Privacy Policy
Last Updated: February 4, 2026
At SalesGuard, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our service.
1. Information We Collect
1.1 Account Information
- Email address
- Account credentials (password is hashed and encrypted)
- Account creation date and last login
1.2 Google OAuth Data
- OAuth access tokens (encrypted)
- OAuth refresh tokens (encrypted)
- Google account ID
- Read-only access to your Google Calendar
1.3 Meeting Metadata
- Meeting titles
- Scheduled start and end times
- Meeting links (Google Meet URLs)
- Participant names and email addresses
- Meeting status (scheduled, active, ended)
1.4 Payment Information
- Stripe customer ID
- Subscription status and plan
- Payment method (stored securely by Stripe, not on our servers)
1.5 Usage Data
- Notification history (what notifications were sent)
- Feature usage patterns
- Error logs and system diagnostics
2. Information We DO NOT Collect
We want to be crystal clear about what we DON'T collect:
- Meeting content: We do not record or store anything discussed in your meetings
- Audio or video: We do not capture or process any audio or video from meetings
- Screen recordings: We do not record or store screen shares
- Chat logs: We do not access or store meeting chat messages
- Transcripts: We do not create or store meeting transcripts
- Files: We do not access files shared in meetings
We only access meeting metadata (times, titles, participants) to send you notifications. We never access the actual content of your meetings.
3. How We Use Your Information
We use your information solely to:
- Provide the SalesGuard service
- Send notifications when participants join your meetings
- Manage your account and subscription
- Process payments through Stripe
- Send important service updates or security alerts
- Improve our service and fix bugs
- Comply with legal obligations
We do NOT sell, rent, or share your personal information with third parties for marketing purposes.
4. Data Storage and Security
4.1 Where We Store Data
Your data is stored securely in Supabase (built on PostgreSQL), which provides:
- Encryption at rest
- Encryption in transit (SSL/TLS)
- Regular automated backups
- Industry-standard security practices
4.2 Security Measures
- OAuth tokens are encrypted using industry-standard encryption
- Passwords are hashed using bcrypt
- Row-level security (RLS) ensures data isolation
- Regular security audits and updates
- Access controls and authentication requirements
4.3 Data Retention
- Meeting data: Automatically deleted after 30 days
- Account data: Retained while your account is active
- After account deletion: All data permanently deleted within 30 days
- Payment records: Retained for 7 years for tax compliance
5. Third-Party Services
We use the following third-party services:
Google (OAuth and Calendar API)
Purpose: Authentication and calendar access
Data shared: OAuth tokens, calendar metadata
Privacy Policy: Google Privacy Policy
Stripe
Purpose: Payment processing and subscription management
Data shared: Email, payment information
Privacy Policy: Stripe Privacy Policy
Resend
Purpose: Email notifications
Data shared: Email address, notification content
Privacy Policy: Resend Privacy Policy
Supabase
Purpose: Database and authentication
Data shared: All stored user data
Privacy Policy: Supabase Privacy Policy
6. Your Rights
You have the right to:
- Access: Request a copy of all data we have about you
- Correction: Update or correct your personal information
- Deletion: Request deletion of your account and all associated data
- Export: Download your data in a portable format
- Opt-out: Unsubscribe from notification emails
- Revoke access: Disconnect your Google account at any time
To exercise any of these rights, contact us at support@salesguardapp.com
7. UK GDPR & Data Protection Compliance
SalesGuard complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. As a UK-based service, we provide the following rights to all users, including those in the United Kingdom and European Economic Area (EEA):
- Right to be forgotten: Request complete deletion of your data
- Data portability: Receive your data in a machine-readable format
- Restrict processing: Limit how we use your data
- Object to processing: Opt-out of certain data uses
- Withdraw consent: Revoke permission for data processing at any time
Legal basis for processing: We process your data based on your consent (by creating an account) and for contractual necessity (to provide the service).
Data Controller: SalesGuard is the data controller for your personal information, operating under UK data protection laws.
8. CCPA Compliance (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to know: What personal information we collect and how we use it
- Right to delete: Request deletion of your personal information
- Right to opt-out: Opt-out of the "sale" of personal information (we do not sell data)
- Right to non-discrimination: We will not discriminate against you for exercising your rights
We do NOT sell your personal information to third parties.
