Privacy Policy
How we collect, use, and protect your data.
Last updated August 16, 2026
This Privacy Policy explains how Centis, operating Dealpilot, handles personal information. Centis is a sole proprietorship registered in the Republic of Korea under business registration number 812-63-00790.
1. Our role
We act as the controller of account, billing, website, and support information. For CRM, contact, and email data that a customer connects to Dealpilot, the customer generally determines the purpose of the processing and Dealpilot processes the data on its instructions.
2. Information we process
- Account details such as name, email address, login method, and password hash.
- Workspace, team member, invitation, and subscription information.
- Connected CRM data, including companies, contacts, deals, tasks, and activities.
- Email data used by a cadence, including sender and recipient details, subject, body, thread history, and attachment metadata.
- Integration credentials and tokens, stored in encrypted form.
- Security and usage information such as IP address, device information, session records, and audit logs.
- Email delivery and engagement events, including opens, clicked links, time, IP address, and user agent.
- Billing identifiers and subscription status received from Polar. We do not store full payment card details.
3. How we use information
We use information to provide and secure Dealpilot, connect requested integrations, run cadences, send and log messages, process billing, provide support, troubleshoot errors, prevent abuse, and comply with legal obligations. We do not sell personal information or use customer contact data for advertising.
4. Email tracking
HTML cadence emails may contain an open pixel and tracked links. These features record delivery and engagement events so workspace users can understand whether a follow-up was opened or clicked. Customers are responsible for using these features lawfully and informing recipients where required.
5. Service providers and international processing
We use service providers only where needed to operate Dealpilot. The main application and database are hosted by Contabo at its Hub Europe data center in Lauterbourg, France, and routine backups of that data are stored off-site with Backblaze. Other providers may process limited information in the United States or globally.
| Provider | Purpose | Primary location |
|---|---|---|
| Contabo | Application and database hosting | France |
| Backblaze | Off-site backup storage | United States |
| Cloudflare | Network security and delivery | Global |
| Vercel | Marketing site hosting | United States / global |
| Sentry | Error monitoring | United States |
| Resend | Service email delivery | United States |
| Polar | Billing and merchant of record | United States |
| Google and Microsoft | Customer-directed account and email connections | Global |
6. Google user data
Dealpilot uses two separate Google connections. Signing in with Google uses the openid, email, and profile scopes to identify your account. Connecting a Gmail mailbox uses the gmail.modify scope, which allows Dealpilot to read the threads a cadence follows and to send follow-up messages from your address, together with the userinfo.email scope to confirm which mailbox was connected. Connecting Outlook uses the equivalent Microsoft Graph scopes Mail.ReadWrite, Mail.Send, and User.Read.
Dealpilot’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice this means:
- We use Google user data only to provide and improve the follow-up features that are visible in the Dealpilot interface.
- We do not transfer Google user data to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data unless you give specific consent, it is necessary for security or to comply with law, or the data is aggregated and anonymized for internal operations.
7. Retention and deletion
We retain information while an account is active and for as long as reasonably needed to provide the service, meet legal obligations, and resolve disputes. Disconnecting an integration does not automatically delete previously synchronized records. You may request deletion by contacting us.
Outbound attachments are handled in two stages. Files you upload while composing are removed when the message is sent, and unsent uploads are removed within about 24 hours. A copy of a sent message’s attachments is kept until we confirm the message appears in your provider’s sent folder, and for no longer than three months. Related metadata and message history may remain after the files are gone.
You can also delete your account yourself from account settings. This erases the account and every workspace you own, immediately and permanently. Where you were only a member of a workspace, your membership and personal data are removed while the workspace itself stays with its owner; records that name you in another person’s workspace, such as an email that was already sent, remain part of that workspace’s history. Security audit logs are retained.
Deletion applies to our live systems. Routine backups may still contain the data for a limited period and are removed as those backups age out of their normal retention cycle.
8. Security
We use measures designed to protect information, including encrypted transport, password hashing, encrypted integration credentials, access controls, and security logging. No system is completely secure, and we cannot guarantee absolute security.
9. Cookies
The application uses an essential session cookie to keep users signed in and protect account access. We do not currently use advertising cookies on the marketing site.
10. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, or a copy of your personal information. We may need to verify your identity and may retain information where required by law. Workspace data requests should normally be made through the organization that controls the workspace.
11. Children
Dealpilot is a business service and is not intended for children under 18. We do not knowingly collect personal information from children.
12. Contact and changes
The privacy officer is Dongyun Lee. Privacy questions and rights requests may be sent to support@dealpilot.dev. We may update this policy and will show the latest revision date above.