Legal
Privacy Policy
Effective date: July 24, 2026 · Last updated: July 24, 2026
Pillar Bridge Solutions LLC (“PBS”, “we”, “us”) helps victims of terrorism and their families pursue claims under programs including the United States Victims of State Sponsored Terrorism Act (USVSST), the Foreign Assistance Support Act Initiative (FASAI), and the Anti-Terrorism Act (ATA).
Because of the nature of this work, we handle sensitive personal, medical, and legal information. This policy explains what we collect, why we collect it, how we protect it, and the control you have over it. It applies to our website, our client dashboard, and all related services.
1. Information We Collect
We collect only what we need to provide our services:
- Account information — name, email address, phone number, and password (stored only as a secure hash, never in readable form).
- Profile information — display name, profile photo, and address or location if you choose to provide it.
- Claim information — details you submit through intake forms, including information about incidents, injuries, family members, and supporting documentation. This may include sensitive categories such as health and legal information.
- Communications — messages you send us through the dashboard, contact forms, or email.
- Connected email data — if you choose to link a Gmail or Outlook account, see sections 3 and 4.
- Technical information — IP address, browser type, and device information, used for security and to keep the service running.
2. How We Use Your Information
- To create and administer your account and verify your identity.
- To prepare, submit, and track claims on your behalf under USVSST, FASAI, ATA, and related programs.
- To communicate with you about your claim, respond to questions, and provide support.
- To display your connected email inbox inside the dashboard, if you have linked an account.
- To meet legal, regulatory, and recordkeeping obligations.
- To secure our services, detect fraud, and prevent abuse.
We do not sell your personal information. We do not use your information for advertising, and we do not share it with data brokers.
3. Google User Data (Gmail)
Linking a Gmail account is entirely optional. The dashboard works fully without it. If you do choose to connect one, the following applies.
What we access
With your explicit consent through Google’s standard OAuth screen, we request the gmail.modifyscope. This allows the dashboard to read your email messages and their metadata, send messages on your behalf when you compose or reply, and change a message’s read status.
Why we need it
This access exists for one purpose: to let you read and reply to your email inside the PBS dashboard, so you can manage claim correspondence without switching between applications. Read access powers the inbox view, send access powers replies, and modify access marks messages as read when you open them.
How we handle it
- We never store the content of your emails. Messages are fetched from Google in real time when you open the inbox and are displayed to you directly. They are not copied into our database.
- We never see your Google password. Authentication happens entirely on Google’s servers. We receive only a revocable access token.
- Access tokens are stored on our servers solely to keep your session working, and are protected by database access controls that restrict every record to its owner.
- Only you can see your own connected mailbox. No other user, and no PBS staff member, can browse your email through the dashboard.
- We do not use Google user data to train any artificial intelligence or machine learning model.
- We do not transfer Google user data to third parties, except as required by law.
- We do not use Google user data for advertising, and we do not sell it.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Microsoft User Data (Outlook)
Linking an Outlook or Hotmail account is also optional. When you connect one, we request permission to read and send mail on your behalf through the Microsoft Graph API. The same protections described in section 3 apply: we do not store your message content, we never receive your password, and access can be revoked by you at any time.
5. Legal Basis for Processing
Where required by law, we rely on the following bases:
- Consent — for optional features such as connecting an email account or sharing your location.
- Contract — to deliver the claim services you have engaged us for.
- Legal obligation — to comply with recordkeeping and reporting requirements.
- Legitimate interests — to keep our services secure and prevent abuse.
7. How We Protect Your Data
- All traffic is encrypted in transit using HTTPS/TLS.
- Database row-level security restricts every record so that users can only access their own data.
- Every request to our servers is authenticated before any data is returned.
- Passwords are stored only as salted hashes and are never readable by us or our staff.
- Email content shown in the dashboard is rendered in a sandboxed frame to block malicious scripts.
- Access to production systems is limited to authorised personnel.
No system can be guaranteed perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law.
8. Data Retention
We keep claim-related records for as long as your claim is active and afterwards for the period required by law and program rules. Account information is kept while your account remains open. If you disconnect an email account, its access tokens are deleted immediately. When you close your account, we delete or anonymise your data except where we are legally required to retain it.
9. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Request deletion of your information, subject to legal retention requirements.
- Object to or restrict certain processing.
- Receive a copy of your data in a portable format.
- Withdraw consent at any time, including for email account access.
To exercise any of these rights, email us at support@pillarbridgesolution.com. We respond within the timeframe required by applicable law.
10. Revoking Email Access
You can disconnect a linked mailbox at any time, using either method:
- From the dashboard — open My Emails and remove the account. Its stored tokens are deleted immediately.
- From Google — visit myaccount.google.com/permissions and remove access for Pillar Bridge Solutions.
- From Microsoft — visit account.live.com/consent/Manage and remove access.
Revoking access stops all future email access immediately and does not affect your claim.
11. International Transfers
We support clients worldwide, and our infrastructure providers may process data in countries other than your own. Where required, we use appropriate safeguards such as standard contractual clauses to protect information transferred across borders.
12. Children’s Privacy
Our services are intended for adults. We do not knowingly collect information directly from children under 13. Where a claim involves a minor, information is provided by a parent or legal guardian acting on their behalf. If you believe a child has provided us information directly, contact us and we will remove it.
13. Changes to This Policy
We may update this policy as our services evolve. When we make material changes, we will update the effective date above and, where appropriate, notify you by email or through the dashboard. Continued use of our services after an update means you accept the revised policy.
14. Contact Us
For any privacy question, request, or concern, contact us:
Pillar Bridge Solutions LLC
Email: support@pillarbridgesolution.com
Phone: +1-929-485-7212
We aim to respond to all privacy enquiries within 30 days.