PC Matic, Inc.

Privacy Policy

Effective Date: June 5, 2026 | Last Updated: June 29, 2026

PC Matic, Inc. (‘PC Matic,’ ‘we,’ ‘us,’ or ‘our’) is an American-made cybersecurity company committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our websites, use our software products and services, or otherwise interact with us.

This policy covers all PC Matic websites (pcmatic.com, pcpitstop.com, portal.pcpitstop.com, cart.pcpitstop.com, delist.pcmatic.com, knowledgebase.pcmatic.com, documentation.pcmatic.com, docs.pcmatic.com, and partners.pcpitstop.com), all software products (PC Matic Home, PC Matic Pro, PC Matic VPN, PC Matic Delist, Identity Protection, and our mobile applications), and all interactions with PC Matic.

Enterprise and government customers should also refer to their service agreements and any applicable Data Processing Addendum. In the event of a conflict between this policy and a specific service agreement, the service agreement will control.

By using our Websites or Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of our Websites and Services.

Section 1: Information We Collect

1.1 Information You Provide

When you create an account, purchase products, or contact us, you may provide:

  • Account and registration information (name, email address, password, company name, job title, address, phone number)
  • Billing and payment information (processed by our third-party payment processor, currently Stripe; we do not store payment card numbers)
  • Customer support communications and attachments (processed through our support platform, currently HelpScout)
  • Marketing preferences and survey responses

1.2 Information Our Software Collects

Our security software requires elevated system privileges to protect your device against malware, ransomware, and other threats. We want to be transparent about what this means for your data.

What we access vs. what we collect: Our software scans files, applications, processes, network configurations, and browsing history on your device to identify threats. We transmit security-relevant data to our servers for analysis — not the contents of your personal documents, emails, or photos. Below is a product-by-product breakdown.

PC Matic Home and PC Matic Pro

Data you provide: Name, email address, password, company name, job title, address, phone number, and software license key.

Data collected automatically:

  • Device identifiers (device ID, machine ID, endpoint ID) and computer hostname
  • Operating system version, hardware configuration, and system status
  • IP address and approximate geolocation
  • Installed software inventory, application metadata, and file names
  • Security event data, malware detection results, and scan reports
  • System performance data, diagnostic logs, and product telemetry
  • License and subscription validation information
  • Network configuration information
  • Browsing history (accessed for security scanning; not stored or transmitted for non-security purposes)

PC Matic VPN

Data collected: Account and subscription information, VPN server connection metadata, connection timestamps, device and application version, IP address (for connection establishment), and diagnostic data.

PC Matic VPN maintains a strict no-log policy — we do not monitor or record browsing activity, website content, or DNS queries while the VPN is in use.

PC Matic Delist

Data you provide: Full name, current and previous addresses, email addresses, phone numbers, and Social Security numbers (SSN). This sensitive information is collected solely for the purpose of searching for and requesting removal of your data from data broker websites.

Data collected automatically: Search and monitoring status, data broker removal request status, service activity logs, account identifiers, device and browser information used to access the service, and IP address and diagnostic information.

SSN data is encrypted in transit and at rest, subject to strict access controls, and deleted within 30 days of service completion or upon request. See Section 7 for additional sensitive data protections.

Identity Protection

Data you provide: Full name, date of birth, address, email, and phone number. Data collected automatically: Service enrollment status, monitoring alerts, authentication logs, device information, and IP address.

Mobile Applications (Android/iOS)

Data collected automatically: Installed application information, device identifiers, operating system information, security and threat detection data, and application usage diagnostics. This data is transmitted only to PC Matic servers and is not shared with third parties.

1.3 Information Collected Through Our Websites

When you visit our Websites, we automatically collect device and browser information (type, version, operating system, screen resolution), network information (IP address, approximate geolocation), and usage data (page views, time on pages, clicks, scroll depth, form submissions, file downloads, session starts, purchase and conversion events) through cookies and tracking technologies. Non-essential tracking technologies activate only after you provide affirmative consent through our Consent Management Platform. See Section 4 for details.

1.4 Information from Third Parties

We may receive information from third-party partners who help us deliver our services. For example, we currently receive identity monitoring data from IdentityForce/TransUnion and data broker scan results from Optery to deliver our Identity Protection and Delist services. These partners may change as our service offerings evolve.

