Legal
Privacy Policy
Effective 9 July 2026. This policy explains what data Pipevale processes and how you control it.
1. Who we are and what this covers
Pipevale is a CRM for sales, communication and automation. This policy covers the website pipevale.com and the application. It applies to workspace owners, invited users and site visitors.
2. Controller and processor
For the data you put into your workspace — contacts, deals, correspondence — you are the controller and Pipevale acts as a processor: we process it on your instructions and solely to provide the service. For your account data and site visitors, Pipevale is the controller.
3. What we process
- Account data: name, email, a secure password hash, two-factor settings.
- Workspace data: whatever you put into the CRM — contacts, companies, deals, tasks, emails, files, automations and settings.
- Technical data: access logs, IP address, device type and the cookies needed to run and secure the service.
4. Legal basis
- Performance of a contract — to provide the service you signed up for;
- Your consent — for optional features such as connecting a Google account or optional analytics;
- Legitimate interest — security, abuse prevention and improving the service, where this does not override your rights;
- Legal obligation — where retention or disclosure is required by law.
5. What we use it for
To give you access to the app, store and process your records, send email on your behalf when you ask us to, protect accounts, keep an audit log and keep the service running. We do not sell your data and do not use the contents of your workspace for advertising.
6. Google data (Gmail)
If you voluntarily connect your Google account, we request the minimum scopes needed:
- gmail.send — to send email on your behalf from a record or a campaign. We do not read your inbox.
- userinfo.email — to identify which account is connected.
Pipevale’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google data for advertising, do not sell it, do not pass it to third parties except where needed to provide the feature itself or required by law, and do not use it to train AI models.
You can revoke access at any time in Settings → Integrations (“Disconnect”), or at Google Account → Permissions.
7. AI features
AI features run on a provider key that you supply yourself. We send the provider only what is needed for the specific action, and we do not use your data — including Google data — to train models.
8. Subprocessors
Always involved:
- Hetzner — hosting of the service and database (Germany, EEA);
- Resend — system email: address confirmation, password reset, team invitations;
- Sentry — technical error monitoring; field values and on-screen text are masked before sending;
- WayForPay — subscription payments; card details are entered on the payment provider’s side and never reach us.
Only if you enable them:
- Google — sign-in and sending from connected Gmail;
- messengers (Telegram, Viber, WhatsApp, Instagram Direct, Slack, Intercom);
- telephony (Binotel, Ringostat);
- an AI provider you choose, using your own key.
We do not pass your data to third parties for their own marketing. The full list with purpose and processing location is in the Data Processing Agreement.
9. International transfers
CRM data itself is stored in the EEA (Germany). Some providers process data outside the EEA: Resend and Sentry in the United States, WayForPay in Ukraine, and Google and your chosen AI provider depending on their terms. In those cases we rely on the safeguards provided by law, including the relevant providers’ standard contractual clauses.
10. Storage and security
Confidential data and integration tokens are stored encrypted, connections are secured with HTTPS, each workspace’s data is isolated, and actions are recorded in an audit log.
We keep data while your account is active. Deleted records go to the Trash first and can be restored, then are permanently removed. After you close your account we delete your data within a reasonable period, except what we must keep by law — accounting records of payments, for example.
11. Cookies and analytics
We use only the cookies needed for sign-in and security, plus lightweight privacy-friendly analytics with no cross-site tracking. Optional analytics runs only with consent, which you can withdraw in your browser settings or by contacting us.
12. Your rights
You can access your data, correct or delete it, export it, restrict or object to certain processing, and withdraw consent you gave earlier. To exercise these rights write to hello@pipevale.com. You also have the right to lodge a complaint with a data protection supervisory authority.
13. Age
The service is intended for business use and is not directed at people under 16. We do not knowingly collect children’s data; if this happens, tell us and we will delete it.
14. Third-party sites
The site and the app may link to external resources. We do not control them and are not responsible for their privacy practices — please read those separately.
15. Changes
We may update this policy. We will announce material changes on the site or in the app and update the date above.
16. Contact
Privacy questions: hello@pipevale.com. Security questions: security@pipevale.com. See also our Terms of Service.