Privacy Policy
We built Pipeline Intelligence for customer-facing teams who trust us with their account and pipeline data. This policy explains what we collect, how we protect it, and what we do not do with your information. We do not sell customer data. We do not share your data with third parties for their own advertising, marketing, or data-broker purposes.
1. Who this policy covers
This policy applies to visitors to our marketing website, users who create a workspace (tenant), invited team members, and enterprise customers who contact sales or are provisioned by our platform administrators. It covers personal information about users and business information your organization stores in the Service (prospects, contacts, notes, activities, and AI-generated briefings). It also covers business contacts who exchange SMS with authorized agents through Pipeline Connect phone features.
2. Information we collect
Account and workspace data
- Name, work email, company name, and authentication credentials (stored securely via our identity provider—we do not store plaintext passwords in our database).
- Workspace settings: branding, subscription plan, seat limits, and billing status.
- Team roster: email, display name, and role (admin or member) within your tenant.
Customer content you enter
- Prospect and account records (company names, contacts, pipeline stage, notes, follow-ups, documents metadata, and similar CRM fields).
- Activity logs and audit events generated in the Service.
- AI intelligence outputs and Deep Research reports saved to accounts when you run those features.
Usage and technical data
- Feature usage (for example monthly intel run counts) to enforce plan limits and improve reliability.
- Server logs (IP address, request time, error diagnostics) for security and operations—retained for a limited period.
- Payment-related identifiers from our payment processor when you subscribe (we do not store full card numbers on our servers).
SMS messaging (Pipeline Connect)
When a workspace enables Pipeline Connect, authorized agents may send and receive SMS with business contacts. For those messages we process:
- Mobile phone numbers of agents and their business contacts (from and to numbers).
- Message body text, timestamps, delivery status, and related metadata needed to display conversation history in the Service and log activity on account records.
- Carrier-assigned message identifiers (for example Twilio message SIDs) for delivery tracking and troubleshooting.
We use SMS data only to deliver messages you or your agents initiate, show conversation threads in account dossiers, log activity for your team, and comply with carrier and legal requirements. We do not use SMS content or contact phone numbers for advertising, sell them to data brokers, or share them with third parties for their own marketing purposes.
Mobile messaging privacy (A2P / carrier compliance): No mobile information or messaging consent obtained for Pipeline Connect SMS will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers and message content are transmitted only to our telephony service provider (Twilio) as a technical subprocessor to deliver voice and SMS on our instructions — not for Twilio’s own marketing or promotional use of your contacts’ mobile information.
Business contacts may opt out of SMS from a Connect line by replying STOP. For help, reply HELP or contact care@pipeline.care. See our Terms of Service — SMS messaging for program details.
Connected Google account (Gmail and Calendar)
When you choose Connect work mailbox and sign in with Google, Pipeline Intelligence requests access to your Google account only to provide mailbox and calendar features inside your workspace. This section describes how we handle Google user data for OAuth verification and transparency.
Google user data we access
- Your Google account email address and basic profile information (such as name) from Google OAuth.
- Gmail message metadata and content needed to show email threads on account records, compose or reply to messages, and log email activity to account timelines.
- Google Calendar event data (such as title, time, attendees, and description) when you use calendar sync or create follow-ups tied to your calendar.
How we use Google user data
We use Google user data only to operate features you request in the Service, including:
- Displaying and searching email threads linked to prospects and accounts in your workspace.
- Sending email on your behalf when you compose or reply from the Service.
- Syncing calendar events and follow-up reminders for your workspace.
- Logging mailbox activity to shared account records for your team, subject to your role and tenant permissions.
We do not use Google user data for advertising, retargeting, interest-based ads, credit decisions, selling to data brokers, building unrelated marketing databases, or training public AI models for products outside your workspace.
How we share Google user data
We do not sell Google user data. We share it only as needed to deliver the Service:
- Nylas (our email and calendar integration provider) processes mailbox and calendar API requests on our instructions to connect your Google account and sync data.
- Your workspace teammates may see email or calendar activity logged to account records they are permitted to access under your tenant’s roles and settings.
- Infrastructure providers (such as Google Firebase / Google Cloud) host encrypted application data, including cached email thread metadata, under our security controls.
We do not transfer or disclose Google user data to third parties for their own advertising, marketing, lead generation, or data-broker purposes.
Protection, retention, and deletion of Google user data
- Google user data is transmitted over HTTPS and stored with tenant isolation and access controls described in this policy.
