Legal

Privacy Policy

Last updated: August 5, 2026

This policy explains how SalesWind ("SalesWind," "we," "us"), operated by Vantaire LLC, doing business as SalesWind, collects and uses personal data in connection with the SalesWind application and websites (the "Service").

Two roles. For the account, billing, and usage data described below, we act as the data controller. For the prospect and workspace data our customers upload — information about the people they want to reach — the customer is the data controller and we act as their processor/service provider, handling that data only on their instructions to provide the Service. If you received an email sent through SalesWind and want to know how your data is handled, see the section "If you received an email sent through SalesWind" below. Our processor commitments to customers, including subprocessors, security measures, and international transfer safeguards, are set out in the Data Processing Addendum.

What we collect

Account and sign-in data

Your name, email address, and a password (stored only as a bcrypt hash). If you sign in with Google or Apple, we receive your name and email address from that provider; we never see your Google or Apple password. We also store your email-verification status and your communications preferences (whether you opted in to product emails and text messages at signup).

Workspace data you import or create (customer-controlled)

Prospect records (names, job titles, seniority, email addresses, phone numbers, LinkedIn URLs, employer, country, timezone, notes), company records (name, website, industry, size, revenue), AI research results and their source citations, generated email sequences and their version history, call logs (type, date, time, duration, outcome, notes), manual notes, send schedules, cadences, and workspace activity history.

Positioning and reference content

The configuration you write in Settings (sender identity, company positioning, tone instructions) and the reference emails you paste to teach the writer your voice.

Mailbox connection data

When you connect Gmail or Microsoft 365: the provider, your mailbox address, connection status and any error messages, and OAuth tokens, which are encrypted at rest. We do not read your inbox — the permissions we request are limited to sending mail and identifying the connected address.

Billing data

Payments are handled by Stripe. We store your Stripe customer and subscription identifiers and your subscription status. We never store card numbers.

Email engagement (open tracking)

If open tracking is enabled, emails sent through the Service include a tracking pixel that records when a message is opened, along with the requesting user agent and the time of the open. This data is processed on behalf of the sending customer.

Technical and usage data

IP addresses and request metadata in server logs (used for security and rate limiting), browser and device information sent with normal web requests, and timestamps of activity. Your login token is stored in your browser's localStorage so you stay signed in; see "Cookies and local storage" below.

How we use data, and our legal bases

  • Providing the Service (legal basis: performance of our contract with you) — operating your workspace, generating research and sequences, scheduling, and sending the emails you compose from your connected mailbox.
  • Transactional email (contract / legitimate interests) — welcome, email-verification, and password-reset messages, sent through Resend.
  • Billing (contract / legal obligation) — subscription management through Stripe, invoices, and tax compliance.
  • Security and reliability (legitimate interests) — authentication, rate limiting, abuse and fraud prevention, debugging, and protecting tenant isolation.
  • Product communications (consent) — product news and marketing messages only if you opted in; you can opt out at any time via the unsubscribe link or by contacting us.
  • Legal compliance (legal obligation) — responding to lawful requests and enforcing our terms.

We do not use your data for third-party advertising, and we do not sell personal data or share it for cross-context behavioral advertising.

AI processing

To generate research and email drafts, we send the minimum relevant content to our AI providers: prospect identity and role details, company information, your positioning and instructions, and (for voice-matching) your reference emails. Web research is performed by Perplexity; drafting and quality review are performed by OpenAI. We access these providers through their business APIs, whose terms restrict use of submitted data to providing the requested output; per those providers' current API data-use policies, API inputs are not used to train their models.

Google user data

When you connect a Gmail account, SalesWind requests the gmail.send permission and basic profile information (your email address). We use this access for exactly one purpose: sending the outreach emails you compose and schedule, from your own account, at your direction. SalesWind does not read, store, or analyze the contents of your inbox, and does not use Google user data for advertising. OAuth tokens are stored encrypted at rest and are deleted immediately when you disconnect the mailbox or delete your account. You can also revoke SalesWind's access at any time from your Google Account security settings.

SalesWind's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft user data

When you connect a Microsoft 365 mailbox, we request only the permission needed to send mail from your account and to identify the connected address. The same commitments apply: sending only at your direction, no reading of your inbox, tokens encrypted at rest and deleted on disconnect or account deletion, and revocable at any time from your Microsoft account settings.

How we share data

We share personal data only with the service providers (subprocessors) needed to run the Service:

  • Railway — cloud hosting and database infrastructure;
  • Stripe — subscription billing and payment processing;
  • Resend — delivery of our own transactional emails;
  • Perplexity and OpenAI — AI research and drafting, as described above;
  • Google and Microsoft — sending your outreach through your own connected mailbox, and sign-in if you use Google sign-in;
  • Apple — sign-in, if you use Apple sign-in.

We may also disclose data where required by law or legal process, to protect the rights, safety, or property of SalesWind, our users, or others, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply and we will provide notice of any change in control). We do not sell personal data.

If you received an email sent through SalesWind

SalesWind is a tool our customers use to send their own business outreach. If you received such an email, the sender is the data controller for your information; SalesWind processes it only on the sender's behalf. That processing may include your name, email address, professional details (employer, title, public profile links), research compiled from public sources, and — if the sender enabled tracking — whether and when their message was opened. To unsubscribe, correct your information, or exercise privacy rights over this data, contact the sender directly (for example by replying to their email); we will assist the sender with such requests as their processor. If you contact us instead, we will refer your request to the relevant sender.

