Privacy Policy

Last updated: August 15, 2026

This Privacy Policy describes how Pludo Inc. (dba Cashmere) ("Cashmere," "we," "us," or "our") collects, uses, and shares personal information. Cashmere provides an AI-powered client intelligence platform for financial institutions such as banks (the "Services"), and operates the website at www.cashmereai.com (the "Site").

This policy covers four contexts, because our obligations differ in each:

  1. Site visitors. People who browse the Site or contact us through it.
  2. Business contacts. People we communicate with for sales, marketing, partnerships, or support.
  3. Enrichment Data. Information about individuals and organizations that we collect from public sources and licensed data providers to power the Services.
  4. Customer Data. Information our customers (the financial institutions that license the Services) submit to the platform. For Customer Data, we act as a service provider processing information on our customers' behalf; that processing is governed by our written agreements with each customer, not by this policy, except as described in Section 6.

1. Information we collect

Site visitors. The public marketing pages of the Site do not set cookies and do not run analytics or advertising trackers. When you visit the Site, our hosting provider processes standard server data (such as IP address and browser type) to deliver pages and maintain security. If you submit our contact form, we collect the information you provide: name, email address, company, and your message. A small number of unlisted demo pages (used for private video walkthroughs we share directly with specific recipients) use analytics that record page views and video playback progress; those pages are not part of the public Site navigation.

Business contacts. If you correspond with us, attend an event or demo, or are a prospective or current customer contact, we collect the information you share with us (name, title, employer, contact details, communication history) and may supplement it with professional information from the sources described below. If you sign in to the Services as an authorized user (for example, through the dashboard), we also collect your account information and usage data, such as IP address, session activity, and feature usage, to operate, secure, and improve the Services.

Enrichment Data. To provide the Services, we collect and license information about individuals, companies, and other entities. This can include: name, job title and employer, business contact information, education and career history, corporate affiliations and roles, property ownership records, and wealth-related and demographic signals derived from public records. Sources include public websites and web-scraping, government and regulatory filings, court and other public records, news and other publicly available media, and licensed third-party data providers. We do not collect this information directly from the individuals it describes.

Customer Data. Customers may submit their own records to the Services, such as CRM records, client lists, communications metadata, and related business information. What a customer submits is determined by that customer. The Services do not require sensitive information such as health information, Social Security numbers, or driver's license numbers, and we direct customers not to submit it.

2. How we use information

We use the information described above to:

  • provide, operate, secure, and support the Site and the Services, including resolving identities and enriching records as directed by our customers;
  • respond to inquiries and manage customer and prospect relationships, including sending communications you may opt out of at any time;
  • conduct research and development, using de-identified or aggregated data where practicable, to build and improve the Enrichment Data that powers the Services;
  • comply with law, enforce our agreements, and protect the rights, safety, and property of Cashmere, our customers, and others.

We do not share Customer Data across customers; no customer's Customer Data appears in the Enrichment Data or in the results delivered to another customer. We do not use Enrichment Data or Customer Data to make decisions about individuals' eligibility for credit, insurance, employment, housing, or similar benefits, and we contractually prohibit our customers from using the Services for those purposes. Cashmere is not a consumer reporting agency, and the Services do not provide consumer reports as defined in the Fair Credit Reporting Act.

3. How we share information

We share personal information with:

  • Our customers. The core function of the Services is delivering Enrichment Data and related insights to the financial institutions that license the Services. Under the California Consumer Privacy Act ("CCPA"), this disclosure may be considered a "sale" or "sharing" of personal information. You can opt out at any time (see Section 7).
  • Service providers that process information on our behalf, under contracts limiting their use of it, including: website hosting, contact-form processing, cloud infrastructure, data vendors, analytics, and business tools such as email and CRM. We share with each provider only the information needed to perform its function, and lookups sent to data vendors do not identify our customers or whose records prompted them.
  • Professional advisors such as lawyers, auditors, and insurers, where reasonably necessary.
  • Authorities and other parties when required by law, such as in response to a subpoena or other legal process, or to protect rights, safety, and property.
  • Parties to a corporate transaction (merger, acquisition, financing, or sale of assets), in which case personal information may be transferred as part of that transaction subject to this policy.

We do not share personal information with third parties for their own cross-context behavioral advertising.

4. Cookies and tracking

The public marketing pages of the Site set no cookies. The unlisted demo-video pages described in Section 1 use analytics cookies to measure viewing; those pages are excluded from search indexing and reachable only by direct link. We treat opt-out preference signals such as Global Privacy Control as valid requests to opt out of sale or sharing; because we do not sell or share information collected from your browser, these signals currently have no further effect. We do not respond to legacy "Do Not Track" signals.

5. Retention

We keep personal information only as long as reasonably necessary for the purposes described in this policy, and then delete or de-identify it. In general: contact-form submissions and business-contact records are kept while we have an active relationship or legitimate business need; Enrichment Data is retained while it remains relevant to the Services and is refreshed or removed as sources change or when we honor a deletion request; Customer Data is retained as directed by the customer and deleted following termination of the customer agreement in accordance with its terms. We may retain information longer where required by law or to resolve disputes.

