Privacy & Data Security

Privacy Policy

Last Updated: May 15, 2026 • CASA Tier-2 Certified Architecture

1. Information We Collect

When you create an account or interact with PitchMint, we collect specific categories of business information necessary to render our services:

  • Account Information: Name, work email address, company name, and workspace credentials provided during registration and onboarding.
  • Prospect Business Data: Professional names, corporate email addresses, job titles, LinkedIn profile URLs, and company domain telemetry uploaded via CSV import or API.
  • Outreach Content: Cold email templates, dynamic sequence variables, AI research prompt settings, and dispatch logs.
  • Payment & Billing Data: Order identifiers and transaction records processed securely through Cashfree Payments. Full credit card and banking credentials are never received or stored on PitchMint servers.

2. How We Use Your Information

We process your data strictly to execute the core operations of PitchMint:

  • Operating automated outreach sequences and scheduling follow-up delays.
  • Synthesizing personalized email drafts based on prospect business telemetry.
  • Tracking campaign deliverability metrics (inbox delivery, bounces, opens, replies).
  • Enforcing account subscription quotas and anti-abuse safeguards.
  • Providing technical customer support and critical platform status alerts.

We never sell your prospect lists, monetize contact directories, or share proprietary customer data with advertisers.

3. Google User Data & Gmail Integration

Google API Services User Data Policy Disclosure

PitchMint's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.1 Requested Google Scopes

When connecting Gmail via OAuth 2.0, PitchMint requests access strictly to:

  • https://www.googleapis.com/auth/gmail.send: Enables the platform to dispatch scheduled outreach emails from your personal or Google Workspace address upon your explicit instruction.
  • https://www.googleapis.com/auth/userinfo.email: Identifies your sender email address to bind credentials to your workspace.

3.2 Scope Safeguards & Inbox Non-Access

PitchMint does NOT request or possess read access to your Gmail inbox (gmail.readonly). We cannot browse, read, scan, index, or harvest your incoming email messages. Reply detection is conducted through engagement link tracking and user manual status triggers.

Google user data is never used to develop, improve, or train generalized AI/ML models. All tokens are encrypted at rest using AES-256-GCM.

4. GDPR & Global Data Protection Rights

Under the EU General Data Protection Regulation (GDPR), UK GDPR, and California Consumer Privacy Act (CCPA), you and your prospects maintain fundamental statutory rights:

  • Right of Access: You may request a machine-readable export of all prospect records and personal data stored in your workspace.
  • Right to Erasure (“Right to be Forgotten”): You may permanently delete your account and all associated prospect records instantly via Settings.
  • Right to Rectification: You may update or correct erroneous prospect details at any time.
  • Right to Object / Unsubscribe: Recipients can unsubscribe with a single click via our automated HMAC verification token.

5. Security & AES-256-GCM Encryption

PitchMint enforces enterprise-grade confidentiality safeguards. All OAuth tokens (Gmail access & refresh tokens) and custom SMTP passwords are encrypted before database insertion using AES-256-GCM with distinct initialization vectors (IV) and authentication tags. Database connections are restricted via Supabase Row-Level Security (RLS), ensuring multi-tenant isolation.

6. Authorized Sub-processors

PitchMint relies on audited enterprise cloud infrastructure providers:

Supabase Inc. / AWSEncrypted PostgreSQL Database & Auth
Cashfree Payments IndiaPCI-DSS Compliant Payment Gateway
Groq Inc.High-Speed Llama-3 AI Inference
Google Cloud PlatformGemini API & OAuth Authentication

7. Data Retention & Account Purge

We retain active prospect and sequence telemetry for the duration of your active subscription. Upon requesting account termination, your user profile, encrypted tokens, and all prospect lists are permanently destroyed across database tables within 30 days.

8. Tracking Pixels & Engagement Telemetry

To provide deliverability analytics, emails may contain a transparent 1x1 pixel image to measure open occurrences and wrapped hyperlinks to detect recipient clicks. Recipients may disable image rendering in their email clients to prevent open tracking.

9. Data Controller & DPO Contact

For any data subject requests, GDPR right-of-access filings, or privacy inquiries, please contact our designated Data Protection Officer:

Data Controller: NovaMint Networks

Attention: Data Protection Officer (DPO)

Official Privacy Inquiries: support@novamintnetworks.in

Alternate Security Contact: privacy@pitchmint.com

Location: Rajasthan, India