Legal
Privacy Policy
Last updated: August 2026
1. Information We Collect
We collect information you provide directly (name, email, company name) when you create an account. When you connect HubSpot, Quarterdeck receives read-only access to a limited set of CRM data required to build your weekly pipeline brief:
- Deals — deal name, amount, stage, pipeline, close date, created date, probability, owner reference, and related deal properties.
- Deal owners — owner names and email addresses, used to display who is accountable for each deal and to flag unowned deals.
- Notes associated with deals — we read the creation timestamp of notes to measure genuine rep activity. We do not use note content for any other purpose. The current integration uses the read-only contacts scope when reading these deal-associated note timestamps; it does not call HubSpot contact-record endpoints or store contact records.
Quarterdeck does not request or access HubSpot companies, marketing data, or any sensitive-data scopes, and never reads contact records for their own sake. Data flows in one direction only: HubSpot → Quarterdeck.
If you configure Slack delivery, Quarterdeck stores the incoming-webhook URL you provide and uses it to send weekly briefing content to that Slack workspace.
2. How We Use Your Data
We use your CRM data solely to provide the Quarterdeck service: detecting material pipeline changes, ranking deals that deserve review, explaining the supporting evidence, and generating weekly briefs or Trust Brief narratives from already-computed facts. We do not sell or rent your data, and we do not use it for advertising. We disclose data to the service providers and customer-configured integrations described below to operate Quarterdeck.
If you create a public report link, anyone who has that bearer link can view the report narrative, metrics, and supporting Trust Brief without signing in. The link does not expire automatically; it remains active until you revoke it or the report is deleted, including through a successful HubSpot disconnect.
3. HubSpot Data
Quarterdeck connects to HubSpot via OAuth 2.0 and requests only read-only scopes (crm.objects.deals.read, crm.objects.owners.read, crm.objects.contacts.read, which the current integration uses for deal-associated note timestamps). We do not write to, modify, or delete any data in your HubSpot account, and we take no autonomous actions in your CRM. You can revoke access at any time from HubSpot's Connected Apps settings. See our Shared Data page for a full breakdown of each scope.
4. Data Storage and Security
Your data is stored in Supabase (PostgreSQL). Quarterdeck's database schema uses row-level security policies to scope workspace-accessible records by tenant membership. HubSpot OAuth tokens are encrypted at the application layer before storage. See our Security page for more detail.
5. Data Retention and Deletion
When Quarterdeck confirms a successful disconnect, it has deleted the stored HubSpot connection and the CRM-derived deals, reports, risk and snapshot data, change and attention history, and watchlist records for that workspace. If a deletion step fails, Quarterdeck reports an error instead of confirming success. To revoke the OAuth grant at HubSpot, also disconnect Quarterdeck from HubSpot Connected Apps. HubSpot disconnect does not delete account, tenant, authentication, subscription, billing, activation, or feedback records. To request deletion of your personal data, email hello@kpappworx.com.
6. Subprocessors and Integrations
We use the following service providers and customer-configured integrations for the functions listed below:
- Supabase — database, authentication, and storage.
- Vercel — application hosting and analytics.
- LemonSqueezy — subscription billing and payment processing.
- Resend — transactional email delivery. When email delivery is configured, messages can contain recipient addresses and weekly pipeline briefing or access-request content.
- Slack (optional integration) — weekly briefing delivery through a webhook configured by the customer. The destination Slack workspace receives briefing content that can include company name, pipeline metrics, deal names, amounts, owners, stages, risk explanations, and generated board questions.
- Anthropic (Claude) — generates the written narrative section of your weekly brief and Trust Brief. Narrative requests contain structured findings that Quarterdeck has already calculated. They can include company name, reporting period, aggregate metrics, deterministic scores, evidence labels, and, where relevant, specific at-risk deal names, HubSpot deal IDs, amounts, and risk reasons. Quarterdeck does not send contact records or note bodies in these narrative requests.
We do not use OpenAI. The implemented narrative provider is Anthropic. Report narratives are produced only after deterministic scoring is complete. The model generates narrative from the disclosed inputs and is not given tools to modify your CRM.
7. Your Rights
You may request access to, correction of, export of, or deletion of your personal data, subject to applicable legal and operational requirements. To make a request, email us at hello@kpappworx.com.
8. Contact
Privacy questions or concerns? Contact KPAppWorx Technologies Pvt Ltd at hello@kpappworx.com.