privacy policy

PART I | TERMS OF USE

Last Updated: July 14, 2026

These Terms of Use ("Terms") govern access to and use of the websites, customer portals, applications, application programming interfaces, embedded players, reporting tools, content-production tools, and other online products and services provided by DesireList, Inc. doing business as The Desire Company ("The Desire Company," "Company," "we," "us," or "our"). Collectively, these products and services are the "Services."

By accessing or using the Services, creating an account, using an API key, submitting content, or agreeing to an order form or statement of work that references these Terms, you agree to be bound by these Terms. If you use the Services on behalf of a company, brand, retailer, agency, marketplace, retail media network, or other organization, you represent that you have authority to bind that organization. In that case, "you" includes both you and the organization.

Do not use the Services if you do not agree to these Terms.

1. Eligibility

You must be at least 18 years old and legally capable of entering into a binding agreement to use the Services. The Services are intended for businesses and adults and are not directed to children under 13.

2. Additional Agreements

Certain Services may be governed by additional agreements, including order forms, statements of work, master services agreements, subscription agreements, API agreements, data-processing agreements, content-production agreements, expert or contractor agreements, retailer requirements, or written service-specific policies.

If an additional written agreement conflicts with these Terms, the additional written agreement controls with respect to the conflicting provision.

3. Accounts and Authorized Users

Some Services require an account. You agree to provide accurate, current, and complete information and keep it updated.

  • Maintain the confidentiality of login credentials and use appropriate authentication controls.

  • Limit access to authorized users and promptly remove access that is no longer appropriate.

  • Accept responsibility for activity conducted through your account and credentials.

  • Notify us promptly of suspected unauthorized access, credential compromise, or security incidents.

  • Do not share individual credentials unless the applicable service plan expressly permits shared access.

We may temporarily suspend access when we reasonably believe an account has been compromised, is being misused, or presents a security or legal risk.

4. Organization Administrators

If your account is provided or managed by an employer, client, agency, retailer, retail media network, marketplace, or other organization, that organization may administer your account and may be able to add or remove users, control permissions, access organizational content and activity, configure integrations, manage API credentials, export organizational data, and terminate access.

Your use of an organization-managed account may also be governed by that organization's policies and agreements.

5. License to Use the Services

Subject to these Terms, payment of applicable fees, and any additional written agreement, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the Services for authorized internal business purposes during the applicable term. No rights are granted except those expressly stated.

6. The Desire Company API

6.1 API Access

We may make application programming interfaces, software-development resources, webhooks, feeds, endpoints, authentication credentials, documentation, or related tools available to you, collectively referred to as the "API." API access may include content metadata, transcripts, video data, structured data, reports, project information, product information, content-delivery functionality, or other information made available through authorized endpoints.

You may use the API only for purposes authorized by us, in accordance with applicable documentation, within usage and rate limits, for approved internal or customer-facing implementations, and in compliance with law and third-party requirements.

6.2 API Credentials

API keys, access tokens, secrets, signing keys, and other credentials are confidential. You may not publish credentials in a public repository, embed secret credentials in publicly accessible client-side code, share credentials with unauthorized parties, use another customer's credentials, or sell, transfer, or sublicense credentials without written permission.

You are responsible for activity performed through credentials issued to you. We may rotate, suspend, or revoke credentials where reasonably necessary for security, maintenance, nonpayment, legal compliance, suspected misuse, or termination of the applicable agreement.

6.3 API Limits and Changes

We may establish and enforce request, token, file-size, storage, concurrency, permitted-domain, permitted-application, data-retention, or other technical and commercial restrictions. You may not evade restrictions through multiple accounts, credential rotation, request distribution, or similar methods.

We may modify, deprecate, replace, or discontinue endpoints, documentation, or response formats. When commercially reasonable, we will provide advance notice of material changes affecting paid integrations. Emergency security changes may be implemented without advance notice.

6.4 API Data and Caching

You may store or cache API responses only as authorized by the applicable agreement, documentation, and law. You must delete or stop using API-derived data when your right to access it ends, we reasonably request deletion, the underlying data is corrected or withdrawn, law requires deletion, or your account or agreement terminates.

