LEGAL & DATA PROTECTION

Privacy Policy

Last updated 24 August 2026

This explains what personal data Outtricks holds, why, and what you can ask us to do with it.

Note: this document is a plain-language draft prepared for this deployment. It has not been reviewed by a qualified privacy lawyer or DPO.

01.Two Different Roles

Outtricks handles personal data in two distinct capacities, and your rights differ depending on which applies:

  • As controller: for data about you as a customer, your name, work email, Organization details, billing records and how you use the product.
  • As processor: for the prospect and contact data you load into or discover through the Platform. There, your Organization decides what is collected and why; we process it on your instructions. Requests from those individuals should reach the Organization that contacted them, and we will support that Organization in responding.

02.What We Collect As Controller

  • Account data: name, email, hashed password or SSO identifier, Organization and role.
  • Billing data: plan, invoices and credit transactions. Card and payment details are handled securely by Paddle.com (our Merchant of Record); we never store full card numbers.
  • Usage data: feature and API usage, request metadata and error reports, used to operate, secure and improve the service.
  • Support data: messages you send us, including through the contact form on this site.

03.Why We Process It

To provide the service you signed up for (performance of a contract); to bill you and keep accounting records (legal obligation); to keep the Platform secure and detect abuse, and to improve it (legitimate interests); and for marketing where you have opted in (consent, withdrawable at any time).

04.Google User Data Policy & Limited Use Disclosure

When you connect your Google Workspace or Gmail account to Outtricks, our platform requests access to your Google account via OAuth 2.0 with minimal required scopes:

  • https://www.googleapis.com/auth/gmail.send — To send user-initiated business emails and customer communication sequences directly through your connected Gmail account.
  • https://www.googleapis.com/auth/gmail.readonly — To synchronize your incoming inbox replies, thread message conversations, and display customer communications inside the unified CRM Unibox.
  • openid and email: to authenticate and verify your connected email address.

We do not request write access to modify or delete your external mailbox (we never request gmail.modify or full account access).

Google API Limited Use Disclosure:

Outtricks’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically regarding Google user data:

  • Sole Purpose: Google user data is accessed and used solely to provide user-facing CRM email features (sending emails, syncing replies, and displaying conversation threads).
  • No Generalized AI/ML Training: Google Workspace and Gmail user data is never used to develop, train, or fine-tune generalized or third-party artificial intelligence (AI) and/or machine learning (ML) models.
  • No Sale or Advertising: Google user data is never sold to third parties, never used for personalized or targeted advertising, and never transferred to data brokers or external marketing entities.
  • Human Access: Human access to Google user data is strictly prohibited, except with your explicit prior consent for troubleshooting, for security investigations, or as required by applicable law.

05.Third Parties We Rely On

We use sub-processors to run the service, including cloud hosting and databases, Paddle.com Market Limited for payments and Merchant of Record compliance, email and telephony providers for outreach you initiate, and AI model providers for generation features. Providers are engaged under data-processing terms and receive only the data needed for their function. Google user data is never shared with third parties for marketing or training purposes.

The AI layer is intentionally pluggable across providers, which means the specific model provider handling a given generation depends on your configuration.

06.Security

  • Data is encrypted in transit (TLS 1.3) and sensitive credentials are encrypted at rest with AES-256.
  • Tenant isolation is enforced in the database with row-level security, not only in application code, so a coding mistake cannot expose another Organization’s data.
  • Audit logs are append-only and cannot be edited or deleted.
  • Access to production data by our staff is restricted and logged.

07.Retention

Account and business data are retained while your Organization is active. After termination we keep only what we must for legal, tax and accounting purposes, then delete it. Audit and ledger records are retained for their statutory period because they are append-only by design.

08.Your Rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive a portable copy, and to withdraw consent. Under GDPR and CCPA we treat these as first-class product operations rather than support exceptions. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

09.International Transfers

Where data moves between regions, we rely on an approved transfer mechanism such as Standard Contractual Clauses, together with technical measures including encryption in transit and at rest.

10.Cookies

The application uses only what it needs to keep you signed in and remember interface preferences such as your theme. This public site does not run advertising or cross-site tracking cookies. For details, see our Cookie Policy.

11.Changes & Contact

We will post material changes to this policy here and, where required, notify you directly.

Privacy questions

Email: privacy@outtricks.com

Or contact us.