BranchPage CRM

Trust

Privacy Policy

This page covers the data BranchPage itself collects and processes as the vendor of this CRM — the workspaces that use it, and the people whose accounts and contact records live inside it. It does not speak for any tenant's own messaging consent, which is that tenant's commitment, published at their own /legal/<slug> page.

Last updated 6 October 2026

What we collect

Your account
Name, email address, and role within your workspace — created when your workspace invites you, or when you sign in.
Contacts and leads
The records a workspace loads into the CRM: names, email addresses, phone numbers, notes, and the history of messages and activity logged against them. This data belongs to the tenant that entered it, not to us.
Inbox digest (optional, off until you turn it on)
If you turn on the inbox digest, BranchPage reads the sender, subject, date and message headers (used only to recognise mailing lists, and not kept) of messages in your connected Microsoft 365 or Gmail inbox from the last 7 days, and never moves, marks or deletes mail. It keeps one line per message (sender name, subject, time, link) for 7 days, visible only to you. Messages from your CRM contacts are not kept.
Summarize my inbox (only when you tap it)
When you tap "Summarize my inbox", BranchPage reads the text of up to 60 messages from the last 24 hours (never attachments) and sends it to our AI service provider, Anthropic, to write a short summary for you. Before anything is sent, the names we know — your CRM contacts, your colleagues and the people who wrote to you — are replaced with placeholders, and email addresses, phone numbers, street addresses, links and account-like numbers are removed. Messages involving your CRM contacts are sent only if they contain no sensitive identifiers or financial documents, and with dollar amounts and other names we can recognize removed. Other names mentioned in messages that don't involve your CRM contacts may be included. Anthropic doesn't use it for training and deletes it within 30 days (longer only for content flagged under its usage policies). The summary is kept for 7 days, visible only to you. Mailbox data is never used for advertising or read by people. BranchPage's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Usage metadata
Sign-ins, feature usage, and API activity, kept for security, billing, and the audit log described on our security page.

How AI is used

Several features send data to an AI provider to generate a result. In every case, content aimed at a client or lead is a draft a person reviews before anything is sent — the AI does not send on its own.

AI Companion
Answers questions about your book of business and drafts replies to leads and clients. Drafted replies are never sent automatically; a person reads, edits, and sends them.
AI Automation module
Plans and runs workflow steps a workspace configures, within limits your workspace sets.
AI Studio
Generates flyers and landing pages from a prompt, for a person to review and publish.
Image generation for Social
Generates images for social posts from a prompt; the resulting post is a draft until a person schedules or publishes it.
Which provider
These features run on third-party AI model providers — see the subprocessor table on /security for what each one receives. Data sent to generate a result is not used to train their models.

Who we share it with

We do not sell personal data. The third parties that process it on our behalf — what each one receives and why — are listed in the Subprocessors table on the security page: Supabase, Vercel, Resend, Twilio, Cloudmersive, Atlassian (Jira), Seamless.AI, UpLead, Stripe, Microsoft (Graph), Meta (Facebook / Instagram), LinkedIn, and the AI model providers behind the features described above.

Your rights

Access
You can ask what personal data we hold about you or your workspace's contacts.
Deletion
Contacts and uploaded documents can be deleted from within the product. On termination of a workspace, its data is deleted on the schedule described on /security. Reach out below for a deletion request outside the product.
Questions
Email support@branchpage.com with any privacy question or request, including access or deletion.

For how we handle security, encryption, and tenant isolation, see /security. Questions this page doesn't answer: support@branchpage.com.