Last updated: January 20, 2025
1. Introduction
DealTracker ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our customer relationship management platform and related services (collectively, the "Service").
2. Information We Collect
2.1 Information You Provide
We collect information you directly provide to us, including:
- Account Information: Name, email address, password, company name, job title
- Profile Information: Photo, bio, preferences, and settings
- Contact Data: Customer information, meeting notes, and communications you store in the Service
- Payment Information: Billing address and payment method details (processed by our payment providers)
- Communications: Feedback, support requests, and correspondence with us
2.2 Information We Collect Automatically
When you use our Service, we automatically collect:
- Usage Data: Features used, actions taken, time spent, and interaction patterns
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, pages viewed, and referring URLs
- Analytics Data: Performance metrics and usage statistics
- AI Usage Data: Queries, prompts, and AI feature interactions (excluding generated content)
2.3 Information from Third-Party Services
If you connect third-party services, we may receive:
- Calendar Data: Meeting information from Google Calendar or other calendar services
- Email Metadata: Sender, recipient, subject, and timestamp (not email content unless you explicitly import it)
- OAuth Information: Basic profile data from authentication providers
3. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Service
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments and questions
- Monitor and analyze usage patterns and trends
- Detect, prevent, and address technical issues
- Provide AI-powered features and insights
- Comply with legal obligations
4. How We Share Your Information
4.1 We Do Not Sell Your Data
We do not sell, trade, or rent your personal information to third parties for their marketing purposes.
4.2 Service Providers
We share information with third-party vendors who help us provide the Service:
- Infrastructure: Cloud hosting and data storage (Supabase, Vercel)
- Payment Processing: Stripe, PayPal, or other payment providers
- Analytics: Google Analytics (anonymized data only)
- AI Services: OpenAI, Anthropic (for AI features)
- Communication: Email service providers
4.3 Legal Requirements
We may disclose information if required to:
- Comply with legal obligations or court orders
- Protect our rights, privacy, safety, or property
- Investigate and prevent fraud or illegal activities
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
5. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption: TLS for data in transit, AES-256 for data at rest
- Access Controls: Role-based permissions and multi-factor authentication
- Data Isolation: Row-level security ensuring account data separation
- Regular Audits: Security assessments and vulnerability testing
- Incident Response: Procedures for detecting and responding to breaches
6. Data Retention
We retain your information for as long as necessary to:
- Provide the Service to you
- Comply with legal obligations
- Resolve disputes and enforce agreements
When you delete your account, we delete or anonymize your data within 90 days, except where retention is required by law.
7. Your Rights and Choices
7.1 Access and Control
You have the right to:
- Access: Request a copy of your personal data
- Correct: Update inaccurate or incomplete information
- Delete: Request deletion of your account and data
- Export: Download your data in a portable format
- Object: Opt-out of certain data processing activities
7.2 Communication Preferences
You can manage your email preferences in account settings or unsubscribe using links in our emails. Note that you cannot opt-out of essential service communications.
7.3 Cookie Preferences
You can control cookies through your browser settings. See our Cookie Policy for more information.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses, to protect your data during international transfers.
9. Children's Privacy
The Service is not intended for children under 16. We do not knowingly collect personal information from children. If we learn we have collected such information, we will promptly delete it.
10. AI and Machine Learning
10.1 How We Use AI
We use AI to enhance the Service by:
- Generating customer insights and recommendations
- Automating activity categorization and triaging
- Providing writing assistance for emails and notes
- Analyzing patterns to improve deal tracking
10.2 AI Data Processing
- AI features process only the data you explicitly submit
- We do not use your data to train external AI models
- AI-generated content belongs to you
- You can opt-out of AI features in your settings
11. California Privacy Rights
California residents have additional rights under the CCPA, including the right to know what personal information we collect, delete personal information, and opt-out of sales (though we do not sell personal information).
12. European Privacy Rights
If you are in the European Economic Area, you have rights under the GDPR, including access, rectification, erasure, portability, restriction, and objection. You may also lodge a complaint with your local supervisory authority.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date indicates when changes were made.
14. Contact Us
If you have questions about this Privacy Policy or our practices, please contact us at:
- Email: privacy@dealtracker.ai
- Address: DealTracker, Inc., San Francisco, CA
- Data Protection Officer: dpo@dealtracker.ai
15. Additional Information for Specific Jurisdictions
15.1 Brazil (LGPD)
Brazilian users have rights under the LGPD similar to GDPR, including access, correction, deletion, and data portability.
15.2 Canada (PIPEDA)
Canadian users can access and correct their personal information and withdraw consent for certain uses of their data.
15.3 Australia (Privacy Act)
Australian users can access and correct personal information and complain about privacy breaches to the Office of the Australian Information Commissioner.