You may not use API data to build, train, enrich, or operate a competing database, content marketplace, machine-learning model, artificial-intelligence model, or commercial product unless expressly authorized in writing.

6.5 API Security and Prohibited Conduct

You must maintain reasonable administrative, physical, and technical safeguards appropriate to the information accessed through the API. You may not probe for vulnerabilities without authorization, introduce malicious code, overload infrastructure, bypass access controls or rate limits, access undocumented endpoints without authorization, or access data you are not authorized to receive.

7. Content, Reports, and Automated Outputs

The Services may generate product-detail-page audits, brand-preparation reports, recommendations, transcripts, captions, summaries, chapters, FAQs, structured data, JSON-LD, product or category comparisons, expert recommendations, matching or scoring information, analytics, metadata, classifications, and other outputs.

Outputs may be produced using automated systems, artificial intelligence, third-party data, website retrieval, transcription, customer-provided information, or combinations of these methods. Website-derived and automated results may be incomplete, delayed, unavailable, or inaccurate because source websites, page structures, product information, retailer rules, and third-party systems change over time.

You are responsible for reviewing outputs before publishing, distributing, relying on, or submitting them to a retailer, marketplace, regulator, customer, or other third party.

  • Outputs are informational and are not legal, regulatory, medical, financial, or other professional advice.

  • Scores, recommendations, audits, and comparisons are not guarantees or certifications.

  • A report does not guarantee retailer or marketplace acceptance.

  • Structured data does not guarantee search-engine indexing, placement, or ranking.

  • Transcripts, captions, metadata, and generated copy may require correction.

8. Customer Content

Customer Content means content, data, files, instructions, URLs, product information, media, trademarks, logos, recordings, comments, feedback, reports, or other materials submitted by you or your authorized users. You retain ownership of your Customer Content.

You grant us and our service providers a worldwide, non-exclusive, royalty-free license to host, reproduce, process, transmit, display, modify, format, analyze, and otherwise use Customer Content as reasonably necessary to provide the Services, complete projects, generate deliverables, maintain and secure the Services, troubleshoot issues, comply with law, enforce agreements, and perform activities authorized by you.

You represent that you have all rights and permissions needed to provide Customer Content, that our authorized use will not violate another party's rights, that Customer Content complies with law, and that required notices, releases, consents, and licenses have been obtained.

9. Personal Information in Customer Content

Do not submit sensitive personal information unless it is required for an authorized service and appropriate safeguards have been established. Unless expressly authorized in writing, you may not submit Social Security numbers, government identification numbers, full payment-card numbers, financial-account credentials, medical records, precise biometric identifiers, children's personal information, passwords, authentication secrets, or other highly sensitive regulated information.

When we process personal information on behalf of a business customer, the customer generally determines the purpose of processing and we process that information as a service provider or processor under the applicable agreement.

10. Expert and Creator Content

Certain Services may involve experts, creators, contractors, talent, employees, or other individuals who appear in or contribute to content. Ownership, licensing, usage rights, approvals, publicity rights, exclusivity requirements, and permitted distribution are governed by the applicable project agreement, talent release, statement of work, or license.

You may not use an individual's name, image, voice, likeness, biography, endorsement, or content beyond the rights granted in the applicable agreement.

11. Intellectual Property

The Services, including software, interfaces, workflows, designs, databases, documentation, trademarks, logos, templates, scoring systems, matching systems, reports, and underlying technology, are owned by or licensed to The Desire Company and protected by intellectual-property laws.

  • Copy, modify, reverse engineer, or attempt to derive source code from the Services.

  • Remove proprietary notices or reproduce documentation except as authorized.

  • Resell, sublicense, frame, or mirror the Services.

  • Extract or compile our databases except through an authorized API and permitted use.

  • Use automated means to access the Services except through an authorized API.

  • Use the Services or documentation to develop a substantially similar or competing product.

  • Use our names, trademarks, or logos without permission.

12. Feedback

If you provide suggestions, ideas, feature requests, or other feedback, you grant us a perpetual, worldwide, irrevocable, royalty-free right to use that feedback without restriction or compensation. This provision does not transfer ownership of Customer Content.

