Privacy Policy
Last updated August 26, 2026
Summary of Key Points
This summary provides key points from our Privacy Notice. See the full policy below for complete details.
Your CRM records stay on your device. Contacts, Leads, Accounts, Opportunities, and Tasks remain on your device in encrypted storage and sync directly with your Salesforce instance. We do not access or store this data on our servers.
We collect minimal information. We store essential account data (email, username, usage counters, app telemetry, and organization metadata) in our secure cloud infrastructure. When you contact support, we collect your message and any attachments you provide. We do not intentionally process sensitive information; if an image or voice note you capture incidentally contains such data, it is processed transiently for extraction only and is not stored by us.
AI processing is temporary. When you invoke Scan or Speak, the captured image or voice recording and limited Salesforce field metadata pass transiently and in memory through our Firebase backend to OpenAI. OpenAI generates the extraction result, which returns to your device for review and is saved to Salesforce only if you confirm the save. We do not persist the captured input, field metadata, or extraction result on our infrastructure. For the Seamless.ly-managed OpenAI account, optional training and evaluation data sharing and the dashboard request-logging setting are disabled; those settings are separate from OpenAI's abuse-monitoring retention, under which OpenAI may retain request inputs and outputs for up to 30 days unless a different approved setting applies. API data is not used to train OpenAI models by default. Post-trial customers who provide their own OpenAI API key are additionally governed by their own account settings.
Your data stays yours. We share information only with essential service providers (cloud infrastructure, AI processing) for core app functionality. We don't share it for marketing, advertising, or any third-party purpose.
You have full control. You can access, delete, correct, or export your data at any time. Log out or delete the app to instantly remove all local data. Email privacy@seamless.ly for account deletion requests.
Table of Contents
- What Information Do We Collect?
- How Do We Process Your Information?
- What Legal Bases Do We Rely On?
- When and With Whom Do We Share Your Personal Information?
- Do We Use Cookies and Other Tracking Technologies?
- Do We Offer Artificial Intelligence-Based Products?
- Is Your Information Transferred Internationally?
- How Long Do We Keep Your Information?
- How Do We Keep Your Information Safe?
- Do We Collect Information From Minors?
- What Are Your Privacy Rights?
- Controls for Do-Not-Track Features
- Do United States Residents Have Specific Privacy Rights?
- Do Other Regions Have Specific Privacy Rights?
- Do We Make Updates to This Notice?
- How Can You Contact Us About This Notice?
- How Can You Review, Update, or Delete Your Data?
1. What Information Do We Collect?
We collect minimal personal information needed to authenticate you with Salesforce and provide app functionality.
Account Data
We store minimal account information in our secure cloud infrastructure (Google Cloud Platform / Firebase) to enable app functionality:
- Salesforce username, user ID, and organization ID
- Name, email address, phone number, job title (if available from your Salesforce profile)
- Authentication and subscription status
- Usage counters (for usage limits)
- App telemetry (app version, build number, platform, OS version, last active timestamp)
- Organization metadata (organization name, Salesforce edition, sandbox status, active user count)
We also create an Account record about each customer organization in our own internal Salesforce CRM (containing the organization name and Salesforce organization ID). We use this to manage our customer relationships, support, and billing. When you submit a support ticket or feedback, your name and email address are recorded on the resulting support Case.
Retention: see the retention schedule in Section 8
Unauthorized Access Attempts
When someone authenticates successfully with Salesforce but is not on our authorized list (for example, their organization or user has not been added to our authorized list yet), we record the attempted Salesforce username, email address, organization ID, organization name, and Salesforce instance URL. We retain this information for security and abuse-prevention purposes.
Retention: Up to 12 months from the most recent rejected attempt, after which records are deleted automatically. You may request earlier deletion of records relating to you by emailing privacy@seamless.ly.
Customer Support Data
When you contact support or submit feedback, we collect:
- Contact information (name, email, phone if provided)
- Support ticket descriptions and feedback
- Screenshots, recordings, or error logs (only if you provide them)
Where this data is stored: in-app feedback and support tickets are stored as Cases (with any attachments) in our internal Salesforce CRM. Submissions made through forms on our website (e.g. trial requests, contact form) are delivered to our team by email via Resend; we may then record the submission in our internal Salesforce CRM as well.
Retention: support tickets and their content are retained for two years after the ticket closes, unless you request earlier deletion, continued retention is required by law or legal hold, or a different period is documented in your organization's support instruction. Request deletion at any time by emailing privacy@seamless.ly.
