Privacy Policy

Last updated: September 14, 2026

This Privacy Policy describes how Pludo Inc. (dba Cashmere) ("Cashmere," "we," "us," or "our") collects, uses, and shares personal information. Cashmere provides an AI-powered client intelligence platform for financial institutions such as banks (the "Services"), and operates the website at www.cashmereai.com (the "Site").

This policy covers four contexts, because our obligations differ in each:

  1. Site visitors. People who browse the Site or contact us through it.
  2. Business contacts. People we communicate with for sales, marketing, partnerships, or support.
  3. Enrichment Data. Information about individuals and organizations that we collect from public sources and licensed data providers to power the Services.
  4. Customer Data. Information our customers (the financial institutions that license the Services) submit to the platform. For Customer Data, we act as a service provider processing information on our customers' behalf; that processing is governed by our written agreements with each customer, not by this policy, except as described in Section 6.

1. Information we collect

Site visitors. The public marketing pages of the Site do not set cookies and do not run analytics or advertising trackers. When you visit the Site, our hosting provider processes standard server data (such as IP address and browser type) to deliver pages and maintain security. If you submit our contact form, we collect the information you provide: name, email address, company, and your message. A small number of unlisted demo pages (used for private video walkthroughs we share directly with specific recipients) use analytics that record page views and video playback progress; those pages are not part of the public Site navigation.

Business contacts. If you correspond with us, attend an event or demo, or are a prospective or current customer contact, we collect the information you share with us (name, title, employer, contact details, communication history) and may supplement it with professional information from the sources described below. If you sign in to the Services as an authorized user (for example, through the dashboard), we also collect your account information and usage data, such as IP address, session activity, and feature usage, to operate, secure, and improve the Services.

Enrichment Data. To provide the Services, we collect and license information about individuals, companies, and other entities. This can include: name, job title and employer, business contact information, education and career history, corporate affiliations and roles, property ownership records, and wealth-related and demographic signals derived from public records. Sources include public websites and web-scraping, government and regulatory filings, court and other public records, news and other publicly available media, and licensed third-party data providers. We do not collect this information directly from the individuals it describes.

Customer Data. Customers may submit their own records to the Services, such as CRM records, client lists, communications metadata, and related business information. What a customer submits is determined by that customer. The Services do not require sensitive information such as health information, Social Security numbers, or driver's license numbers, and we direct customers not to submit it.

2. How we use information

We use the information described above to:

  • provide, operate, secure, and support the Site and the Services, including resolving identities and enriching records as directed by our customers;
  • respond to inquiries and manage customer and prospect relationships, including sending communications you may opt out of at any time;
  • conduct research and development, using de-identified or aggregated data where practicable, to build and improve the Enrichment Data that powers the Services;
  • comply with law, enforce our agreements, and protect the rights, safety, and property of Cashmere, our customers, and others.

We do not share Customer Data across customers; no customer's Customer Data appears in the Enrichment Data or in the results delivered to another customer. We do not use Enrichment Data or Customer Data to make decisions about individuals' eligibility for credit, insurance, employment, housing, or similar benefits, and we contractually prohibit our customers from using the Services for those purposes. Cashmere is not a consumer reporting agency, and the Services do not provide consumer reports as defined in the Fair Credit Reporting Act.

3. How we share information

We share personal information with:

  • Our customers. The core function of the Services is delivering Enrichment Data and related insights to the financial institutions that license the Services. Under applicable privacy laws, this disclosure may be considered a "sale" or "sharing" of personal information. You can opt out at any time (see Section 7).
  • Service providers that process information on our behalf, under contracts limiting their use of it, including: website hosting, contact-form processing, cloud infrastructure, data vendors, analytics, and business tools such as email and CRM. We share with each service provider only the personal information necessary for that service provider to perform its function. When we query vendors to enrich or verify those records, those queries do not reveal the identity of the customers on whose behalf the query is made.
  • Professional advisors such as lawyers, auditors, and insurers, where reasonably necessary.
  • Authorities and other parties when required by law, such as in response to a subpoena or other legal process, or to protect rights, safety, and property.
  • Parties to a corporate transaction (merger, acquisition, financing, or sale of assets), in which case personal information may be transferred as part of that transaction subject to this policy.

We do not make personal information available to third parties for targeted advertising or cross-context behavioral advertising.

4. Cookies and tracking

Cookies on the public Site. The public marketing pages of the Site do not set cookies or use tracking technologies.

Unlisted demo pages. A small number of unlisted demo-video pages, described in Section 1, use analytics cookies to measure video viewing activity. These pages are not indexed by search engines and are accessible only by direct link.

Opt-out preference signals. Our Enrichment Data is collected from public sources and licensed data providers rather than from consumers online through browsers or devices. Accordingly, the Site is not currently configured to detect or respond to opt-out preference signals such as Global Privacy Control (GPC). If we begin selling or sharing personal information collected through the Site in the future, we will update this policy and implement processes to honor opt-out preference signals as required by applicable law. You may opt out of the sale or sharing of Enrichment Data by submitting a request as described in Section 7 (How to submit a request).

Do Not Track. We do not respond to legacy “Do Not Track” browser signals, as there is no industry-standard protocol for honoring them.

5. Retention

We keep personal information only as long as reasonably necessary for the purposes described in this policy, and then delete or de-identify it. In general: contact-form submissions and business-contact records are kept while we have an active relationship or legitimate business need; Enrichment Data is retained while it remains relevant to the Services and is refreshed or removed as sources change or when we honor a deletion request; Customer Data is retained as directed by the customer and deleted following termination of the customer agreement in accordance with its terms. We may retain information longer where required by law or to resolve disputes.