13. Acceptable Use

You may not use the Services to violate law; infringe intellectual-property, privacy, publicity, or contractual rights; upload unlawful or malicious material; harass or impersonate others; send spam; distribute malware; attempt unauthorized access; interfere with service availability; circumvent security, usage, or payment controls; scrape the Services except as authorized; misrepresent automated outputs as independently verified; create deceptive endorsements; make false product claims; use content outside its licensed scope; conduct unlawful surveillance or discrimination; or assist another person in doing any of these things.

We may investigate suspected violations and suspend or terminate access where reasonably necessary.

14. Third-Party Websites and Services

The Services may connect to or contain information from third-party websites, retailers, marketplaces, hosting providers, social platforms, analytics providers, cloud services, or other external systems. We do not control third-party services and are not responsible for their availability, content, security, privacy practices, terms, system changes, or actions regarding your account or content.

Your use of third-party services is governed by their own terms and policies.

15. Retailer and Marketplace Requirements

Retailers, marketplaces, social platforms, and retail media networks may maintain technical specifications, content rules, advertising standards, terms, and submission requirements. You are responsible for confirming that your use of the Services, outputs, integrations, and content complies with all applicable third-party requirements.

The Desire Company may assist with interpreting or applying requirements but does not guarantee that a retailer or platform will approve, accept, publish, display, index, rank, or continue hosting content. The Desire Company may assist with interpreting or applying requirements but does not guarantee that a retailer or platform will approve, accept, publish, display, index, rank, or continue hosting content.

16. Fees, Billing, and Taxes

Paid Services are subject to the pricing, billing schedule, usage limits, and payment terms specified in the applicable order form, subscription, checkout page, or agreement. Unless otherwise stated, fees are in U.S. dollars, are nonrefundable except where required by law or agreed in writing, and exclude applicable taxes. Usage above plan limits may result in additional charges, restricted access, or a required plan change.

We may suspend paid Services for overdue undisputed amounts after providing any notice required by the applicable agreement.

17. Beta and Evaluation Services

Services identified as beta, preview, experimental, evaluation, or early access may be incomplete and may change or be discontinued. Unless otherwise agreed, beta Services are provided without service-level commitments and should not be used for critical production functions.

18. Service Availability

We may perform maintenance, install updates, or change the Services. We do not guarantee uninterrupted or error-free operation. Availability may be affected by maintenance, internet failures, third-party providers, cloud infrastructure, retailer websites, source-system changes, security incidents, force majeure events, or circumstances outside our reasonable control. Any service-level commitment must be stated in a separate written agreement.

19. Suspension and Termination

You may stop using the Services at any time. Subscription cancellation and termination rights are governed by the applicable agreement.

We may suspend or terminate access if you materially violate these Terms, payment is overdue, your use creates a security or legal risk, your activity could harm the Services or another user, law requires suspension, a third-party provider prevents continued service, your organization requests termination, or the applicable agreement permits it.

Upon termination, your right to use the Services ends. Provisions concerning ownership, confidentiality, disclaimers, liability limitations, indemnification, and dispute resolution survive to the extent appropriate.

20. Confidentiality

Each party may receive nonpublic information from the other party that is identified as confidential or should reasonably be understood to be confidential. The receiving party will use confidential information only to perform or receive the Services, protect it using reasonable care, and disclose it only to personnel and service providers with a need to know and appropriate confidentiality obligations.

Confidential information does not include information the receiving party can demonstrate was lawfully known without restriction, independently developed, lawfully received from another source, or publicly available through no breach of obligation.

21. Copyright Complaints

We respect intellectual-property rights. A copyright owner or authorized agent who believes material available through the Services infringes copyright may send a written notice to hello@thedesirecompany.com with the subject line "Copyright Notice." The notice should identify the copyrighted work and allegedly infringing material, provide contact information, include the required good-faith and accuracy statements, and contain a physical or electronic signature.

Where the Digital Millennium Copyright Act applies, formal notices should be sent to the Company's registered DMCA agent. The Company should publish the agent's complete information after registration with the U.S. Copyright Office.