Service Data does not include any CRM Record, Captured Input, AI Output or other Customer-provided content contained in a support request, attachment, screenshot, recording or diagnostic file. Such material is Customer Data and, to the extent it contains Personal Data, Customer Personal Data processed under the DPA. The support requester's business contact details and ticket-administration metadata remain Service Data.
Device Data
CRM Records (Contacts, Leads, Accounts, Opportunities, Tasks) are stored locally on your device in encrypted storage and in your Salesforce org, and synchronise directly between them. They are not transmitted to or stored on Seamless.ly's infrastructure. App Preferences (display settings, default values, customizations) are stored only on your device.
Retention: Logging out deletes the local CRM cache; uninstalling removes all app-local data. CRM Records remain in your Salesforce org.
AI Processing Data
When you use AI features (image scanning, voice notes), the following data is processed temporarily by our AI service provider via our backend:
- Images (sent to our AI service provider for text extraction)
- Voice recordings (sent to our AI service provider for transcription and field extraction)
- Metadata (necessary technical information to enable accurate data extraction)
This data passes through our servers in memory only and is immediately forwarded to our AI service provider. The extraction result returns to your device for review and is saved to Salesforce only if you confirm the save.
We do not send your existing CRM records (Contacts, Leads, Accounts, Opportunities, or Tasks) to our AI service provider. Only the audio or image you capture and the field metadata necessary to map extracted values into the correct Salesforce fields are sent.
API Keys: During your initial trial period, AI processing uses a Seamless.ly-managed API key on the Seamless.ly-managed OpenAI account, which is configured to disable training, evaluation sharing, and API request logging. After the trial, your organization can either continue using our managed environment (the same privacy settings remain in effect) or provide your own OpenAI API key (you maintain a direct billing relationship with OpenAI and control your own account settings, including data sharing and privacy controls). We encourage organizations to provide their own key for direct cost visibility and granular control, but it is optional. If you provide your own key, it is stored securely in our infrastructure and is only used server-side to process your Scan and Speak requests; you may revoke it at any time.
Retention on our infrastructure: none. Audio, images, field metadata, and extraction results pass through our servers in memory only and are never written to disk. For the Seamless.ly-managed OpenAI account, optional training and evaluation data sharing and the dashboard request-logging setting are disabled; those settings are separate from OpenAI's abuse-monitoring retention, under which OpenAI may retain request inputs and outputs for up to 30 days unless a different approved setting applies. API data is not used to train OpenAI models by default. Post-trial customers who provide their own OpenAI API key are additionally governed by their own account settings, controlled by their administrator.
Opt Out: Don't use AI features. You can manually enter all data.
Automatically Collected Data
We automatically collect device information and pseudonymized usage data through Firebase Analytics (a Google service) to improve the service:
- Device type, operating system, app version, build number, locale
- Per-install identifier generated by Firebase Analytics
- Product-usage events (e.g. onboarding completed, scan started, scan completed, voice note started, voice note completed, record created, search performed, scan-location saved, usage-limit reached, screen viewed) with limited parameters such as Salesforce object type, error code, or screen name
We do not attach your name, email, Salesforce username, record contents, or campaign names to these events. See Section 5 for details and opt-out.
We also process your IP address in memory when you sign in or submit a form on our website, solely for rate limiting and abuse prevention. It may be recorded in server logs when a rate limit is exceeded.
2. How Do We Process Your Information?
We process minimal personal information to authenticate you and enable core features, for these specific purposes:
- To authenticate you with Salesforce (we facilitate direct connection between your device and Salesforce)
- To manage your account (we store basic account information to enable app functionality and subscription management)
- To enable AI extraction (transient processing of images and audio; nothing is stored on our servers)
- To provide customer support (only when you contact us)
- To ensure security (preventing unauthorized access)
- To comply with legal obligations (when required by law)
Important: Your CRM records (Contacts, Leads, Accounts, Opportunities, Tasks) remain on your device and sync directly with your Salesforce instance. We do not store them on our servers and we do not send them to our AI service provider.
3. What Legal Bases Do We Rely On to Process Your Information?
We only process your personal information when we have a valid legal reason to do so.
Our two roles
When Seamless.ly processes Customer Personal Data under the Data Processing Addendum (captured images and recordings, field metadata, extraction results, and customer content in support requests), it acts on the customer's documented instructions as Processor or Sub-Processor; the customer determines the applicable lawful basis. Seamless.ly acts as an independent Controller for Service Data used for its own purposes, as described below.
To the extent Service Data is processed solely on Customer's documented instructions to provide the Services, that data is Customer Personal Data and the DPA applies.
