Privacy Policy

Effective Date: April 17, 2026

Company: Marta Tools LLC

DealSights AI ("we", "our", "Service") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.

1. Data We Collect

Account data: Name, email address, password (hashed).

CRM data: Deals, contacts, activities, and pipeline data from your connected CRM (via Merge.dev). Accessed read-only unless you enable write-back features.

Email metadata: Subject lines, timestamps, sender/recipient. We do not read email body content.

Calendar data: Meeting titles, times, attendees from Google Calendar (read-only).

Usage data: Feature usage, queries made, credits consumed.

Payment data: Processed by Stripe. We do not store credit card numbers.

2. How We Use Your Data

We use your data solely to: provide AI-powered revenue insights; sync and display your CRM data; send transactional emails (confirmations, alerts); process billing; improve the Service.

3. AI Processing

Your data is sent to AI providers (Anthropic, xAI, OpenAI) to generate insights. These providers process data per their own policies and do not retain your data for training. We send only the minimum data necessary for each query.

4. Data Storage & Security

Data is stored on servers hosted by DigitalOcean (US). All data is encrypted in transit (TLS) and at rest. Multi-tenant isolation ensures your data is never accessible to other customers. We use row-level security on all database tables.

5. Data Sharing

We do not sell your data. We share data only with: service providers necessary to operate the platform (Stripe, SendGrid, Merge.dev, AI providers); law enforcement when legally required.

6. Data Retention

We retain your data for as long as your account is active. Upon account deletion, all your data is permanently removed within 30 days.

7. Your Rights

You have the right to: access your data; export your data; correct inaccurate data; delete your account and all associated data; revoke third-party connections at any time.

8. Cookies

We use essential cookies for authentication only. We do not use tracking or advertising cookies.

9. Third-Party Services

We integrate with: Merge.dev (CRM connectivity), Stripe (payments), SendGrid (email), Google (calendar), Anthropic/xAI/OpenAI (AI processing). Each has their own privacy policy.

10. Children

The Service is not intended for users under 18.

11. Changes

We will notify you of material changes via email at least 30 days before they take effect.

12. Contact

For privacy questions or data requests, email ryan@dealsights.ai