Legal

Privacy Policy

How RevenuePilot collects, uses, and protects your information.

1. Introduction

RevenuePilot ("we," "our," "us") provides a revenue operations platform for lead-driven businesses. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Service.

By using the Service, you agree to this policy. If you do not agree, do not use the Service.

2. Account Information

We collect information you provide when creating an account: - Name and email address - Password (hashed, never stored in plaintext) - Organization name and details - Business profile (industry, size, model)

This information is used to provide the Service, authenticate you, and communicate with you about your account.

3. Organization Information

When you create or join an organization, we collect: - Organization name, slug, country, currency, timezone - Website, business model, logo - Settings and preferences

This information is visible to other members of your organization according to their roles.

4. Leads, Contacts, and Conversations

**Customer-controlled data:** You control the leads, contacts, and conversation data in your organization. This includes: - Lead/contact details (name, email, phone, company, custom fields) - Conversation history (messages, attachments, metadata) - Pipeline deals and revenue records - Qualification responses and scores - Integration data synced from external platforms

**We do not:** Use this data for our own marketing, sell it, or share it with third parties except as needed to provide the Service (e.g., AI processing, integration sync).

5. Marketing Attribution Data

We collect attribution data to connect marketing spend to revenue: - UTM parameters and referrer data - Campaign, ad set, and ad identifiers - Click and impression timestamps - Conversion events

This data is used solely for your organization's attribution reporting.

6. Integrations

When you connect third-party integrations (Meta Ads, Google Ads, HubSpot, Slack, etc.), we: - Store OAuth tokens encrypted at rest - Sync data per your configuration - Use integration data only for your organization's operations

You can disconnect integrations at any time. Disconnection revokes our access and stops syncing.

7. Logs and Device Data

We automatically collect: - IP address, browser type, operating system - Access timestamps, page views, feature usage - Error logs and performance metrics

This data is used for security, debugging, and product improvement.

8. AI Processing

RevenuePilot uses AI (including third-party providers like OpenAI) for: - Growth Analyst queries - Conversation summarization - Lead scoring - Risk detection - Automation suggestions

**Data sent to AI providers:** - Only the minimum context needed for the task - No API keys, passwords, or encryption keys - Processed under data processing agreements

**You can:** Disable AI features in organization settings.

9. Cookies and Analytics

We use: - **Essential cookies:** Session management, authentication, security - **Analytics cookies:** Product usage (opt-out available)

We do not use third-party advertising cookies. Analytics data is aggregated and not linked to personal identity where possible.

10. Analytics

We use privacy-friendly analytics (e.g., Vercel Analytics) to understand product usage. No personally identifiable information is sent to analytics providers.

11. Purposes of Processing

We process your information to: - Provide and improve the Service - Authenticate and authorize users - Send service communications (billing, security, updates) - Respond to support requests - Comply with legal obligations - Prevent fraud and abuse - Enforce our Terms of Service

12. Service Providers

We share data with vetted subprocessors only as needed: - **Hosting:** Vercel, Supabase (AWS) - **AI:** OpenAI (data processing agreement in place) - **Email:** Resend - **Payments:** Stripe (when billing enabled) - **Monitoring:** Vercel, Sentry

Full subprocessors list available on request.

13. Storage and Retention

- Account data: Retained while account is active - Organization data: Retained while organization exists - Leads/contacts/conversations: Retained per your retention settings - Logs: 90 days (security), 1 year (audit) - Deleted data: Purged within 30 days of deletion request

Backups retained up to 90 days for disaster recovery.

14. Security

- Encryption at rest (AES-256) and in transit (TLS 1.3) - Row-level security on all tenant tables - Service-role keys never leave server environment - Regular penetration testing - SOC 2 Type II in progress (not yet certified) - Incident response plan documented

15. Data Export

Organization admins can export organization data (leads, contacts, conversations, deals, revenue) in CSV/JSON format from Settings → Data Export.

16. Data Deletion

Organization admins can request full organization deletion. This permanently removes all data within 30 days. Individual leads/contacts can be deleted by authorized users per RBAC.

17. Your Privacy Rights

Depending on your jurisdiction, you may have rights to: - Access your personal data - Rectify inaccurate data - Erase your data ("right to be forgotten") - Restrict processing - Data portability - Object to processing - Withdraw consent (where applicable)

Submit requests via Settings → Privacy or email privacy@revenuepilot.com.

19. International Data Transfers

Our infrastructure is hosted in the US (AWS us-east-1) and EU (Frankfurt). If you're outside these regions, your data will be transferred internationally. We rely on Standard Contractual Clauses and adequacy decisions where applicable.

20. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect children's data. If you believe we have, contact us immediately.

21. Policy Updates

We may update this policy. Material changes will be communicated via email and in-app notification 30 days before effective date. Continued use constitutes acceptance.

22. Contact

Questions about this policy or your data: - Email: privacy@revenuepilot.com - In-app: Settings → Privacy - Mail: RevenuePilot, [Company Address - TBD]

Last updated: September 2025

--- **Note:** Company registration details, governing law, and Data Protection Officer contact to be finalized with legal counsel.

Legal review pending

This policy is a functional draft. Company registration details, governing law, Data Protection Officer contact, and subprocessors list require legal counsel review before commercial launch.