If you are located in the EU or UK
For our independent-controller processing, we rely on the following legal bases:
- Legitimate Interests: authenticating users and administering accounts and licences under our customer contracts; protecting the service and preventing abuse (including recording rejected sign-in attempts and rate limiting by IP address); administering support and customer relationships; and producing aggregate service-improvement analytics, subject to the objection mechanism in Section 5. We process the minimum needed and balance this against your rights.
- Performance of a Contract: where you are directly party to the contract with us
- Contract and Legal Obligations: billing, tax, and accounting
- Legal Obligation or Legitimate Interests: compliance and legal claims, as applicable
- Consent: any optional features that ask for it (you can withdraw at any time)
If you are located in Canada
We process your information with your express or implied consent, which you can withdraw at any time.
If you are located in the United States
We process your information in accordance with our Terms of Service and this Privacy Notice.
4. When and With Whom Do We Share Your Personal Information?
We share information only with essential service providers.
Service Providers
We use trusted service providers for:
- Google Cloud Platform / Firebase (USA): cloud infrastructure, database hosting, authentication, server-side logs, and Firebase Analytics for in-app product-usage events
- OpenAI (USA): AI processing for image scanning and voice transcription. Trial customers and post-trial customers using our managed environment have requests routed through the Seamless.ly-managed OpenAI account; post-trial customers may optionally provide their own OpenAI API key for direct billing.
- Resend (USA): transactional email delivery for our website forms (e.g., trial requests, contact submissions). When you submit a form on seamless.ly, your name, email, company, phone (if provided), Salesforce ID (if provided), and message are delivered to our team via Resend.
- Salesforce (USA / EU, depending on your edition): in addition to your direct authentication with your own Salesforce instance (see “Other Sharing” below), we maintain our own internal Salesforce org used as our CRM. We create an Account record in our internal CRM for each customer organization (containing the organization name and Salesforce organization ID), and we record support tickets and feedback you submit as Cases carrying your name and email address (with attachments if provided).
Other Sharing
We may share your information in these situations:
- Salesforce (direct authentication with your Salesforce instance)
- Legal Requirements (when required by law or to protect rights)
- Business Transfers (in connection with merger, sale, or acquisition)
Limits on Sharing
We do not:
- Sell your personal information
- Share your Salesforce records
- Allow third parties to use your information for their own purposes
Sub-Processor Changes
Our current list of sub-processors is maintained at seamless.ly/subprocessors and in our Data Processing Addendum (Schedule 3). We email each customer's contractual administration or privacy contact at least 30 days before authorising a new sub-processor to process Customer Personal Data. Full security documentation is available under NDA.
5. Do We Use Cookies and Other Tracking Technologies?
Our website does not use advertising or cross-site tracking cookies. We do not run Google Analytics, Meta Pixel, Hotjar, or similar trackers on our marketing site. The site may use essential cookies for basic functionality only.
In-App Analytics
Our mobile application uses Firebase Analytics (a Google service) to record pseudonymized product-usage events that help us understand which features are used and where users encounter errors. The events recorded include: onboarding completion, scan started, scan completed, voice note started, voice note completed, record created, search performed, scan-location saved, usage-limit reached, and screen viewed (which screen of the app is open, by screen name only — never where you tap, hover, or scroll). Each event may include limited parameters such as the Salesforce object type (e.g., Lead, Contact), an error code, or a result count. Firebase Analytics generates a per-install identifier and sends standard device metadata (model, OS version, locale) to Google. Because this identifier exists, the data is pseudonymous rather than fully anonymous: it is not linked to your name or Salesforce account, but it is distinct per app install. We do not attach your name, email, Salesforce username, record contents, or campaign names to these events.
Firebase Analytics is on by default. User-level and event-level analytics data is retained in Firebase for 14 months and is used only to produce aggregate statistics for improving the service. You can stop analytics collection for your installation at any time by emailing privacy@seamless.ly: we will disable collection for your account without undue delay, and the app applies that choice from its next start. Disabling analytics does not affect core functionality.
6. Do We Offer Artificial Intelligence-Based Products?
We use AI for transient processing only: nothing is stored on our servers and your data is never used to train AI models. OpenAI may retain inputs and outputs for up to 30 days solely for abuse and misuse monitoring, after which they are deleted.
How We Use AI
Our AI features enable you to:
- Extract text from images
- Transcribe voice recordings to create tasks
- Process natural language for data extraction
For information about how AI features work and acceptable use, see our Terms of Service Section 5.
What Data is Sent to Our AI Service Provider
When you use AI features, the following data is temporarily sent to our AI service provider via our backend:
- Images or voice recordings (for text extraction and transcription)
- Metadata (technical information necessary for accurate data extraction)
See Section 1 for complete details.
