NNimbly AI
Solution About Us

Nimbly Pulse

Measure foot traffic, store visits, and dwell time to identify conversion opportunities across your stores.

Nimbly Echo

Track promotion, upsell, and service execution across relevant frontline conversations.

Nimbly AI Buddy

Ask questions across your connected store data and see where action is needed most.

Nimbly Operations

Digital checklists, audits and issue tracking that keep every location running to standard.

Privacy Policy

Last updated: August 25, 2026

Nimbly provides software and AI-powered tools for multi-location businesses. This Privacy Policy explains how Nimbly Technologies Pte. Ltd. and its subsidiaries (collectively, “Nimbly,” “we,” “us,” and “our”) collect, use, disclose, and protect personal information when you visit our websites, contact us, request a demo, or use our products and services (collectively, the “Services”).

In this Policy, “personal information” includes “personal data” and similar terms used under applicable privacy laws.

1. Scope and our role

Nimbly Technologies Pte. Ltd. is responsible for personal information collected through our websites, sales and marketing activities, account administration, billing, and direct communications with you. For personal information processed in connection with our Services, the relevant Nimbly entity is identified in the applicable customer agreement.

When a business customer uses our Services to process information about its employees, customers, suppliers, or other individuals (“Customer Data”), that customer generally controls the information. Nimbly processes it on the customer’s behalf as a processor, service provider, or data intermediary under the applicable customer agreement. If you have a request concerning Customer Data, please contact the relevant customer first. We will assist our customer as required by applicable law and our agreement with that customer.

If this Policy and a customer agreement differ regarding Customer Data, the customer agreement will apply.

2. Information we collect

Depending on how you interact with us and which Services are used, we may collect the following categories of information:

  • Business and account information, such as your name, work email address, telephone number, job title, company, country, login information, billing details, demo preferences, and communications with us.
  • Customer Data, meaning information submitted to or generated through the Services. Depending on the products and settings selected by a customer, this may include operational records, checklists, forms, images, video, audio, transcripts, location information, sensor-derived metrics, prompts, analytics, and AI-generated outputs.
  • Technical and usage information, such as your IP address, browser and device information, identifiers, timestamps, pages or features used, diagnostic logs, and cookie data.
  • Information from other sources, such as customer-authorized integrations, business partners, events, referrals, and publicly available business sources.

Please do not provide personal information that is not needed for the relevant purpose or that you are not authorized to provide.

3. How we use personal information

We may use personal information to:

  • Provide, configure, maintain, and support the Services;
  • Respond to inquiries, arrange demos, and manage customer relationships;
  • Authenticate users and administer accounts, billing, and contracts;
  • Monitor performance, troubleshoot issues, and improve the functionality and reliability of the Services;
  • Protect the security and integrity of our Services, customers, and business;
  • Communicate service information, product updates, and relevant marketing, subject to your choices and applicable law;
  • Analyze website and service usage;
  • Develop new products, features, and capabilities; and
  • Comply with legal obligations, enforce our agreements, and protect our rights and the rights of others.

Where required by law, we rely on an appropriate legal basis, such as performing a contract, taking steps at your request, pursuing legitimate business interests, obtaining consent, or complying with a legal obligation.

4. Customer Data, AI, and monitored information

Our customers retain ownership of their Customer Data. We process Customer Data to provide, secure, support, maintain, and improve the contracted Services, comply with applicable law, and follow the customer’s instructions and agreement with us.

Some features use third-party AI service providers. We provide those providers only with the information reasonably needed to perform the requested function and require them to protect it and use it only for the agreed purpose. We do not use identifiable Customer Data to train shared or general-purpose AI models or permit our service providers to do so.

AI-generated insights are intended to support, not replace, human judgment. Customers determine how to review and use those outputs.

Some Services can process audio, images, video, location information, or information relating to frontline activity. Customers are responsible for providing required notices, obtaining appropriate permissions, and using these features in accordance with applicable privacy, employment, workplace monitoring, and recording laws. The Echo product does not use voice recognition, voiceprinting, or speaker identification to identify specific individuals by default. Features designed to identify an individual by voice, if offered, would be subject to additional contractual and privacy requirements before activation.

5. Aggregated and de-identified information

We may create aggregated or de-identified information from Customer Data to operate, secure, analyze, and improve the Services, as permitted by applicable law and our customer agreements.

With the customer’s prior written authorization, we may disclose or license aggregated or de-identified information to research organizations or AI developers for research, benchmarking, product development, and the training or evaluation of AI systems.

Before doing so, we take reasonable measures to ensure that the information cannot reasonably identify an individual or, unless the customer expressly agrees otherwise, the customer, brand, or specific location. We do not attempt to re-identify this information, and we contractually require recipients to maintain it in de-identified form and not attempt to re-identify it. We also take reasonable steps to monitor compliance with these commitments.

