Last Updated: January 28, 2026
Baseplate ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our business management platform and related services (collectively, the "Services").
1. Information We Collect
1.1 Information You Provide
We collect information that you provide directly to us, including:
- Account information (name, email address, company details)
- Profile information (job title, phone number)
- CRM data (contacts, companies, deals, pipeline stages, email campaigns)
- Delivery data (clients, projects, invoices, time entries, expenses)
- Financial data (payment information, bank account details for receiving payments)
- Communications with us (support requests, inquiries)
- Payment information (processed securely by third-party payment processors)
1.2 Information Collected Automatically
When you use our Services, we automatically collect certain information, including:
- Usage data (features accessed, time spent, interactions)
- Device information (IP address, browser type, operating system)
- Log data (access times, pages viewed, errors encountered)
- Cookies and similar tracking technologies
1.3 Gmail & Google Calendar Integration Data
When you connect your Gmail and/or Google Calendar accounts, we collect:
- Email metadata (sender, recipient, subject, date)
- Email content (for matching to contacts and activity tracking)
- Calendar event data (event titles, dates, times, attendees)
- OAuth tokens (securely stored for authorized access)
We only access emails and calendar data to provide CRM features such as contact matching, activity tracking, and linking meetings to deals. We do not use this data for advertising or share it with third parties.
1.4 Bank Account Data (Plaid Integration)
When you connect your bank accounts through our integration with Plaid Inc., we collect:
- Account information (account name, type, and masked account numbers)
- Account balances (current and available balances)
- Transaction data (transaction amounts, dates, merchant names, categories)
- Institution information (bank name and identifiers)
We use this data solely to provide expense tracking, transaction categorization, invoice matching, and financial reporting features. We do not sell your financial data or use it for advertising purposes.
By connecting your bank account, you also agree to Plaid's End User Privacy Policy. Plaid's services are governed by their privacy policy and terms of service.
2. How We Use Your Information
We use the collected information for the following purposes:
- Providing, maintaining, and improving our Services
- Managing CRM data (contacts, companies, deals, pipelines)
- Syncing and tracking email communications via Gmail integration
- Syncing calendar events via Google Calendar integration
- Sending email campaigns and tracking engagement
- Creating and managing invoices
- Importing and categorizing bank transactions via Plaid
- Matching payments to invoices and tracking cash flow
- Generating financial reports and business insights
- Tracking time entries and project expenses
- Communicating with you about your account and our Services
- Sending administrative information and updates
- Detecting and preventing fraud and security incidents
- Complying with legal obligations
3. Data Storage and Security
Your data is stored securely on Amazon Web Services (AWS) infrastructure with the following protections:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication options
- Regular security assessments and audits
- Role-based access controls
- Automated backups with point-in-time recovery
- Incident response procedures
4. Information Sharing and Disclosure
We may share your information in the following circumstances:
- Within Your Organization: With authorized team members in your organization based on role-based access controls
- Service Providers: With third-party vendors who assist in providing our Services (hosting, analytics, payment processing)
- Legal Requirements: When required by law, subpoena, or legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- Consent: When you have given us explicit consent to share your information
We do not sell your personal information or business data to third parties.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide our Services. When you delete your account, we will delete or anonymize your data within 30 days, except where retention is required for legal or legitimate business purposes (such as tax records or financial audit trails).
6. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
- Access: Request access to your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your information
- Export: Export your business data in standard formats (CSV, PDF)
- Opt-Out: Opt out of marketing communications
- Revoke Access: Disconnect Gmail, Google Calendar, or bank account integrations at any time
To exercise these rights, please contact us at privacy@baseplate.us or through your account settings.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to improve your experience, maintain your session, and analyze usage patterns. You can control cookies through your browser settings, though disabling cookies may affect functionality.
8. Third-Party Services
Our Services integrate with third-party services including:
- Google (Gmail & Calendar): For email sync, activity tracking, and calendar integration. Subject to Google's Privacy Policy.
- Plaid Inc.: For bank account connections and transaction data. Subject to Plaid's End User Privacy Policy. When you connect a bank account, Plaid collects and transmits your financial data to us. You can revoke Plaid's access through your bank's website or by contacting Plaid directly.
Your use of these integrations is subject to the privacy policies of those third parties. You can disconnect any integration at any time through your account settings.
9. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will promptly delete it.
10. International Data Transfers
Your information may be transferred to and processed in the United States. We ensure appropriate safeguards are in place for such transfers in compliance with applicable laws, including GDPR where applicable.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of our Services after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: privacy@baseplate.us