This Privacy Policy explains how SalesGPT.work ("we", "us", "our") collects, uses, discloses, and safeguards personal data when you use our website and AI-powered sales platform (the "Service").
1. Who this policy applies to
This Policy applies to visitors, registered users, and enterprise administrators who access or use SalesGPT.work. The platform is intended for individuals aged 18 and above.
Controller / Processor roles (clarification): SalesGPT.work acts as a Data Controller for personal data relating to website visitors, account registration, billing, and direct communications. When customers use the platform to process personal data of their own end users, prospects, or employees, SalesGPT.work acts as a Data Processor and processes such data on the customer's documented instructions.
2. Data we collect
- Account & identity data: name, email, password hashes, organization, role.
- Usage & device data: IP address, browser type, device IDs, activity logs, crash/diagnostic data.
- Business data you provide: uploaded files, CRM fields, prompts, chat transcripts, and outputs generated by the platform.
- Enrichment data: when you use enrichment features, we may supplement your uploaded data with information sourced from third-party business intelligence providers and publicly available business information (as requested by you). This may include email addresses, phone numbers, job titles, company information, and profile URLs. You are responsible for ensuring you have a lawful basis to process enriched data.
- Mailbox integration data: when you connect email accounts (e.g., Gmail, Outlook), we may access messages and related metadata you authorize, contact data, and deliverability metrics (opens, clicks, bounces, replies) to provide analytics and outreach functionality. This data is processed in accordance with your account settings.
- Instagram / Meta platform data: when you connect your Instagram Business account, we receive and store your Instagram user ID, username, and an OAuth access token issued by Meta. We use this solely to publish content on your behalf. We do not access your followers, messages, or any data beyond what is required by the
instagram_business_basicandinstagram_business_content_publishpermissions you explicitly grant. - Outreach & communication data: recipient email addresses, message content, delivery metadata, and engagement metrics. For outreach data, SalesGPT.work acts as a Data Processor on your documented instructions.
- Payments: limited billing details and transaction IDs (processed via third-party payment providers; we do not store full card numbers).
- Cookies & similar technologies: see our Cookie Policy for details.
- Support & feedback: messages or files you share with our support team and survey responses.
- Marketing preferences: newsletter/communication choices and event registrations.
3. Sources of data
- Directly from you (forms, chat, uploads, support tickets).
- Automatically via cookies, SDKs, and analytics.
- Third-party integrations (e.g., HubSpot, Salesforce, email providers) when you connect them.
- Data enrichment sources: third-party business intelligence providers and publicly available business information (as requested by you).
4. How we use data (purposes)
- Provide, personalize, and improve the platform and its features.
- Authenticate users, secure accounts, and prevent abuse.
- Process payments, subscriptions, and invoices.
- Analytics, research, troubleshooting, and feature development.
- Communications: service announcements, security notices, and—where permitted—marketing updates (with opt-out).
- Compliance with legal obligations and enforcement of our Terms and policies.
5. Legal bases
GDPR (where applicable):
- Contract performance (Article 6(1)(b)) to provide and operate the platform.
- Legitimate interests (Article 6(1)(f)) such as security, fraud prevention, service reliability, and product improvement, where not overridden by your rights.
- Legal obligations (Article 6(1)(c)) where we must comply with law.
- Consent (Article 6(1)(a)) only where explicitly obtained and required (e.g., optional marketing communications and non-essential cookies).
DPDP Act: consent, certain legitimate uses permitted by law, and performance of lawful purposes consistent with the notice provided to users.
6. Cookies & tracking
We use essential and optional cookies/SDKs for authentication, performance, analytics, and personalization. EU/UK users will see a consent banner for optional cookies. Manage preferences in our Cookie Policy and your browser settings.
