Privacy Policy
This Privacy Policy explains how Sensale, Inc. (“Sensale,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the Sensale customer relationship management platform and related websites, applications, and services (collectively, the “Services”).
Sensale is a business-to-business product. The Services are sold to and used by organizations (each, a “Customer”). When a Customer uses the Services, the Customer is the controller of personal information it submits or processes through the Services, and Sensale acts as a service provider or processor on the Customer’s behalf. This Policy describes our own practices. Where we process personal information on a Customer’s behalf, the Customer’s own privacy notice and our written agreement with that Customer govern.
Please read this Policy together with our Terms of Service.
1Scope and the role we play
This Policy applies to personal information we handle as a business in our own right (for example, information about prospective customers, website visitors, account administrators, and billing contacts), which we refer to as “Account and Site Data.”
Separately, our Customers upload, import, or generate data about their own contacts, leads, and accounts when they use the Services (“Customer Content”). We process Customer Content only to provide the Services and under the instructions of the Customer. If you are an individual whose information appears in a Customer’s account and you wish to exercise rights over that information, please contact that Customer directly; we will support the Customer in responding to your request.
2Information we collect
Information you provide
- Account and registration data: name, business email address, job title, organization name, and credentials when an account is created.
- Billing and transaction data: billing contact, billing address, and payment-related identifiers. Card payments are handled by our third-party payment processor; we do not store full payment card numbers.
- Support and communications data: information you provide when you contact us, respond to surveys, or participate in onboarding.
Information collected automatically
- Usage and device data: log data, IP address, browser and device characteristics, pages or screens viewed, features used, and timestamps.
- Cookies and similar technologies: identifiers used to operate the Services, remember preferences, and measure performance. See “Cookies and tracking technologies” below.
- Audit and security event data: records of authentication events, administrative actions, and access events generated by the Services for security, troubleshooting, and compliance purposes.
Information from other sources
- Identity and single sign-on providers: where a Customer enables SAML-based single sign-on through a third-party identity provider, we receive authentication assertions and limited profile attributes needed to authenticate users.
- Service providers and integrations: information from analytics, infrastructure, and other vendors that support the Services.
3How we use information
We use Account and Site Data for the following purposes:
- To provide, operate, secure, and maintain the Services.
- To create and administer accounts, authenticate users, and manage role-based access.
- To process transactions, billing, and renewals.
- To provide customer support and respond to inquiries.
- To monitor, detect, investigate, and prevent security incidents, fraud, and abuse, including through audit logging.
- To analyze and improve the Services and develop new features.
- To send administrative and service-related communications, and, where permitted, marketing communications you can opt out of.
- To comply with legal obligations and enforce our agreements.
4Automated processing and agent features
The Services include automated and agent-based features that process Customer Content and operational data to perform tasks, generate suggestions, and assist users. These features operate within the scope and instructions configured by the Customer.
Sensale does not use automated processing to make decisions that produce legal or similarly significant effects about an individual without a human able to review, interpret, and change the outcome. To the extent any automated decision-making technology is used in a manner that triggers consumer rights under applicable state law, we and our Customers provide the disclosures and opt-out or review mechanisms those laws require.
We do not use Customer Content to train general-purpose models for our own unrelated purposes. Any use of Customer Content to provide model-driven features is performed to deliver the Services to the Customer and subject to our agreement with that Customer.
5Google user data and Limited Use
When you connect a Gmail mailbox to Sensale, our zero-entry Capture feature reads messages from that mailbox to turn them into signals on your own deals, so your records build themselves and you never do manual data entry. This section describes how Sensale accesses, uses, stores, and shares Google user data.
What we access
Capture runs on Sensale’s own Google Cloud OAuth application and requests a single restricted scope, read-only access to your Gmail messages (the gmail.readonly scope), and nothing broader. You grant access for each mailbox you connect from inside the product, and you can disconnect at any time. No third-party service sits on your credentials or your mail.
How we use it
We use the data we read from your mailbox only to provide and improve the Capture feature you see in the product: turning your email into structured signals, activities, and brief content on your own deals. We do not use Google user data for any purpose that is not visible to you in the Sensale interface.
