Privacy Policy

How RevOps Labs s.r.o. collects, uses, and protects personal data in Salescheck.io.

Effective date: [SET WHEN PUBLISHED] · Last updated: [SET WHEN PUBLISHED]

Draft — not yet reviewed by a lawyer. This is a complete, Salescheck.io-specific starting point based on how the product actually works today (including that Sentry error monitoring, EU region, is being added — see §7). Before publishing: have a qualified lawyer review it (ideally one familiar with Czech and EU/GDPR law), fill in the [bracketed placeholders] — the contact email isn't decided yet — and confirm the data-residency notes on Clerk and Creem in §8, which we haven't verified directly with those providers.

Contents

  1. 1. Who we are
  2. 2. Scope
  3. 3. What personal data we collect
  4. 4. Why we process it, and on what legal basis
  5. 5. Who we share data with
  6. 6. Third-party providers you connect yourself
  7. 7. Error monitoring (Sentry)
  8. 8. International data transfers
  9. 9. How long we keep data
  10. 10. Security
  11. 11. Your rights
  12. 12. Self-service export & erasure
  13. 13. Cookies
  14. 14. Children's privacy
  15. 15. Changes to this policy
  16. 16. Contact & complaints

1. Who we are

RevOps Labs s.r.o. ("we", "us"), a company registered in the Czech Republic under IČO 21705534, with its registered seat at Hlaváčkova 1334/19, Košíře, 150 00 Praha 5, Czech Republic, is the data controller for the personal data described in this policy, unless stated otherwise below.

2. Scope

This policy covers the Salescheck.io website, dashboard, and API (the "Service"). Where you connect a CRM (HubSpot, Pipedrive, Salesforce) or a third-party data provider, that provider's own privacy policy also applies to how they process data — see §6.

3. What personal data we collect

CategoryWhat it includesSource
Account & authentication Name, email address, organization membership and role You, via Clerk (our authentication provider)
CRM-derived business data Company/deal names, country, industry codes (MCC/NAICS), and — if you supply it — a crypto wallet address, for records you authorize us to read from your connected CRM Your connected CRM (HubSpot/Pipedrive/Salesforce), via OAuth you grant
CRM user list Email addresses of your CRM's users, used only to count billable seats (deduplicated against your Salescheck.io organization members) Your connected CRM
Scoring records A compliance-decision audit trail: the input used, which rule matched, the result, and the reason shown Generated by the Service
Billing data Billing contact email, self-entered legal name/tax ID/address (optional, for your own invoicing records), subscription and payment status You and our payment processor, Creem — Creem holds your actual card details, never us
Support & admin actions Support emails/messages you send us; a log of when a platform administrator accessed your account for support (impersonation) — who, when, which account You; generated by the Service
Technical data IP address, request metadata, and error diagnostics Generated automatically (Cloudflare Workers Logs; Sentry once added — see §7)

Some of this — particularly CRM-derived business data — may itself be personal data about your own contacts and customers, not about you. For that data, you are the data controller and we act as your data processor; you're responsible for having a lawful basis to share it with us (see our Terms of Service, §5).

4. Why we process it, and on what legal basis

PurposeLegal basis (GDPR Art. 6(1))
Operating the Service: authentication, scoring, CRM sync, dashboards(b) performance of our contract with you
Billing, invoicing, and fraud/abuse prevention(b) contract; (f) legitimate interest
Security, rate limiting, and detecting misuse(f) legitimate interest
Diagnosing bugs and errors (including via Sentry, see §7)(f) legitimate interest — keeping the Service working
Responding to support requests(b) contract; (f) legitimate interest
Complying with tax, accounting, and other legal obligations(c) legal obligation

5. Who we share data with

We share personal data with the following processors, only as needed to provide the Service:

ProcessorPurpose
Clerk, Inc.Authentication, organization/user management
CreemPayment processing (acting as merchant of record)
NeonDatabase hosting (our production database runs in the eu-central-1 AWS region, Frankfurt)
Cloudflare, Inc.Application hosting, infrastructure, request logs
SentryError monitoring — being added, see §7

We don't sell personal data, and we don't use it for advertising.

6. Third-party providers you connect yourself

If you connect your own HubSpot, Pipedrive, or Salesforce account, or your own account with a third-party sanctions/risk data provider (ComplyAdvantage, Sanctions.io, OpenCorporates, TRM Labs), we send that provider only the specific data needed to fulfill the request you've configured (e.g. a company name or wallet address to screen). Each provider processes that data under its own privacy policy and its relationship with you, not with us.

7. Error monitoring (Sentry)

Planned We are integrating Sentry for error monitoring, so we can detect and fix bugs faster instead of only finding them by manually tailing logs. Sentry will be configured to run in Sentry's EU region, and we aim to minimize the personal data it receives — for example, by scrubbing request bodies and known PII fields from error reports before they're sent. Sentry may still incidentally capture technical diagnostic data (like a stack trace, request URL, or browser/device information) at the moment an error occurs. This section will be finalized once the integration is live.

8. International data transfers

Most of our infrastructure (Neon, and Sentry once added) runs in the EU. Some of our processors — including Clerk and Creem — may process data outside the EU/EEA, for example in the United States. [TO CONFIRM: verify Clerk's and Creem's exact data-processing locations and, where data leaves the EU/EEA, the transfer mechanism they rely on — typically the EU Standard Contractual Clauses — and reference that mechanism here specifically rather than generically.]

9. How long we keep data

We keep your account and Customer Data for as long as your organization has an active account, plus a limited period afterward to allow you to reactivate, to comply with legal/accounting retention obligations (Czech law generally requires accounting records to be kept for several years), and to resolve any disputes. [TO CONFIRM: set and document an exact post-termination retention period — e.g. 30 days before permanent deletion, followed by longer retention of billing/accounting records only, as required by Czech tax law.] You can also erase your organization's operational data yourself at any time — see §12.

10. Security

We apply technical and organizational measures appropriate to the data we hold, including:

No method of transmission or storage is 100% secure; we can't guarantee absolute security.

11. Your rights

If you are in the EEA/UK (and, as a matter of practice, wherever you are), you have the right to:

To exercise any of these, contact us at [CONTACT EMAIL], or use the self-service tools below.

12. Self-service export & erasure

Organization admins can, at any time, from Company & Billing → Data & privacy:

For full account/organization closure (removing the organization itself, not just its data), contact us at [CONTACT EMAIL].

13. Cookies

We use only the strictly necessary cookies/local storage needed to keep you signed in, set by our authentication provider, Clerk. We don't use advertising or analytics tracking cookies.

14. Children's privacy

Salescheck.io is a business-to-business service and isn't directed at, or knowingly used by, children.

15. Changes to this policy

We may update this policy from time to time. We'll notify you of material changes by email or in the Service before they take effect.

16. Contact & complaints

RevOps Labs s.r.o. · IČO 21705534 · Hlaváčkova 1334/19, Košíře, 150 00 Praha 5, Czech Republic
Email: [CONTACT EMAIL]

You can also lodge a complaint with the Czech data protection authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz), or with the supervisory authority in your own EU/EEA country of residence.

← Back to Salescheck.io