Privacy Policy
Last updated: March 3, 2026
1. Information We Collect
We collect information you provide directly to us, including:
- Name, email address, and billing information
- Company information and size
- Account credentials (securely hashed)
- Usage data and interactions with our service
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send billing information
- Send technical notices and support messages
- Respond to comments and questions
- Monitor and analyze usage patterns
3. Google User Data
When you connect your Google account to Rally CRM, we access certain Google user data through Google's OAuth 2.0 authorization flow. This section describes how we handle that data in compliance with Google's API Services User Data Policy.
Data We Access
Depending on the integrations you enable, Rally CRM may request access to:
- Google Calendar events — to create, read, update, and delete calendar events when you schedule meetings or activities in the CRM, and to sync events between Google Calendar and Rally CRM.
- Gmail messages — to read, send, and organize emails within Rally CRM's inbox, enabling two-way email sync with your Gmail account.
- Email address — to identify which Google account is connected and display it in your integration settings.
How We Use Google User Data
Google user data is used solely to provide the CRM features you have enabled:
- Calendar data is used to synchronize meetings and activities between Rally CRM and your Google Calendar.
- Email data is used to display and manage your email conversations within Rally CRM's unified inbox.
- We do not use Google user data for advertising, marketing to third parties, or any purpose unrelated to providing Rally CRM's functionality.
- We do not use Google user data to train artificial intelligence or machine learning models.
Sharing and Disclosure of Google User Data
We do not sell, rent, or share your Google user data with any third parties. Google user data is only accessible to:
- You — the authenticated user who authorized the connection.
- Your tenant members — other users within your Rally CRM workspace may see shared calendar events or email threads, consistent with your CRM's team collaboration features.
- Infrastructure providers — our hosting and database providers process data on our behalf under strict data processing agreements. They do not have independent access to your Google user data.
We may disclose Google user data if required by law, regulation, or valid legal process.
Retention and Deletion of Google User Data
We retain Google user data only for as long as necessary to provide the services you have enabled:
- OAuth tokens — stored encrypted for as long as your Google integration remains connected. When you disconnect your Google account via the Calendar or Email Sync settings, tokens are deleted immediately.
- Synced calendar events — stored as activities in your CRM for as long as your account is active. Deleted when you delete the activity, disconnect the integration, or delete your account.
- Synced emails — stored in your CRM inbox for as long as your account is active. Deleted when you disconnect the email integration or delete your account.
- Account deletion — when you delete your Rally CRM account, all Google user data including OAuth tokens, synced events, and synced emails is permanently deleted within 30 days.
You can revoke Rally CRM's access to your Google data at any time by disconnecting the integration in Rally CRM settings or by removing access in your Google Account permissions.
4. Data Security
We implement appropriate technical and organizational security measures to protect your data:
- Encryption in transit (TLS) and at rest for sensitive tokens and credentials
- Security testing and code review practices
- Access controls and authentication
- Daily encrypted backups
5. Your Rights
You have the right to:
- Access and receive a copy of your data
- Rectify inaccurate data
- Request deletion of your data
- Object to processing of your data
- Data portability
6. GDPR Compliance
We comply with the EU General Data Protection Regulation (GDPR). If you're located in the EU, you have additional rights regarding your personal data.
7. Contact Us
If you have questions about this Privacy Policy, please contact us at:privacy@rallycrm.io