UnboothOpen app

Legal

Privacy Policy

This policy explains what personal data Unbooth processes, why it is used, who receives it, and the choices available to you.

Effective July 29, 2026

1. Who is responsible for the data?

Unbooth is operated by the person or entity identified as the seller on your receipt or order confirmation. That operator is the controller of account, billing, support, security, and product-usage data used to provide Unbooth.

For contact data captured or uploaded by a workspace—such as event leads, badges, business cards, conversation notes, and follow-up content—the workspace customer generally decides why and how the data is used. In that context, the customer is the controller or business and Unbooth acts as its processor or service provider. Questions from a captured contact should normally be directed to the organization that collected the information.

2. Information we process

  • Account and workspace data: name, email address, authentication identifiers, workspace membership, roles, invitations, and settings.
  • Event contact data: name, role, company, work email, phone number, LinkedIn and company URLs, badge or business-card details, event name, conversation notes, and enriched person or company descriptions.
  • Audio and images: recordings submitted for transcription and badge or business-card images submitted for extraction. Unbooth sends these to the processing provider and does not intentionally retain the original audio or image in its application database after processing. The resulting transcript or extracted fields may be saved.
  • Drafts and communications: follow-up prompts, generated drafts, recipients, subject lines, and delivery status when you choose to send a message.
  • Integration data: encrypted authorization tokens, connected account identifiers, campaign selections, webhook destinations, and data exchanged at your direction.
  • Payment and credit data: Stripe customer and transaction references, purchases, amounts, currency, credit balance, and credit-ledger activity. Stripe, not Unbooth, handles full card details.
  • Technical data: IP address, device and browser information, request timing, security events, error logs, and product interactions.

3. How we obtain information

We receive information directly from users, workspace administrators, connected services, event contact submissions, payment providers, and enrichment or research providers. We also collect limited technical data automatically when the service is used.

4. Why we use information

We process personal data to:

  • authenticate users and operate accounts and collaborative workspaces;
  • capture, transcribe, extract, organize, and enrich event contacts;
  • generate user-requested follow-up drafts and send approved messages;
  • connect to user-selected CRMs, outreach tools, and webhooks;
  • process payments, allocate credits, and maintain transaction records;
  • provide support, detect abuse, secure the service, and troubleshoot errors;
  • measure and improve product reliability and usability; and
  • comply with law and enforce our agreements.

Depending on context and location, our legal bases include performing a contract, legitimate interests in operating and securing the service, consent where requested, compliance with legal obligations, and the workspace customer’s documented instructions.

5. Providers and recipients

We share data only as needed with categories of recipients such as:

  • Clerk for authentication and workspace identity;
  • Vercel for hosting and application delivery;
  • our managed PostgreSQL provider for application data storage;
  • OpenAI for transcription, image extraction, and user-requested drafting;
  • Clay and other research providers for contact and company enrichment;
  • Stripe for payment processing and fraud prevention;
  • Gmail, HubSpot, Salesforce, HeyReach, or a webhook recipient when a user connects or directs data to that service;
  • professional advisers, authorities, or counterparties where legally required.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

6. Google user data and Gmail

If you connect Gmail, Unbooth requests access only to identify the connected account and send messages that you review and direct. Unbooth does not read or index your inbox. Google access tokens are encrypted, and you may disconnect Gmail from the integrations page.

Unbooth handles Google API data in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used for advertising, sold, or used to train generalized AI or machine learning models.

7. International transfers

Providers may process data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism.

8. Retention

Account, workspace, lead, and draft data is generally retained while the account or workspace is active and for a reasonable period afterward to support recovery, security, and legal obligations. Encrypted integration credentials are retained until the integration is disconnected, the workspace is deleted, or they are no longer needed. Billing and security records may be retained longer where law or fraud prevention requires it.

We delete or anonymize data when it is no longer reasonably needed, subject to backups and legal holds.

9. Security

We use administrative, technical, and organizational safeguards designed to protect data, including access controls, encrypted integration credentials, HTTPS, and scoped workspace permissions. No system is completely secure, and we cannot guarantee absolute security.

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent. You may also have a right to complain to a data-protection authority. We will not discriminate against you for exercising privacy rights.

Workspace users should first contact their workspace owner for contact data controlled by that organization. You may also email privacy@unbooth.io. We may need to verify your identity and, where we act for a customer, refer the request to that customer.

You can revoke a connected service from Unbooth’s integrations page and, where applicable, from that provider’s security settings.

11. Cookies and children

Unbooth uses cookies and similar storage needed for authentication, security, preferences, and core service operation. We do not currently use advertising cookies. The service is intended for business users aged 18 or older and is not directed to children.

12. Changes and contact

We may update this policy as the service changes. We will post the revised policy, update its effective date, and provide reasonable notice of material changes.

Privacy questions or requests may be sent to privacy@unbooth.io. General support questions may be sent to support@unbooth.io.

© 2026 Unbooth
AboutTermsPrivacyRefund policy