WARM Systems - Privacy Policy

Last Updated: January 26, 2026

Overview

WARM Systems LLC ("we," "us," "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI-powered sales automation platform.

1. Information We Collect

Information You Provide

  • Account Information: Name, email address, company name, job title

  • Payment Information: Billing address, payment method (processed by Stripe)

  • Company Profile: Company description, products/services, target industries, differentiators

  • Communication Preferences: Tone settings, sign-off preferences, working hours

Information from Connected Services

When you connect your CRM (HubSpot or Salesforce), we access:

  • Contact and company records

  • Deal/opportunity data

  • Activity history and notes

  • Email communications (as permitted by your CRM settings)

Automatically Collected Information

  • Usage Data: Features used, actions taken, timestamps

  • Device Information: Browser type, operating system, IP address

  • Analytics: Page views, session duration, referral sources

2. How We Use Your Information

We use your information to:

  • Provide and improve the Service

  • Generate AI-powered sales communications

  • Analyze CRM data for insights and recommendations

  • Process payments and manage subscriptions

  • Send service-related communications

  • Ensure security and prevent fraud

  • Comply with legal obligations

3. Google API Data Disclosure

This section specifically addresses how WARM Systems handles data accessed through Google APIs (Gmail).

Data Accessed

When you connect your Google account, WARM Systems accesses:

  • Gmail Send Scope: Permission to send emails on your behalf through the Gmail API

  • User Email Address: Your Gmail address for sender identification

Data Usage

Google user data is used exclusively to:

  • Send AI-generated sales emails that you have reviewed and approved

  • Log email send confirmations to your connected CRM (HubSpot or Salesforce)

WARM Systems does not use Google user data for advertising, market research, or any purpose unrelated to the core email sending functionality.

Data Sharing

Google user data is:

  • Never sold to third parties

  • Never shared for advertising purposes

  • Only transmitted to your connected CRM for activity logging

  • Processed by our infrastructure providers (Supabase, Vercel) solely to deliver the Service

Data Storage & Protection

  • Emails are sent directly through the Gmail API and are not stored on our servers

  • OAuth tokens are encrypted at rest (AES-256) and stored securely in our database

  • Access tokens are refreshed automatically; refresh tokens are stored with row-level security ensuring tenant isolation

  • All API communications use TLS 1.2+ encryption

Data Retention & Deletion

  • Gmail OAuth tokens are retained only while your account is active

  • Upon disconnecting your Google account or canceling your WARM subscription, OAuth tokens are deleted within 24 hours

  • To request immediate deletion of your Google-related data, contact privacy@warmsystems.ai

  • You can also revoke access at any time through your Google Account permissions (https://myaccount.google.com/permissions)

4. AI Processing

Our AI systems process your data to:

  • Generate personalized email content

  • Identify opportunities for re-engagement (Lazarus Brain)

  • Validate outputs for brand safety (Compliance Officer)

  • Analyze CRM data quality (SCRUB Engine)

Important: All AI-generated content is provided for your review before sending. You maintain full control over what communications are sent.

5. Data Sharing

We do NOT sell your personal information. We share data only with:

Service Providers

  • Supabase: Database and authentication

  • Vercel: Application hosting

  • Stripe: Payment processing

  • OpenAI: AI model provider

  • Email Services: For sending approved communications

Legal Requirements

We may disclose information if required by law, court order, or to protect our rights and safety.

Business Transfers

In the event of a merger, acquisition, or sale, your data may be transferred to the successor entity.

6. Data Retention

We retain your data for as long as your account is active. Upon cancellation:

  • Account data is deleted within 30 days

  • Backups are purged within 90 days

  • Aggregated, anonymized data may be retained for analytics

You may request data deletion at any time by contacting us.

7. Data Security

We implement industry-standard security measures:

  • Encryption: TLS in transit, AES-256 at rest

  • Access Control: Role-based permissions, multi-factor authentication

  • Infrastructure: SOC 2 compliant hosting (Supabase, Vercel)

  • Row-Level Security: PostgreSQL RLS ensures tenant data isolation

  • Audit Trails: Complete logging of AI decisions and data access

8. Your Rights

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data

  • Correction: Update inaccurate information

  • Deletion: Request removal of your data

  • Portability: Receive your data in a structured format

  • Objection: Opt out of certain processing activities

  • Restriction: Limit how we use your data

To exercise these rights, contact us at privacy@warmsystems.ai.

9. California Privacy Rights (CCPA)

California residents have additional rights:

  • Right to know what personal information is collected

  • Right to delete personal information

  • Right to opt out of sale of personal information (we do not sell data)

  • Right to non-discrimination for exercising privacy rights

10. International Data Transfers

If you are located outside the United States, your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place to protect your data.

11. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Functions: Authentication, security, preferences

  • Analytics: Understanding usage patterns (Google Analytics)

You can control cookies through your browser settings. Disabling cookies may affect Service functionality.

12. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these sites.

13. Children's Privacy

The Service is not intended for individuals under 18. We do not knowingly collect information from children.

14. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Service. Your continued use constitutes acceptance of the updated policy.

15. Contact Us

For privacy-related questions or requests:

WARM Systems LLC Email: legal@warmsystems.ai

For data protection inquiries, you may also contact your local data protection authority.

By using WARM Systems, you acknowledge that you have read and understood this Privacy Policy.