Privacy Policy

Effective date: August 1, 2026

This policy describes how DealDocket, operated by Uptime Advisory ("we," "us"), collects, uses, and protects information when you use the Service.

1. Information we collect

  • Account information — name, email address, and organization details, processed through our authentication provider (Clerk).
  • Customer content — buyer contacts, deal records, templates, notes, and reports that your organization stores in the Service. This data belongs to you.
  • Connected mailbox data — described in section 2 below.
  • Usage and log data — standard server logs and event records needed to operate and secure the Service.

2. Google user data

If you connect a Google mailbox, we request the gmail.send and gmail.modify scopes to send email on your behalf and to detect replies to deal outreach. Our access is deliberately narrow:

  • Outbound email is sent from your own mailbox only when you or automation you configure initiates it.
  • For inbound mail we process message metadata (sender, subject, thread id, timestamp, and a short preview snippet) and only for messages that match a deal thread we sent or a buyer contact on one of your active deals. All other mail — anything unrelated to your deal processes — is ignored and never stored.
  • For matched replies we store the metadata, a classification, and a short excerpt whose length your organization controls (which may be zero). We do not store full message bodies or attachments.
  • OAuth refresh tokens are encrypted at rest. Disconnecting your mailbox in Settings revokes our access and stops all processing.

DealDocket's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train generalized machine-learning models, and allow human access only with your consent, for security purposes, or as required by law.

3. How we use information

  • To provide, secure, and improve the Service.
  • To classify matched buyer replies, we send the message metadata and preview snippet to Anthropic's Claude API. Anthropic processes this data as a service provider and does not use it to train models.
  • We do not sell personal information or use customer content for advertising.

4. Service providers

We use a small set of subprocessors to run the Service: Railway (hosting), Neon (database), Clerk (authentication), Google Cloud (email notifications infrastructure), Inngest (job scheduling), and Anthropic (reply classification). Each processes data only as needed to provide their function.

5. Security

Data is encrypted in transit and at rest. Tenant isolation is enforced at the database layer (row-level security). OAuth tokens are encrypted with keys held outside the database. State-changing actions are attributable and recorded in an append-only log.

6. Retention and deletion

Customer content is retained while your account is active. Upon account termination or verified request, we delete your organization's data within 30 days, except where retention is required by law. You may request export of your data before deletion.

7. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal information. Contact us and we will honor verified requests within applicable timelines.

8. Changes

We may update this policy; material changes will be communicated to account holders and reflected by the effective date above.

9. Contact

Privacy questions or requests: [email protected].