Skip to main content

Legal

Privacy Policy

This Privacy Policy explains what personal information Repzo Workstation collects, how we use it, and what rights you have over it.

Last updated:

1. Introduction

Repzo Workstation ("Repzo", "we", "us") is a multi-tenant business platform that helps teams manage customer relationships, support, projects, and internal operations.

This policy applies to data we collect through workstation.repzo.com, the Repzo desktop applications, and any related services. By using Repzo, you agree to the practices described here.

2. Information we collect

Account information: name, email, role, password (hashed), and company affiliation.

Workspace data: the records you create inside Repzo — leads, deals, contacts, tickets, projects, messages, attachments, and the metadata around them.

Usage information: pages visited, features used, approximate location derived from IP address, browser type, device fingerprint, and timestamps. We use this for product analytics and security.

Communications: support emails, in-app messages, and any other content you send to us directly.

Payment information: handled by our payment processor (Stripe). We never store full card numbers.

3. How we use information

To provide and operate the service — authenticate users, sync data across modules, deliver notifications, and process payments.

To improve the product — usage analytics, debugging, A/B testing of new features.

To communicate with you — service notices, security alerts, and (with your consent) product updates and offers.

To detect and prevent abuse — rate limiting, fraud detection, audit logging.

4. Google services and Google Ads data

Google Ads is Repzo's primary Google integration. When a workspace administrator connects Google Ads, Repzo uses the Google Ads API authorization scope to access the Google Ads customer and manager accounts that the administrator is permitted to manage. The data we access may include account identifiers, account names, currency and status; campaigns, ad groups, ads, budgets, dates, destinations, and tracking URL templates; lead-form assets and lead-form submissions, including information a lead submitted such as name, email address, phone number, company, job title, and form responses; and advertising performance data such as impressions, clicks, cost, click-through rate, conversions, and engagements.

We use Google Ads data only to provide the advertising-management features requested by the workspace: letting an administrator select connected ad accounts; synchronizing and displaying account, campaign, ad, lead, and performance information in Repzo; importing selected Google Ads lead-form submissions into the CRM; measuring and attributing campaign results; and, only when an administrator enables automatic tracking, reading and updating campaign tracking URL templates. Repzo does not make other changes to a Google Ads account unless an authorized user requests or enables the corresponding feature.

For other optional Google integrations, the data accessed depends on the service you choose to connect. It may include your Google account name, email address, and profile information; Gmail messages and message metadata such as senders, recipients, subjects, timestamps, labels, threads, and attachments; Google Contacts data used to find recipients; and Google Calendar calendars, events, attendees, and related event details. We use this data to connect your account, synchronize relevant email and calendar activity with your workspace, display communications and events, find recipients, send email, and create, update, or delete calendar events at your direction.

We use Google user data only to provide or improve the user-facing features described above. We do not use it to serve targeted, personalized, interest-based, or retargeted ads on behalf of Repzo or unrelated third parties; determine credit-worthiness; make lending decisions; or sell it to data brokers or information resellers. We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.

We do not sell Google user data. We do not transfer or disclose Google user data to third parties except to service providers acting on our behalf where necessary to operate or secure the features you request, when you direct or consent to the transfer, or when disclosure is required by law. Those providers are subject to contractual confidentiality and data-protection obligations.

We store Google authorization credentials, selected Google Ads account configuration, account identifiers, synchronization metadata, and Google data imported into your workspace only as needed to provide the connected features and in accordance with the retention periods in this policy. Disconnecting a Google Ads account or other Google service stops future access and removes its stored OAuth access and refresh tokens. Google data already imported into workspace records remains subject to your workspace controls and can be deleted through the service or by contacting [email protected]. You can also revoke Repzo's access from your Google Account permissions page.

5. How we protect data

Security procedures are in place to protect the confidentiality, integrity, and availability of personal information, including sensitive Google user data, against unauthorized or unlawful access, use, alteration, disclosure, loss, or destruction.

We use encryption to protect Google user data and other personal information: data is encrypted in transit using HTTPS/TLS and encrypted at rest in the systems where we store it. Google OAuth tokens and application credentials are treated as secrets, restricted to authorized server-side processes, never displayed in full through the user interface, and removed from our active connection records when the connection is disconnected.

We also use authentication, role-based and least-privilege access controls, logical isolation between customer workspaces, restricted production access, audit logging, security monitoring, backups, vulnerability management, and incident-response procedures. Employees and service providers may access personal information only when needed to perform authorized duties and are subject to confidentiality obligations.

No method of transmission or storage is completely secure. We regularly review our safeguards and update them in light of changes to our services, risks, and applicable requirements.

6. Sharing with third parties

We share data only with sub-processors that we engage to operate the service: cloud hosting (AWS, Cloudflare), payment processing (Stripe), error monitoring (Sentry), and analytics. A current list of sub-processors is available on request.

We do not sell personal data. We do not share data with advertisers. We disclose data to law enforcement only when legally required and, where permitted, after notifying the affected customer.

7. Data retention

Active workspace data is retained for as long as your account is active. When you delete a record, it enters a soft-deleted state for 30 days before permanent purge.

When you delete your account, we delete personal data within 90 days, except where retention is required by law (e.g. tax records) or to defend legal claims.

Audit logs and security records are retained for 12 months.

8. Your rights

Under GDPR, CCPA, and similar regulations you have the right to access, correct, export, and delete your personal data, and to object to or restrict its processing.

You can exercise most rights directly in the app: account settings let you export your data, change information, or delete your account. For other requests, email [email protected] — we respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority.

9. Cookies and tracking

We use essential cookies for authentication and session management. We use a minimal set of analytics cookies to understand how the product is used.

We do not use third-party advertising cookies, and we honor Do Not Track signals.

10. International transfers

Repzo is operated from servers in the United States. By using the service, you consent to your data being transferred to and processed in the United States.

For EU/UK customers, we rely on Standard Contractual Clauses for international transfers and apply technical safeguards (encryption in transit and at rest) to data crossing borders.

11. Children's privacy

Repzo is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced via email and an in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the current version.

13. Contact us

For privacy questions or to exercise your rights, email [email protected].

Repzo Workstation, 8 The Green, Suite R, Dover, DE 19901, United States.