This Privacy Policy explains how Profitalize, Inc. ("Profitalize," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our platform and services (collectively, the "Service"). We are committed to protecting your privacy and handling your data with transparency. This policy applies to all users of the Service, including website visitors, trial users, and paying customers. By using the Service, you consent to the data practices described in this policy.
We collect information to provide and improve the Service.
Account Information
When you create an account, we collect your name, email address, company name, job title, and password. For paid plans, we also collect billing information (processed securely by Stripe—we do not store full credit card numbers).
Usage Data
We automatically collect information about how you use the Service, including pages visited, features used, actions taken, timestamps, and session duration. This data helps us understand usage patterns and improve the platform.
Customer Data
Data you upload, create, or generate through the Service, including contacts, deals, automations, analytics, and integrations. You are the data controller for Customer Data; we are the data processor.
Device & Technical Data
We collect browser type, operating system, IP address, device identifiers, and referring URLs. This data is used for security, performance optimization, and troubleshooting.
Cookies & Tracking
We use cookies and similar technologies for authentication, preferences, analytics, and marketing. See Section 8 for full cookie details and your control options.
Third-Party Data
If you connect third-party integrations (Shopify, Stripe, HubSpot, etc.), we receive data from those services as authorized by you. We only access data necessary for the integration to function.
Service Delivery
To provide, maintain, and improve the Service. To process transactions, send service notifications, and respond to support requests.
Automation & AI
To power your automations, AI-driven recommendations, and analytics. Your data is processed to generate insights specific to your account. We do not use your data to train AI models for other customers.
Security
To detect, prevent, and respond to security incidents, fraud, and abuse. To enforce our Terms of Service and protect the rights and safety of our users.
Communication
To send you account-related communications, product updates, and, with your consent, marketing materials. You can opt out of marketing communications at any time.
Analytics & Improvement
To understand usage patterns, measure feature adoption, and improve the Service. We use aggregated, anonymized data for product development and benchmarking.
Legal Compliance
To comply with legal obligations, respond to lawful requests, and protect our legal rights.
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data based on the following legal bases:
Contract Performance
Processing necessary to provide the Service as described in our Terms of Service—including account management, billing, and core platform functionality.
Legitimate Interests
Processing necessary for our legitimate business interests, such as improving the Service, ensuring security, and communicating relevant updates—balanced against your privacy rights.
Consent
Processing based on your explicit consent, such as marketing communications, optional analytics cookies, and certain data enrichment features. You may withdraw consent at any time.
Legal Obligation
Processing necessary to comply with legal requirements, such as tax reporting, audit requirements, and responding to valid legal process.
We do not sell your personal information. We share data only in the following circumstances:
Service Providers
We use trusted third-party providers for hosting (AWS), payment processing (Stripe), email delivery (SendGrid), analytics (internal tools), and monitoring. All providers are bound by data processing agreements and process data only on our instructions.
Integrations
When you connect third-party tools, data flows between Profitalize and those tools as configured by you. We do not share data with integrations you have not explicitly connected.
Legal Requirements
We may disclose information if required by law, subpoena, court order, or government request. We will notify you of such requests unless legally prohibited.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you before your data is subject to a different privacy policy.
With Your Consent
We may share data with third parties when you have given us explicit consent to do so.
Profitalize is based in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. For transfers from the EEA, UK, and Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Enterprise customers may request regional data residency options. We ensure that all international data transfers provide an adequate level of data protection consistent with applicable law.
We retain your data for as long as your account is active or as needed to provide the Service. Account information is retained for the duration of your subscription plus 30 days for data export. After account termination, Customer Data is permanently deleted within 30 days. Backup copies are purged within 90 days. Usage logs and analytics data are retained in anonymized form for up to 2 years. Billing records are retained for 7 years as required by tax law. You may request deletion of your personal data at any time (see Section 9 for your rights).
Depending on your location, you may have the following rights regarding your personal data:
Right to Access (GDPR Art. 15 / CCPA)
Request a copy of the personal data we hold about you. We will respond within 30 days.
Right to Rectification (GDPR Art. 16)
Request correction of inaccurate or incomplete personal data. You can update most information directly in your account settings.
Right to Erasure (GDPR Art. 17)
Request deletion of your personal data. We will comply unless we have a legal obligation to retain it.
Right to Data Portability (GDPR Art. 20)
Request your data in a structured, machine-readable format. Export is available through the platform or on request.
Right to Object (GDPR Art. 21)
Object to processing based on legitimate interests, including profiling and direct marketing.
Right to Restrict Processing (GDPR Art. 18)
Request restriction of processing while we verify accuracy or assess an objection.
CCPA Rights
California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information.
How to Exercise Your Rights
Contact us at [email protected] with your request. We will verify your identity and respond within 30 days. You will not be discriminated against for exercising your rights.
The Service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will promptly delete that information. If you believe a child has provided us with personal information, please contact us at [email protected].
We implement industry-standard security measures to protect your data. This includes: encryption at rest (AES-256) and in transit (TLS 1.3); network segmentation and firewall protection; regular security assessments and penetration testing; access controls with role-based permissions and audit logging; SOC 2 Type II certified infrastructure; 24/7 monitoring with automated threat detection; incident response plan with 72-hour notification for confirmed breaches. No system is 100% secure. While we take extensive measures to protect your data, we cannot guarantee absolute security.
Some features let you connect a Google account. We request only the access each feature needs, you choose which to connect, and you can disconnect at any time. Profitalize’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Google Calendar
When you connect Google Calendar, we read the events on your calendars so your calls and meetings appear on your Profitalize calendar and dashboard and can be matched to the contacts and deals they concern. We create, update, or cancel an event on your calendar only when you do so from Profitalize, or — if you turn on “My task due dates” for a calendar — to keep all-day entries for your own task due dates in step with your tasks; turning it off removes them. Synced event details (title, time, attendees, and meeting link) are stored in your workspace.
Gmail (send only)
When you connect Gmail, we can send email from your address that you write or approve in Profitalize. This permission lets us send mail only; it does not let us read, search, or delete anything in your mailbox.
Google Drive
When you attach a Google Drive file to a project, you choose it in Google’s own file picker, and we can access only the files you pick. The Drive access token stays in your browser and is never stored on our servers; we keep only the link and name of the file you attached.
How we protect it
Google access and refresh tokens are encrypted at rest with AES-256-GCM, are never written to logs, and are never returned to your browser. They are used only to provide the features described above, for you.
What we never do with it
We do not sell Google user data, use it for advertising, or transfer it to third parties except as needed to provide the features above, to comply with law, or with your consent. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models. Our staff do not read it unless you ask us to (for example, for support), it is necessary for security or to comply with law, or it has been aggregated and anonymized.
Disconnecting and deletion
You can disconnect Google Calendar or Gmail at any time in Settings, or remove Profitalize’s access from your Google Account permissions page. Disconnecting revokes our access with Google and deletes the stored credentials. Calendar events already synced remain in your workspace history until you delete your account or ask us to delete them at [email protected].
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email and by posting a notice on the Service at least 30 days before the changes take effect. The "Last updated" date at the top of this policy indicates when the latest revision was made. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
For questions or concerns about this Privacy Policy or our data practices, please contact us at: [email protected]. Data Protection Officer: [email protected]. For EU/EEA representatives, contact our designated representative at [email protected]. Profitalize, Inc. — Delaware, United States. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
Contact our privacy team for any questions about how we handle your data.