Legal · Privacy

Privacy Policy

A clear account of the information OpsPilot processes, why we use it, and the controls available to you.

Effective July 20, 2026

01

Scope

This Privacy Policy explains how OpsPilot Systems (“OpsPilot,” “we,” “us,” or “our”) handles information when authorized users access our invite-only customer relationship management service (the “Service”). It applies to account holders, invited users, and people whose business contact information is entered into the Service by a customer.

Organizations and users that upload or enter CRM records are responsible for having a lawful basis to collect, use, and contact the people represented in those records.

02

Information we collect

We process the following categories of information:

  • Account information: name, email address, password-derived authentication credentials, role, account theme, invitation status, and account timestamps.
  • Security and session information: session identifiers, expiration times, IP address, browser or device user agent, and rate-limit records.
  • CRM information: company, contact, lead, deal, task, note, location, email address, phone number, pipeline, and communication records entered or imported by users.
  • Email activity: recipients, subject lines, message bodies, delivery provider, send status, errors, and timestamps for messages initiated through the Service.
  • Support communications: information you provide when contacting us for help or exercising a privacy request.
03

Google user data

If Gmail delivery is enabled, OpsPilot requests only the gmail.send permission. We use this permission solely to send messages that an authorized user instructs the Service to send. OpsPilot does not use this permission to read Gmail inboxes, contacts, message history, or attachments.

To provide this feature, the Service processes the connected sender email address and OAuth credentials needed to obtain short-lived access tokens. OAuth secrets are stored as protected server-side deployment configuration and are not exposed to the browser. Email content is transmitted to Google only when a user initiates sending.

OpsPilot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train generalized artificial-intelligence or machine-learning models.

04

How we use information

We use information to operate the CRM, authenticate users, enforce invite-only access, isolate customer records, import and organize leads, send requested email, display activity history, save preferences, prevent abuse, troubleshoot failures, maintain security, and comply with applicable law.

We do not sell personal information. We do not use CRM records or Google user data for targeted advertising.

05

How information is shared

We disclose information only as needed to provide and protect the Service:

  • Infrastructure providers that host the application, database, and supporting systems.
  • Email providers: Google receives sender, recipient, subject, and message content for Gmail delivery. If a custom email endpoint is configured, that provider receives the recipient, subject, message body, and relevant lead metadata required to send the message.
  • Legal and safety recipients when disclosure is reasonably necessary to comply with law, protect rights and safety, investigate abuse, or secure the Service.
  • Business successors in connection with a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality protections.

We do not permit service providers to use information for their own advertising purposes.

06

Retention and deletion

We retain account and CRM information while the applicable account remains active and as needed to provide the Service. Security logs, send history, and backups may be retained for a limited period for security, reliability, dispute resolution, and legal compliance. When information is no longer required, we delete or de-identify it using reasonable measures.

You may request account or data deletion by emailing parkerduthaler@gmail.com. Revoking Google access stops future OAuth access but may not automatically delete CRM records or prior email logs; contact us to request deletion of those records.

07

Security

We use administrative, technical, and organizational safeguards designed to protect information, including authenticated access, invite-only registration, server-side secrets, encrypted network transport, tenant-scoped database access, and row-level security controls. No storage or transmission system is completely secure, and we cannot guarantee absolute security.

Users must protect their credentials, use the Service only through authorized accounts, and notify us promptly of suspected unauthorized access.

08

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information, or to object to certain processing. You may also revoke OpsPilot’s Google access from your Google Account permissions page. We may need to verify your identity before fulfilling a request.

If your information was entered by an OpsPilot customer rather than directly by you, we may direct your request to that customer because it controls the relevant CRM record.

09

Children and international use

The Service is intended for business users and is not directed to children under 13. We do not knowingly collect personal information directly from children. Information may be processed in the United States and other locations where our providers operate, subject to applicable safeguards.

10

Changes to this policy

We may update this policy as the Service or legal requirements change. We will update the effective date and provide additional notice when required. Material changes to how Google user data is used will be disclosed before that new use begins where required.

11

Contact us

For privacy questions, requests, or complaints, contact OpsPilot Systems at parkerduthaler@gmail.com.