Pengo ("Pengo", "we", "us" or "our") provides trade-fair research software: it reads public exhibitor directories, company pages and event agendas, scores the companies it finds against a description of who a customer sells to, and presents the result. This Privacy Policy describes how we handle personal information collected through our website at trypengo.com, the product at app.trypengo.com, our MCP and API endpoints, and our email and support conversations (together, the "Service").
Personal information we collect
Information you give us
- Account data — your name, email address and the credentials you set, handled by our authentication provider Clerk. We never see or store your password.
- Profile and research settings — the description of who you sell to, your region, industry and home base, and your company website. These are the settings every score is decided against.
- Communications data — what you write to us by email or in support, and our replies.
- Transactional data — your plan, your credit balance, the ledger of what each research pass cost, and your order history. Card details are taken and held by our payment provider Polar; they do not reach our servers.
- Work you record in the product — the booths you mark as go, skip or visited, and the notes you type against a stand or a person. This is yours, it is stored separately from anything a research pass writes, and no research pass ever overwrites it.
Information we collect automatically
- Device and log data — IP address, browser and operating system, pages requested and timestamps, collected by our hosting providers to serve the Service and keep it working.
- Error reports — when something breaks, our error monitoring provider records the failure with the request that caused it, which can include your account identifier.
- Usage data — which research passes ran, what they cost and whether they succeeded. This is what the spend view and the credit ledger are built from.
We do not collect precise geolocation, financial account or government identification numbers, biometric data, or any of the special categories of data described under the heading on sensitive information below.
Information from public sources
The product's whole purpose is reading public pages: exhibitor directories published by fair organisers, company websites, and published conference agendas. Those pages sometimes name people — a speaker, a panellist, a stand contact — and where they do, the research records what the page states.
People our research finds
If you are named on a public exhibitor listing or a published conference agenda, a Pengo customer's research pass may have recorded you. This section says exactly what that means, because it is the part of the Service most likely to concern somebody who has never used it.
- What is recorded
- Your name, your job title, the company you were listed under, the fair and session you were listed for, a link to the page you were read from, and — only where the page itself states one — a business email address or a LinkedIn profile. Nothing is inferred: an address that was not read on a page is discarded rather than guessed, and a profile link is stored only when the profile confirms the name.
- What is never recorded
- Home addresses, personal phone numbers, personal email addresses, and any assessment of you as an individual. Pengo scores companies, not people; there is no fit score, no ranking and no profile of you anywhere in the product.
- Where it came from
- A page a fair organiser or your employer published. Every listing carries the source URL it was read from, and it is shown to the customer beside your name.
- Why we hold it
- Our legitimate interest, and our customers', in knowing who is representing which company at a professional event they are attending — the same interest that makes an exhibitor directory public in the first place. It is business-context information about you in a professional capacity.
- How long
- Until the listing stops being published or is refreshed away. When a fair's roster is re-read and you are no longer on it, your listing is retired.
You can object to this processing, ask for a correction, or ask to be removed entirely, by writing to hey@trypengo.com with the name and the fair. You do not need an account and we do not charge for it. If you ask to be removed, we suppress the name so a later research pass does not re-add it.
Cookies and similar technologies
The product sets the cookies it needs to keep you signed in and to protect the session against forgery. These are strictly necessary: the Service cannot work without them, and there is no version of it that does.
We run no advertising cookies, no advertising pixels, and no cross-site tracking. We do not participate in interest-based advertising and we share nothing with advertising networks, which is why this policy has no advertising opt-out — there is nothing to opt out of.
Some browsers send a "Do Not Track" or Global Privacy Control signal. Because we neither sell personal information nor advertise on the basis of it, there is no processing for those signals to stop; we honour them as opt-out requests where any applicable law requires it.
How we use personal information
- Running the Service — creating your account, running the research passes you buy, quoting and charging credits, keeping the ledger, and supporting you when something goes wrong.
- Security — authenticating you, enforcing rate limits and daily spend caps, detecting abuse, and investigating incidents.
- Improvement — understanding which passes fail and why, so the extraction gets better. This is aggregate work; we do not read your notes to improve the product.
- Communication — service messages about your account, your balance and material changes to this policy. Marketing email is separate and you can unsubscribe from it from any message.
- Compliance and protection — complying with law, responding to lawful requests, and establishing or defending legal claims.
Artificial intelligence, and what is not done with your data
Pengo sends prompts to third-party model providers to extract facts from public pages and to score companies against your description of your buyer. Those requests carry the page content being read and, for scoring, your seller description. They do not carry your notes, your customer records or your billing data.
We do not use your data to train models, and our model providers are contractually prohibited from using data submitted through their APIs to train theirs. Pengo makes no automated decision about you that produces a legal or similarly significant effect: the scores in the product are one customer's ranking of companies, and they are advisory.
