Microsoft, Microsoft 365, Outlook, SharePoint, OneDrive, Microsoft Teams, Microsoft Graph, Azure, and Entra are trademarks of the Microsoft group of companies. ImpressionsDirect360 is an independent provider and is not affiliated with, sponsored by, or endorsed by Microsoft.
Last Updated: August 23, 2026
IMPRESSIONSDIRECT360 LLC ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of information we receive through our Services.
By accessing our platform, you consent to the data practices described in this policy. This policy is governed by the laws of the State of Missouri.
Managed Microsoft 365 customers: sections 1–8 describe how we handle your account with us. Where we administer your own Microsoft 365 tenant, we are handling your data on your behalf, and the Data Processing Addendum at the end of this page sets out that arrangement.
In order to better provide you with products and services offered, we may collect personally identifiable information, such as:
We collect and use your personal information to operate and deliver the services you have requested, including:
We do not sell, rent, or lease our customer lists to third parties. We may share data with trusted service providers to help perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries. Those service providers are permitted to use your personal information only to provide those services to us, and are required to keep it confidential. That restriction does not cover the advertising and analytics vendors described immediately below: they use what they collect for their own purposes as well as ours, and it would be untrue to tell you otherwise.
Advertising and analytics on our site. Two third-party scripts load on every page of ImpressionsDirect360, including pages you are signed in to: Google AdSense (publisher ID ca-pub-3671254323987566) and the TikTok advertising pixel. They receive ordinary web analytics — which pages you visit on our site, and device and browser information, including the IP address that any request to their servers necessarily carries — and they set and read their own cookies and identifiers. The TikTok pixel is also sent two commercial events: that a plan was viewed on the pricing page, with that plan's name and price, and that an account was created. Google and TikTok use that data for their own advertising and measurement purposes, which can include profiling and targeting you on other sites. We do not control that use and we cannot make a promise on their behalf.
Purchases are also reported to TikTok from our servers. When you start a checkout or complete a purchase, we send TikTok a conversion event containing the amount and currency, together with your email address, phone number and account id hashed with SHA-256 so TikTok can match the purchase to an ad without receiving the values in the clear. A hash is still an identity-matching key, so we would rather say so plainly than call this anonymous. Until August 23, 2026 the pixel was additionally sent those same details unhashed from your browser on every page; that was wrong, was never disclosed, and has been removed. There is currently no consent banner gating any of this.
What those scripts do not receive: the contents of a Microsoft 365 tenant we manage — mail, files, or calendar — or what you create in ID360 Studio. None of that is passed to them. On paid plans the ad unit is suppressed, but the plan check runs in your browser after the page has loaded, so the AdSense script will already have been requested by the time it finishes. We do not offer an in-product switch to turn these scripts off, and we will not describe one until we build it — blocking them in your browser or with an extension does work. Both vendors are named for completeness on our subprocessors page, although they are not subprocessors of customer data.
Disclosure for Law Enforcement: Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency), specifically including those within the jurisdiction of St. Louis, Missouri.
We secure your personal information from unauthorised access, use, or disclosure using industry-standard encryption protocols (SSL/TLS). However, no transmission of data over the Internet is guaranteed to be completely secure. It may be possible for third parties not under the control of ImpressionsDirect360 to intercept or access transmissions or private communications unlawfully.
This Privacy Policy is governed by the laws of the State of Missouri without regard to its conflict of laws provisions. Any dispute arising from this Policy or our data practices shall be resolved exclusively in the state or federal courts located in the City of St. Louis, Missouri.
ImpressionsDirect360 reserves the right to change this Privacy Policy from time to time. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address specified in your account or by placing a prominent notice on our site. Your continued use of the Services available through this Site after such modifications will constitute your: (a) acknowledgment of the modified Privacy Policy; and (b) agreement to abide by and be bound by that Policy.
ImpressionsDirect360 welcomes your questions or comments regarding this Statement of Privacy.
ImpressionsDirect360 Legal Dept.
Attn: Privacy Officer
St. Louis, Missouri
legal@impressionsdirect360.comAddendum A · Added August 23, 2026
This addendum applies to customers of our managed Microsoft 365 service — the service in which we administer a Microsoft 365 tenant that belongs to you. It describes how we handle the content inside that tenant. Sections 1–8 above continue to apply to your ImpressionsDirect360 account, billing, saved projects, and product records. Where the two disagree about tenant content, this addendum is the one that governs.
This is not legal advice.
This addendum was written in-house and published so you can review it. It has not been drafted or reviewed by an attorney, and nobody here is one. Have your own counsel review it before you rely on it or sign anything that references it. If your counsel needs a change, tell us — we would rather negotiate the wording than have you assume it.
For everything inside your Microsoft 365 tenant, you are the data controller and IMPRESSIONSDIRECT360 LLC is a processor acting on your behalf. You decide what data exists, who may see it, and how long it is kept. We do not sell your tenant content, share it for advertising, or use it to train models. We do keep operational records derived from it — details our automations extract from the mail they handle — because that is how the service runs and bills; section 6 sets out exactly what those records contain and where they sit.
We act only on your documented instructions, which are:
If we believe an instruction would break the law, we will say so before acting on it rather than quietly carrying it out. For your ImpressionsDirect360 account, billing records, saved projects, and product records, we are the controller and the sections above apply instead.
You buy and hold your own Microsoft 365 licences, in your own name. We do not resell Microsoft licences today — the tenant, the subscription, and the billing relationship with Microsoft are all yours.