9. Cookies and Tracking
We use cookies for:
- Authentication: Maintaining your login session
- Security: Protecting against CSRF attacks
- Preferences: Remembering your settings
We do NOT use cookies for advertising or tracking across other websites.
10. Children's Privacy
SalesGuard is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you are a parent and believe your child has provided us with personal information, please contact us immediately.
11. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify you within 72 hours via email
- Explain what data was affected
- Describe steps we're taking to resolve the issue
- Provide recommendations to protect your account
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. For significant changes, we will notify you via email.
13. Contact Information
If you have questions about this Privacy Policy or want to exercise your rights, please contact us:
UK Data Protection Authority
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the UK's supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
14. SalesGuard Sentinel Chrome Extension
Information Collected
Meeting Codes: When you start monitoring a Google Meet session, the extension reads the meeting code from your browser's URL (e.g., "abc-defg-hij"). This meeting code is sent to our servers to enable email alert delivery and is stored in our database for up to 90 days to provide alert history in your dashboard.
Participant Counts: The extension monitors the number of participants in your Google Meet session by reading the participant count displayed in the meeting interface. We collect only the count (e.g., "3 participants"), NOT the names, email addresses, or identities of participants. Participant count data is sent to our servers when an alert is triggered and is stored for up to 90 days.
Monitoring State: The extension stores your monitoring preferences (whether monitoring is active or inactive) locally on your device using Chrome's storage API.
Alert Timestamps: When we send you an alert, we record the timestamp, meeting code, and participant count at the time of the alert. This data is stored for 90 days to provide alert history.
What We Do NOT Collect
- Participant names, email addresses, or identities
- Meeting content (video, audio, chat messages, screen shares)
- Meeting recordings
- Any personal information about other meeting participants
- Your browsing history outside of Google Meet
- Data from tabs or websites other than Google Meet
How We Use This Information
- To detect when participants join your meetings and send you email alerts
- To display alert history in your dashboard
- To provide customer support if you report issues
- To improve the accuracy of participant detection
Data Storage and Transmission
- Meeting codes and participant counts are transmitted to our servers via HTTPS
- Data is stored in our secure database (hosted by Supabase) with encryption at rest
- Monitoring state is stored locally on your device and never leaves your computer
- We do not share meeting codes or participant data with third parties, except as required to provide the service (email delivery via Resend.com)
Data Sharing
We share limited data with the following third-party service providers:
Resend.com (Email Delivery): When we send you an alert email, Resend.com processes the email containing your meeting code and participant count. Resend.com does not store or use this data for any other purpose. Privacy policy: resend.com/legal/privacy-policy
Stripe (Payment Processing): Your payment information is processed by Stripe. We do not store your credit card details. Privacy policy: stripe.com/privacy
Supabase (Database Hosting): Meeting codes and participant data are stored in our database hosted by Supabase. Privacy policy: supabase.com/privacy
We do not sell, rent, or share your data with advertisers, data brokers, or marketing companies.
Data Retention
- Meeting codes and alert data: 90 days, then automatically deleted
- User account information: Until you delete your account
- Subscription data: As long as your subscription is active, plus 1 year for tax and accounting purposes
Your Rights and Control
You can control your data at any time:
- Start/stop monitoring via the extension popup
- Uninstall the extension to stop all data collection
- Contact support@salesguardapp.com to delete your account and remove all stored data
- Request data export or deletion by emailing support@salesguardapp.com
- Disable browser notifications in your Chrome settings
Account deletion requests are processed within 30 days.
Chrome Web Store User Data Policy Compliance
The use of information received from Google Meet will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We collect and use meeting codes and participant count data solely to provide the meeting monitoring and alert service described above. We do not use this data for advertising, credit decisions, or any purpose unrelated to the core functionality of SalesGuard Sentinel.
GDPR Compliance
If you are located in the European Union or United Kingdom:
- We collect this data based on your consent (provided when you install the extension and start monitoring)
- You have the right to access, correct, delete, or export your data
- You have the right to withdraw consent at any time by uninstalling the extension or deleting your account
- You have the right to lodge a complaint with your local data protection authority
For GDPR-related requests, contact: privacy@salesguardapp.com
By using SalesGuard, you acknowledge that you have read and understood this Privacy Policy.