Cookies and local storage

The app does not use advertising or third-party analytics cookies. We use browser localStorage to hold your login token — this is strictly necessary for the Service to function and is cleared when you log out. Some third-party content is loaded to make the app work: fonts from Google Fonts and sign-in libraries from Google and Apple; when your browser fetches these, those companies receive standard request data such as your IP address and user agent. Stripe's checkout and billing pages set their own cookies under Stripe's policies. Because we do not track you across other sites or sell or share personal data, browser signals such as Do Not Track and Global Privacy Control do not change how the Service treats you — there is no cross-site tracking to opt out of.

Security

Passwords are hashed with bcrypt. OAuth tokens and API keys are encrypted at rest. All traffic is encrypted in transit with TLS. Workspace data is isolated per company (tenant) at multiple layers, sessions can be revoked immediately by logging out or changing your password, and endpoints are rate limited. No method of transmission or storage is 100% secure, but we work to protect your data and will notify affected users of a breach as required by applicable law. To report a security vulnerability, contact [email protected].

Data retention and deletion

  • While your account is active, we retain your data so the Service works.
  • Deleting your account (Settings → Delete account) is permanent. If you are the only member of your workspace, it immediately erases the whole workspace: contacts, companies, sequences and versions, cadences, call logs, notes, schedules, reference emails, configuration, and all mail-connection credentials. If other members remain, your own user record, personal settings, and any data not shared with the workspace are erased immediately, and the workspace's shared data stays with the remaining members — who continue as its controller. To have shared workspace data erased, ask a workspace owner, or delete the workspace by removing the remaining accounts.
  • Deleting a person from your workspace moves them to a recoverable bin. After 30 days they are permanently erased, along with their drafted sequences, notes, call logs, and any unsent scheduled emails. A record of emails that were actually sent to that address is retained as a business record of your own outreach — the recipient, subject, and message body of messages already delivered — so you keep an accurate history of what you sent and to whom.
  • Disconnecting a mailbox deletes its stored OAuth tokens immediately.
  • Security and administrative logs (sign-in protection events, team and permission changes, mailbox connections) are retained for up to 1 year and then deleted.
  • Residual copies in server logs and encrypted infrastructure backups are rotated on a short cycle and are purged within 30 days.
  • Billing records are retained as required for tax and accounting law.

International transfers

The Service is operated from the United States and data is processed there and wherever our subprocessors operate. Where personal data of individuals in the EEA, UK, or Switzerland is transferred to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) with our subprocessors.

Your rights

Everyone: you can access and update most of your data directly in the app, export contacts, sequences, calls, and schedules as CSV, and delete your account (and all its data) from Settings at any time.

EEA/UK/Swiss residents: subject to conditions in law, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including to processing based on legitimate interests), and the right to withdraw consent at any time without affecting prior processing. You may also lodge a complaint with your local supervisory authority.

California residents: under the CCPA/CPRA you have the right to know and access the personal information we collect, to correct it, to delete it, and to non-discrimination for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising — and have not done so in the preceding 12 months — so there is nothing to opt out of. We use and disclose sensitive personal information only for purposes permitted by the CCPA (providing the Service and securing accounts), so no right-to-limit applies. For the prospect data our customers upload, we act as a "service provider" and process it only on the customer's behalf. The categories of personal information we collect as a "business" come from you directly, from your device and browser, or from Google or Apple if you use their sign-in, and are handled as follows:

CCPA categoryExamples we collectBusiness purposesDisclosed toSold or shared?
IdentifiersName, email address, IP addressAccount creation, sign-in, transactional email, securityRailway, Resend, Stripe; Google or Apple if you use their sign-inNo
Commercial informationSubscription status and billing history (card numbers are held by Stripe, never by us)Billing and tax complianceStripe, RailwayNo
Internet or other electronic network activityServer logs, request metadata, activity timestampsSecurity, rate limiting, debuggingRailwayNo
Professional or employment-related informationYour workspace's company name and your role in itOperating team workspacesRailwayNo
Sensitive personal informationAccount log-in credentials (password stored only as a bcrypt hash)Authentication onlyRailwayNo

Retention periods for each category follow "Data retention and deletion" above.

Other US states: residents of states with comprehensive privacy laws (such as Colorado, Connecticut, Texas, and Virginia) have similar rights of access, correction, deletion, and portability, and the right to opt out of targeted advertising, sales of personal data, and certain profiling — none of which we engage in.

To exercise any of these rights, use the in-app tools or contact [email protected]. We may need to verify your identity, and an authorized agent may submit requests on your behalf where the law permits. We respond within the timelines required by applicable law; if we decline all or part of a request, you may appeal by replying to our response, and if your appeal is denied, residents of some states may contact their state attorney general. Remember: for prospect data, the sending customer is the controller — see "If you received an email sent through SalesWind."

Children

The Service is a business tool for adults. It is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. We will post the new version here with an updated date and, for material changes, notify you in the app or by email before the change takes effect.

Contact

Privacy questions and requests: [email protected], or Vantaire LLC (doing business as SalesWind), 1401 21st Street, Sacramento, CA 95811, USA.