Legal

Privacy Policy

Effective Date: July 13, 2026

SOC2 & ISO27001 Certified
Read our Terms of Service →

1. Who we are

SooqSense ("we", "us") operates SooqSense Prospects, a sales/prospecting CRM that lets a user connect their own Gmail, Google Calendar, LinkedIn, and WhatsApp accounts to manage outreach, scheduling, and conversations in one place. This policy explains what data we collect, why, and how it is used — with particular detail on data obtained through Google APIs, as required by the Google API Services User Data Policy.

Contact: privacy@sooqsense.com

2. Google API Services User Data Policy — Limited Use disclosure

SooqSense Prospects' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means:

  • We use Google user data only to provide or improve user-facing features of the App described in Section 4 below.
  • We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not sell Google user data, and we do not transfer it to data brokers, ad networks, or ad-related businesses.
  • We do not use Google user data to train, improve, or build generalized/non-personalized AI or machine-learning models. Where AI is used (Section 6), it processes a user's own data transiently to generate output for that same user's request and is not used to train underlying third-party models.
  • We allow humans to read Gmail message content only: (a) with the affected user's affirmative consent for a specific support request, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for the App's internal operations (e.g. debugging a sync failure), and even then only to the extent reasonably necessary and logged.

3. Information we collect

3.a Account and identity data

Name, email, and organization membership, managed via our authentication provider, Clerk. We store a Clerk-issued user/organization ID to associate your data across the App.

3.b Google user data

If you connect a Google account, we request the following OAuth scopes through a single consent screen (connecting either Gmail or Calendar links both):

ScopeWhat it lets us access
gmail.readonlyRead your email messages and metadata
gmail.sendSend email on your behalf, only when you (or an AI draft you approve) trigger a send
gmail.modifyApply labels and read/unread status when syncing your inbox
userinfo.email, userinfo.profileYour Google account email and basic profile, to identify the connected account
calendar.readonlyRead your calendar events
calendar.eventsCreate and update calendar events (e.g. booking a meeting through the App)

From these APIs we store: email subject, body, sender/recipient addresses, thread/label metadata, attachment metadata (attachment content is fetched on demand, not stored), and calendar event titles, descriptions, locations, times, and attendee lists.

3.c LinkedIn and WhatsApp data

If you connect LinkedIn or WhatsApp (via our messaging infrastructure provider, Unipile), we store conversation threads, messages, and contact profile data needed to display and sync those conversations in the App.

3.d Usage and engagement data

When you send email through the App, we record whether and when a recipient opened it or clicked a link (via a tracking pixel/link redirect), including the requester's IP address and user-agent, to power open/click analytics on your own outbound messages.

4. How we use your data (app functionality only)

  • Sync and display your Gmail inbox and Calendar events inside the App.
  • Send emails and create/update calendar events at your explicit action.
  • Link inbound/outbound emails, calendar events, and messages to the correct contact/prospect record.
  • Generate AI-assisted email draft suggestions and meeting summaries for you to review, edit, and approve (Section 6).
  • Show you engagement analytics (opens/clicks) on emails you sent.
  • Maintain your account, authenticate you, and enforce organization-level access control.

We do not use this data for any purpose outside the features above.

5. Meeting recording feature

If you enable meeting recording/notes for a calendar event, our recording provider, Recall.ai, joins the meeting as a bot, records it, and returns a transcript, video, and/or audio file. Recordings are stored in our cloud storage (AWS S3) and the transcript may be summarized by AI (Section 6). This only happens for meetings you explicitly enable it for.

6. AI processing

We use OpenAI's API to: (a) generate suggested email replies/outreach drafts from your email thread context, and (b) summarize meeting transcripts. We use Langfuse to log prompts and responses for debugging and quality monitoring of these AI features.

  • AI output is always a suggestion — nothing is sent or saved on your behalf without you reviewing and approving it, except automatic labeling/sync metadata which does not involve message content.
  • Data sent to OpenAI is used to generate your response and is not used by OpenAI to train its models (per our API configuration and OpenAI's API data-usage terms).
  • AI processing is limited to the specific user's own data for that user's own feature request — it is never aggregated across users to build a separate model.

7. How we share data

We share data only with trusted service providers necessary to run the features above, each bound by a data-processing agreement or equivalent terms.

We do not sell your data. We do not share it with advertisers or data brokers.

8. Data retention and deletion

We retain your connected-account data for as long as your account is active. Disconnecting a Google/LinkedIn/WhatsApp account stops future syncing; previously synced messages/events may remain in our database, associated with your CRM records, until you request deletion. To request deletion of your account and associated data, contact privacy@sooqsense.com. You can also revoke the App's access at any time from your Google Account permissions page, which immediately invalidates our stored tokens for future access (already-synced data is handled per your deletion request).

9. Data security

OAuth credentials and application data are stored in access-controlled infrastructure. Access to production data is restricted to authorized personnel on a need-to-know basis. No method of transmission or storage is 100% secure, but we apply industry-standard safeguards throughout.

10. Your rights and choices

  • Disconnect any connected account at any time from the App's settings.
  • Revoke Google access directly at https://myaccount.google.com/permissions.
  • Request a copy of, or deletion of, your data by contacting privacy@sooqsense.com.
  • Depending on your jurisdiction, you may have additional rights (access, correction, portability, objection) under laws such as GDPR or CCPA — contact us to exercise them.

11. Children's privacy

The App is not directed to individuals under 16, and we do not knowingly collect data from them.

12. International data transfers

Your data may be processed in countries other than your own by us or our service providers listed in Section 7, with appropriate safeguards in place.

13. Changes to this policy

We may update this policy from time to time. Material changes will be notified via the App or email, and the "Effective date" above will be updated.

14. Contact us

Questions about this policy or your data: privacy@sooqsense.com

Compliance Standards

SOC2

Type II Certified

Audited annually

ISO

ISO 27001

Global standard

GDPR

Fully Compliant

EU data protection

Contact Us

Have specific questions regarding this Privacy Policy, our data practices, or requesting a DPA? Our dedicated Privacy Team responds to all inquiries within 24 hours.