Privacy Policy
How RevOps Labs s.r.o. collects, uses, and protects personal data in Salescheck.io.
Contents
- 1. Who we are
- 2. Scope
- 3. What personal data we collect
- 4. Why we process it, and on what legal basis
- 5. Who we share data with
- 6. Third-party providers you connect yourself
- 7. Error monitoring (Sentry)
- 8. International data transfers
- 9. How long we keep data
- 10. Security
- 11. Your rights
- 12. Self-service export & erasure
- 13. Cookies
- 14. Children's privacy
- 15. Changes to this policy
- 16. Contact & complaints
1. Who we are
RevOps Labs s.r.o. ("we", "us"), a company registered in the Czech Republic under IČO 21705534, with its registered seat at Hlaváčkova 1334/19, Košíře, 150 00 Praha 5, Czech Republic, is the data controller for the personal data described in this policy, unless stated otherwise below.
2. Scope
This policy covers the Salescheck.io website, dashboard, and API (the "Service"). Where you connect a CRM (HubSpot, Pipedrive, Salesforce) or a third-party data provider, that provider's own privacy policy also applies to how they process data — see §6.
3. What personal data we collect
| Category | What it includes | Source |
|---|---|---|
| Account & authentication | Name, email address, organization membership and role | You, via Clerk (our authentication provider) |
| CRM-derived business data | Company/deal names, country, industry codes (MCC/NAICS), and — if you supply it — a crypto wallet address, for records you authorize us to read from your connected CRM | Your connected CRM (HubSpot/Pipedrive/Salesforce), via OAuth you grant |
| CRM user list | Email addresses of your CRM's users, used only to count billable seats (deduplicated against your Salescheck.io organization members) | Your connected CRM |
| Scoring records | A compliance-decision audit trail: the input used, which rule matched, the result, and the reason shown | Generated by the Service |
| Billing data | Billing contact email, self-entered legal name/tax ID/address (optional, for your own invoicing records), subscription and payment status | You and our payment processor, Creem — Creem holds your actual card details, never us |
| Support & admin actions | Support emails/messages you send us; a log of when a platform administrator accessed your account for support (impersonation) — who, when, which account | You; generated by the Service |
| Technical data | IP address, request metadata, and error diagnostics | Generated automatically (Cloudflare Workers Logs; Sentry once added — see §7) |
Some of this — particularly CRM-derived business data — may itself be personal data about your own contacts and customers, not about you. For that data, you are the data controller and we act as your data processor; you're responsible for having a lawful basis to share it with us (see our Terms of Service, §5).
4. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Operating the Service: authentication, scoring, CRM sync, dashboards | (b) performance of our contract with you |
| Billing, invoicing, and fraud/abuse prevention | (b) contract; (f) legitimate interest |
| Security, rate limiting, and detecting misuse | (f) legitimate interest |
| Diagnosing bugs and errors (including via Sentry, see §7) | (f) legitimate interest — keeping the Service working |
| Responding to support requests | (b) contract; (f) legitimate interest |
| Complying with tax, accounting, and other legal obligations | (c) legal obligation |
5. Who we share data with
We share personal data with the following processors, only as needed to provide the Service:
| Processor | Purpose |
|---|---|
| Clerk, Inc. | Authentication, organization/user management |
| Creem | Payment processing (acting as merchant of record) |
| Neon | Database hosting (our production database runs in the eu-central-1 AWS region, Frankfurt) |
| Cloudflare, Inc. | Application hosting, infrastructure, request logs |
| Sentry | Error monitoring — being added, see §7 |
We don't sell personal data, and we don't use it for advertising.
6. Third-party providers you connect yourself
If you connect your own HubSpot, Pipedrive, or Salesforce account, or your own account with a third-party sanctions/risk data provider (ComplyAdvantage, Sanctions.io, OpenCorporates, TRM Labs), we send that provider only the specific data needed to fulfill the request you've configured (e.g. a company name or wallet address to screen). Each provider processes that data under its own privacy policy and its relationship with you, not with us.
7. Error monitoring (Sentry)
8. International data transfers
Most of our infrastructure (Neon, and Sentry once added) runs in the EU. Some of our processors — including Clerk and Creem — may process data outside the EU/EEA, for example in the United States. [TO CONFIRM: verify Clerk's and Creem's exact data-processing locations and, where data leaves the EU/EEA, the transfer mechanism they rely on — typically the EU Standard Contractual Clauses — and reference that mechanism here specifically rather than generically.]
9. How long we keep data
We keep your account and Customer Data for as long as your organization has an active account, plus a limited period afterward to allow you to reactivate, to comply with legal/accounting retention obligations (Czech law generally requires accounting records to be kept for several years), and to resolve any disputes. [TO CONFIRM: set and document an exact post-termination retention period — e.g. 30 days before permanent deletion, followed by longer retention of billing/accounting records only, as required by Czech tax law.] You can also erase your organization's operational data yourself at any time — see §12.
10. Security
We apply technical and organizational measures appropriate to the data we hold, including:
- encryption in transit (TLS) for all traffic to the Service;
- encryption at rest (AES-256-GCM) for third-party CRM and data-provider credentials stored in our database;
- role-based access control within your organization (Admin vs. Compliance) and a separate, email-allow-listed layer for our own staff's cross-organization admin access;
- a logged audit trail for both compliance scoring decisions and platform-admin actions like account impersonation;
- rate limiting on key API endpoints to reduce abuse.
No method of transmission or storage is 100% secure; we can't guarantee absolute security.
11. Your rights
If you are in the EEA/UK (and, as a matter of practice, wherever you are), you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten"), subject to legal retention obligations;
- Restrict or object to certain processing;
- Port your data to another provider in a structured, machine-readable format;
- Withdraw consent at any time, where we rely on it;
- Lodge a complaint with a supervisory authority — see §16.
To exercise any of these, contact us at [CONTACT EMAIL], or use the self-service tools below.
12. Self-service export & erasure
Organization admins can, at any time, from Company & Billing → Data & privacy:
- Export everything Salescheck.io holds for your organization as a JSON file — risk categories, rules, scoring history, and CRM/provider connection metadata (never encrypted credentials);
- Erase that same data, after typing your organization's exact name to confirm. This resets your organization's data — your account and members stay intact, but you'll need to reconnect your CRM and rebuild your rules.
For full account/organization closure (removing the organization itself, not just its data), contact us at [CONTACT EMAIL].
13. Cookies
We use only the strictly necessary cookies/local storage needed to keep you signed in, set by our authentication provider, Clerk. We don't use advertising or analytics tracking cookies.
14. Children's privacy
Salescheck.io is a business-to-business service and isn't directed at, or knowingly used by, children.
15. Changes to this policy
We may update this policy from time to time. We'll notify you of material changes by email or in the Service before they take effect.
16. Contact & complaints
RevOps Labs s.r.o. · IČO 21705534 · Hlaváčkova 1334/19, Košíře, 150 00 Praha 5, Czech Republic
Email: [CONTACT EMAIL]
You can also lodge a complaint with the Czech data protection authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz), or with the supervisory authority in your own EU/EEA country of residence.
← Back to Salescheck.io