Section 2: How We Use Your Information

We use your information for the following purposes:

  • Providing, operating, and improving our Websites and Services
  • Processing transactions, managing subscriptions, and fulfilling orders
  • Delivering cybersecurity protection, including malware detection, threat analysis, and security alerting
  • Providing identity monitoring and data broker removal services
  • Communicating with you about your account, orders, and support requests
  • Sending marketing and promotional communications (with your consent)
  • Analyzing website usage and measuring advertising effectiveness (with your consent)
  • Detecting and preventing fraud (via ClickCease and Google reCAPTCHA)
  • Complying with legal obligations and responding to lawful requests
  • Conducting anonymized aggregate research for threat intelligence and product improvement

We do not use personal information for purposes materially different from those described above without providing you notice and, where required, obtaining your consent.

Section 3: How We Share Your Information

PC Matic does not sell your personal information in the traditional sense. However, our use of advertising technologies may constitute ‘sharing’ of personal information under certain state privacy laws. You may opt out of this sharing at any time (see Section 6).

3.1 Service Providers

We may share personal information with third-party service providers who process data on our behalf for purposes such as payment processing, cloud hosting and infrastructure, customer support, technical support, identity monitoring, data broker removal, application monitoring, and related business functions. These providers are contractually required to protect your data and use it only for the services they perform on our behalf. Our current service providers include, but are not limited to:

  • Stripe — payment processing (billing information, transaction details, and customer contact information necessary for payment processing)
  • Amazon Web Services (AWS) — cloud hosting and infrastructure (all service data)
  • HelpScout — customer support platform (support tickets, contact info, attachments)
  • Agilant Solutions, Inc. — premium technical support (customer name, email, phone, account information, support case details, device and system information, diagnostic logs, software inventory, security-related information, and remote desktop session information)
  • Rollbar, Inc. — application error monitoring (error logs, exception reports, diagnostic data, device and browser information, IP address, account identifiers, and session metadata; personal data is not intentionally collected but may be incidentally included in error reports)
  • IdentityForce / TransUnion — identity protection services (information required for monitoring)
  • Optery — data broker removal services (personal information including SSNs submitted by Delist users)

We may add, remove, or replace service providers from time to time. Material changes to our service provider relationships will be reflected in updates to this policy.

3.2 Advertising and Analytics Partners

With your consent, we may share cookie identifiers, IP address, browser/device information, and website interaction data with advertising and analytics partners for campaign measurement, audience targeting, and remarketing. The specific partners we work with may change over time as our marketing programs evolve.

As of the date of this policy, these partners include, but are not limited to: Google (Analytics, Ads, reCAPTCHA), Meta/Facebook, LinkedIn, Microsoft (Ads, Clarity), Spotify, StackAdapt, Vibe, Wrangler Media, CJ (Commission Junction), Trackable, and Zoho (PageSense). All advertising and analytics technologies activate only after affirmative consent through our Consent Management Platform.

3.3 Other Disclosures

We may also disclose your information in the following circumstances:

  • To comply with applicable law, respond to lawful requests (subpoenas, warrants, court orders), or protect our rights and safety
  • In connection with a merger, acquisition, or sale of assets (with prior notice to affected users)
  • In de-identified, aggregated form for threat intelligence and research that cannot reasonably identify you

Section 4: Cookies and Tracking Technologies

Our Websites use cookies and similar technologies managed through Google Tag Manager (GTM-N36L2Q) and our Consent Management Platform, Cookiebot. Strictly necessary cookies are always active. All other cookies require your affirmative consent before activation.

4.1 Technologies We Use

We may use various cookies, pixels, tags, and similar tracking technologies on our Websites for analytics, advertising, fraud prevention, and functionality purposes. The specific technologies we use may change over time. As of the date of this policy, our tracking technologies include, but are not limited to, the following:

Analytics and Performance: Google Analytics (GA4, with IP anonymization enabled by default), Microsoft Clarity, and Zoho PageSense. These tools help us understand how visitors use our Websites through page view tracking, session recording, and heatmap analysis.

Marketing and Advertising: Google Ads, Meta/Facebook Pixel, LinkedIn Insight Tag, Microsoft Ads, Spotify, StackAdapt, Vibe, Wrangler Media, CJ (Commission Junction), and Trackable. These technologies measure advertising effectiveness and enable remarketing, and activate only with your consent.

Fraud Prevention: ClickCease (click fraud detection) and Google reCAPTCHA (bot detection). These technologies may operate without consent as they protect the integrity of our services.

