Privacy Policy
1. Who we are
Opspanel ("we", "us", "our") provides a CRM platform built for AI agents. This Privacy Policy describes how we collect, use, and share information when you visit opspanel.ai, sign up for the private beta, or use the Opspanel console and APIs.
If you have questions about this policy or how we handle your data, contact us at privacy@opspanel.ai.
2. What we collect
Information you give us
- Account data — name, email, organisation, and authentication identifiers when you sign in via Google or another supported identity provider.
- Workspace data — the records you load into Opspanel (contacts, companies, deals, tasks, messages, calls, agents, workflows, and the events they emit).
- Communications — emails, support tickets, and waitlist submissions you send us.
- Billing data — when paid plans launch, billing identifiers and invoice metadata returned by our payment processor. We do not see or store full card numbers.
Information collected automatically
- Usage data — pages and procedures called, request timing, errors, and the workspace they belong to. Used to operate the service and improve performance.
- Device & network data — IP address, user agent, language, and approximate location derived from IP. Used for security, fraud prevention, and routing.
- Cookies & similar technologies — strictly-necessary cookies for sign-in and CSRF protection, plus optional analytics cookies you can decline.
Information from third parties
When you connect a third-party tool through MCP, OAuth, or our integration catalog (for example: Google Workspace, Slack, Twilio, Apollo, Stripe), we receive only the data you authorise that integration to share. Each integration is scoped, revocable, and logged.
3. How we use your data
- Provide the service — store and process records, run agents, dispatch messages and calls, and surface activity in your workspace.
- Operate & secure the platform — rate-limit abuse, detect compromised credentials, run audit trails, and respond to security events.
- Customer support — answer your questions and reproduce issues you report.
- Improve the product — debug performance, understand which features are used, and prioritise the roadmap. We use aggregated, de-identified usage data wherever possible.
- Comply with the law — respond to lawful requests, enforce our Terms, and prevent harm.
We do not sell your data, and we do not use customer workspace contents to train foundation models.
4. AI agents and model providers
Opspanel passes the prompts, tool calls, and context you authorise to the model providers you configure (e.g. Anthropic, OpenAI). Those providers process the data under their own terms, which you accept when enabling them. We do not retain prompts on Opspanel for training, and we redact known sensitive fields (auth tokens, API keys, payment data) from telemetry before it leaves your workspace.
5. Sharing
We share information only with:
- Sub-processors who run our infrastructure (cloud hosting, transactional email, error tracking, payments) under contract obligations to protect your data.
- Workspace members you grant access to, in line with the role and scope you set.
- Authorities when required by law, to defend our rights, or to prevent imminent harm.
- An acquirer in the event of a merger, acquisition, or asset sale, with notice to you and continued protection of your data.
6. International transfers
Our infrastructure runs in the United States and the European Union. When we transfer data out of your home region, we rely on Standard Contractual Clauses or equivalent safeguards.
7. Security
We encrypt data in transit (TLS 1.2+) and at rest, isolate workspaces at the database layer with row-level security, sign every JWT, and append-only-log every action to an audit ledger. We are pursuing SOC 2 Type II — see the latest status in the console.
8. Retention
We retain workspace data for as long as your account is active. After termination we delete or anonymise data within 30 days, except where law requires us to keep it longer (for example, financial records).
9. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. Email privacy@opspanel.ai and we'll respond within 30 days.
10. Children
Opspanel is not directed to children under 16 and we do not knowingly collect their data.
11. Changes
We will post material changes to this policy on this page and, where required, notify you by email. Continued use of Opspanel after a change means you accept the updated terms.
12. Contact
Privacy questions: privacy@opspanel.ai
General contact: hello@opspanel.ai