How we store and protect it
Your Google OAuth tokens are encrypted at rest using AES-256-GCM. Message content is processed under our data-governance posture: it is isolated to your workspace, and personal information is masked before it is sent to any model provider. Sensale does not use your Google user data, or anything derived from it, to train or fine-tune any general-purpose or foundation model, and the model providers we use operate under zero-retention, no-training terms.
Human access
Processing is automated. People do not read your Google user data except with your affirmative agreement (for example, to provide support you have asked for), where it is necessary for security or to comply with the law, or in a limited, aggregated form for internal operations such as preventing abuse.
What we never do
We do not sell your Google user data. We do not transfer it to data brokers, advertising platforms, or resellers, and we do not use it to serve advertising or to make credit decisions.
Retention and deletion
You can disconnect a mailbox at any time from inside Sensale, which revokes our access and deletes the stored Google credentials for that mailbox. Signals derived from your mail are Customer Content held under your organization’s agreement with us; we return or delete Customer Content on termination as described in our Terms of Service, and we honor verified deletion requests.
The policy that governs this
Sensale’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can read that policy at https://developers.google.com/terms/api-services-user-data-policy Opens in a new tab..
6How we disclose information
We do not sell personal information for money. We disclose information only as described here:
- Service providers: vendors that host infrastructure, process payments, provide analytics, send communications, or otherwise support the Services, bound by contract to protect the information and use it only for us.
- Identity providers: where single sign-on is enabled, to authenticate users.
- Within a Customer’s organization: to administrators and authorized users according to the access controls the Customer configures.
- Legal and safety: to comply with law, respond to lawful requests, enforce our terms, and protect the rights, property, or safety of Sensale, our Customers, or others.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
Certain disclosures to advertising or analytics partners using cookies may be considered “sharing” or a “sale” under some state privacy laws even when no money changes hands. Where that is the case, we honor opt-out requests, including browser-based opt-out preference signals such as Global Privacy Control, as described below.
7Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding personal information we hold about you as a business:
- Access and portability: to know what personal information we process and to obtain a copy.
- Correction: to correct inaccurate personal information.
- Deletion: to request deletion of personal information, subject to legal exceptions.
- Opt out of sale or sharing: to opt out of any sale or sharing of personal information and of targeted advertising.
- Opt out of certain automated decision-making: where provided by applicable law.
- Non-discrimination: to not receive discriminatory treatment for exercising your rights.
To exercise these rights, contact us at privacy@sensale.ai. We will verify your request before responding and will respond within the time required by applicable law. You may use an authorized agent where the law permits.
Opt-out preference signals
We recognize the Global Privacy Control (GPC) and similar browser-based opt-out preference signals. When we detect such a signal, we treat it as a valid request to opt out of sale or sharing for that browser or device.
If your information is in a Customer’s account
If you are a contact, lead, or account record within a Customer’s Sensale workspace, please direct rights requests to that Customer, who controls that data. We will assist the Customer as their processor.
8Data retention
We retain Account and Site Data for as long as needed to provide the Services and for legitimate business and legal purposes. Audit and security event logs are retained for a default period of twelve (12) months and may be configured by a Customer for a longer period of up to seven (7) years where the Customer’s plan supports it. When information is no longer needed, we delete or de-identify it.
Customer Content is retained and deleted in accordance with the Customer’s configuration and our agreement with the Customer.
9Data security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption of data in transit and at rest, role-based access controls, least-privilege access, and audit logging of access and administrative events. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10Data location and transfers
We currently store and process personal information in the United States. The Services are offered for use within the United States in this version. If we begin offering data residency or processing in other regions, we will update this Policy and provide any additional disclosures required by applicable law.
11Cookies and tracking technologies
We use cookies and similar technologies to operate the Services, remember preferences, maintain sessions, and measure performance. You can control cookies through your browser settings and, where offered, through our cookie preferences tool. Disabling some cookies may affect how the Services function. Browser-based opt-out preference signals are honored as described above.
12Children’s privacy
The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
13Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new effective date and, where required, provide additional notice. Your continued use of the Services after an update means you accept the revised Policy.
14Contact us
If you have questions or requests regarding this Policy, contact us at:
Sensale, Inc. privacy@sensale.ai