22. Disclaimers

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES AND ALL OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE." THE DESIRE COMPANY DISCLAIMS ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AVAILABILITY, AND RESULTS.

WE DO NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE; ALL DEFECTS WILL BE CORRECTED; REPORTS OR OUTPUTS WILL BE COMPLETE OR ACCURATE; THIRD-PARTY WEBSITES WILL REMAIN ACCESSIBLE OR UNCHANGED; CONTENT WILL BE ACCEPTED BY A RETAILER OR PLATFORM; STRUCTURED DATA WILL AFFECT SEARCH RESULTS; OR ANY RECOMMENDATION WILL PRODUCE A PARTICULAR RESULT.

Some jurisdictions do not allow certain warranty exclusions, so some exclusions may not apply to you.

23. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE DESIRE COMPANY AND ITS AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, CONTRACTORS, LICENSORS, AND SERVICE PROVIDERS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, BUSINESS, GOODWILL, OR OPPORTUNITIES, EVEN IF ADVISED THAT SUCH DAMAGES WERE POSSIBLE.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICES OR THESE TERMS WILL NOT EXCEED THE GREATER OF: (A) THE AMOUNT YOU PAID TO THE DESIRE COMPANY FOR THE APPLICABLE SERVICES DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM; OR (B) ONE HUNDRED U.S. DOLLARS IF YOU USED ONLY FREE SERVICES.

These limitations do not apply where prohibited by law or to liability that cannot legally be limited.

24. Indemnification

To the extent permitted by law, you agree to defend, indemnify, and hold harmless The Desire Company and its affiliates, officers, directors, employees, contractors, and service providers from claims, losses, liabilities, damages, judgments, penalties, costs, and reasonable attorneys' fees arising from your Customer Content; use of the Services; violation of these Terms or law; violation of third-party rights; your products, claims, or published content; unauthorized use of API data; or activity through your account or credentials. This provision does not require indemnification for claims caused by our gross negligence or willful misconduct.

25. Governing Law and Venue

These Terms are governed by the laws of the State of Illinois, without regard to conflict-of-law principles. Unless another written agreement provides otherwise, any legal action arising out of or relating to these Terms or the Services must be brought in the state or federal courts located in Cook County, Illinois, and each party consents to their jurisdiction and venue.

Nothing in this section prevents either party from seeking temporary or injunctive relief in a court of competent jurisdiction to protect intellectual property, confidential information, data, or systems.

26. Export and Sanctions Compliance

You may not use, export, re-export, or make the Services available in violation of U.S. export-control or sanctions laws. You represent that you are not located in, ordinarily resident in, or controlled from a prohibited jurisdiction and are not a restricted or sanctioned person.

27. Changes to These Terms

We may update these Terms from time to time. If we make material changes, we may provide notice through the Services, by email, or through another reasonable method. Updated Terms become effective on the date stated in the revised version unless a different date is specified. Your continued use after the effective date constitutes acceptance.

28. General Provisions

If a provision is unenforceable, it will be modified to the minimum extent necessary and the remaining provisions remain effective. Failure to enforce a provision is not a waiver. You may not assign these Terms without our written consent. We may assign them in connection with a merger, acquisition, corporate reorganization, financing, or sale of assets.

Neither party is liable for delay caused by circumstances beyond its reasonable control, except for payment obligations. These Terms and applicable written agreements constitute the entire agreement concerning their subject matter. Headings are for convenience and do not affect interpretation.

29. Contact Us

Questions about these Terms may be sent to:

DesireList, Inc. dba The Desire Company
4245 N. Knox Avenue
Chicago, Illinois 60641
United States

Email:hello@thedesirecompany.com

PART II | PRIVACY POLICY

Last Updated: July 14, 2026

This Privacy Policy explains how DesireList, Inc. doing business as The Desire Company ("The Desire Company," "Company," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with our websites, customer portals, applications, application programming interfaces, embedded players, reporting tools, content-production services, and other products and services that link to this Privacy Policy. Collectively, these are the "Services."

