Legal

Privacy Policy

This Privacy Policy explains how Pipemetry ("Pipemetry", "we", "us") collects, uses, shares, and protects information in connection with our marketing site at pipemetry.com and the Pipemetry application (together, the "Service"). It also describes the choices you have about your information. If you connect a CRM, you do so as the controller of that data and we act as your processor under your instructions and your subscription agreement.

Who we are

Pipemetry provides sales-pipeline analytics and revenue forecasting. To do that, we process opportunity data you choose to connect from your CRM. We do not sell personal information, and we do not use your CRM data to train models that serve any other customer.

Information we collect

How we use information

We do not sell your data, and we do not use your CRM data to train models for other customers. Optional AI features only send the specific context needed to answer your request, and only when you use them (see Subprocessors).

Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal data on the bases of performance of a contract (providing the Service you requested), our legitimate interests (operating, securing, and improving the Service) balanced against your rights, consent (where required, e.g. certain cookies), and compliance with legal obligations. For CRM data you connect, you are the controller and we are your processor; our processing is governed by your subscription agreement and our Data Processing Addendum.

How we share information

We share information with the subprocessors that help us run the Service, listed on our Subprocessors page, each under contractual confidentiality and data-protection terms. Separately, you can direct the Service to send your data to destinations you choose — for example, an outbound webhook to a URL you register, our read API (using a workspace API key), a signed spreadsheet export link, or a public board-snapshot share link you create. When you configure any of these, you (or your workspace administrator) instruct the transfer and choose the destination and its recipients; for that transfer you act as the data exporter and are responsible for the security and lawful use of the destination and everyone you give access to. We sign outbound webhook payloads (HMAC) and guard against server-side request forgery, but we do not control an endpoint you register or who holds a link you share. We may also disclose information if required by law or to protect the rights, safety, and security of Pipemetry, our customers, or the public. We do not share your CRM data across customers.

Public share links (board snapshots)

A workspace administrator can create a public, read-only snapshot of an executive board to share with people who do not have a login. A share link uses an unguessable token, is set to expire (currently 30 days), is served with instructions telling search engines not to index it, is watermarked, and freezes a point-in-time copy that cannot be edited through the link; an administrator can revoke it at any time. A snapshot may include personal data such as sales-owner names and deal values. Because anyone who holds the link can open it until it expires or is revoked, the administrator who creates a link decides who may see it and is responsible for that choice. Revoking a link stops future views but cannot retract copies that have already been opened or downloaded. Do not create a public snapshot of data you are not authorized to disclose.

Security

We design for tenant isolation as a first principle: each customer's data is segregated and access is enforced at the database layer (row-level security keyed to your workspace), the application connects with a least-privilege role, secrets are encrypted at rest, and access to sensitive records is recorded to a write-once audit log. Data is encrypted in transit over public networks. We are building toward SOC 2 and implement controls accordingly. No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard safeguards.

Where data is hosted & international transfers

The Service is hosted in the United States, and some subprocessors process data in the United States or globally. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, which are incorporated into our Data Processing Addendum.

Data retention & deletion

We retain account and CRM data for as long as your workspace is active and as needed to provide the Service. When you disconnect a CRM, we stop ingesting new data from it; when you ask us to delete your workspace, or after your subscription ends, we delete or de-identify customer data after the export window described in our Terms of Service closes (we target completing deletion within 30 days after that), except where we must retain limited records to comply with legal, tax, or security obligations. In particular, write-once (WORM) security and billing audit records — who accessed or changed what, and when — are retained after workspace deletion to satisfy legal and security obligations (GDPR Art. 17(3)(b)/(e)); they are not used for any other purpose. Backups are purged on a rolling schedule. You can request deletion at any time using the contact below.

Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. For CRM data you connected, direct requests to your own organization's administrator (the controller); we will assist them as your processor. To exercise rights in personal data we control, email [email protected]. We will not discriminate against you for exercising these rights.

Cookies

The marketing site currently sets no analytics cookies; any cookies present are strictly for essential functionality. The application uses cookies/local storage strictly necessary to keep you signed in. We do not use third-party advertising cookies.

Children

The Service is for business use and is not directed to children under 16, and we do not knowingly collect their data.

Changes to this policy

We may update this policy as the Service evolves. We will revise the "last updated" date above and, for material changes, provide additional notice. Continued use of the Service after an update means you accept the revised policy.

Contact

Questions or requests about privacy? Email [email protected]. For security matters, email [email protected].