Skip to content
Privacy

Privacy

Written to describe what the system actually does. Where something is not implemented, it is not claimed.

If you received a message from a customer of ours

A business using this platform found you as a potential referral partner and approached you. They chose to contact you; we prepared the message and, for email, delivered it on their behalf.

We hold your name, role, company, and publicly available professional information used to assess the fit, plus the message sent and any reply. That data belongs to the customer who contacted you and is visible only to them.

To stop: use the unsubscribe link in the message, or reply and say so. Either one stops outreach on every channel, immediately and permanently. A reply is read by a person.

If you are a customer

We hold your business profile, campaigns, partner records, messages, replies, and outcomes. Your data is isolated from every other customer at the database level, not only in application code.

Sending credentials you provide are encrypted at rest with authenticated encryption and are never returned by any interface, including to you. They are decrypted only inside the send path.

Connecting your Gmail account (Google user data)

You may connect your own Google account so the platform can send your approved outreach as you. The connection uses Google’s OAuth: you authorize it on Google’s own screens, and we never see, ask for, or store your Google password.

We request a single Gmail permission — the gmail.send scope — which allows sending email on your behalf and nothing else. It does not grant, and we do not request, the ability to read, search, delete, or otherwise access the contents of your mailbox. What Google returns is an authorization token (a refresh token), which we store encrypted with authenticated encryption, isolated to your tenant, used only inside the send path, and never exposed by any interface.

We use this access solely to send the messages you approve in the platform. We do not use Google user data for advertising, do not sell it, and do not transfer it to others except as necessary to perform the send you requested. You can revoke access at any time — from your Google Account’s security settings, or by disconnecting the sender in the app — after which we stop sending as you until you reconnect.

Referral Network Builder’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Third parties we use

  • A company-data provider, to find and verify candidate businesses
  • An AI provider, to draft offers and messages you then approve
  • An email provider you choose and connect, to deliver your email
  • A hosting and database provider

Retention and deletion

Records are retained while your account is active. Deleting a tenant cascades to its owned records. Suppression and unsubscribe records are deliberately kept after deletion of other data — forgetting that someone opted out would let us contact them again.

Contact

Reply to any message you received from us, or use the form on the home page.