- OAuth tokens and synced mailbox data are retained while your mailbox remains connected and as needed to operate the Service.
- You can disconnect your Google mailbox at any time from mailbox settings in the app; we stop new sync and remove integration credentials.
- Workspace administrators can export or purge workspace data, including cached email metadata, from the Security Panel or by contacting support.
4. How we use information
We use collected information only to:
- Provide, operate, and secure the Service for your workspace.
- Authenticate users, enforce tenant isolation, and prevent abuse.
- Process subscriptions and send transactional email (verification, invites, billing receipts where applicable).
- Run AI-powered features you request (account intelligence, live search, Deep Research) using the account context you supply.
- Deliver SMS and voice features you enable through Pipeline Connect, including routing messages, logging threads, and processing opt-out keywords such as STOP and HELP.
- Respond to support requests and comply with law when required.
5. What we do not do
- We do not sell your personal information or customer content.
- We do not share your data with third parties for their own marketing, lead generation, or advertising networks.
- We do not share mobile information or SMS messaging consent with third parties or affiliates for marketing or promotional purposes.
- We do not use your prospect lists to train public AI models for unrelated products.
- We do not allow other customers to access your tenant data—each workspace is logically isolated.
6. Service providers (limited subprocessors)
To run a secure cloud product, we rely on a small set of vetted infrastructure and service providers. They process data only on our instructions to deliver the Service—not for their own commercial use of your content. Categories include:
- Hosting and database — cloud infrastructure and database services (including Google Firebase / Google Cloud) for encrypted storage, authentication, and application delivery.
- Payments — Stripe (or equivalent) for subscription checkout and billing; payment card data is handled by the processor under their security standards.
- Email delivery — transactional email providers (for example Resend or SMTP) to send verification, invite, and operational messages.
- AI and research features — when you enable intelligence or Deep Research, relevant account fields and queries are sent to our configured AI and web-research providers solely to generate the briefing you requested. We select providers with contractual confidentiality obligations where available.
- Telephony and SMS (Twilio) — when you enable Pipeline Connect, phone numbers and message content are processed by Twilio solely to deliver voice calls and SMS on our instructions. Twilio does not use your message content for its own marketing.
We do not authorize these providers to use your customer content for their own product development or marketing. If you need a current list of subprocessors for vendor review, contact care@pipeline.care.
7. How we protect your data
- Production traffic is served over HTTPS (TLS encryption in transit).
- Data at rest is encrypted by our cloud provider’s platform standards.
- Tenant isolation — prospects, users, and billing are scoped to your workspace; access is enforced by authentication, server-side authorization, and Firestore security rules.
- Least privilege — production secrets (API keys, service accounts) are stored in environment configuration, not in client-side code or customer-visible fields.
- Email verification — solo signup and invited users must verify email before accessing workspace data.
- Audit logging — sensitive admin actions are recorded for security review within your tenant.
No method of transmission or storage is 100% secure. We continuously improve controls and respond to incidents per our internal procedures (see also our security documentation for administrators).
8. Your control: export and deletion
- Export — Workspace admins can export tenant data from the Security Panel (JSON bundle of workspace configuration, prospects, users, and recent audit events).
- Deletion — You may delete accounts and records within the Service. Platform administrators can purge a workspace when contractually required; certain protected system tenants cannot be deleted via automation.
- Retention — Customer content remains until you or your administrator deletes it or the workspace is purged. Operational logs are kept for limited periods for security and troubleshooting.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or restrict certain processing of your personal information. Workspace admins can manage roster users and much of your organization’s data directly in the app. For requests we must handle ourselves, email care@pipeline.care from your work address and we will respond within a reasonable time.
10. International users
The Service is operated from the United States. If you access the Service from other regions, you understand that data may be processed in the U.S. and where our subprocessors operate. We implement appropriate safeguards for cross-border processing required by applicable law.
11. Children
The Service is a business-to-business product not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy as the product or law changes. We will post the revised version on this page with an updated “Last updated” date. Material changes may also be communicated by email or in-app notice where appropriate. Continued use of the Service after changes take effect constitutes acceptance of the updated policy for new activity; where required by law we will seek additional consent.
13. Contact us
Questions about privacy or data protection: care@pipeline.care.
Tryedent · Pipeline Intelligence
Marketing site: pipelineintelligence.io · Application:
crm.pipelineintel.io