Privacy Policy

Last updated 19 August 2026

Sellsmith is a sales platform that brings a CRM, email, calendar, meeting recording and pipeline analytics into one workspace. Delivering that means handling personal data, both about you and about the people you sell to. This policy sets out what we collect, why, who we share it with, how long we keep it, and what you can ask us to do about it.

1. Who we are

Sellsmith is operated by Punk Digital B.V.(“Sellsmith”, “we”, “us”), the data controller for the processing described in this policy. For questions about it, or to exercise any of the rights described in section 10, contact hello@sellsmith.io.

Punk Digital B.V.Lutmastraat 192-31074 VA AmsterdamThe NetherlandsChamber of Commerce (KVK): 80356281VAT identification number: NL861644499B01

Where you use Sellsmith to process personal data about your own contacts and customers, you are the data controller for that data and we act as your processor. Where we process data about you as our customer (your account, your billing, your use of the product), we are the controller. Section 5 explains the split.

2. What we collect

Account and workspace data. Your name, email address, job title, profile details and workspace settings. Authentication is handled by Supabase Auth. If you sign in with Google we receive your email address, name and profile picture from Google. We never see or store your Google password.

CRM records you create or import. Contacts, companies, deals, notes, tasks and custom fields. This routinely includes personal data about third parties: names, work email addresses, phone numbers, job titles, LinkedIn URLs and location.

Email content. If you connect a Gmail or Outlook mailbox, we sync message headers, bodies, attachment metadata and send status so that the unified inbox and sequences work. Connection is by OAuth through Nylas; we store the resulting grant, not your mailbox password. If you instead use the forwarding capture address, we receive and parse whatever you forward to it.

Calendar events. Event times, titles, locations, descriptions, organisers and attendee email addresses, used to build the meeting timeline and to decide which meetings to record.

Meeting recordings and transcripts. Where recording is enabled, a notetaker bot joins the call and produces an audio recording and a speaker-separated transcript. We store the audio and the transcript, and we derive structured facts from the transcript such as buyer commitments, deal signals and coaching flags. We do not store video. Section 6 covers recording consent.

Product analytics and diagnostics. Pages viewed, features used, approximate location derived from IP address, device and browser type, and error reports including stack traces. We use these to find faults and to understand which parts of the product are worth improving.

Billing data. Plan, subscription status, invoices and usage counts. Card details are collected and stored by Stripe; they do not reach our servers.

3. Why we process it, and our legal basis

  • To provide the service you signed up for (account data, CRM records, email and calendar sync, recordings). Legal basis: performance of a contract.
  • To keep the service secure and working (error diagnostics, audit logging, abuse prevention). Legal basis: legitimate interests.
  • To improve the product (aggregate product analytics, evaluating the quality of AI output). Legal basis: legitimate interests.
  • To bill you and meet our tax obligations. Legal basis: contract, and compliance with a legal obligation.
  • To send you product and lifecycle email. Legal basis: legitimate interests for service messages, and consent where marketing consent is required. You can opt out of non-essential email at any time.

4. How we use AI, and what is sent where

Sellsmith uses large language models to draft emails, summarise calls, extract deal signals from transcripts and analyse pipeline health. To do that, the relevant content is sent to our AI sub-processors: Anthropic (primary) and OpenAI (model routing and text embeddings). That content can include email bodies, call transcripts, CRM records and documents you upload to the knowledge base.

We use the commercial APIs of these providers. Under those API terms, content we submit is not used to train their models. We do not sell personal data, and we do not use your data or your contacts to train models of our own that would be exposed to other customers.

AI output can be wrong. Anything a model drafts or infers is a suggestion for a person to review, not a statement of fact, and it should not be relied on without checking.

5. Personal data about your contacts

Most of the personal data in a Sellsmith workspace is not about you, it is about the people you sell to. For that data you are the controller and we are your processor: we process it on your documented instructions, which for normal product use means the actions you take in the product.

That makes some things your responsibility rather than ours. You are responsible for having a lawful basis to hold and contact the people you import, for honouring their objections and erasure requests, and for complying with the marketing and anti-spam rules that apply where they are. We give you the tools to delete or export that data on request; we cannot judge whether your basis for holding it is valid.

If a person contacts us directly about data held in a customer workspace, we will refer them to the customer who controls it, and assist that customer in responding.

6. Meeting recording and consent

Recording is off unless it is switched on for your workspace. When it is on, a notetaker bot joins meetings that have at least one attendee from outside your organisation, and it is visible in the participant list for the duration of the call.

Sellsmith includes consent tooling that workspace administrators configure: a pre-meeting notice email, an in-call notice, and a strict mode that can be enabled for named jurisdictions where all-party consent is required. Consent-relevant events are logged against the call.

Recording law varies by country and by state, and in many places recording a call without the consent of everyone on it is unlawful. Configuring that tooling correctly, and obtaining consent where it is required, is the responsibility of the workspace that switches recording on.

