Privacy Policy
Last updated: August 18, 2026 Effective: August 18, 2026
Pipeflow ("Pipeflow," "we," "us") provides a customer relationship management application for real estate professionals at pipeflowhub.com (the "Service"). This policy explains what information we collect, how we use it, who we share it with, and the choices available to you.
Pipeflow is operated by Pipeflow LLC, a New York limited liability company, with a place of business at 418 Broadway, Ste N, Albany, NY 12207.
Questions about this policy or your data: support@pipeflowhub.com.
1. Who this policy covers
This policy covers two groups of people:
- Users — real estate professionals who create a Pipeflow account, and the brokerages or teams they belong to.
- Third parties — clients, counterparties, attorneys, and other individuals whose information a User enters into Pipeflow or whose correspondence appears in a mailbox a User connects. These individuals do not have Pipeflow accounts.
If you are a third party and want to know what a User has stored about you, contact that User directly. Pipeflow processes that information on the User's instruction and cannot identify or release it to you without them. You may also contact us at support@pipeflowhub.com and we will route your request.
Your use of the Service is also governed by our Terms of Service.
2. Information we collect
2.1 Information you provide
- Account information — your name, email address, and authentication credentials, handled by our authentication provider.
- Organization information — the brokerage or team you belong to, your role within it, and invitations you send or accept.
- CRM content you enter — deals, contacts, tasks, notes, calendar events, property records, map pins, milestones, closing details including prices and commissions, and any files or text you add.
2.2 Information from a connected mailbox
If you choose to connect a Google or Microsoft mailbox, we access your messages in order to identify referrals, contacts, and deal activity, and to send replies you compose in Pipeflow. Connecting a mailbox is optional. Pipeflow's other features work without it.
What we store from your mailbox:
- Message identifiers, thread identifiers, and mailbox labels
- Sender name and sender email address
- Subject line and a short preview snippet
- The date the message was received
- Whether the message has an attachment
- Which of your contacts, if any, the message was matched to
- Text extracted from PDF attachments where that text contains referral or deal information
What we do not store:
- We do not store full message bodies. When you open a message in Pipeflow, its body is fetched from your mail provider at that moment and is not retained afterward.
- We do not store attachment files. Where a PDF is processed, only the extracted text is saved; the file itself is not.
- We do not store your mail account password. Access is by OAuth token, which you can revoke at any time (see Section 8).
2.3 Information collected automatically
- Technical and log data — IP address, browser and device type, and timestamps of requests, retained for security, abuse prevention, and debugging.
- Local preferences — a small number of display preferences (such as your theme choice) stored in your browser, not on our servers.
We do not use advertising cookies and we do not operate advertising trackers.
2.4 Location data
Where you enter a property address, we send that address to geocoding services to obtain coordinates and, for New York City addresses, public parcel identifiers. We do not collect the physical location of your device.
3. How we use information
We use the information above to:
- Provide, operate, and secure the Service
- Identify referrals, contacts, and deal activity in a connected mailbox and draft records for you to confirm
- Send email you compose within Pipeflow, from your own connected mailbox
- Produce analytics, reminders, and suggestions within your own account or organization
- Respond to support requests
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use your data, including mailbox data, to train machine learning models, and we do not permit our vendors to do so.
4. Google user data — Limited Use
Pipeflow requests the following Google API scopes:
| Scope | Why |
|---|---|
gmail.readonly | To read messages in your mailbox so Pipeflow can identify referrals, contacts, and deal activity, including information contained in PDF attachments. Referral details appear in message text and attachments, and no narrower Gmail scope exposes them. |
gmail.send | To send replies and new messages that you compose inside Pipeflow, from your own account. |
Pipeflow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve user-facing features that are prominent in Pipeflow's interface.
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition, and in each case subject to the Limited Use requirements.
- We do not use Google user data for serving advertising.
- We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and de-identified.
- We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
You can review and revoke Pipeflow's access at any time at myaccount.google.com/permissions.
5. Microsoft user data
Where you connect a Microsoft or Outlook mailbox, Pipeflow requests mail read permissions through the Microsoft Graph API for the same purposes described in Section 4, and handles that data on the same terms: we do not sell it, do not use it for advertising, and do not use it to train machine learning models.
You can review and revoke Pipeflow's access at any time at myapps.microsoft.com.
