Privacy Policy
Last Updated: February 23, 2026
At Contndr, we take your privacy seriously. This policy outlines how we collect, use, store, and protect your information — including data accessed through third-party services like Google.
1. Information Collection
We collect account information (email, name) and usage data to improve our services. We also process lead data you upload securely. When you connect third-party accounts (such as Google, Outlook, or SMTP providers), we collect authentication tokens and limited profile information necessary to operate the platform on your behalf.
2. How We Use Your Data
Your data is used to:
Provide and improve the Contndr platform
Send outbound emails on your behalf via connected email providers
Track email delivery status and replies
Power CRM, outbound automation, and engagement features
Process payments and billing
Send critical service updates
Enrich leads at your specific request
We do not use your data for advertising purposes.
3. Google User Data (Gmail API) Disclosure
If you connect your Google account, Contndr requests access to Google user data via Google APIs to provide core email and inbox-sync functionality.
Scopes we request
https://www.googleapis.com/auth/gmail.send — to send emails from your Gmail account inside Contndr
https://www.googleapis.com/auth/gmail.readonly — to sync your inbox (messages/threads) for reply detection, conversation history, and CRM logging
https://www.googleapis.com/auth/userinfo.email— to identify the connected Google account
https://www.googleapis.com/auth/userinfo.profile — to display the connected Google account name and avatar
How we use Gmail data
We use Gmail data only to:
Send outbound emails you initiate through the Contndr platform
Sync inbox threads to detect replies and associate conversations with leads
Display email history inside the CRM (if enabled)
We do not use Google data for advertising, profiling, or any purpose unrelated to providing the Contndr service.
What we store
Depending on your settings, we may store limited email data such as:
Message and thread identifiers, timestamps, sender/recipient addresses, subject lines, and snippets
Email content required to display conversation history inside Contndr (if the inbox-sync feature is enabled)
OAuth access tokens are stored encrypted at rest using industry-standard encryption. Access to tokens and credentials is restricted and logged.
Data sharing & disclosure
We do not sell Google user data. We only share data with service providers needed to operate Contndr:
Cloud hosting & database/infrastructure providers — secure compute, storage, and database hosting (Supabase)
Email infrastructure providers — delivery and tracking
Logging & monitoring providers — error tracking and operational health
Payment processing — Stripe for billing and subscriptions
These vendors are contractually required to protect data and use it only to provide services to Contndr.
Data retention and deletion
We retain Google user data only as long as necessary to provide the service, comply with legal obligations, or until you delete your account and/or request deletion.
You can request deletion at any time by contacting privacy@contndr.com. Upon account deletion, we will remove your Google user data within 30 days, except where retention is required by legal obligation.
User control and revocation
You can revoke Contndr's access to your Google account at any time by visiting:
https://myaccount.google.com/permissions
Revoking access will disconnect your Gmail integration from Contndr. You may also disconnect your account from within the Contndr settings page at any time.
Limited Use & AI/ML training compliance
Contndr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data to train generalized AI or machine learning models.
Google data is never used to:
Train AI or machine learning models
Sell, lease, or trade data to third parties
Build advertising or user-profiling systems
Any purpose not explicitly disclosed in this policy
4. Data Security
We use industry-standard encryption (AES-256) for data at rest and TLS for data in transit. Our servers are hosted in secure SOC2-compliant data centers. Access to production systems is restricted, logged, and audited.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy or as required by law. You may request deletion of your data at any time. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by legal obligation.
6. User Rights
You have the right to:
Access your personal data we hold
Correct inaccurate or incomplete data
Delete your personal data
Revoke access to connected third-party services (Google, Outlook, etc.)
Export your data in a portable format
Manage communication preferences in your account settings
7. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised “Last Updated” date. Your continued use of Contndr after changes are posted constitutes acceptance of the updated policy.
8. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us at privacy@contndr.com.