs — retained for a short operational window, then rotated.

When we no longer need personal information, we delete it or de-identify it, subject to any legal-hold or audit-hold obligation.

6. Your choices and how to reach us

You can:

  • Sign out at any time — this clears the session cookie in your browser and ends the active session.
  • Request access to the personal information we hold about you.
  • Request correction of information that is inaccurate.
  • Request deletion of your account and associated personal information, subject to the retention obligations described in Section 5.

To exercise any of these rights, email support@bigintelligenceai.com from the email address on your account. We may verify your identity by responding to that address before acting on any request.

7. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA") gives you the following rights:

  • Right to know what personal information we collect, use, disclose, and (if applicable) sell or share about you;
  • Right to delete personal information we hold about you, subject to legal exceptions;
  • Right to correct inaccurate personal information;
  • Right to opt out of sale or sharing of personal information (including for cross-context behavioral advertising);
  • Right to limit the use of sensitive personal information;
  • Right to non-discrimination — we will not deny service, charge different prices, or provide a different level of quality because you exercised a CCPA right.

Do we sell or share your personal information? No. We do not "sell" personal information as defined by the CCPA, and we do not "share" personal information for cross-context behavioral advertising. We have not done so in the twelve (12) months preceding the Effective date of this Policy.

Categories of personal information we collect (using CCPA categories):

  • Identifiers (email address, IP address, session token);
  • Commercial information (purchase history, invoice details);
  • Internet or other electronic-network activity (pages viewed, referring URL, user-agent);
  • Inferences drawn from the above (for example, which vehicles you are comparing).

We collect these categories for the purposes described in Section 2 and share them with the processors described in Section 3.

How to submit a California request. Email support@bigintelligenceai.com with the subject line "California Privacy Request." We may need to verify your identity before processing. We will respond within the timeframes required by the CCPA. You may designate an authorized agent to submit a request on your behalf; your agent will need to provide proof of authorization.

8. European visitors (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following also applies.

Data controller. BIG INTELLIGENCE AI, LLC, a Michigan limited liability company, is the controller of the personal information described in this Policy. You can contact the controller at support@bigintelligenceai.com.

Lawful bases for processing. We rely on:

  • Contract performance (Article 6(1)(b)) — to verify your email, sign you in, take payment, and deliver your Reports;
  • Legitimate interests (Article 6(1)(f)) — to prevent fraud, secure the Service, and improve the product, balanced against your rights and interests;
  • Legal obligation (Article 6(1)(c)) — to keep required records and respond to lawful requests;
  • Consent (Article 6(1)(a)) — where we ask for it (for example, for optional communications you opt into).

Your rights. You have rights of access, rectification, erasure, restriction, portability, and objection, and — where processing is based on consent — the right to withdraw consent at any time. To exercise these rights, email support@bigintelligenceai.com. You also have the right to lodge a complaint with your local supervisory authority.

International data transfers. Our servers and processors are located primarily in the United States. When personal information is transferred from the EEA, the United Kingdom, or Switzerland to the United States, we rely on the mechanisms permitted under applicable law (for example, standard contractual clauses in place between us and our processors, and the corresponding transfer safeguards our processors have adopted). You can request more information about transfer safeguards by emailing us at the address above.

Retention. As described in Section 5.

9. Children's privacy

The Service is not directed to children under thirteen (13), or under sixteen (16) in jurisdictions where sixteen is the applicable minimum age for online consent. We do not knowingly collect personal information from children under those ages. If you are a parent or guardian and believe we have collected personal information from a child, contact us at support@bigintelligenceai.com and we will delete it.

10. Security

We use industry-standard practices to protect personal information: TLS in transit, access-controlled managed databases, secret rotation for API and webhook credentials, least-privilege access to production systems, and signed short-lived URLs for Report downloads. Card data is handled by Stripe under the Payment Card Industry Data Security Standard (PCI DSS); we do not receive or store full card numbers. No system is perfectly secure. If we suffer a data-security incident that requires notification under applicable law, we will notify affected users and regulators as required and on the timelines required by law.

11. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date at the top of this page and, for material changes, take reasonable steps to notify existing account holders (for example, by email to the address on file, or by an on-site notice). Continued use of the Service after the effective date of an updated Policy constitutes acceptance of the updated Policy.

12. Contact

BIG INTELLIGENCE AI, LLC A Michigan limited liability company support@bigintelligenceai.com