Transient Processing
Your images and recordings pass through our servers in memory only, are never persisted to disk by Seamless.ly, and are immediately forwarded to our AI service provider for extraction. The extraction result returns to your device for review and is saved to Salesforce only if you confirm the save.
For the Seamless.ly-managed OpenAI account, optional training and evaluation data sharing and the dashboard API request-logging setting are disabled. Those settings are separate from OpenAI's abuse-monitoring retention: under the applicable API terms and account configuration, OpenAI may retain request inputs and outputs for up to 30 days for abuse and misuse monitoring unless a different approved setting applies. Post-trial customers who provide their own OpenAI API key have requests handled by their organization's OpenAI account, where their administrator controls these settings directly, and those settings also govern.
For OpenAI's own public statements about API data handling — including their default no-training-on-API-data commitment, security framework, and compliance certifications — see OpenAI's Enterprise Privacy page. Audit reports (SOC 2 Type II, ISO 27001 family) are available via the OpenAI Trust Portal. Note: certain customer-controlled retention features described on the Enterprise Privacy page apply specifically to ChatGPT Enterprise products; the API Platform retention model — which is what Seamless.ly uses — is described separately in OpenAI's API Platform documentation.
We do not send your existing CRM records (Contacts, Leads, Accounts, Opportunities, Tasks) to our AI service provider. Only the audio or image you capture and the field metadata necessary to map extracted values into the correct Salesforce fields are sent.
7. Is Your Information Transferred Internationally?
Our backend services are hosted in the United States. If you are located outside the United States, your authentication tokens and account data will be transferred to and processed in the US.
When a User invokes Scan or Speak, the Captured Input and limited Salesforce field metadata pass transiently and in memory through Seamless.ly's US-based Firebase backend to OpenAI. The resulting AI Output returns to the User's device for review and is saved to Salesforce only if the User confirms the save. Seamless.ly does not persist the Captured Input, field metadata or AI Output on its infrastructure.
Your Salesforce records stay on your device: All Contacts, Leads, Accounts, Opportunities, and Tasks remain on your device and sync directly with your Salesforce instance.
International Transfer Safeguards: Seamless.ly App Ltd is established in the United Kingdom. Transfers from the EEA and Switzerland to us are covered by the applicable adequacy decisions for the United Kingdom. Onward transfers to our sub-processors in the United States are protected by data processing agreements incorporating the EU Standard Contractual Clauses (2021) and, for UK data, the UK International Data Transfer Addendum. Our service providers maintain certifications under industry-standard security frameworks including ISO 27001 and SOC 2.
8. How Long Do We Keep Your Information?
We keep information no longer than the periods below. Device data is deleted instantly when you log out or delete the app.
Retention Periods
- Device data (CRM records) — deleted immediately when you log out or uninstall the app
- Captured images and audio, field metadata, and extraction results on our infrastructure — no persistence; discarded after the request completes
- OpenAI copies of captured inputs and extraction results — up to 30 days for abuse and misuse monitoring unless the applicable account setting provides otherwise
- Account, authentication, licensing, organization-administration, and internal customer-account data — deleted within 30 days after the relevant subscription terminates or an effective account-deletion request, subject to the categories below
- Customer-supplied API credentials — deleted within 30 days after revocation or termination
- Usage counters — reset monthly; deleted within 30 days after termination
- App telemetry — deleted or anonymized 12 months after collection
- Rejected-access and security records — 12 months after the relevant event
- Firebase user-level and event-level analytics — 14 months; genuinely aggregate, non-personal statistics may be retained longer
- Support tickets and their content — two years after ticket closure, subject to customer instructions for Customer Personal Data, a valid earlier deletion request, applicable law, or legal hold
- Non-customer website enquiries and trial/contact requests — 12 months after the last substantive interaction
- Invoices, tax records, and accounting records — six years after the end of the relevant financial year
- Backup remnants following primary deletion — up to 98 days, remaining protected and inaccessible in normal operation
9. How Do We Keep Your Information Safe?
We use industry-standard security with encryption at rest and in transit.
Security Measures
- Device storage uses platform-level encryption
- All data transmission uses TLS/HTTPS encryption
- Authentication tokens stored in secure device keychain
- No server-side storage of Salesforce records
Compliance and Certification
We have successfully passed Salesforce's AppExchange Security Review (September 2025), demonstrating our commitment to security best practices and data protection standards.