This Privacy Policy does not apply where we process personal information solely on behalf of a business customer under a separate agreement. In those situations, the business customer generally controls the information, and its privacy policy governs its collection and use.

1. Scope and Roles

Depending on the circumstances, The Desire Company may act as a controller or business when we determine why and how personal information is processed, or as a processor, service provider, or contractor when we process personal information on behalf of a customer according to that customer's instructions.

For example, we may act as a controller for website visitors, account contacts, prospective customers, and our own marketing activities. We may act as a processor or service provider when handling project data, content, user information, or API data on behalf of a brand, agency, retailer, retail media network, marketplace, or other customer.

2. Personal Information We Collect

The information we collect depends on how you interact with us and which Services you use.

2.1 Information You Provide

We may collect information you provide directly, including:

  • Name, business email address, telephone number, job title, and organization.

  • Account username, password or authentication information, and communication preferences.

  • Billing contact, transaction, subscription, and payment-status information.

  • Support requests, survey responses, messages, correspondence, and feedback.

  • Project instructions, product and brand information, URLs submitted for analysis, comments, approvals, and review activity.

  • Files, transcripts, media, recordings, logos, and other content.

  • Expert or creator profiles, professional experience, qualifications, images, audio, video, voice, likeness, and biography information.

2.2 Account and Organization Information

When you use an account provided by an organization, we may collect:

  • Organization name, user role, permissions, associated brands, projects, and teams.

  • Administrator information, account status, login history, authentication events, and workspace activity.

2.3 Project and Content Information

Our Services may process information associated with content-production and fulfillment workflows, such as:

  • Project, order, scheduling, product, SKU, and product-detail-page information.

  • Production notes, shipping information, comments, approvals, and content versions.

  • Media files, transcripts, captions, download activity, expert selections, qualifications, and project information.

  • Brand, retailer, delivery, hosting, and integration information.

2.4 API Information

When you access or integrate with our API, we may collect:

  • Account, organization, API-key, application, and domain identifiers.

  • Authentication and token events, endpoint requests, timestamps, IP addresses, and request parameters.

  • Product identifiers, URLs, file identifiers, usage volume, rate-limit information, errors, and security events.

  • Integration configuration and data submitted to or retrieved through authorized endpoints.

2.5 Information Collected Automatically

When you interact with the Services, we may automatically collect:

  • IP address, browser, device, operating system, identifiers, language, and referring URL.

  • Pages and features viewed, links clicked, date and time, session duration, and approximate location derived from IP address.

  • Login, authentication, error, crash, performance, download, playback, and diagnostic information.

2.6 Embedded Players and Content Delivery

When a player, landing page, QR-code destination, analytics integration, or content-delivery feature is accessed, we may collect:

  • IP address, browser, device, referring page, page or player identifier, and content identifier.

  • Playback, start, completion, duration, error, approximate location, timestamp, and engagement information.

2.7 Information from Customers and Business Partners

We may receive information from your employer or organization, brands, agencies, retailers, retail media networks, marketplaces, production partners, experts and creators, technology providers, authentication providers, analytics providers, payment processors, public sources, and other partners.

2.8 Information from Public Sources and Websites

Certain Services may retrieve or analyze publicly accessible online information, including product-detail pages, titles, descriptions, images, ratings, pricing, availability, attributes, categories, structured data, retailer specifications, and other webpage information. Website-derived data may change and may not always be complete or accurate.

Payment-card information may be collected directly by a payment processor. We may receive limited transaction details without receiving the full card number.

We may log API requests and metadata to authenticate requests, operate the API, enforce limits, troubleshoot errors, prevent abuse, support customers, maintain security, and comply with law.

3. Cookies and Similar Technologies

We and our service providers may use cookies, local storage, pixels, software development kits, server logs, and similar technologies to keep users signed in, authenticate users, maintain security, remember settings, provide functionality, analyze performance, diagnose errors, measure content engagement, improve the Services, and support marketing where permitted.

Strictly Necessary Cookies

Required for authentication, security, account access, and essential functionality.

Functional Cookies

Remember preferences and improve usability.

