How SalesTablet collects, uses and protects personal information.
Last updated 23 September 2026
This Privacy Policy describes how SalesTablet ("we", "us") collects, uses, discloses and protects personal information in connection with the SalesTablet customer relationship management service (the "Service"). It applies to all users of the Service and to visitors to salestablet.com.
For any question about this policy, or to exercise any right described in it, contact hello@salestablet.com.
Account information. Your email address, and a password if you create one. Authentication is provided by Supabase. We do not receive or store your Google account password.
Customer relationship data. Information you enter into or import into the Service, including company names, contact names, email addresses, telephone numbers, notes, tasks, pipeline stages and deal values.
Messages you compose in the Service. Where you write an email within SalesTablet and send it, we retain the subject and body of that message and attach it to the relevant record, so the history of the conversation remains available to you. We hold that content because you entered it here. It is not retrieved from your mailbox.
Booking information. Where you publish a booking page, the name, email address, company, telephone number and any message submitted by a visitor who books an appointment with you.
Telephony metadata. Where you provision a telephone number through the Service, the numbers dialled, the date and time of each call, and its duration. We do not record call audio, and no call recording functionality is enabled in the Service.
Email correspondence you forward to us. The Service can issue you a private email address. Where you choose to blind-copy that address on a message, or configure your mail provider to forward messages to it, we receive and store that message, including its subject, body and the addresses of the correspondents, and associate it with the relevant record in your account.
This is an optional feature that operates entirely by your own action. Messages reach us only because you send them to us. It does not involve access to your mailbox and uses no permission granted through your email provider. Correspondence captured this way may include messages written by third parties who have written to you; the section below on data you hold about others applies to it.
Technical information. Standard server request logs retained by our hosting provider. We do not operate advertising trackers, behavioural analytics or profiling on the Service.
Connecting a Google account is optional. The Service is fully functional without it.
Where you choose to connect a Google account, SalesTablet requests a single
OAuth scope: https://www.googleapis.com/auth/gmail.send. This scope
permits the Service to send an email message that you have composed and
expressly directed the Service to send.
SalesTablet does not request any scope permitting access to the contents of a Gmail mailbox. We do not read, search, index, store or analyse the messages in your mailbox through any Google API, and we are technically unable to do so, as we do not hold the authorisation required. Access tokens issued by Google are held in volatile memory for the duration of a session and are not written to persistent storage.
For the avoidance of doubt, this is distinct from the optional forwarding feature described above, under which you may choose to send particular messages to an address we provide. Messages received that way are delivered to us by you and are not obtained from Google.
You may revoke this authorisation at any time from within the Service, or directly through your Google account at myaccount.google.com/permissions.
We process personal information for the following purposes only:
We do not use personal information held in the Service to train machine learning models, to construct advertising profiles, or for any purpose unrelated to providing the Service. We do not sell personal information.
We engage the following service providers, each of which processes personal information on our behalf and under contract:
Certain of these providers process and store information outside Canada, including in the United States, where it may be subject to the laws of those jurisdictions and accessible to their authorities under applicable law. Where data residency is a requirement for your organisation, contact us before subscribing.
A substantial proportion of the personal information within the Service relates to your own contacts rather than to you. In respect of that information you determine the purposes and means of processing, and SalesTablet acts as a service provider processing it on your instructions.
Accordingly, you are responsible for ensuring you have a lawful basis for collecting and retaining that information, and for complying with the laws applicable to you and to the individuals concerned, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL) where applicable.
We retain personal information for as long as your account remains open. Following deletion of an account, associated data is removed from production systems within 30 days, and from routine backups shortly thereafter. Records we are required by law to retain, such as financial records, are kept for the period prescribed by the applicable law and no longer.
Subject to applicable law, you may request:
Requests should be sent to hello@salestablet.com. We will respond within 30 days. If you are in Canada and are not satisfied with our response, you may make a complaint to the Office of the Privacy Commissioner of Canada.
Personal information is encrypted in transit and at rest. Access to customer records is segregated at the database level through row-level security policies, such that one account cannot access the records of another. Credentials granting privileged database access are held only in server-side environment configuration and are not exposed to client applications.
No method of transmission or storage is entirely secure. In the event of a breach of security safeguards creating a real risk of significant harm, we will notify affected users and the appropriate regulatory authority as required by applicable law.
The Service is intended for business use by persons aged 16 or over. We do not knowingly collect personal information from children.
We may update this policy from time to time. The date of the most recent revision appears at the top of this page. Where a change materially affects the processing of your personal information, we will provide notice by email in advance of the change taking effect.