Functional: Vimeo (video playback) and HelpScout (customer support chat).

Consent Management: Cookiebot manages your cookie preferences, blocks non-essential technologies before consent, and honors Global Privacy Control (GPC) signals.

4.2 Managing Your Preferences

You can control tracking technologies through:

  • Our cookie consent banner (displayed on your first visit)
  • The persistent privacy settings icon in the lower-left corner of our Websites
  • The ‘Do Not Sell My Info’ link in our website footer
  • Your browser’s built-in cookie settings
  • Enabling Global Privacy Control (GPC) in your browser

For a complete cookie inventory, see our Cookie Policy at pcmatic.com/privacy/cookies.asp.

4.3 Do Not Track and Global Privacy Control

We recognize and honor the Global Privacy Control (GPC) signal through Cookiebot. When we detect GPC, we automatically disable non-essential tracking and treat it as a valid opt-out of the sale or sharing of personal information.

We do not currently respond to Do Not Track (DNT) browser signals, as there is no uniform industry standard for DNT. We encourage users who wish to opt out to enable GPC or use our cookie consent controls.

Section 5: Data Security

As a cybersecurity company, data security is foundational to our mission. We implement comprehensive technical and administrative safeguards to protect your information.

Technical safeguards include encryption of all data at rest (AES-256 equivalent) and in transit (TLS 1.2+), hosting on SOC 2 certified Amazon Web Services infrastructure in the United States, and role-based access controls limiting data access to 55 authorized employees and contractors.

Administrative safeguards include a written Information Security Program, a documented Incident Response Plan for breach detection, containment, and notification, security awareness training for all personnel with data access, and contractual security requirements for third-party service providers. Stripe, our payment processor, is PCI DSS compliant.

Social Security numbers and other sensitive data collected by PC Matic Delist are subject to enhanced protections, including additional access restrictions, dedicated encryption controls, and accelerated deletion timelines.

Despite these measures, no method of transmission or storage is completely secure. To report a security concern, contact [email protected].

Section 6: Your Privacy Rights

6.1 Rights Available to All Users

PC Matic provides all U.S. residents with meaningful privacy rights regardless of your state of residence. Twenty U.S. states currently have comprehensive consumer privacy laws — California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — with additional states taking effect in 2027.

We extend the core rights provided under these laws to all of our users. Your rights include:

  • Right to Access — request disclosure of the personal information we have collected, the sources, the purposes, and the third parties with whom we share it
  • Right to Delete — request deletion of your personal information, subject to certain legal exceptions
  • Right to Correct — request correction of inaccurate personal information
  • Right to Data Portability — receive a copy of your data in a portable, readily usable format
  • Right to Opt-Out of Targeted Advertising — adjust your cookie preferences or enable GPC in your browser
  • Right to Opt-Out of Sale/Sharing — click “Do Not Sell My Info” in our footer or enable GPC
  • Right to Opt-Out of Profiling — opt out of profiling that produces legal or similarly significant effects
  • Right to Appeal — if we deny your request, you may appeal and we will provide instructions
  • Right to Non-Discrimination — we will not discriminate against you for exercising your rights

6.2 California CCPA/CPRA Disclosures

In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:

  • Identifiers (name, email, IP address, device identifiers)
  • Customer Records (name, address, phone, financial information)
  • Commercial Information (purchase history, subscriptions)
  • Internet/Electronic Network Activity (browsing data, website interaction data)
  • Geolocation Data (approximate location from IP)
  • Professional Information (company name, job title for business customers)
  • Sensitive Personal Information (Social Security numbers collected by PC Matic Delist)

We disclose all of the above categories to service providers for business purposes. We share Identifiers and Internet/Electronic Network Activity with advertising partners for cross-context behavioral advertising, with your consent. We do not sell personal information.

You have the right to limit our use and disclosure of sensitive personal information to purposes necessary to perform the services you requested.

Financial Incentives. PC Matic does not offer financial incentives, price differences, or service differences in exchange for the collection, retention, sale, or sharing of your personal information.

Data Broker Status. PC Matic is not a data broker as defined under the California Delete Act (SB 362) or any other applicable state law. PC Matic Delist assists consumers in removing their information from third-party data brokers but does not itself operate as a data broker.

Do Not Track. For information about how our Websites respond to Do Not Track and Global Privacy Control signals, see Section 4.3.

