Privacy notice
Last updated: [DATE]. [YOUR COMPANY NAME] (“we”) runs RingSparrow.
Template: review with a lawyer and fill in every [BRACKET] before launch.
The short version
Your CRM lives on your device. Our servers only do what they must to send your messages through your own accounts, and they delete message data as soon as your app has picked it up.
What stays on your device
Contacts, conversations, notes, tags, pipeline stages, templates, workflows, campaigns and campaign results. These are stored in your browser (IndexedDB) and never sent to us. Your AI provider key also stays in your browser, unless you turn on “Answer texts even when RingSparrow is closed” (see below).
If you save a workspace to Google Drive
The workspace becomes one file in your own Google Drive. Your browser reads and writes it directly with Google, using only the “drive.file” permission: RingSparrow can open files it created or that you pick, and nothing else in your Drive. Your Google sign-in stays in your browser and is never sent to our servers, and our servers never see the file’s contents. Your AI key is never written to the file; it stays on each device. Google Drive’s own terms and privacy policy apply to the file.
Google sign-in, Drive and Gmail
You sign in with Google. RingSparrow asks Google for two permissions: to open Google Drive files that RingSparrow creates or that you pick (“drive.file”), and to send email from your Gmail (“gmail.send”). It can’t read, search or delete your email or see other Drive files. Emails you write are sent from your browser straight to Gmail; the recipient and message pass through our server once to check unsubscribes and count sends, and aren’t stored. Your Google permission stays with you: its one-hour access key is kept in this browser’s storage so a reload doesn’t ask again. To keep you connected without asking every hour, Google also gives a longer-lived renewal key at sign-in; our server keeps it encrypted, tied to your RingSparrow account, and uses it only to get fresh access from Google. It’s deleted when Google reports the access was removed, and the one-hour key is removed from the browser when you sign out of RingSparrow, and you can cut off access any time at myaccount.google.com/permissions.
RingSparrow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What our servers hold
- Your account: you sign in with Google. Our sign-in provider, Supabase, keeps your email address, name and an account id from your Google account.
- Your team: the emails and roles of people you add to a workspace, the id and name of its Google Drive file, and which of your team’s open devices is currently picking up new texts. Removed members are deleted straight away.
- Your licence: which codes you redeemed, and a monthly count of messages sent (a number, not the messages).
- If you buy a licence from us: a record of the payment (PayPal or Dodo Payments order id, the plan, the amount and currency, the email PayPal or Dodo gives us, the time, and the licence code it produced), kept as an accounting record. If the payment is refunded or lost in a dispute, the licence is switched off and the record is marked refunded. We never see or store your card or PayPal details; those go straight to PayPal or Dodo Payments.
- Your provider connections: the Twilio and email keys you enter, encrypted, plus your business name, postal address and reply-to email, which are added to email footers. You can disconnect them at any time.
- Messages in transit: when you send a message, it passes through our server to your provider. When you schedule messages to go out while the app is closed, the recipient’s number or email and the message text are stored until they are sent, then deleted.
- AI replies while the app is closed (only if you turn it on): your AI key, business description and assistant settings, encrypted; and, per contact, the last few messages of the conversation (encrypted, deleted after 7 days) plus reply counters so the assistant respects your limits. Turning it off deletes the key and settings; erasing the workspace deletes everything.
- Missed-call text-back (only if you turn it on): your text-back message, voicemail wording and settings, your number’s previous call settings (so we can restore them), the number to alert about missed calls, if you add one, and the time each caller was last texted or alerted about, so no one is texted twice.
- Google Calendar (only if you connect it): a lasting key that lets RingSparrow add your bookings to your own calendar and see which times are busy, stored encrypted and never shown to your browser, the Google address you connected and your choices. When someone books, their name, phone, email and notes pass through our server to Google Calendar and are not kept by us. We read only the start and end times of your other events to hide busy times on your booking page (for one minute, with no titles or guests), and whether events RingSparrow made were deleted or moved. Disconnecting deletes the key and asks Google to revoke it.
- After-hours reply (only if you turn it on): your opening hours, time zone and reply wording, and the time each number was last sent the reply (so nobody gets it twice in a row).