Incident Notification
If a security incident affects Customer Personal Data, Seamless.ly notifies the customer under the Data Processing Addendum, and the customer determines any notices to its personnel, other affected individuals, or regulators. If an incident affects Service Data for which Seamless.ly is Controller, Seamless.ly will assess and make any regulator or individual notifications required by applicable law. The DPA's 72-hour contractual target is not a promise that every affected individual will be notified within 72 hours.
10. Do We Collect Information From Minors?
No. Our service is for business use only. We do not knowingly collect data from anyone under 18 years of age. This is a business application designed for professional use. If we learn that we have collected information from a minor, we will delete that information immediately. Please contact us if you believe we have inadvertently collected information from a minor.
11. What Are Your Privacy Rights?
You have full control over your data. Depending on your location, you have the following rights:
Your Rights
- Access (request a copy of your personal information)
- Delete (request deletion of your account and data)
- Correct (update inaccurate information)
- Export (receive your data in a portable format)
- Object (opt out of certain processing)
- Restrict (limit how we use your information)
- Withdraw Consent (remove permission for optional features)
Immediate Control
Log out or delete the app at any time to instantly remove all local data including all Salesforce records. Your data in Salesforce remains under your control through Salesforce.
Complaints
You can lodge a complaint about our use of your personal information by emailing privacy@seamless.ly. We will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EU/EEA, to your local data protection supervisory authority.
12. Controls for Do-Not-Track Features
Our mobile application does not track users across websites. We do not engage in cross-site tracking or behavioral advertising.
13. Do United States Residents Have Specific Privacy Rights?
Yes, US residents have specific rights under state privacy laws.
Your Rights Under State Laws
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may, where the relevant state law applies, have the right to:
- Know what personal information we collect
- Access your personal data
- Correct inaccuracies
- Delete your personal data
- Opt out of sale (we do not sell personal data)
- Non-discrimination for exercising rights
US state privacy rights and obligations vary and apply only where the relevant law and thresholds cover the processing. Seamless.ly does not sell Personal Data or share it for cross-context behavioural advertising. Contact privacy@seamless.ly to exercise any applicable right.
California Residents
Under CCPA/CPRA, you have additional rights including the right to know if we sell or share personal information (we don't) and to request information about our data practices. Seamless.ly does not intentionally request sensitive personal information for its own purposes. Captured images, recordings, or support materials may incidentally contain sensitive information and are handled as described in this Policy and the DPA.
14. Do Other Regions Have Specific Privacy Rights?
Depending on your location and the law applicable to the relevant processing, you may have additional privacy rights. Contact privacy@seamless.ly and we will respond in accordance with applicable law.
15. Do We Make Updates to This Notice?
We may update this Privacy Notice from time to time. We will indicate changes by updating the "Last updated" date at the top of this notice. We encourage you to review this notice periodically. Your continued use of the Services after changes are posted constitutes acceptance of the updated notice.
16. How Can You Contact Us About This Notice?
If you have questions or comments about this notice, you may contact us at:
Seamless.ly App Ltd.
124 City Road
London, England EC1V 2NX
United Kingdom
Privacy inquiries: privacy@seamless.ly
General contact: contact@seamless.ly
17. How Can You Review, Update, or Delete Your Data?
You have several options to manage your data:
Your Options
- Immediate Deletion — Delete the app to instantly remove all local data including all Salesforce records (Contacts, Leads, Accounts, Opportunities, Tasks)
- Account Deletion — Email privacy@seamless.ly to request account deletion. We will use commercially reasonable efforts to delete your account data within 30 days of your request; certain residual data (e.g., system logs and automated backup snapshots, the latter retained for up to 98 days) may persist for the duration of standard retention cycles, after which it is deleted.
- Data Access — Contact us for a copy of your personal information
- Salesforce Data — Manage your Contacts, Leads, Accounts, Opportunities, and Tasks through your Salesforce instance directly
Data Processing Addendum
Our Data Processing Addendum (DPA) applies as part of our Terms of Service or the Master Subscription Agreement, and governs our processing of personal data on your behalf. A copy, or a countersigned copy, is available by contacting privacy@seamless.ly. Our DPA includes:
- The transfer mechanisms used for international data transfers
- Technical and organizational security measures
- Complete sub-processor list with notification obligations
- Data subject rights procedures
- Detailed data processing descriptions
The DPA describes the transfer mechanisms used for Customer Personal Data. It does not itself reproduce the EU Standard Contractual Clauses or UK Addendum. Where required, onward transfers are protected through the relevant service-provider data-processing agreement incorporating the 2021 EU SCCs and, for UK transfers, the UK Addendum, as applicable.
Copies are typically requested by enterprise customers, security auditors, and regulatory compliance reviewers.