1. Information we collect
We collect the information you give us directly, information generated by your use of the service, and information created when you connect other services to your account.
Account and organization information
- Account details: your name, email address, and a securely hashed version of your password. We never store your password in plain text. If you create your account using “Sign in with Google” instead, we receive your name, email address, and Google account ID from Google, and no password is collected or stored.
- Organization information: your company or team name, the roles you assign to teammates (Owner, Admin, Manager, Member), and the email addresses you use to invite them.
Usage data
- Actions you take in the product — searches you run, leads you save, pipeline stages you move leads through, campaigns you create, and similar activity we need in order to run the service and keep an activity history on your team's records.
- Standard technical data such as IP address, browser type, and timestamps, collected automatically as part of operating and securing the service.
Payment data
Billing is handled entirely by Stripe, our payment processor. SeamMagnet does not collect or store your card number, expiry date, or CVC on our own servers — that data goes directly to Stripe. We retain only the billing metadata Stripe provides back to us, such as your subscription tier, seat count, invoice history, and payment status.
Data you import or search for
When you use SeamMagnet to search Google Maps and Apollo, or to import leads from a CSV/XLSX file, the resulting lead records — company names, contact details, addresses, notes, and any other data your team adds — are stored in your organization's shared pipeline. This data is provided by you or by the third-party sources you choose to search, not collected by us independently.
Calendar data (if you connect Google Calendar or Outlook)
If you choose to connect a calendar, we access only what is needed to power scheduling: your free/busy availability, so the app can compute open time slots, and the ability to create a calendar event when you or a lead books a meeting through the Service. We do not read the content, attendees, or details of your other, unrelated calendar events. You can disconnect your calendar at any time from Settings, which immediately deletes the stored access credentials; you can also revoke access directly from your Google Account at myaccount.google.com/permissions.
2. How we use your information
We use the information we collect to:
- Provide, operate, and maintain the service, including your shared team pipeline, outreach campaigns, reports, and integrations.
- Process payments, manage subscriptions and seat counts, and send billing communications.
- Respond to support requests and communicate important service updates.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Maintain rate limiting, session security, and an origin allowlist that protect the API and your account from unauthorized access.
We do not use your data to train third-party advertising models, and we do not sell your personal information.
3. Legal bases and your rights (EU/EEA — GDPR)
If you are located in the European Union or European Economic Area, we process your personal data under the following legal bases: performance of a contract (providing the service you've signed up for), legitimate interests (security, fraud prevention, and improving the service), and legal obligation (such as tax and accounting recordkeeping).
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data, subject to legal or contractual retention requirements.
- Port your data to another provider in a structured, commonly used format.
- Object to or restrict certain processing of your data.
To exercise any of these rights, contact us at [email protected].
4. California residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion of that information, and to opt out of the "sale" of personal information. SeamMagnet does not sell your personal information, and has not sold personal information in the preceding twelve months. To exercise your CCPA rights, contact us at [email protected].
5. Cookies and similar technologies
The SeamMagnet application uses session cookies to keep you signed in and to protect your account. This marketing site does not set third-party advertising or ad-tracking cookies. We do not run third-party ad networks or ad-tracking pixels on our sites.
6. Third-party service providers
We share data with a limited set of service providers, each acting on our behalf and only to the extent needed to deliver the service:
- Payment processing: Stripe handles all card data and billing directly; we never see your full card number.
- Email delivery: an SMTP/email provider sends transactional email (such as account and billing notices) and, when you connect your own mailbox, delivers your outreach campaign emails.
- Lead-data source integrations: if your organization chooses to connect them, Google Maps, Apollo, Hunter.io, and LinkedIn are used to search for and enrich lead data. These connections are opt-in and configured by your organization.
- Google sign-in and calendar: if you use “Sign in with Google” or connect Google Calendar, Google acts as our authentication and scheduling provider for that feature, governed by the Google API Services User Data Policy described in Section 7 below.
- Cloud hosting: our infrastructure runs on a cloud hosting provider that stores and processes data on our behalf under contractual confidentiality and security terms.
We do not permit these providers to use your data for any purpose other than providing services to us.
7. Google API Services User Data Policy
SeamMagnet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, when you use “Sign in with Google” or connect Google Calendar:
- We only use the Google user data we receive (your name, email address, Google account ID, and calendar free/busy availability) to provide the sign-in and scheduling features described in this policy — nothing else.
- We do not use Google user data for advertising or ad targeting of any kind.
- We do not allow humans to read Google user data, except in the limited cases the Limited Use requirements permit: with your affirmative consent, for security purposes (such as investigating abuse), to comply with applicable law, or to service the specific support request you sent us about your own account.
- We do not use Google user data to train or improve generalized artificial intelligence or machine learning models.
- We do not sell, rent, or transfer Google user data to any third party.
8. Data retention
We retain your personal data for as long as your account is active. If you close your account, we retain data for a reasonable period afterward to comply with legal obligations, resolve disputes, maintain backups, and enforce our agreements, after which it is deleted or anonymized. You can request deletion of your account and associated data at any time by contacting [email protected].
9. Data security
We take the security of your data seriously. Every stored secret — mailbox passwords, LinkedIn session tokens, calendar refresh tokens, webhook signing secrets, and provider API keys — is encrypted at rest using AES-256-GCM. All database access goes through stored procedures rather than inline SQL, and the service is served exclusively over HTTPS. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices.
10. Children's privacy
SeamMagnet is not directed at children under 16, and we do not knowingly collect personal data from anyone under that age. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.
11. International data transfers
Your information may be transferred to, stored, and processed in a country other than the one in which you reside, including the United States, where our service providers operate. Where required, we rely on appropriate safeguards to protect personal data transferred internationally, consistent with applicable data protection law.
12. Changes to this policy
We may update this policy from time to time. When we do, we will post the revised policy on this page and update the "Last updated" date above. If changes are material, we will provide additional notice where appropriate.
13. Contact us
This policy is issued by SKYFALL Labs LLC, a Wyoming limited liability company, and is governed under the laws of the State of Wyoming, USA. If you have questions about this policy or how we handle your data, contact us at [email protected]. We do not list a physical mailing address for correspondence.