Consumer Request Metrics. In the preceding 12 months (June 2025 – June 2026), PC Matic received [NUMBER] verifiable consumer requests under the CCPA. This figure will be updated annually.

6.3 Sensitive Personal Information

Certain data we collect is classified as sensitive personal information under state privacy laws, including:

  • Social Security numbers (collected only by PC Matic Delist for data broker removal)
  • Browsing history (accessed by our security software for threat scanning, not stored for non-security purposes)
  • Approximate geolocation (derived from IP address)

We collect sensitive data only for the specific purposes disclosed in this policy and do not use it for secondary purposes. Where required by applicable state law, we obtain your affirmative consent before collecting or processing sensitive personal information. You may withdraw your consent or request that we limit our use of sensitive personal information at any time by contacting us using the information in Section 12.

6.4 Automated Decision-Making and Profiling

PC Matic does not use automated decision-making processes that produce legal or similarly significant effects on individuals without human involvement. Our cybersecurity software uses automated threat detection and analysis to protect your devices, but these automated processes relate to device security, not to decisions about you as an individual (such as creditworthiness, employment, insurance, or access to services). Our advertising technologies use automated audience segmentation and targeting, which you may opt out of at any time through your cookie preferences or by enabling GPC. If we implement automated decision-making that produces legal or similarly significant effects in the future, we will update this policy and provide appropriate notice and opt-out mechanisms as required by applicable law.

6.5 How to Exercise Your Rights

To submit a privacy request, contact us through any of the following channels:

We will verify your identity before processing access, deletion, or correction requests. Verification may require you to provide information that matches what we have on file for your account. We will respond within the timeframes required by applicable law: 45 days under the CCPA (with a 45-day extension where reasonably necessary), 30 days under the GDPR (with a 60-day extension for complex requests), and comparable timeframes under other state privacy laws. If we deny your request, we will explain the reason and provide instructions for how to appeal. Appeals will be processed within 60 days.

You may designate an authorized agent to submit requests on your behalf. Authorized agents must provide signed written authorization or a valid power of attorney. Even when an authorized agent submits a request, we may verify your identity directly to protect your account.

Nevada residents may submit a separate opt-out-of-sale request using the same contact information.

6.6 European Economic Area, United Kingdom, and Switzerland (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and applicable national implementing laws apply to our processing of your personal data. This section supplements the rights described above with information specific to GDPR requirements.

Legal Bases for Processing. We process your personal data only where we have a valid legal basis under Article 6 of the GDPR:

  • Contract performance (Article 6(1)(b)) — processing necessary to provide the cybersecurity services you purchased, including account management, license verification, delivery of security updates, and customer support.
  • Legitimate interests (Article 6(1)(f)) — processing necessary for network and information security purposes, including malware detection, threat analysis, security telemetry collection, and protection against cyber threats. GDPR Recital 49 expressly recognizes ensuring network and information security as a legitimate interest. We have conducted a balancing assessment and concluded that our security interests do not override your fundamental rights and freedoms, particularly given the nature of our services and the security benefits to you.
  • Consent (Article 6(1)(a)) — processing based on your freely given, specific, informed, and unambiguous consent, including marketing communications, optional product improvement telemetry, and the placement of non-essential cookies and tracking technologies. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Legal obligation (Article 6(1)(c)) — processing necessary to comply with applicable laws, regulations, court orders, or legal proceedings.

Your Rights Under the GDPR. In addition to the rights described in Section 6.1, EEA/UK/Swiss residents have the following additional rights under the GDPR:

  • Right to restriction of processing (Article 18) — you may request that we restrict processing of your personal data while we verify its accuracy, while we assess an objection, where processing is unlawful but you prefer restriction over erasure, or where we no longer need the data but you require it for legal claims.
  • Right to object (Article 21) — you may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. For direct marketing, the right to object is absolute and we will cease processing immediately upon your request.
  • Right to data portability (Article 20) — you may receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
  • Right not to be subject to automated decision-making (Article 22) — you have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects on you. Our security software makes automated threat detection and quarantine decisions for your protection; you may request human review of any automated decision.

Response Timeframe. We will respond to GDPR data subject requests within 30 calendar days. If we need additional time due to the complexity or volume of requests, we will notify you within the initial 30-day period and may extend the response time by up to 60 additional days (90 days total).