6. Automated processing and artificial intelligence
Pipeflow uses a third-party large language model provider, Anthropic PBC, to identify referrals and deal information in your mailbox and to power Pipeflow's in-app assistant.
You should understand what this means in practice:
- Message content is transmitted to Anthropic for processing. This includes message text and text extracted from PDF attachments, sent over an encrypted connection.
- It is not used for model training. Under our commercial terms with Anthropic, content submitted through the API is not used to train models.
- It is not retained for our benefit. Anthropic processes the content to return a result; we do not authorize retention beyond what is required to deliver that result and to meet Anthropic's own legal and safety obligations.
- Outputs are suggestions, not conclusions. Pipeflow may draft a deal, note, task, or message. These drafts can be wrong, incomplete, or misattributed. Nothing in the Service is a substitute for your own review, and you remain responsible for what you accept into your records and for anything you send.
If you do not want your mailbox processed this way, do not connect a mailbox. Pipeflow's manually-entered CRM features do not require it.
7. How we share information
We share information only as follows:
Within your organization. Pipeflow is designed for brokerages and teams. Depending on your role and your organization's configuration, colleagues, team leads, and owners may see records you create. Your sent mail is scoped to your own account and is not visible to colleagues.
Service providers (sub-processors). We use the following vendors, each of which processes data only to provide services to us:
| Vendor | Role |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Application hosting and serverless functions |
| Anthropic PBC | Language model processing, as described in Section 6 |
| Google LLC | Mail access, where you connect a Google mailbox |
| Microsoft Corporation | Mail access, where you connect a Microsoft mailbox |
| Geocoding providers | Address lookup (NYC GeoSearch, NYC Geoclient, US Census, OpenStreetMap/Photon) |
Legal and safety. We may disclose information where required by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud or abuse.
Business transfer. If Pipeflow is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this policy and, for Google user data, to the Limited Use requirements.
We do not share your information with data brokers, advertisers, or analytics networks.
8. Your choices and controls
- Disconnect a mailbox. You can disconnect a connected mailbox at any time from within Pipeflow, and revoke access directly with Google or Microsoft using the links in Sections 4 and 5. Disconnecting stops further synchronization.
- Edit or delete records. You can edit or delete deals, contacts, tasks, notes, and other records from within the Service.
- Delete your account. Contact us at support@pipeflowhub.com to request deletion of your account and associated data.
- Access and portability. Contact us to request a copy of the personal information we hold about you.
9. Retention
We retain your account and CRM content for as long as your account is active.
When you disconnect a mailbox, we stop synchronizing new messages. Previously synchronized message metadata and extracted text remain in your CRM unless you delete those records, because they may be attached to deals and contacts you still rely on. You may ask us to delete them.
When you delete your account, we delete your account and associated content within 30 days, except where we are required to retain records to comply with a legal obligation, resolve disputes, or enforce our agreements. Backups are purged on our standard backup cycle.
10. Security
We use industry-standard measures to protect information, including:
- Encryption in transit (TLS) for all connections
- Row-level security in our database, so that records are readable only by the account and organization entitled to them
- Access controls restricting mail credentials to server-side processes, never exposed to browsers or to other users
- Least-privilege OAuth scopes — we request the narrowest permissions that support the features described in this policy
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.
11. International users
Pipeflow is operated from the United States and information is processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
12. Your rights
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect, use, and disclose; to request deletion; to request correction; and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising these rights. To make a request, contact support@pipeflowhub.com.
If you are in the European Economic Area or the United Kingdom, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. Where Pipeflow processes personal data on behalf of a User, that User is the controller and Pipeflow is the processor; direct your request to them, or to us and we will route it. Our lawful bases for processing are performance of a contract, our legitimate interests in operating and securing the Service, and your consent where you connect a mailbox.
Other US states. Residents of states with comprehensive privacy laws may have comparable rights. Contact us and we will honor requests to the extent the applicable law requires.
13. Children
Pipeflow is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy
We may update this policy. If we make a material change, we will update the "Last updated" date above and, where the change materially affects how we handle your data, provide notice within the Service before it takes effect. Material changes affecting Google user data will not be applied retroactively without your consent where consent is required.
15. Contact
Pipeflow LLC 418 Broadway, Ste N, Albany, NY 12207 support@pipeflowhub.com