Privacy Policy

Last Updated: February 23, 2026

At Contndr, we take your privacy seriously. This policy outlines how we collect, use, store, and protect your information — including data accessed through third-party services like Google.

1. Information Collection

We collect account information (email, name) and usage data to improve our services. We also process lead data you upload securely. When you connect third-party accounts (such as Google, Outlook, or SMTP providers), we collect authentication tokens and limited profile information necessary to operate the platform on your behalf.

2. How We Use Your Data

Your data is used to:

  • Provide and improve the Contndr platform

  • Send outbound emails on your behalf via connected email providers

  • Track email delivery status and replies

  • Power CRM, outbound automation, and engagement features

  • Process payments and billing

  • Send critical service updates

  • Enrich leads at your specific request

We do not use your data for advertising purposes.

3. Google User Data (Gmail API) Disclosure

If you connect your Google account, Contndr requests access to Google user data via Google APIs to provide core email and inbox-sync functionality.

Scopes we request

https://www.googleapis.com/auth/gmail.send — to send emails from your Gmail account inside Contndr

https://www.googleapis.com/auth/gmail.readonly — to sync your inbox (messages/threads) for reply detection, conversation history, and CRM logging

https://www.googleapis.com/auth/userinfo.email— to identify the connected Google account

https://www.googleapis.com/auth/userinfo.profile — to display the connected Google account name and avatar

How we use Gmail data

We use Gmail data only to:

  • Send outbound emails you initiate through the Contndr platform

  • Sync inbox threads to detect replies and associate conversations with leads

  • Display email history inside the CRM (if enabled)

We do not use Google data for advertising, profiling, or any purpose unrelated to providing the Contndr service.

What we store

Depending on your settings, we may store limited email data such as:

  • Message and thread identifiers, timestamps, sender/recipient addresses, subject lines, and snippets

  • Email content required to display conversation history inside Contndr (if the inbox-sync feature is enabled)

OAuth access tokens are stored encrypted at rest using industry-standard encryption. Access to tokens and credentials is restricted and logged.

Data sharing & disclosure

We do not sell Google user data. We only share data with service providers needed to operate Contndr:

  • Cloud hosting & database/infrastructure providers — secure compute, storage, and database hosting (Supabase)

  • Email infrastructure providers — delivery and tracking

  • Logging & monitoring providers — error tracking and operational health

  • Payment processing — Stripe for billing and subscriptions

These vendors are contractually required to protect data and use it only to provide services to Contndr.

Data retention and deletion

We retain Google user data only as long as necessary to provide the service, comply with legal obligations, or until you delete your account and/or request deletion.

You can request deletion at any time by contacting privacy@contndr.com. Upon account deletion, we will remove your Google user data within 30 days, except where retention is required by legal obligation.

User control and revocation

You can revoke Contndr's access to your Google account at any time by visiting:

https://myaccount.google.com/permissions

Revoking access will disconnect your Gmail integration from Contndr. You may also disconnect your account from within the Contndr settings page at any time.

Limited Use & AI/ML training compliance

Contndr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data to train generalized AI or machine learning models.

Google data is never used to:

Train AI or machine learning models

  • Sell, lease, or trade data to third parties

  • Build advertising or user-profiling systems

  • Any purpose not explicitly disclosed in this policy

4. Data Security

We use industry-standard encryption (AES-256) for data at rest and TLS for data in transit. Our servers are hosted in secure SOC2-compliant data centers. Access to production systems is restricted, logged, and audited.

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy or as required by law. You may request deletion of your data at any time. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by legal obligation.

6. User Rights

You have the right to:

  • Access your personal data we hold

  • Correct inaccurate or incomplete data

  • Delete your personal data

  • Revoke access to connected third-party services (Google, Outlook, etc.)

  • Export your data in a portable format

  • Manage communication preferences in your account settings

7. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised “Last Updated” date. Your continued use of Contndr after changes are posted constitutes acceptance of the updated policy.

8. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us at privacy@contndr.com.