Privacy Policy - SalesCompass
Last Updated: October 28, 2024
Company: SalesCompass
Website: https://www.salescompass.ai
1. Introduction
SalesCompass ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our sales call analysis platform.
2. Information We Collect
2.1 Account Information
Email address
Name
Account credentials (encrypted)
Profile information
2.2 Sales Call Data
Call transcripts uploaded by users
Call metadata (date, duration, title)
AI-generated analysis and scores
User-created notes and comments
2.3 Zoom Integration Data
When you connect your Zoom account:
OAuth access tokens (encrypted)
List of cloud recordings
Recording metadata (meeting title, date, duration)
Audio transcripts from Zoom recordings
We do NOT store video files or full audio recordings
2.4 Payment Information
Payment processing is handled by Stripe
We store subscription status and plan information
We do NOT store credit card numbers or payment credentials
2.5 Usage Information
Login timestamps
Feature usage analytics
Error logs and diagnostic data
3. How We Use Your Information
We use collected information for:
3.1 Service Delivery
Providing AI-powered sales call analysis
Generating scorecards and coaching insights
Managing your account and subscription
Importing recordings from connected Zoom accounts
3.2 Service Improvement
Analyzing usage patterns to improve features
Debugging technical issues
Developing new capabilities
3.3 Communication
Sending transactional emails (receipts, notifications)
Responding to support requests
Sending important service updates
3.4 Security
Detecting and preventing fraud
Protecting against unauthorized access
Monitoring for security vulnerabilities
4. Data Storage and Security
4.1 Infrastructure
Data stored in Supabase (PostgreSQL database)
Hosted on secure cloud infrastructure (AWS/GCP)
All data encrypted at rest
All connections encrypted in transit (TLS 1.2+)
4.2 Access Controls
Row Level Security (RLS) policies enforce data isolation
Each user can only access their own data
Administrative access is logged and audited
Authentication via secure OAuth 2.0
4.3 Third-Party Services
Supabase: Database and authentication
OpenAI: AI analysis (transcripts sent for scoring)
Stripe: Payment processing
Zoom: Recording imports (with user consent)
Vercel: Application hosting
All third-party services are vetted for security and comply with industry standards.
5. Data Retention
Active accounts: Data retained while account is active
Deleted accounts: Data permanently deleted within 30 days
Backups: Backup copies removed within 90 days
Legal holds: Data may be retained longer if required by law
6. Data Sharing and Disclosure
6.1 We DO NOT Sell Your Data
We never sell, rent, or trade your personal information.
6.2 Service Providers
We share data with trusted service providers only as necessary:
OpenAI (for AI analysis of transcripts)
Stripe (for payment processing)
Supabase (for data storage)
Vercel (for hosting)
6.3 Legal Requirements
We may disclose information when required by law or to:
Comply with legal process
Protect our rights and property
Prevent fraud or illegal activity
Protect user safety
6.4 Business Transfers
If SalesCompass is acquired or merged, user data may be transferred to the successor entity.
7. Your Rights and Choices
7.1 Access and Control
View and download your data at any time
Delete individual calls or your entire account
Export your data in standard formats
Disconnect Zoom integration at any time
7.2 Communication Preferences
Opt out of marketing emails (we don't send many!)
Cannot opt out of transactional emails (receipts, security alerts)
7.3 Data Portability
Request a copy of your data in machine-readable format.
8. Third-Party Integrations
8.1 Zoom Integration
When you connect Zoom:
We request read-only access to your recordings
We import only recordings you explicitly select
You can disconnect at any time
Disconnecting revokes our access immediately
8.2 OpenAI Processing
Call transcripts sent to OpenAI for analysis
OpenAI does not train models on your data (per our agreement)
Processing happens in real-time and is not stored by OpenAI
9. Children's Privacy
SalesCompass is not intended for users under 18 years of age. We do not knowingly collect information from children.
10. International Users
SalesCompass is operated from the United States. By using our service, you consent to the transfer and processing of your data in the United States.
11. California Privacy Rights (CCPA)
California residents have the right to:
Know what personal information is collected
Access their personal information
Request deletion of their information
Opt out of data sales (we don't sell data)
Contact us to exercise these rights.
12. European Users (GDPR)
For users in the European Economic Area:
Legal basis: Contract performance and legitimate interests
Data controller: SalesCompass
Data transfers: Standard contractual clauses
Rights: Access, rectification, erasure, restriction, portability, objection
13. Cookies and Tracking
We use minimal cookies for:
Session management (authentication)
Security (CSRF protection)
Analytics (aggregate usage statistics)
You can disable cookies in your browser, but this may limit functionality.
14. Security Measures
We implement industry-standard security practices:
Encryption at rest and in transit
Regular security audits
Access controls and authentication
Secure development lifecycle
Incident response procedures
Dependency vulnerability scanning
15. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via:
Email notification
In-app notification
Updated "Last Updated" date
Continued use after changes constitutes acceptance.
16. Contact Us
For privacy questions, concerns, or requests:
Email: support@salescompass.ai
Website: https://www.salescompass.ai
For data deletion or access requests, please include:
Your account email
Specific request details
Verification of your identity
We will respond within 30 days.
17. Data Breach Notification
In the event of a data breach affecting your personal information, we will:
Notify affected users within 72 hours
Provide details of the breach and impact
Describe steps taken to mitigate harm
Offer guidance on protective measures
18. Compliance Certifications
SalesCompass adheres to:
OWASP security best practices
OAuth 2.0 security standards
SOC 2 principles (in progress)
GDPR requirements for EU users
CCPA requirements for California users
---
Last Reviewed: October 28, 2024
Version: 1.0