Privacy Policy
LAST UPDATED · AUGUST 28, 2026
This policy describes how SidePrompt AI ("we", "us") handles personal data when you use Cold Call Cockpit (the "Service") or visit coldcallcockpit.com. The short version: your CRM stays your system of record, we never touch call audio, and we don't sell data.
1. Data we collect
- Account data. Name, email address, and sign-in provider (Google, Microsoft, or email and password), handled through Firebase Authentication. We never see or store your password in plain text.
- Workspace configuration. Workspace membership, roles, and the per-member settings that map your team to your CRM and phone-system accounts.
- CRM data, on your instruction. The Service reads leads, contacts, activities, and related records from your Pipedrive account, and writes back call outcomes, notes, scheduling, and enrichment. Pipedrive remains the system of record — we do not maintain a copy of your CRM as our own database.
- Call metadata. When you dial through the Service we process call events from your phone-system provider — timestamps, durations, outcomes, and call identifiers. Never call audio: the Service does not record, store, transcribe, or listen to your calls.
- Activity telemetry. To power team day tapes and scorecards, the Service records lightweight presence heartbeats while the app is open (active, idle, or on-call, by minute). This is visible to your workspace's administrators as part of team reporting.
- Usage and diagnostics. Product analytics and error reports (feature usage, page events, crash traces) used to improve the Service.
- Billing data. Payments are processed by Stripe. Card details go directly to Stripe and never touch our servers; we hold subscription status and invoicing records.
2. How we use data
- To provide the Service: presenting your queue, placing calls through your phone system, automating post-call administration, and writing results back to your CRM.
- To enrich prospect records you already hold, using third-party business-data sources, and to generate AI-assisted research and summaries of your call notes.
- To show calling activity and performance to you and your workspace administrators.
- To operate, secure, support, and improve the Service, and to communicate with you about it.
- To bill for subscriptions.
We do not sell personal data, and we do not use your CRM data to train AI models.
3. AI processing
Some features send text you already control — such as your call notes or a prospect's CRM record — to AI providers to produce summaries and research briefs. These providers process the data to return the result and are bound by contract not to use it for their own purposes. No call audio exists to be processed.
4. Service providers
We use a small set of subprocessors to run the Service: Google (Firebase — hosting, authentication, and application data), Pipedrive and your phone-system provider (as connected by you), Stripe (payments), business-data providers for enrichment, AI providers for summaries and research, and tooling for product analytics, error reporting, and transactional email. Access tokens for your connected services are encrypted at rest.
5. Legal bases
Where the GDPR or similar law applies, we process data to perform our contract with you, to pursue legitimate interests (operating, securing, and improving the Service), to comply with legal obligations, and with consent where required. For prospect data inside your CRM, your organization is the data controller and we act as a processor on its instructions.
6. Retention
Account and workspace data is kept while your account is active and deleted or anonymized within a reasonable period after closure. CRM data lives in your Pipedrive account and follows your retention there. Telemetry and diagnostics are retained on a rolling basis. Billing records are kept as required by tax and accounting law.
7. Security
Data is encrypted in transit and at rest. Third-party access tokens are additionally encrypted at the application layer. Access to production systems is restricted and audited. No system is perfectly secure; if a breach affects your data we will notify you as required by law.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Contact us at the address below and we will respond within the timelines required by applicable law. Where we act as a processor for your organization's CRM data, we will refer or assist with the request as appropriate. You may also complain to your local data-protection authority.
9. International transfers
Our infrastructure runs on Google Cloud in the United States. Where data is transferred across borders we rely on appropriate safeguards, such as standard contractual clauses, as required by applicable law.
10. Website
coldcallcockpit.com is a static site. It loads fonts from Google Fonts, which involves your browser requesting the font files from Google. The early-access form is relayed by FormSubmit and delivered to our inbox; we use what you enter only to contact you about access. The site sets no advertising cookies.
11. Changes
We may update this policy from time to time; material changes will be announced by email or in the product before they take effect. The date above always reflects the current version.
12. Contact
Privacy questions and requests: support@coldcallcockpit.com