Analytics Cookies

Help us understand traffic, performance, and use of the Services.

Advertising or Marketing Cookies

May be used to measure campaigns or provide relevant advertising where such technologies are used and legally permitted.

You can manage cookies using browser controls and any preference tools we make available. Blocking some cookies may prevent parts of the Services from operating correctly. Specific providers currently in use should be identified in the Company's cookie notice or consent-management interface where required.

4. How We Use Personal Information

4.1 Provide the Services

  • Create and manage accounts and authenticate users.

  • Provide portals, dashboards, content workflows, hosting, media delivery, reports, audits, transcripts, captions, structured data, and API access.

  • Process projects, orders, scheduling, review, approvals, integrations, support, and contractual obligations.

4.2 Process and Generate Content

  • Analyze product pages and other authorized sources.

  • Generate reports, recommendations, summaries, chapters, FAQs, transcripts, metadata, JSON-LD, structured information, and deliverables.

  • Match projects with experts and support content-production workflows.

4.3 Operate and Secure the Services

  • Monitor performance, diagnose errors, prevent fraud and abuse, detect unauthorized activity, enforce limits, protect credentials, maintain logs, investigate incidents, back up systems, and maintain business continuity.

4.4 Communicate With You

  • Respond to inquiries, provide support, send service and security messages, provide project updates, and send billing, policy, or account notices.

4.5 Improve and Develop the Services

  • Analyze trends, evaluate features, develop and test functionality, improve workflows and automated systems, conduct internal research, and create aggregated statistics.

4.6 Marketing

  • Send newsletters, product information, event or survey invitations, and measure or personalize business communications, subject to applicable law and your preferences.

4.7 Legal and Business Purposes

  • Comply with law, respond to legal process, enforce agreements, conduct audits, protect rights and safety, complete corporate transactions, and satisfy accounting, tax, insurance, and recordkeeping obligations.

Where we use artificial-intelligence or automated-processing providers, we will configure and contract with those providers as appropriate to the service and our customer commitments. Unless expressly disclosed and authorized, we do not use confidential Customer Content to train publicly available general-purpose artificial-intelligence models.

5. Legal Bases for Processing

Where European, United Kingdom, or similar data-protection law applies, we may process personal information based on performance of a contract, legitimate interests, consent, legal obligation, or protection of rights and safety. Where we rely on legitimate interests, we consider the nature of the information, reasonable expectations, and potential effects of processing.

6. How We Disclose Personal Information

6.1 Service Providers

We may disclose information to vendors that help host infrastructure, store or deliver data and media, authenticate users, process payments, send communications, provide support, monitor systems, analyze usage, transcribe or process content, prevent fraud, maintain security, or provide professional services.

6.2 Customers and Organization Administrators

If you use the Services through an organization, we may disclose account, project, usage, or activity information to its authorized administrators. Project information may be shared with authorized brands, agencies, retailers, marketplaces, retail media networks, production partners, and designated participants.

6.3 Experts, Creators, and Production Partners

We may disclose information needed to coordinate projects with experts, creators, talent, contractors, production companies, shipping providers, editors, reviewers, and other participants.

6.4 Integrations and Customer-Directed Disclosures

We may disclose information through APIs, exports, webhooks, embedded players, customer-configured destinations, and other connections enabled or requested by a customer.

6.5 Affiliates and Corporate Transactions

We may disclose information to affiliates under common ownership or control and in connection with a proposed or completed merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction.

6.6 Legal Compliance and Protection

We may disclose information when reasonably necessary to comply with law, respond to lawful requests, enforce agreements, investigate fraud or misuse, protect security, protect rights or safety, or establish and defend legal claims.

6.7 With Consent

We may disclose information for another purpose when you direct us to do so or provide consent.

7. Sale and Sharing of Personal Information

We do not sell personal information for money. Some privacy laws define sale, sharing, or targeted advertising broadly enough to include certain disclosures involving advertising cookies or similar technologies.

If we use technologies that constitute selling, sharing, or targeted advertising under applicable law, eligible individuals may opt out through a "Your Privacy Choices" link, cookie-preference tool, recognized opt-out preference signal where required, or the contact methods below. We do not knowingly sell or share the personal information of individuals under 16.