7. Sub-processors

We use the following providers to run Sellsmith. Each is bound by a data processing agreement and may process personal data only on our instructions.

Sub-processorWhat it does
SupabasePrimary database, authentication and file storage (EU region)
RailwayBackend application and background workers
VercelWeb application hosting and delivery
NylasEmail and calendar connections, outbound sending, and the meeting notetaker. Nylas uses AssemblyAI to transcribe recordings. Our Nylas application is in the EU region.
AnthropicLarge language model processing (drafting, summarisation, extraction)
OpenAIModel routing, and text embeddings for search over your knowledge base
StripeSubscription billing and payment processing
UpstashRedis cache and background job queue
PostHogProduct analytics
SentryError monitoring and diagnostics
MailgunInbound email capture for the forwarding address (EU region)

We will update this list before adding a new sub-processor that handles personal data.

8. International transfers

Our database, file storage, email and calendar infrastructure and inbound email capture are hosted in the European Union. Some sub-processors, including our AI, analytics, error monitoring and hosting providers, process data in the United States. Where personal data leaves the UK or the EEA we rely on the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable.

9. How long we keep it

DataRetention
Account, CRM records, email and calendar dataFor as long as your workspace is active. Deleted or anonymised on request, or after your account is closed.
Meeting recording audio365 days by default, then automatically purged by a nightly job. Workspace administrators can set a shorter period, or disable purging so that recordings are kept indefinitely.
Meeting transcripts and derived analysisKept with the deal record, and not covered by the audio purge above. Removed when the workspace or contact is erased.
Internal pipeline signal events30 days after processing, then deleted.
Billing recordsRetained for as long as tax and accounting law requires, typically seven years.
Audit logs and aggregate usage countsRetained after erasure, with personal data removed. See section 11.

10. Your rights

If you are in the UK or the EEA you have the right to access your personal data, correct it, have it erased, restrict or object to how we process it, and receive it in a portable format. You can also withdraw consent where consent is the basis we rely on, and complain to your data protection authority. Similar rights apply under California and other state privacy laws, including the right not to be discriminated against for exercising them.

To exercise any of these, email hello@sellsmith.io. We respond within one month. We do not charge a fee unless a request is manifestly unfounded or excessive.

11. What erasure actually does

We are specific about this because our approach is not a simple row delete, and you are entitled to know what survives it.

When we action an erasure request, we anonymise in place. Names, email addresses, phone numbers, avatars, biographies, signatures, locations and custom fields on the workspace, its users and its contacts are overwritten with non-reversible placeholder values. The email address becomes a random token that cannot be resolved back to the original. The record is then stamped as anonymised and marked deleted, and is no longer reachable in the product.

Some derived data cannot be meaningfully redacted in place, because there the personal data is the content. Those records are deleted outright rather than scrubbed: learned writing-style profiles built from your sent mail, AI feedback snapshots, extracted transcript quotes, per-contact engagement telemetry, and the search index built over your sent email.

What we retain after an erasure is a set of aggregate ledgers: cost and usage counters, and the append-only audit log. These hold counts, timestamps and actions, never names or email addresses. We keep them so that billing history and the security audit trail remain intact after a workspace is erased, which is itself a legal obligation. The audit log is never rewritten, including by an erasure.

Backups are retained on a rolling schedule and are overwritten in the normal cycle. Data already anonymised in the live database is not restored from an older backup.

12. Google API Limited Use disclosure

Where you connect a Google account, Sellsmith receives data through Google APIs. Sellsmith's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data obtained through Google APIs is:

  • used only to provide or improve user-facing features that are prominent in the Sellsmith interface;
  • never transferred or sold to third parties for advertising, market research or any other unrelated purpose;
  • never used to serve advertisements;
  • never read by a human, except with your explicit consent for a specific message, where required for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.

Where Google data is passed to our AI sub-processors to power a feature you have asked for, that transfer is limited to providing that feature, and those providers may not use the content to train their models.

You can disconnect a Google account at any time in Settings, and revoke access directly from your Google account permissions page.

13. Cookies and similar technologies

We set a small number of cookies. Authentication cookies keep you signed in and are strictly necessary; the product does not work without them. Our analytics provider sets cookies to recognise a returning browser and measure feature usage. We do not run advertising cookies, and we do not sell the data these cookies generate.

14. Security

Data is encrypted in transit and at rest. Workspaces are isolated from one another at the database level, and that isolation is enforced by the database rather than trusted to application code. Access to production systems is limited to the people who need it, protected by multi-factor authentication, and recorded in an append-only audit log. Third-party credentials such as mailbox grants are stored encrypted.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as the law requires.

15. Children

Sellsmith is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

16. Changes to this policy

We will update this page when our processing changes, and revise the date at the top. If a change materially affects your rights we will tell you by email or in the product before it takes effect.

17. Contact

Questions, requests and complaints go to hello@sellsmith.io. If you are unhappy with our response, you have the right to complain to your local data protection authority.

See also our Terms of Service.