Legal

Privacy Policy

Effective date: March 1, 2026

Closin.ai

1. Introduction

Closin.ai("Closin," "we," "us," or "our") provides an AI-powered revenue intelligence platform (the "Service") to enterprise customers. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our Service, website, and related applications.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you are using the Service on behalf of an organization, you represent that you are authorized to accept these terms on its behalf.

2. Information We Collect

2.1 Information You Provide

  • Account information: information needed to create and maintain your account, such as your name, email address, and company details.
  • CRM data: business data from your connected CRM platform, limited to the scope you authorize during integration setup.
  • Communications: information you provide when you contact us for support, submit feedback, or participate in surveys.
  • Payment information: billing details processed by our third-party payment processor. We do not store full payment card numbers.

2.2 Information Collected Automatically

  • Usage data: pages viewed, features used, search queries, and interaction patterns within the Service.
  • Device and browser information: IP address, browser type and version, operating system, device identifiers, and screen resolution.
  • Log data: server logs including access times, referring URLs, and error reports.
  • Cookies and similar technologies: we use essential cookies for authentication and session management, and analytics cookies to understand usage patterns. See Section 9 for details.

2.3 Information from Third Parties

  • CRM platforms: data synchronized from your connected CRM per your authorization scope.
  • Identity providers: authentication attributes provided through SSO/SAML integrations.
  • Business partners: information from resellers or referral partners as part of the sales process.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including AI-powered forecasting, deal health scoring, and analytics.
  • Process and synchronize CRM data to deliver real-time revenue intelligence.
  • Improve and develop our AI models and machine learning algorithms using aggregated, de-identified data. Google user data is excluded from this use — see Section 5.
  • Send transactional communications (e.g., alerts, forecasts, and system notifications).
  • Respond to support requests and provide customer service.
  • Detect, prevent, and address security incidents, fraud, and technical issues.
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell your personal information or CRM data to third parties. We do not use your CRM data to train AI models shared with other customers. Customer-specific data is isolated per tenant.

4. AI and Machine Learning

Our Service uses artificial intelligence and machine learning to provide forecasting, deal health scoring, and predictive analytics.

  • Tenant isolation: your CRM data is processed within your tenant boundary. AI models trained on your data are not shared with other customers.
  • Aggregated insights: we may use aggregated, de-identified, and anonymized data across customers to improve our general-purpose models (e.g., industry benchmarks). This data cannot be traced back to any individual or organization. Google user data — including aggregated, anonymized, or derived forms — is never used for this purpose (see Section 5).
  • Third-party AI providers: we may use third-party AI services (e.g., large language model providers) to power certain features. Data sent to these providers is subject to our data processing agreements and is not used to train their general models.
  • Human review: we do not routinely review individual customer data. Access is limited to authorized personnel for troubleshooting and support purposes, subject to strict access controls.

5. Google User Data

If you connect your Google account, the Service accesses Google user data through Google APIs. This section describes that access and applies to Google user data in addition to the rest of this policy.

  • What we access: Gmail message metadata only — headers such as sender, recipients, subject, and timestamps. We never access, request, or store email message bodies or attachments. We also access your Google Calendar events on a read-only basis (event times, titles, and attendees).
  • Why we access it: to match email and meeting activity to your CRM records, so the Service can show communication activity, surface engagement gaps on deals, and inform forecasting features you request.
  • Limited Use:Closin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
  • No AI/ML training:we do not use Google user data — whether raw, aggregated, anonymized, or derived — to create, train, or improve any machine learning or artificial intelligence models, whether ours or a third party's. This exclusion overrides the general AI provisions in Sections 3 and 4.
  • Third-party AI processing: Google user data may be processed by our AI subprocessors solely to provide the features you request. These providers are contractually prohibited from using this data to train their models, and we do not permit any such use.
  • No sale or unrelated transfer: we do not sell Google user data, and we do not transfer it to third parties except as necessary to provide or improve user-facing features of the Service, for security purposes, or to comply with applicable law.
  • Human access: humans do not read Google user data except with your explicit permission (e.g., a support request), when necessary for security purposes such as abuse investigation, to comply with applicable law, or in aggregated, de-identified form for internal operations.
  • Deletion: disconnecting your Google account revokes our access, and stored Google user data is deleted in accordance with Section 8. You can also revoke access at any time via your Google Account security settings.

6. How We Share Information

We share information only in the following circumstances:

  • Service providers: with vendors who process data on our behalf (e.g., cloud hosting, analytics, payment processing), bound by data processing agreements.
  • Your organization: with administrators of your enterprise account, who may access usage data and reports for users within their organization.
  • Legal compliance: when required by applicable law, regulation, legal process, or governmental request.
  • Business transfers: in connection with a merger, acquisition, reorganization, or sale of assets, where your information may be transferred as a business asset.
  • With your consent: when you direct us to share data with a third-party integration or service.

7. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Infrastructure: hosted on AWS with SOC 2 Type II compliant infrastructure, including VPC isolation, security groups, and network access controls.
  • Access controls: role-based access control (RBAC), multi-factor authentication, and the principle of least privilege for all personnel.
  • Monitoring: continuous monitoring, intrusion detection, and automated alerting for anomalous activity.
  • Data isolation: multi-tenant architecture with row-level security ensuring strict data separation between customers.

While we strive to protect your information, no method of transmission or storage is 100% secure. We encourage you to use strong passwords and enable multi-factor authentication.

8. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Specifically:

  • CRM data: synchronized data is retained while your CRM integration is active.
  • Account information: retained for the duration of the business relationship plus a reasonable period for legal and compliance purposes.
  • Usage and log data: retained for up to 12 months for analytics and troubleshooting.
  • Backups: encrypted backups are retained for up to 90 days.

You may request deletion of your data at any time by contacting us at support@closin.ai.

9. Cookies and Tracking Technologies

We use the following types of cookies:

  • Essential cookies: required for authentication, session management, and security. These cannot be disabled.
  • Analytics cookies: help us understand how the Service is used so we can improve it. You can opt out of analytics cookies through your browser settings.

We do not use advertising or third-party tracking cookies. We do not participate in cross-site behavioral advertising.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

9.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose.
  • Delete your personal information, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information. Note: we do not sell personal information.
  • Non-discrimination for exercising your privacy rights.
  • Limit use of sensitive personal information to purposes necessary to provide the Service.

To exercise these rights, contact us at support@closin.ai. We will verify your identity before processing your request and respond within 45 days.

11. International Data Transfers

Your information may be transferred to and processed in the United States, where our servers are located. If you are located outside the United States, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or other approved transfer mechanisms under applicable data protection laws.

12. Third-Party Integrations

The Service integrates with third-party platforms (e.g., CRM platforms, messaging tools). When you enable an integration, data may be shared between our Service and the third party in accordance with the permissions you grant. We are not responsible for the privacy practices of third-party services, and we encourage you to review their privacy policies.

13. Children's Privacy

The Service is designed for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will promptly delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice within the Service or sending an email to the address associated with your account at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

This privacy policy was last updated on March 1, 2026. For questions, contact support@closin.ai.