- Workflows while the app is closed: a copy of your active workflows (their steps and message text, and the quiet hours and business name they use). For each person in a workflow, a small record with their name, phone number or email, tags and stage, and where they are in the workflow, kept until they finish or leave it; plus a cache of contact first and last names so name tags can be filled in. Their messages are sent through your own provider. Deleting a workflow, or erasing the workspace, removes these records.
- Reply times: the times of the last 20 texts from each contact who replies, so “if they replied” workflow steps can be decided while the app is closed. No message content.
- Delivery results: when you check campaign delivery, the app reads delivery statuses straight from your Twilio account through our server. Nothing is stored.
- Website form submissions and webhook contacts: the name, phone, email and message someone submits (on a form page or in the chat button on your website), the page they submitted from, and their consent wording. If your chat button is a live chat, what a visitor types is sent to your AI provider (with your key) to get an answer and is not stored on our server while they chat; if they leave their number, the conversation is saved with the sign-up and, for 7 days (encrypted), in the assistant’s memory so it can continue by text. A per-day answer counter is kept. Held until your app next syncs, then deleted.
- Appointment bookings: the name, phone, email, notes, chosen time and consent wording someone submits on your booking page. Held until your app next syncs, then deleted. Reminder texts (the number and message) wait on our server until they are sent or the appointment is cancelled. The server also keeps which times are taken, without names or numbers.
- Review ratings: the star rating and any feedback, held until your app next syncs. The link identifies the contact only through a random code your app knows.
- Your form, booking, review and webhook settings: form wording and options, your booking page’s services, hours and wording, your Google review link, the webhook addresses you add, the result of the last delivery to each, and your signing secret.
- Opt-outs: numbers that texted STOP, so forms and webhooks never text them.
- Keywords and short links: your sign-up keywords and their replies; for campaign links you choose to track, the link address and, when someone taps it, which campaign and which contact ending it was, until your app next syncs. The tapping person’s IP address isn’t stored.
- Abuse protection: for public forms, booking and review pages, a one-way hash of the visitor’s IP address and a count of submissions, reset every hour.
- Calls made from the app (only when you press Call): with the in-browser phone, your browser talks to Twilio directly (signalling and audio, using a short-lived token we sign with a key stored encrypted in your workspace), so the conversation never passes through our server; we only see the result of the call (how it ended and how long it lasted), which is held until your app next syncs, then deleted. With ring-my-phone, your phone number and the contact’s number are sent to your provider to place the call. Calls are not recorded unless you turn on Record calls (below). Your own phone number is kept on your device, not on our server. The microphone is used only during a call.
- Call recordings (only if you turn on Record calls): your provider records the call in your own account. When RingSparrow is open, your browser downloads the audio through our server (it passes through and is never stored here) and saves it in a “RingSparrow recordings” folder in your own Google Drive, then asks your provider to delete its copy. We keep only a note that a recording exists (its provider ID and length) until your app next syncs. If you choose the spoken notice, the other person hears it before you’re connected; you’re responsible for following the recording rules where you and your contacts are.
- Incoming replies, calls, voicemails and unsubscribes: for calls and voicemails, the caller’s number, the length and (for a voicemail) the id of the recording; the audio itself stays in your own texting provider account and never passes through our servers except when your app fetches it to play it or save it to your Google Drive. Held until your app next syncs, then deleted. Records of who unsubscribed from email are kept so we never email them again from your account.
We don’t sell data, show ads, or use your data to train AI.
Who processes data for us
- Netlify (hosting and server functions), [REGION]
- Supabase (sign-in), [REGION]
- PayPal and Dodo Payments (taking payment when you buy a licence from us; Dodo Payments is the seller of record for card payments and handles sales tax)
Your messages are also processed by the providers you connect (for example Twilio or Mailgun), under your own agreements with them. AI requests go directly from your browser to the AI provider you choose.
Your rights
You can export your data from the app, disconnect providers, erase a workspace (which also removes its server records), or ask us to delete your account at [SUPPORT EMAIL].
People you message
You are the controller of your contacts’ data; we act as your processor for the limited server-side data above. If someone asks you to delete their data, delete the contact in the app.
Contact
[SUPPORT EMAIL]