7. Data retention
We retain personal data for as long as necessary to fulfill the purposes described, comply with legal obligations, resolve disputes, and enforce agreements.
| Data category | Typical retention |
|---|---|
| Account data | Until account deletion, plus up to 30 days for backup recovery purposes. |
| User-uploaded data | Until account deletion or user-initiated removal. |
| Enriched data | Until you delete it or your account is terminated; may be refreshed periodically. |
| AI prompts/outputs (unsaved) | Up to 90 days for abuse monitoring and service reliability; then purged unless saved. |
| Activity logs & usage data | Up to 90 days (rolling) for operational and security purposes. |
| Billing records | Up to 7 years from last transaction for tax and accounting obligations. |
| Support communications | Up to 3 years from last interaction for quality assurance and dispute resolution. |
| Backups and system logs | Typically up to 90 days before automated purging. |
| Instagram / Meta connection data (user ID, username, access token) | Until you disconnect your Instagram account or request deletion. Deleted immediately upon disconnection or within 30 days of a deletion request. |
Users may request deletion of their account and associated data at any time. Upon deletion request, we will delete personal data within 30 days, subject to statutory retention requirements and technical backup constraints (backups purged within 90 days).
8. Sharing & international transfers
- Service providers: cloud hosting, analytics, support, and payment processors under contractual safeguards.
- Integrations: when you connect third-party tools, data may flow to those tools per your configuration; their processing is governed by their terms and privacy policies.
- Legal & safety: to comply with law, enforce our terms, or protect rights, security, or property.
Transfers: personal data may be transferred to and processed in countries outside the European Economic Area, including the United States and India. Where required by law, such transfers are governed by appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), which are incorporated into our Data Processing Addendum.
9. Security
- TLS encryption in transit; encryption at rest where applicable.
- Role-based access controls, MFA for internal admin access, audit logging.
- Vendor due diligence and data processing agreements with sub-processors.
No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
10. Your rights
Subject to applicable law, you may have the right to access, correct, update, port, restrict, object to processing, or delete your personal data. You can exercise these rights by contacting us at admin@salesgpt.work. We respond to verified requests within 30 days, or as required by law.
Under the DPDP Act, you may also nominate an individual to exercise your rights in the event of your incapacity or death where supported by our processes. If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority.
11. Children
Our services are intended for adults (18+). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us to delete it.
12. Contact & grievance / DPO
Email (DPO/Grievance): admin@salesgpt.work
Registered office: FIRST FLOOR, 10, SHIVAM, OPPOSITE NARSINGH MANDIR, AGRASEN BAZAR, BEAWAR, Ajmer, Rajasthan, 305901, India.
Grievance Officer / DPO: Grievance Officer – SalesGPT, admin@salesgpt.work (as applicable under DPDP/GDPR).
13. Jurisdiction
Subject to applicable law, disputes will be governed by the laws of India with courts at Ajmer, Rajasthan having exclusive jurisdiction.
14. Changes to this policy
We may update this Policy from time to time. Material changes will be notified via the website or email, and the "Effective date" above will be updated. Continued use of the platform after changes constitutes acceptance of the updated Policy.
15. Instagram / Meta platform data & deletion
SalesGPT integrates with the Instagram Graph API to allow you to publish posts to your Instagram Business account. When you connect your Instagram account, Meta shares the following Platform Data with us:
- Instagram user ID
- Instagram username
- An OAuth access token to post content on your behalf
This data is stored securely in our database and is used exclusively to publish content you create within SalesGPT. We do not sell, share, or use this data for advertising or any purpose other than providing the Instagram posting feature.
How to delete your Instagram data from SalesGPT
Option 1 — Instant self-service (recommended):
- Log in to SalesGPT at salesgpt.work
- Go to Social Media Connections
- Click the delete (🗑) icon next to your Instagram account
This immediately and permanently removes your Instagram access token and all associated data from our system.
Option 2 — Email request: Email us at admin@salesgpt.work with the subject "Instagram Data Deletion Request". We will permanently delete your data within 30 days.
Note: Deleting your Instagram connection from SalesGPT does not delete your Instagram account or any posts already published to Instagram. To manage your Instagram account or revoke app permissions directly, visit Instagram > Settings > Apps and Websites.
Additional disclosures: Our standard Data Processing Addendum (DPA), which incorporates the EU Standard Contractual Clauses, is available at https://salesgpt.work/dpa. Our subprocessors are listed at https://salesgpt.work/subprocessors.