6. Our role as service provider

When we process Customer Data, we do so on behalf of and at the direction of the customer that submitted it, as a "service provider" (or equivalent role) under applicable privacy laws. The customer, not Cashmere, decides what is collected and why. If you have questions about information your financial institution has submitted to the Services — or want to access, correct, or delete it — please contact that institution directly; we will support their response as required by our agreement with them. If you contact us directly about Customer Data, we will refer your request to the relevant customer where we can identify them.

7. Your privacy rights

Depending on your state of residence, applicable privacy law may give you the right to:

  • Know what personal information we collect about you, the sources, purposes, and the categories of third parties we disclose it to;
  • Access the specific pieces of personal information we hold about you;
  • Delete personal information we have collected about you;
  • Correct inaccurate personal information;
  • Opt out of targeted advertising and the "sale" or "sharing" of your personal information;
  • Limit the use of sensitive personal information, to the extent we process any for purposes beyond those permitted by applicable privacy law; and
  • Not be discriminated against for exercising any of these rights.

Residents of other U.S. states with comprehensive privacy laws may have similar additional rights, which we honor where they apply. Available rights may vary by state and include the right to opt out of certain profiling. If we deny your request, you may appeal by replying to our response.

How to submit a request. Email privacy@cashmereai.com. Tell us which right you are exercising and the email address (and, if helpful, the name and employer) associated with your information. We will respond within the time required by law. An authorized agent may submit a request on your behalf; we require proof of the agent's authorization and may confirm the request with you directly.

Opting out of sale or sharing. You may opt out of the sale or sharing of your personal information by submitting a request according to the instructions in the “How to submit a request” section above. Because browser-based opt-out signals alone may not identify your personal information within our Enrichment Data, we may request additional information by email to match our records. Once we process your opt-out, we stop selling or sharing your personal information and add associated identifiers to a suppression list so the information is not re-collected into the data we deliver to customers.

Requests to know, access, correct, or delete. We verify these requests, typically by confirming your control of the email address associated with the information, or by asking for additional information where needed. Some Enrichment Data may include information that is "publicly available" information as defined by the applicable privacy law and may be excluded from the applicable definition of personal information. However, inferences we derive from publicly available information are subject to your privacy rights. We honor deletion and access requests regardless of whether the underlying source data is publicly available.

California data broker registration. Cashmere is registered as a data broker with the California Privacy Protection Agency. In addition to contacting us directly, California residents may submit a single deletion request to all registered data brokers through the CPPA's Delete Request and Opt-Out Platform (DROP); we access and process DROP requests at least every 45 days as required by law.

California “Shine the Light” disclosure. Under California Civil Code § 1798.83, California residents may request information regarding the disclosure of their personal information to third parties for those third parties’ direct marketing purposes. Cashmere discloses Enrichment Data, which may include your name, business contact information, professional and employment-related information, education history, corporate affiliations, and demographic data, to our financial institution customers, who may use that information for their own direct marketing purposes, such as client acquisition and prospecting outreach. As permitted under § 1798.83(b), rather than providing an individualized accounting of third-party recipients upon request, we offer you the ability to opt out of such disclosures. To opt out, contact us at privacy@cashmereai.com or use the opt-out process described above.

Requests concerning Customer Data are handled as described in Section 6.

California disclosure details

Categories of personal information (as defined in Cal. Civ. Code § 1798.140) we have collected in the preceding 12 months:

CategorySourcesPurposesSold or shared toRetention
Identifiers (name, business contact details)Public sources; licensed vendors; you (contact form, correspondence)Services and enrichment; communicationsCustomers (Enrichment Data only)While relevant to the Services or to our relationship with you
Professional or employment-related informationPublic sources; licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Education informationPublic sources; licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Commercial information (corporate affiliations, roles, property ownership records)Public records, court filings, and licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Characteristics of protected classifications (e.g., age, gender, marital status, where part of demographic data)Public sources, court filings, and licensed vendorsServices and enrichmentCustomersWhile relevant to the Services
Inferences (wealth-related and demographic signals)Derived from the categories aboveServices and enrichmentCustomersWhile relevant to the Services
Internet or network activity (authorized-user sessions in the Services; unlisted demo-video pages)AnalyticsOperate, secure, and improve the Services; measure engagementNot sold or sharedWhile needed to operate and secure the Services

We do not collect biometric information, precise geolocation, audio or sensory data, or health or financial-account information in the ordinary course of our business.

8. Security

We maintain a formal information security program, including encryption of data in transit and at rest, access controls, continuous vulnerability management, and third-party security assessments. Cashmere is SOC 2 Type 2 compliant. No system is perfectly secure, and we cannot guarantee absolute security; if we become aware of a breach affecting your personal information, we will notify affected parties as required by law. Security questions or reports: security@cashmereai.com.

9. Children

The Site and the Services are intended for business use and are not directed to anyone under 18. We do not knowingly collect personal information from children, and we do not sell or share the personal information of consumers we have actual knowledge are under 18 years of age. If you believe we have collected information about a child, contact privacy@cashmereai.com and we will delete it.

10. Where information is processed

Cashmere is based in the United States, and the Site and Services are operated from and intended for use in the United States. If you access the Site from outside the U.S., you understand that your information will be processed in the U.S., where laws may differ from those of your jurisdiction.

11. Changes to this policy

We may update this policy from time to time. We will post the revised version here and update the "Last updated" date above; for material changes, we will provide more prominent notice (for example, on the Site or by email to affected contacts).

12. Contact us

Privacy requests and questions: privacy@cashmereai.com
Security: security@cashmereai.com
Mail: Pludo Inc. (dba Cashmere), 8500 Steller Dr, Unit 1, Culver City, CA 90232