Skip to main content

SalesOS Privacy & Sub-processors

What SalesOS does with your data, the controls you have over it, and every company that processes it for us.

Export and delete your data yourself

On the Data & privacy page (/dashboard/settings/privacy), any signed-in user can:

  • Export their data as a JSON file: profile, preferences, organization memberships, AI conversations, and the leads, contacts, accounts, deals, activities, notes, tasks and email threads they own in the current organization (up to 5,000 rows per type, with a flag when a list was cut short). The download link lasts 7 days.
  • Delete their account. Deletion runs 30 days after the request and can be cancelled until then. It anonymizes the profile, removes the user's AI conversations and privacy preferences, ends every session and revokes their API keys. CRM records that belong to the organization are kept, attributed to a deleted user.

These tools act on one person's data. To have a whole organization's data deleted, email [email protected].

Data retention

What SalesOS keeps and for how long
DataHow long
Your CRM records, users and settingsKept while your organization’s account exists. Cancelling a subscription does not delete data.
Signed-in session recordsRemoved 30 days after they expire
Revoked sign-in tokensRemoved once they would have expired
Sent, failed and cancelled items in the email queueRemoved after 30 days
Meeting invitation responsesRemoved after 90 days
Data export files (Data & privacy page)Download link valid for 7 days
An account you ask us to deleteDeleted 30 days after the request unless you cancel it
Not in place yet: API request logs (which include IP addresses), audit logs, notifications, product analytics events and export files that have passed their 7-day link have no automatic deletion period yet; they are kept until an operator removes them. Setting fixed retention periods is on the roadmap.

Product analytics

SalesOS measures how the product is used with its own first-party analytics. There are no third-party analytics, advertising or session-recording scripts on salesos.org.

  • Nothing is recorded unless you accept analytics cookies in the cookie banner, and nothing is recorded when your browser sends a Global Privacy Control signal.
  • Events are milestones such as “deal created”, “quote sent” or a page view. A page view records the route with record ids removed, for example /dashboard/deals/:id.
  • Each event stores the event name, the route, a random id for the browser tab, and, when you are signed in, your user and organization ids.
  • Events do not store your IP address, browser user agent, names, email addresses or record contents, and the server discards any property that looks like one.

You can change your choice at any time by clearing the cookie preference in your browser.

Sub-processors

These companies process customer data on our behalf. The list comes from what this deployment actually uses.

SalesOS sub-processors
CompanyPurposeDataLocation
Oracle Cloud InfrastructureHosting for the application, database and backupsAll customer dataIndia (Mumbai, ap-mumbai-1)
CloudflareDNS, TLS and proxying for all traffic to salesos.orgAll requests and responses in transit, including IP addressesCloudflare global network
Google (Gmail SMTP)Sending transactional email such as invitations, password resets and notificationsRecipient email addresses and message contentGoogle global infrastructure
GenAI Core (api.genaicore.com)Gateway for AI features. The configured model is Anthropic Claude, reached through the gatewayOnly when AI features are used.Prompts and the CRM content you ask an AI feature to work onNot yet confirmed with the provider
StripeSubscription paymentsPayments are not live yet: Stripe runs in test mode, so no real charges are made.Billing contact and payment details, entered on StripeStripe global infrastructure

Loaded by your browser

These services do not receive your CRM data, but your browser contacts them when it loads a page, so they see your IP address.

  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com)Web fonts on every page
  • logo.dev (img.logo.dev)Brand logos on marketing and integration pages
  • Unsplash (images.unsplash.com)Photos on some marketing pages
  • ui-avatars.comA placeholder image when an integration’s logo fails to load (the integration’s name only)

Integrations you choose to connect

When your organization connects a service such as Google Workspace, Microsoft 365, Salesforce, HubSpot, Slack, Zoom or Twilio, data flows between SalesOS and that service under your own account with it. None of these is connected for all customers.

Razorpay: not activeThird-party analytics: noneCloud object storage: none

Data Processing Agreement

Organization owners and admins can read and accept the SalesOS Data Processing Agreement on the DPA page and download a copy of the version they accepted. Our full Privacy Policy covers the rest.

Questions or requests about your data: [email protected]

Last reviewed 29 September 2026. Questions about anything here: [email protected].