Privacy Policy - SalesCompass


Last Updated: October 28, 2024 Company: SalesCompass Website: https://www.salescompass.ai

1. Introduction


SalesCompass ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our sales call analysis platform.


2. Information We Collect


2.1 Account Information

  • Email address
  • Name
  • Account credentials (encrypted)
  • Profile information

  • 2.2 Sales Call Data

  • Call transcripts uploaded by users
  • Call metadata (date, duration, title)
  • AI-generated analysis and scores
  • User-created notes and comments

  • 2.3 Zoom Integration Data

    When you connect your Zoom account:

  • OAuth access tokens (encrypted)
  • List of cloud recordings
  • Recording metadata (meeting title, date, duration)
  • Audio transcripts from Zoom recordings
  • We do NOT store video files or full audio recordings

  • 2.4 Payment Information

  • Payment processing is handled by Stripe
  • We store subscription status and plan information
  • We do NOT store credit card numbers or payment credentials

  • 2.5 Usage Information

  • Login timestamps
  • Feature usage analytics
  • Error logs and diagnostic data

  • 3. How We Use Your Information


    We use collected information for:


    3.1 Service Delivery

  • Providing AI-powered sales call analysis
  • Generating scorecards and coaching insights
  • Managing your account and subscription
  • Importing recordings from connected Zoom accounts

  • 3.2 Service Improvement

  • Analyzing usage patterns to improve features
  • Debugging technical issues
  • Developing new capabilities

  • 3.3 Communication

  • Sending transactional emails (receipts, notifications)
  • Responding to support requests
  • Sending important service updates

  • 3.4 Security

  • Detecting and preventing fraud
  • Protecting against unauthorized access
  • Monitoring for security vulnerabilities

  • 4. Data Storage and Security


    4.1 Infrastructure

  • Data stored in Supabase (PostgreSQL database)
  • Hosted on secure cloud infrastructure (AWS/GCP)
  • All data encrypted at rest
  • All connections encrypted in transit (TLS 1.2+)

  • 4.2 Access Controls

  • Row Level Security (RLS) policies enforce data isolation
  • Each user can only access their own data
  • Administrative access is logged and audited
  • Authentication via secure OAuth 2.0

  • 4.3 Third-Party Services

  • Supabase: Database and authentication
  • OpenAI: AI analysis (transcripts sent for scoring)
  • Stripe: Payment processing
  • Zoom: Recording imports (with user consent)
  • Vercel: Application hosting

  • All third-party services are vetted for security and comply with industry standards.


    5. Data Retention


  • Active accounts: Data retained while account is active
  • Deleted accounts: Data permanently deleted within 30 days
  • Backups: Backup copies removed within 90 days
  • Legal holds: Data may be retained longer if required by law

  • 6. Data Sharing and Disclosure


    6.1 We DO NOT Sell Your Data

    We never sell, rent, or trade your personal information.


    6.2 Service Providers

    We share data with trusted service providers only as necessary:

  • OpenAI (for AI analysis of transcripts)
  • Stripe (for payment processing)
  • Supabase (for data storage)
  • Vercel (for hosting)

  • 6.3 Legal Requirements

    We may disclose information when required by law or to:

  • Comply with legal process
  • Protect our rights and property
  • Prevent fraud or illegal activity
  • Protect user safety

  • 6.4 Business Transfers

    If SalesCompass is acquired or merged, user data may be transferred to the successor entity.


    7. Your Rights and Choices


    7.1 Access and Control

  • View and download your data at any time
  • Delete individual calls or your entire account
  • Export your data in standard formats
  • Disconnect Zoom integration at any time

  • 7.2 Communication Preferences

  • Opt out of marketing emails (we don't send many!)
  • Cannot opt out of transactional emails (receipts, security alerts)

  • 7.3 Data Portability

    Request a copy of your data in machine-readable format.


    8. Third-Party Integrations


    8.1 Zoom Integration

    When you connect Zoom:

  • We request read-only access to your recordings
  • We import only recordings you explicitly select
  • You can disconnect at any time
  • Disconnecting revokes our access immediately

  • 8.2 OpenAI Processing

  • Call transcripts sent to OpenAI for analysis
  • OpenAI does not train models on your data (per our agreement)
  • Processing happens in real-time and is not stored by OpenAI

  • 9. Children's Privacy


    SalesCompass is not intended for users under 18 years of age. We do not knowingly collect information from children.


    10. International Users


    SalesCompass is operated from the United States. By using our service, you consent to the transfer and processing of your data in the United States.


    11. California Privacy Rights (CCPA)


    California residents have the right to:

  • Know what personal information is collected
  • Access their personal information
  • Request deletion of their information
  • Opt out of data sales (we don't sell data)

  • Contact us to exercise these rights.


    12. European Users (GDPR)


    For users in the European Economic Area:

  • Legal basis: Contract performance and legitimate interests
  • Data controller: SalesCompass
  • Data transfers: Standard contractual clauses
  • Rights: Access, rectification, erasure, restriction, portability, objection

  • 13. Cookies and Tracking


    We use minimal cookies for:

  • Session management (authentication)
  • Security (CSRF protection)
  • Analytics (aggregate usage statistics)

  • You can disable cookies in your browser, but this may limit functionality.


    14. Security Measures


    We implement industry-standard security practices:

  • Encryption at rest and in transit
  • Regular security audits
  • Access controls and authentication
  • Secure development lifecycle
  • Incident response procedures
  • Dependency vulnerability scanning

  • 15. Changes to This Policy


    We may update this Privacy Policy periodically. Material changes will be communicated via:

  • Email notification
  • In-app notification
  • Updated "Last Updated" date

  • Continued use after changes constitutes acceptance.


    16. Contact Us


    For privacy questions, concerns, or requests:


    Email: support@salescompass.ai Website: https://www.salescompass.ai

    For data deletion or access requests, please include:

  • Your account email
  • Specific request details
  • Verification of your identity

  • We will respond within 30 days.


    17. Data Breach Notification


    In the event of a data breach affecting your personal information, we will:

  • Notify affected users within 72 hours
  • Provide details of the breach and impact
  • Describe steps taken to mitigate harm
  • Offer guidance on protective measures

  • 18. Compliance Certifications


    SalesCompass adheres to:

  • OWASP security best practices
  • OAuth 2.0 security standards
  • SOC 2 principles (in progress)
  • GDPR requirements for EU users
  • CCPA requirements for California users

  • ---


    Last Reviewed: October 28, 2024 Version: 1.0