Before publication, the Company should confirm whether advertising, retargeting, cross-context behavioral advertising, or third-party campaign pixels are active and ensure the website configuration matches this disclosure.

8. Data Retention

We retain personal information for as long as reasonably necessary to provide the Services, maintain accounts, fulfill projects, honor customer instructions, meet contractual obligations, maintain security, resolve disputes, enforce agreements, and comply with legal, accounting, tax, and recordkeeping requirements.

Retention periods vary by information type, customer agreement, sensitivity, and law. Account information may be retained while active and for a reasonable period afterward; project content according to applicable agreements; API and security logs for troubleshooting, security, compliance, and abuse prevention; transaction records for accounting and tax requirements; and marketing information until opt-out or no longer needed.

Backup copies may remain for a limited period until overwritten under ordinary procedures. We may retain aggregated or deidentified information that cannot reasonably be linked to an individual.

9. Security

We use administrative, technical, and physical safeguards designed to protect personal information, such as access controls, authentication, role-based permissions, encryption where appropriate, logging, monitoring, secure-development practices, vendor management, backup and recovery, and incident response.

No transmission or storage system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting account credentials and API secrets and notifying us promptly of suspected unauthorized access.

10. International Data Transfers

The Desire Company is based in Chicago, Illinois, United States. Personal information may be processed in the United States and other countries where we or our service providers operate. Those countries may have data-protection laws different from the laws where you live.

Where required, we use recognized safeguards for international transfers, which may include contractual protections, data-processing agreements, or other legally approved mechanisms.

11. Your Privacy Rights

Depending on where you live and subject to exceptions, you may have the right to know whether we process your personal information; request access, correction, deletion, or portability; restrict or object to processing; opt out of sale, sharing, or targeted advertising; withdraw consent; opt out of marketing; appeal certain decisions; and not receive discriminatory treatment for exercising a right.

These rights are not absolute. We may retain information needed to complete a transaction, provide a service, maintain security, comply with law, protect legal rights, or fulfill another permitted purpose.

11.1 Submitting a Request

Submit a request by emailing hello@thedesirecompany.com with the subject line "Privacy Request." Describe the right you wish to exercise, your relationship with The Desire Company, the email address associated with your account or interaction, and information reasonably necessary to locate your records. We may request additional information to verify identity and protect against fraudulent requests.

11.2 Authorized Agents

Where permitted, you may authorize another person to submit a request. We may require evidence of authority and may verify your identity directly.

11.3 Customer-Controlled Data

If we process information solely on behalf of a customer, we may direct your request to that customer or assist the customer in responding. The relevant brand, retailer, agency, employer, or other organization may be responsible for the request.

11.4 Appeals

Where applicable law provides an appeal right, you may appeal a denial by replying to our decision or emailing us with the subject line "Privacy Request Appeal."

12. California Privacy Notice

This section applies to California residents and supplements the rest of this Privacy Policy.

12.1 Categories of Personal Information

Depending on your interaction, we may collect identifiers; California customer-record information; commercial information; internet or electronic-network activity; approximate geolocation; audio, electronic, and visual information; professional or employment information; inferences; and limited sensitive information such as account credentials. We do not necessarily collect every example included within a statutory category.

12.2 Sources

We collect these categories from you, your organization, customers, business partners, experts and creators, service providers, devices and browsers, public sources, integrations, and connected services.

12.3 Business and Commercial Purposes

We use these categories to provide and support Services, process projects and transactions, authenticate users, operate APIs and integrations, generate requested content and reports, maintain security, analyze and improve services, communicate, market, comply with law, and protect legal rights.

12.4 Categories Disclosed for Business Purposes

We may disclose these categories to cloud, hosting, security, analytics, payment, communication, transcription, content-processing, professional-service, customer, organization-administrator, project participant, affiliate, and customer-selected integration recipients.

12.5 Sale, Sharing, and Targeted Advertising

We do not sell personal information for money. Depending on website technologies, certain advertising-related disclosures may be considered sharing. Where applicable, California residents may opt out through the mechanisms in Section 7.

