Privacy Policy

Last updated: August 11, 2026 • Effective ahead of Fall 2026 Public Launch

1. Overview & Principles

At scratchly ("Scratchly", "we", "us", or "our"), privacy is not an afterthought; it is built into the architecture of our CRM. We believe that your pipeline, contact histories, and deal intelligence belong solely to your organization.

Key Guarantee: Scratchly does not sell customer data, monetize contact records, or train foundational AI models on your private deal threads.

2. Information We Collect

We collect information in three specific contexts:

  • Account & Waitlist Information: Your full name, work email address, team size, role, and custom survey feedback provided during registration or early pass generation.
  • Workspace & Customer Data: Contact records, sales opportunities, deal values, company tags, and communication summaries you create or import.
  • Technical & Telemetry Data: Browser type, operating system, IP address, and platform usage metrics collected strictly to optimize application performance.

3. Protection of CRM Data

All data stored in Scratchly is protected using enterprise-grade security protocols:

Encryption In Transit

TLS 1.3 encryption across all client-to-server and API communication channels.

Encryption At Rest

AES-256 bit encryption on all underlying database volumes and backup snapshots.

4. AI Copilot & Model Isolation

When you interact with the Scratchly Deal Copilot or automated timeline summarization tools, inference is conducted through isolated enterprise endpoints. Your deal memos and executive communications are never stored in third-party public training corpora.

5. Data Sharing & Third-Party Processors

We only share data with essential cloud infrastructure providers (such as Google Cloud / Firebase and AWS) under strict Data Processing Agreements (DPAs) that comply with ISO 27001 and SOC2 standards.

6. Your Rights (GDPR & CCPA)

Regardless of your geographical location, Scratchly grants all users the following fundamental privacy rights:

  • Right to Access & Portability: Export all workspace records in standard CSV or JSON format at any time.
  • Right to Rectification: Edit or update any contact or personal details directly from your settings.
  • Right to Erasure ("Right to be Forgotten"): Request complete, permanent deletion of your account and all associated pipeline data within 30 days.

7. Retention & Deletion

We retain account data only as long as your workspace remains active. When an account is terminated, all primary database records and automated backups are permanently purged within 30 days.

8. Contact Our Data Privacy Officer

For questions regarding this policy or to exercise your GDPR/CCPA rights, contact us at:

privacy.scratchly@gmail.com