6. Our role as service provider

When we process Customer Data, we do so on behalf of and at the direction of the customer that submitted it, as a "service provider" (or equivalent role) under applicable privacy laws. The customer, not Cashmere, decides what is collected and why. If you have questions about information your financial institution has submitted to the Services — or want to access, correct, or delete it — please contact that institution directly; we will support their response as required by our agreement with them. If you contact us directly about Customer Data, we will refer your request to the relevant customer where we can identify them.

7. Your privacy rights

If you are a California resident, the CCPA gives you the right to:

  • Know what personal information we collect about you, the sources, purposes, and the categories of third parties we disclose it to;
  • Access the specific pieces of personal information we hold about you;
  • Delete personal information we have collected about you;
  • Correct inaccurate personal information;
  • Opt out of the "sale" or "sharing" of your personal information;
  • Limit the use of sensitive personal information, to the extent we process any for purposes beyond those permitted by the CCPA; and
  • Not be discriminated against for exercising any of these rights.

Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and Texas) may have similar rights, which we honor where they apply. If we deny your request, you may appeal by replying to our response; where state law provides, you may contact your state attorney general if your appeal is denied.

How to submit a request. Email privacy@cashmereai.com. Tell us which right you are exercising and the email address (and, if helpful, the name and employer) associated with your information. We will respond within the time required by law. An authorized agent may submit a request on your behalf; we require proof of the agent's authorization and may confirm the request with you directly.

Opting out of sale or sharing. We do not require verification for opt-out requests. Once we process your opt-out, we stop selling or sharing your personal information and add associated identifiers to a suppression list so the information is not re-collected into the data we deliver to customers.

Requests to know, access, correct, or delete. We verify these requests, typically by confirming your control of the email address associated with the information, or by asking for additional information where needed. Some Enrichment Data is "publicly available" information as defined by the CCPA and excluded from that law's definition of personal information; we honor deletion requests for it anyway, deleting the information we hold about you and suppressing it from re-collection as described above.

California data broker registration. Cashmere is registered as a data broker with the California Privacy Protection Agency. In addition to contacting us directly, California residents may submit a single deletion request to all registered data brokers through the CPPA's Delete Request and Opt-Out Platform (DROP); we access and process DROP requests at least every 45 days as required by law.

Requests concerning Customer Data are handled as described in Section 6.

California disclosure details

Categories of personal information (as defined in Cal. Civ. Code § 1798.140) we have collected in the preceding 12 months:

CategorySourcesPurposesSold or shared toRetention
Identifiers (name, business contact details)Public sources; licensed vendors; you (contact form, correspondence)Services and enrichment; communicationsCustomers (Enrichment Data only)While relevant to the Services or to our relationship with you
Professional or employment-related informationPublic sources; licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Education informationPublic sources; licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Commercial information (corporate affiliations, roles, property ownership records)Public records, court filings, and licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Characteristics of protected classifications (e.g., age, gender, marital status, where part of demographic data)Public sources, court filings, and licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Inferences (wealth-related and demographic signals)Derived from the categories aboveServices and enrichmentCustomersWhile relevant to the Services
Internet or network activity (authorized-user sessions in the Services; unlisted demo-video pages)AnalyticsOperate, secure, and improve the Services; measure engagementNot sold or sharedWhile needed to operate and secure the Services

We do not collect biometric information, precise geolocation, audio or sensory data, or health or financial-account information in the ordinary course of our business.

8. Security

We maintain a formal information security program, including encryption of data in transit and at rest, access controls, continuous vulnerability management, and third-party security assessments. Cashmere is SOC 2 Type 2 compliant. No system is perfectly secure, and we cannot guarantee absolute security; if we become aware of a breach affecting your personal information, we will notify affected parties as required by law. Security questions or reports: security@cashmereai.com.

9. Children

The Site and the Services are intended for business use and are not directed to anyone under 16. We do not knowingly collect personal information from children, and we do not sell or share the personal information of consumers we have actual knowledge are under 16 years of age. If you believe we have collected information about a child, contact privacy@cashmereai.com and we will delete it.

10. Where information is processed

Cashmere is based in the United States, and the Site and Services are operated from and intended for use in the United States. If you access the Site from outside the U.S., you understand that your information will be processed in the U.S., where laws may differ from those of your jurisdiction.

11. Changes to this policy

We may update this policy from time to time. We will post the revised version here and update the "Last updated" date above; for material changes, we will provide more prominent notice (for example, on the Site or by email to affected contacts).

12. Contact us

Privacy requests and questions: privacy@cashmereai.com
Security: security@cashmereai.com
Mail: Pludo Inc. (dba Cashmere), 8500 Steller Dr, Unit 1, Culver City, CA 90232