12.6 California Rights

California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive information where applicable, and receive equal service and pricing when exercising rights.

Requests may be submitted under Section 11.

13. European Economic Area, United Kingdom, and Switzerland

Individuals in the European Economic Area, United Kingdom, or Switzerland may have rights to access, correct, erase, restrict, object to processing, and receive certain personal information in portable form. You may withdraw consent where processing is based on consent and may lodge a complaint with a local data-protection authority.

Where a customer or another organization is the controller, requests should be directed to that organization.

14. Other U.S. State Privacy Rights

Residents of other U.S. states may have similar rights, including access, correction, deletion, portability, opt-out of targeted advertising or certain sales, and appeal. We will process verified requests as required by applicable law.

15. Automated Processing

The Services may use algorithms, matching systems, scoring tools, artificial intelligence, or other automated technologies to assist with product analysis, content recommendations, expert matching, categorization, transcription, report generation, structured-data generation, fraud prevention, security, and workflow automation.

These tools support business processes and may not always be accurate. Unless expressly disclosed, we do not use automated processing to make decisions that produce legal or similarly significant effects about consumers without meaningful human involvement.

16. Children's Privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information, contact hello@thedesirecompany.com and we will investigate and take appropriate steps.

Business customers must not submit children's personal information unless expressly authorized and all required notices, permissions, and parental consents have been obtained.

17. Third-Party Services and Links

The Services may contain links to or integrate with third-party websites and services. We are not responsible for the privacy, security, content, or practices of third parties. Review their policies before providing information.

18. Email Communications

You may opt out of promotional emails by using the unsubscribe link. Even after opting out of marketing, you may receive account, security, project, transaction, legal, or other non-promotional messages.

19. Do Not Track and Opt-Out Signals

Some browsers transmit Do Not Track signals. Because there is no universally accepted technical standard, the Services may not respond to traditional Do Not Track signals.

Where required by law, we will process recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of covered sale or sharing activity for the associated browser or device.

20. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our Services, practices, technology, or legal obligations. When we make material changes, we may provide notice through the Services, by email, or another reasonable method. The Last Updated date identifies when the revised policy became effective.

We will not use previously collected personal information in a materially different manner without notice or consent where required by law.

21. Contact Us

Questions, concerns, or privacy requests may be sent to:

DesireList, Inc. dba The Desire Company
4245 N. Knox Avenue
Chicago, Illinois 60641
United States

Email:hello@thedesirecompany.com


Publication Checklist

Before publication, Company leadership and qualified counsel should confirm each item below and revise the document where needed:

  • Current legal entity name, trade name, principal business address, and contact email.

  • Illinois governing law and Cook County venue are the intended contractual choices.

  • All Services and account types covered by the Terms, including public tools, customer portal, expert workflows, players, analytics integrations, hosting, reporting, and APIs.

  • Current API endpoints, data types, permitted uses, rate limits, domain restrictions, caching rules, and termination requirements.

  • Current analytics, advertising, consent-management, email, payment, hosting, transcription, artificial-intelligence, and other subprocessors.

  • Whether any advertising, retargeting, cross-context behavioral advertising, sale, or sharing activity occurs.

  • Whether Global Privacy Control and other legally required opt-out signals are technically supported.

  • Actual retention periods for accounts, media, transcripts, projects, reports, API logs, security logs, analytics, backups, and billing data.

  • Whether confidential Customer Content is ever used to train or improve any machine-learning model and whether customer authorization is obtained.

  • Privacy-request intake, identity verification, appeal, deletion, correction, export, and service-provider escalation procedures.

  • Data Processing Addendum, international transfer mechanism, security exhibit, and subprocessors list for business customers.

  • Designated DMCA agent information and U.S. Copyright Office registration.

  • Insurance, limitation-of-liability, indemnification, warranty, refund, renewal, and termination positions align with commercial agreements.

  • Cookie banner and privacy-choice user interface match the published policy.

  • Accessibility, versioning, publication date, and internal ownership for future policy updates.