Only what the automations and support you asked for actually touch:
The data subjects are your own staff and the people who correspond with them. You nominate the mailboxes, sites, and calendars the automations run against, and that is what they are configured to touch. Be clear about what that limit is: it is a setting in our configuration, not a boundary Microsoft enforces on us. The permissions our application actually holds are tenant-wide. Section 5 says how wide, and what you can do in your own tenant to narrow it.
The permission set is not negotiated per customer. There is one multitenant application with one fixed set of Microsoft Graph application permissions — Mail.ReadWrite, Mail.Send, Calendars.Read, Sites.ReadWrite.All, and User.Read.All — and every customer consents to the same five. Microsoft shows them to your administrator on its own consent screen before anything is approved. The permission list on our Microsoft 365 security page lists these same five. If the two ever differ, this page is the one to believe — and the Microsoft consent screen in your own tenant beats us both.
We do not ask for special categories of personal data and the service is not designed around them. We cannot stop such data arriving in a mailbox we process, so if it routinely will, raise it with us before onboarding — see the certification note in section 5.
Your tenant content is processed to deliver the automations and the support you configured, and to keep the operational and billing records that running them produces — described in section 6. We do not sell it, rent it, or share it for advertising, and we do not use it to train models — ours or anyone else's.
The AI paths, precisely. Qwen 3.8 Max is used only to create and refine websites through Vercel AI Gateway, and those calls require zero-data-retention-capable routing. The storefront assistant, logo prompts, and content tools use Google's Gemini API on Google's paid tier. A prompt is processed by the provider assigned to that feature and its response is returned to you. We keep no extra copy of the prompt beyond the customer records you choose to save and the operational record described in section 6.
Every AI action is metered per customer, because your plan includes a monthly allowance. Metering records that an action ran, for which customer, and its size for cost attribution — it is a billing record, not a copy of what the action was about.
The vendors that can touch your data on our behalf are listed, with what reaches each one and where they process it, at /trust/subprocessors. That page is the live list — we keep it current rather than restating a copy here that could drift out of date, and it carries the date it was last reviewed.
We use no subprocessor that is not on that page. When we add one, the page is updated. If you object to a new subprocessor, email support@impressionsdirect360.com and we will explain what it does and offer an alternative where one exists. Where none exists, you can cancel. Cancel anytime — your plan stays active until the end of the period you've paid for. Payments are non-refundable.
Described as they are today, not as a wish list:
What we do not have. We hold no SOC 2 report, no ISO 27001 certification, and no HIPAA attestation, and we have not been audited by a third party. Card payments are handled by Stripe, so card data never reaches our servers; that is Stripe's compliance, not ours. Our subprocessors hold certifications of their own — those are theirs, and we do not present them as ours.
Granular delegated administration (GDAP) is not what is in place today. GDAP is created through Microsoft Partner Center and our reseller enrolment has not completed, so we will not describe our access as delegated administration until it is true. Today it is the application consent described above: it has no built-in expiry date, and it ends when you revoke it.
The row-by-row version, including which vendor handles which category, is on the security page.
Your content. Mail bodies and documents live in your tenant and we hold no copy of them, so there is nothing of that kind for us to return at the end. We do not delete them. The single exception is an automation you configured to archive or delete on your own retention policy, with your sign-off; that acts on your instruction, not ours.
What we do hold is not nothing. The operational records in section 6 contain details extracted from your mail, and those are on our side. You can ask us for a copy of them, and you can ask us to delete them.
When the service ends. You revoke the application's consent in your own admin center and our access stops immediately; scheduled automations stop with it. Your tenant, licences, mail, files, and anything an automation filed for you are all unaffected and stay exactly where they are.
How long we keep our operational records. We keep them while your account is open, and afterwards where we still need them — billing, tax, and accounting records, and the automation record itself. There is no automated deletion schedule for any of it today. Nothing expires these records on a timer; they stay until somebody deletes them, and we are not going to claim a retention clock we do not run. Ask us what we hold about your account and we will send you a copy, delete what we are able to delete, and say plainly what we have to keep and why.
Your automation record. Email support@impressionsdirect360.com and we will send you the record of what our automations did in your tenant over the period you name. For access by a person here rather than by an automation, the record is Microsoft's audit log in your own tenant, not ours — see section 5.
Rights requests. If someone exercises a data protection right — access, correction, deletion, export — and you need our help, email support@impressionsdirect360.com. Because the mail and files sit in your own tenant, you can often action a request yourself with Microsoft's tools faster than we can; where you cannot, we will help you find, export, correct, or delete it. The extracted details in our own operational records are ours to search, not yours — tell us the request covers those too and we will include them. As a processor we answer to you, not to your staff or your customers directly, so we will refer a request that reaches us straight to you unless you ask us to handle it. Requests are worked during our support hours, Monday–Friday, 9:00 AM – 6:00 PM Central, under the response target for your plan.
Breach notification. If we become aware of a personal data breach affecting your tenant data, we will notify you without undue delay with what we know at the time: what happened, which of your data was involved as far as we can tell, what we have done, what we are still doing, and anything we need from you. If the picture is incomplete we will say so rather than wait for a tidy story, and we will follow up as it changes.
We do not quote a fixed notification clock in hours, because we do not yet run the round-the-clock monitoring that would let us honour one. How to report a suspected incident to us, and what we do in the first hours, is on /trust/incident-response.
IMPRESSIONSDIRECT360 LLC
A Missouri limited liability company
701 Market St Ste 110 #2008
Saint Louis, MO 63101-1824
Support hours: Monday–Friday, 9:00 AM – 6:00 PM Central