1. Our Roles
- Controller. We act as a data controller for personal data of website visitors, account holders, and billing contacts ("Account Data"), and for marketing and analytics data.
- Processor. We act as a data processor for personal data our customers submit to or process through the Service — e.g., prospect contact details, mailbox contents, deal records, and CRM-style pipeline data ("Customer Data"). Our processing of Customer Data is governed by our Data Processing Addendum and the customer's instructions. If your data appears in a customer's workspace, that customer is the controller — contact them directly to exercise your rights; we will assist them as required by law.
2. Data We Collect
Data you provide:
- Account and profile data: name, work email, company name, password (hashed), role.
- Billing data: plan, billing address, tax IDs. Card details are processed by our payment processor (Stripe); we do not store full card numbers.
- Communications: support tickets, emails, chat messages, survey responses.
- Third-party connections: OAuth tokens and configuration metadata when you connect Google Workspace, Microsoft 365, CRMs, or sending tools. Tokens are encrypted at rest and used only to provide the features you enable.
Data collected automatically:
- Usage data: pages viewed, features used, actions taken, timestamps.
- Device and log data: IP address, browser type, operating system, referring URLs, error logs.
- Cookies and similar technologies: see Section 9.
Customer Data processed on customers' behalf:
- Prospect and contact records (names, emails, companies, titles, notes).
- Mailbox metadata and, where a feature requires it, message content from connected mailboxes.
- Pipeline and deal information.
Data from third parties:
- Enrichment or verification providers, where you enable such features.
- Advertising and analytics partners (in aggregate or pseudonymous form).
We do not knowingly collect data from children under 16. The Service is for business use only.
3. How We Use Personal Data
We use Account Data and related personal data to:
- Provide, operate, secure, and maintain the Service.
- Authenticate users and manage accounts.
- Process payments, invoices, and taxes.
- Provide support and respond to inquiries.
- Send transactional communications (receipts, security alerts, service notices).
- Send product updates and marketing where permitted — you can opt out at any time via the unsubscribe link or by emailing tim@coldbean.ai.
- Monitor, analyze, and improve performance, deliverability, and features, including using aggregated or de-identified data.
- Detect, prevent, and investigate fraud, abuse, spam, and security incidents.
- Comply with legal obligations and enforce our Terms.
We use Customer Data only to provide the Service per our customers' instructions, our Terms, and the DPA — never for advertising, and never to build marketing profiles of data subjects.
Google API Services. Coldbean's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data accessed via connected Workspace accounts is used only to provide user-facing features you enable, is not used for advertising, and is not transferred except as necessary to provide those features, for security, or to comply with law.
4. Legal Bases (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on these bases:
- Contract (Art. 6(1)(b)): providing the Service, accounts, billing, support.
- Legitimate interests (Art. 6(1)(f)): securing the Service, preventing abuse, product analytics, B2B marketing to business contacts — balanced against your rights.
- Consent (Art. 6(1)(a)): non-essential cookies, certain marketing. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): tax, accounting, lawful requests.
6. International Transfers
We are a U.S.-based company and process data in the United States and other jurisdictions where our subprocessors operate. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA), adequacy decisions where available, and supplementary measures such as encryption in transit and at rest.
7. Retention
- Account Data: for the life of the account and up to 24 months after closure, unless a longer period is required (e.g., tax and accounting records, typically 7 years).
- Customer Data: for the subscription term; deleted or de-identified within 90 days after termination, plus backup expiry of up to 35 days, per the DPA.
- Logs and security data: typically 12–18 months.
- Marketing data: until you opt out or after prolonged inactivity.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. EEA/UK residents may lodge a complaint with their supervisory authority.
California residents (CCPA/CPRA): you have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information, and the right to non-discrimination. We do not sell or share personal information as those terms are defined by the CPRA, and we do not use sensitive personal information beyond permitted purposes.
To exercise rights, email tim@coldbean.ai. We will verify your identity and respond within the legally required timeframe (generally 30 days under GDPR, 45 days under CCPA). If we hold your data only as a processor for one of our customers, we will refer your request to that customer and assist them.
10. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest, access controls with least-privilege and MFA, network isolation, logging and monitoring, and vendor due diligence. Details are described at coldbean.ai/security. No system is perfectly secure; you are responsible for safeguarding your credentials.
If we become aware of a personal data breach affecting your data, we will notify you and regulators as required by applicable law and the DPA.
11. Third-Party Sites
The Service may link to third-party sites and services. Their privacy practices are governed by their own policies, which we do not control.
12. Changes to This Policy
We may update this Policy from time to time. We will post the revised version with an updated date and, for material changes, notify account holders by email or in-product notice before the changes take effect.
13. Contact
Xquare Labs LLC, 166 Geary St, San Francisco, CA 94108, USA. Email: tim@coldbean.ai.
EEA/UK data subjects may contact our designated privacy contact at the same address. If we are required to appoint an EU or UK representative under Art. 27 GDPR, their details will be listed here.
This Policy works alongside our Terms of Service and Data Processing Addendum. See also our Security practices.