We do not sell or license identifiable Customer Data.

We do not include raw audio, video, images, transcripts, or granular location information in these external disclosures unless the customer separately authorizes that use in writing and the information has been de-identified to the standard described above.

6. How we disclose information

We may disclose personal information to:

  • Nimbly companies that support the purposes described in this Policy;
  • Service providers and subprocessors that provide hosting, communications, analytics, customer support, security, payment, professional, or AI-related services;
  • Customers and authorized users when needed to provide the Services;
  • Customer-authorized integrations and partners at the customer’s direction;
  • Professional advisers, such as lawyers, auditors, insurers, and financial advisers;
  • Government authorities or other parties when required by law or reasonably necessary to protect rights, safety, security, or property; and
  • Parties to a business transaction, such as a merger, financing, acquisition, reorganization, or sale of assets.

We may also disclose aggregated or de-identified information as described in Section 5. Our use of website analytics and advertising technologies is described in Section 7.

We require service providers that process personal information for us to protect it and use it only for the services they provide.

7. Cookies and similar technologies

We use essential cookies and similar technologies to operate our websites and Services. We may also use analytics and advertising technologies to understand usage, improve performance, and measure our communications and campaigns.

Where required, we ask for consent before using non-essential cookies. You can manage your choices through any cookie controls we provide and through your browser settings. Disabling certain cookies may affect how some features work.

8. Marketing communications

We may send product updates and relevant insights where permitted by law or with your consent. You can unsubscribe at any time by using the link in a marketing email or contacting us. We may still send necessary service, security, account, or transactional communications.

9. International transfers

Nimbly operates internationally. We and our service providers may process personal information in Singapore and other countries where we or they operate. These countries may have different data protection laws from your country.

Where required, we use contractual, organizational, and technical safeguards designed to provide an appropriate level of protection for personal information transferred across borders.

10. Security

We use administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, and loss. These safeguards include access controls, encryption, monitoring, security testing, and incident-response procedures. We regularly review and improve our safeguards.

Nimbly maintains an ISO/IEC 27001-certified information security management system. However, no system or method of transmission is completely secure.

11. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining business and legal records, meeting legal obligations, resolving disputes, and enforcing agreements.

Retention of Customer Data is governed by the applicable customer agreement, the customer’s instructions, product settings, and applicable law. Recordings and transcripts follow the retention period selected or agreed to by the customer, and backup copies are removed through our ordinary backup-retention processes.

We retain business contact and account information while we have an active or prospective business relationship and for a reasonable period afterward. We retain marketing information until you unsubscribe or it is no longer needed, although we may keep a minimal suppression record to honor your preference. When information is no longer required, we delete it, de-identify it, or securely isolate it, as appropriate.

12. Your rights and choices

Depending on where you live and subject to applicable exceptions, you may have the right to:

  • Access or receive a copy of your personal information;
  • Correct inaccurate or incomplete information;
  • Request deletion of your information;
  • Restrict or object to certain processing;
  • Withdraw consent where processing is based on consent;
  • Request transfer of your information in a portable format; and
  • Opt out of certain marketing or data-use activities.

To submit a request, contact us using the details below. We may need to verify your identity before completing the request. If your information was provided to us by your employer or another Nimbly customer, please direct your request to that organization first.

Withdrawing consent does not affect processing that occurred before the withdrawal or processing supported by another lawful basis.

You may also have the right to lodge a complaint with the data protection or privacy authority in your jurisdiction.

13. Children

Our websites and Services are intended for businesses and are not directed to children. We do not knowingly collect personal information directly from children through our websites. If Customer Data includes information relating to a child, the relevant customer is responsible for ensuring that it has an appropriate legal basis for providing that information to Nimbly.

14. Third-party services and links

Our websites and Services may link to or integrate with third-party services. Their privacy practices are governed by their own policies, and we encourage you to review them.

15. Changes to this Policy

We may update this Policy as our Services, business, or legal obligations change. We will post the revised version on this page, update the “Last updated” date, and provide additional notice when required by law.

16. Contact us

For questions, concerns, or requests relating to this Policy or our privacy practices, contact:

Data Protection Officer
Nimbly Technologies Pte. Ltd.
100 Peck Seah Street, #08-14, PS100
Singapore 079333
Email: [email protected]

NNimbly AI
Powered by Nimbly Technologies

© 2026 Nimbly Technologies. All rights reserved.

PrivacyTerms

We use cookies to improve your experience and analyze site traffic. By clicking “Accept”, you consent to our use of cookies. Privacy Policy