TEXAS GATEWAY ALLIANCE

Privacy Policy

How information is handled when you visit TGA, apply for access, use TGA AI or request an introduction.

Updated September 8, 2026 · Draft version 2026-09-08

1. Scope and contact

This notice describes information handled through the Texas Gateway Alliance website and member workspace. It covers visitors, applicants, organization contacts and users of TGA AI and introductions. Third-party websites, banks and service providers have their own privacy practices.

For privacy questions or requests, contact admin@tgaalliance.com. This is the TGA service contact; the operator’s final legal identification and this draft remain subject to confirmation before the public launch.

2. Information collected

Information you provide can include your name, email and business contact details; company and role information; application, onboarding and project details; profile publication choices; introduction messages; uploaded documents; and support correspondence.

We also handle account identifiers, roles, authentication and security events, consent and workflow records, AI questions and responses, saved items and usage information. Public business records and program information may come from government or other identified sources. Public availability does not make every use of personal information appropriate.

3. Why information is used

We use relevant information to review applications, authenticate users, manage organization access, provide research and AI features, publish authorized profiles, process introductions, send service notifications and respond to requests.

Information is also used to operate and improve the service, understand usage, troubleshoot failures, protect accounts, prevent abuse, maintain workflow records and address applicable legal obligations or disputes.

4. TGA AI and conversation history

When you use AI features, your question and relevant conversation or retrieved context can be sent to the configured AI processing service to generate a response. Conversation messages may be stored to provide history and support the feature.

The current implementation includes Anthropic-based processing and a TGA AI runtime. Do not assume prompts stay only in your browser or that third-party retention is zero. Provider handling depends on the applicable service configuration and contract; this draft does not promise that every provider excludes all data from training. Avoid unnecessary personal or confidential information.

5. Cookies, analytics and session recording

Cookies and similar storage support authentication, language preferences, application continuation and other service functions. Blocking them can prevent those functions from working.

The production application is configured to use PostHog analytics, automatic interaction capture and session recording when enabled and configured. These can include page activity, device/browser information, identifiers and content visible on screen, including business information or AI conversation text. Input-field masking alone does not mean all displayed text is masked.

A dedicated analytics preference panel is not currently available. Contact us about analytics-related requests. Browser controls can limit some storage, but are not a guarantee that all analytics stops. We must review applicable notice, choice and masking requirements before wider public use.

6. Recipients and service providers

Information needed for operations may be processed by hosting and infrastructure, authentication/database/storage, email, AI and analytics providers. Current services include Vercel, Supabase, Resend, Anthropic and PostHog, as applicable to the feature and deployment. This list describes processing functions, not a promise that every provider receives every category of information.

Authorized organization users and TGA staff may access information as needed for their roles. Profiles and introduction details are shared according to the publication, request and acceptance workflow and the choices presented to you. We do not describe every business record as confidential or every profile as public.

Information may also be disclosed where required by law or reasonably necessary to address fraud, security incidents, legal claims or protection of rights. A bank or other partner may collect additional information directly under its own notice; TGA contact sharing does not authorize unrelated uses of that information.

7. Retention and deletion

Retention depends on the type of record and the purpose for keeping it, including account operations, application review, conversation history, introduction and consent records, security, dispute handling and legal requirements. No single fixed retention period applies to every category in this draft.

Closing an account or removing a screen item does not necessarily delete audit records, backups or third-party copies. Some historical workflow records are append-only. A deletion request requires checking what can be removed, what must be retained and how associated provider or backup copies are handled. This notice does not promise immediate or automatic deletion.

8. Your choices and requests

You can request access, correction, deletion or account closure through admin@tgaalliance.com and manage available profile publication choices in the service. Depending on applicable law and your circumstances, you may have additional rights concerning data portability, consent withdrawal, certain processing or an appeal of a request decision.

Tell us which service and request are involved. We may need to verify your identity and authority over organization information without collecting more information than needed. Legal or operational limits may prevent some requests from being fulfilled in full. If you disagree with a response, reply to request a review; this does not limit rights available under applicable law.

9. Security and international processing

TGA uses access controls and other safeguards, but no system or transmission is completely secure. Do not share account credentials or submit sensitive information through channels not intended for it. Notify admin@tgaalliance.com of suspected unauthorized access.

TGA and its service providers may process information in the United States and other countries where they operate. Protections and legal requirements can differ from those where you live. This draft does not assert that a particular cross-border compliance mechanism applies to every transfer.

10. Audience and changes

TGA is intended for business and professional use, not services directed to children. If you believe a child has provided personal information, contact us so we can review it.

We will identify revisions with an updated date and version. Material changes to information handling may require additional notice or choices under applicable law. This draft should not be treated as a statement that all legal review or operational privacy work is complete.