How we share personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it in these situations only:
- Service providers
- Hosting and application infrastructure, database and backend hosting, authentication, payment processing, transactional email, error monitoring, and the search and language-model providers that read public pages. Each is bound by contract to process data only on our instructions.
- Systems you connect yourself
- If you connect a CRM, pressing the push button sends the company and contact rows you selected into your own CRM. That happens only on your press, never on a schedule, and never in the background. What you send is then in your system under your policy, and we cannot retract it.
- Agents you connect yourself
- If you connect Pengo to an MCP client, that client reads what your account holds when you ask it to. What the client does with the answer is governed by whoever operates it.
- Professional advisers
- Lawyers, accountants, auditors and insurers, in the course of the services they provide us.
- Authorities
- Law enforcement and government authorities where we believe in good faith that disclosure is required by law, or necessary to protect the rights, property or safety of anybody.
- Business transfers
- A counterparty and its advisers in an actual or prospective investment, financing, merger, acquisition or sale of assets, and the acquirer or successor afterwards.
Retention
We keep account and billing data for as long as you have an account and afterwards for as long as we need it to meet tax, accounting and legal obligations. Your notes and your marked booths are deleted with your account. Research findings about companies are shared facts and outlive any one account; findings about a person are retired when the page they were read from stops listing them, and deleted on request.
Security
We use technical, organisational and physical safeguards designed to protect personal information: encryption in transit, access control on the systems that hold it, and separation between what the research writes and what a customer records. Security risk is inherent in all internet technologies, so we cannot guarantee the security of information transmitted to us.
Sensitive information
Please do not send us sensitive personal information — data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sex life or sexual orientation, biometric or genetic data, or criminal records — through the Service or otherwise. We do not ask for it, we have no field for it, and the free-text boxes in the product are not a place for it.
International transfers
We are based in India and our providers operate in several countries, including the United States and the European Union. Using the Service therefore involves transferring your personal information across borders. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one covers the destination, and otherwise on the European Commission's standard contractual clauses or the UK international data transfer addendum. You can ask us which mechanism applies to a particular transfer.
Children
The Service is for business use and is not intended for anybody under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, write to us and we will delete it.
Other sites
Pengo links out to exhibitor directories, company websites and organiser pages, and shows the source of every fact it holds. Those sites are not ours, we do not control them, and their privacy policies are their own.
Your rights
Wherever you are, you can ask us to give you a copy of what we hold about you, correct it, delete it, or stop a particular use of it, by writing to hey@trypengo.com. We may ask for information to confirm who you are before we act, and we will tell you our reasons if we cannot do what you asked. We do not charge for this and we do not treat you differently for asking.
If you are in the European Economic Area or the United Kingdom
Pengo is the controller of the personal information described in this policy. Under the GDPR you have the rights to access, correct, delete, port and restrict your personal information, to object to processing carried out on the basis of our legitimate interests, and to withdraw consent where we relied on it. Withdrawing consent does not affect processing carried out before you withdrew it.
The legal bases we rely on are these:
- Running the Service and taking payment
- Performance of our contract with you.
- Security, abuse prevention and product improvement
- Our legitimate interest in keeping the Service working, safe and accurate, weighed against the limited business-context data involved.
- Recording people named on public exhibitor listings and agendas
- Our legitimate interest, and our customers', in knowing who represents which company at a professional event. You can object at any time and we will remove the listing.
- Marketing email
- Your consent, or our legitimate interest where the law allows us to write to an existing customer about the product they use. Every message can be unsubscribed from.
- Meeting legal obligations and defending claims
- Compliance with law, and our legitimate interest in establishing or defending legal claims.
If you are not satisfied with how we have handled your information you can complain to the data protection authority where you live or work. In the United Kingdom that is the Information Commissioner's Office. We would rather hear from you first.
If you are in India
Under the Digital Personal Data Protection Act, 2023 you may ask for a summary of the personal data we process about you and how we process it, ask for correction, completion, updating or erasure, nominate somebody to exercise your rights if you die or become incapacitated, and complain about how we handled a request. Write to hey@trypengo.com and mark it for the Grievance Officer; we answer grievances within the period the Act requires. If you are not satisfied you may take the complaint to the Data Protection Board of India.
If you are in the United States
Where a state privacy law applies to us, you may request the categories of personal information we collected about you and the categories of third parties we disclosed it to, request a copy, correct it, delete it, and appeal a decision we make on any of those requests. Two answers that state laws require us to give plainly: we do not sell your personal information and we do not share it for targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects. You may use an authorised agent, and we may need to verify their authority.
Changes to this policy
We may modify this policy. If we make material changes we will update the effective date at the top and, where the change affects you materially, tell you in the product or by email before it takes effect. Using the Service after a modified policy takes effect means the modified policy applies to you.
How to contact us
Write to hey@trypengo.com for anything in this policy — a question, a data request, an objection, or a complaint. It is one inbox, watched by people rather than a form, and a request sent to it does not need an account behind it.