EU Representative. As required by Article 27 of the GDPR, PC Matic is in the process of appointing a representative in the European Union who will serve as a point of contact for data subjects and supervisory authorities regarding our processing activities. Details of our EU Representative will be published on this page and at pcmatic.com/privacy once the appointment is finalized. In the interim, EEA/UK/Swiss residents may direct privacy inquiries to [email protected].

Right to Lodge a Complaint. If you believe our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. We encourage you to contact us first at [email protected] so we can attempt to resolve your concern directly.

6.7 Canada (PIPEDA)

If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation govern our processing of your personal information. We process your data in accordance with PIPEDA’s ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance. Canadian residents have the right to access their personal information held by PC Matic and to challenge its accuracy. To submit a request, contact us at [email protected]. If you are unsatisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada.

Section 7: Data Retention

We retain personal information only as long as necessary for the purposes described in this policy:

  • Account information — retained while active; deleted or anonymized within 90 days of account closure
  • Security telemetry and diagnostics — retained for 12–24 months, then anonymized for aggregate threat intelligence
  • PC Matic Delist data (including SSNs) — deleted within 30 days of service completion or upon request
  • Identity Protection data — deleted within 90 days of service cancellation
  • Advertising and analytics data — retained per third-party platform policies; deleted when consent is withdrawn
  • Customer support records — retained for up to 3 years for quality and training purposes
  • All data may be retained longer when required by applicable law or legal proceedings

When data is no longer needed, we delete or anonymize it using commercially reasonable methods designed to prevent reconstruction or re-identification.

Section 8: Data Breach Notification

All 50 U.S. states, the District of Columbia, and U.S. territories have enacted data breach notification laws. PC Matic maintains an Incident Response Plan and will notify affected individuals and relevant state authorities in accordance with applicable law if a breach involving personal information occurs.

Notifications will be provided without unreasonable delay and will include a description of the incident, the types of information involved, the steps we have taken in response, and recommendations for affected individuals to protect themselves.

Section 9: Children’s Privacy

Our Websites and Services are not directed to children under 13 (or under 16 in certain states). We do not knowingly collect personal information from children under 13.

Where state law restricts the sale or sharing of data for minors under 16, we comply with those requirements. If we discover a child has provided personal information, we will delete it promptly. Parents or guardians may contact us using the information in Section 12.

Section 10: International Data Transfers

PC Matic is based in the United States, and all data is processed and stored in the U.S. via Amazon Web Services. If you are outside the U.S., your information will be transferred to and processed in the U.S., where data protection laws may differ from those in your jurisdiction.

For EEA/UK/Swiss residents, we rely on the following transfer mechanisms as required by the GDPR to ensure your personal data receives adequate protection when transferred to the United States:

  • EU–U.S. Data Privacy Framework (DPF). PC Matic is pursuing certification under the EU–U.S. Data Privacy Framework, as approved by the European Commission’s adequacy decision of July 10, 2023. Once certified, transfers of personal data from the EEA to PC Matic will be covered by the DPF. Certification status will be published at dataprivacyframework.gov and updated on this page.
  • Standard Contractual Clauses (SCCs). We maintain the European Commission’s Standard Contractual Clauses (Commission Implementing Decision 2021/914) as a transfer mechanism for personal data from the EEA/UK/Switzerland to the United States. These clauses provide contractual safeguards ensuring your data receives protection equivalent to what it would receive within the EEA.
  • Supplementary measures. We implement technical and organizational supplementary measures to protect transferred data, including encryption in transit and at rest via AWS, access controls restricting personnel access to personal data, and contractual restrictions on our service providers’ use of your data.

For Canadian residents, your personal information is transferred to and processed in the United States. We process your data in accordance with PIPEDA principles and maintain contractual protections with our service providers. You have the right to be informed that your data may be accessible to U.S. authorities under applicable U.S. law.

Section 11: Additional Information

Third-Party Links. Our Websites may contain links to third-party websites or services. We are not responsible for their privacy practices and encourage you to review their privacy policies before providing any personal information.

Changes to This Policy. We may update this Privacy Policy periodically. Material changes will be communicated via email and a prominent notice on our Websites. The ‘Last Updated’ date will be revised, and significant changes may require re-consent for cookie preferences.

Accessibility. If you have difficulty accessing this policy due to a disability, contact us and we will provide it in an alternative format.

Section 12: Contact Us

If you have questions, concerns, or wish to exercise your privacy rights, please contact us: