Legal
Privacy Policy
Last updated: October 1, 2026
1. Who we are
TillQuest (“TillQuest,” “we,” “us,” or “our”) provides a multi-tenant B2B CRM and outreach platform at tillquest.com (marketing) and app.tillquest.com (product). This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our websites, create a workspace, or use the Service.
For questions, contact support@tillquest.com.
2. Roles: controller vs. processor
- Account & billing data. When you sign up, we act as a controller for your account profile, authentication, and billing records.
- Workspace CRM data. Content you import or create in a workspace (organizations, people, notes, outreach history, suppressions, etc.) is processed on behalf of the customer workspace. The workspace customer is typically the controller; TillQuest is the processor.
3. Information we collect
Account & workspace administration
- Name, email address, password (hashed), and workspace membership details
- Company name, workspace slug, and industry pack selection
- Billing identifiers and subscription status via our payment provider (Stripe)
Customer CRM & outreach content
- Organization and person records, pipeline stages, notes, tasks, and exports
- Email, SMS, and call metadata generated through connected tools
- Suppression lists, consent flags, and privacy request records
Integrations & enrichment
- Credentials and OAuth tokens for workspace tools you connect (for example Gmail, Microsoft 365, SMTP/IMAP, Twilio, Calendly, Cal.com)
- Discovery and enrichment results from platform data sources (for example Google Places, Brave Search, Apollo, NeverBounce, Claude, website crawlers), metered in prepaid credits
Technical & usage data
- IP address, device/browser type, approximate location derived from IP, and logs
- Product analytics events needed to operate and secure the Service
4. How we use information
- Provide, maintain, and improve the Service
- Authenticate users, enforce roles, and prevent abuse
- Process subscriptions, trials, invoices, and credit-pack purchases
- Run discovery, enrichment, verification, and outreach features you enable
- Comply with law, respond to lawful requests, and enforce our Terms and AUP
- Send transactional messages (security alerts, billing notices, product updates)
We do not sell personal information. We do not use one customer’s CRM records to enrich another customer’s workspace.
5. Sharing & subprocessors
We share information with:
- Infrastructure & ops providers (hosting, databases, queues, email delivery for transactional mail, error monitoring)
- Stripe for payment processing and subscription management
- Integration providers you connect or enable, under their terms (mailbox providers, Twilio, scheduling tools, and platform enrichment APIs)
- Professional advisors or authorities when required by law or to protect rights and safety
Where Google services are used (for example Google Places or Gmail OAuth), processing is also subject to Google’s applicable terms and policies.
6. Retention
We retain account and billing records for as long as your workspace remains active and as needed for legal, tax, and accounting obligations. Workspace CRM data is retained until the customer deletes it or the workspace is closed, subject to backup and audit-retention windows defined by the customer’s seat plan. Platform crawl caches and similar operational caches are retained only for limited periods consistent with product configuration.
7. Security
We use industry-standard measures appropriate to a multi-tenant SaaS product, including encryption in transit (HTTPS/TLS), host isolation by workspace, access controls, and audit logging. No method of transmission or storage is 100% secure; please use strong passwords and protect API tokens and mailbox credentials.
8. Your choices & rights
- Workspace administrators can manage members, integrations, suppressions, and privacy requests from Settings → Privacy in the product.
- Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Contact support@tillquest.com or use in-product privacy tools where available.
- You may unsubscribe from non-transactional emails using the links in those messages.
9. International transfers
We may process data in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms for cross-border transfers.
10. Children
The Service is designed for business users. It is not directed to children under 16, and we do not knowingly collect personal information from children.
11. Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated in-product or by email to workspace owners.
12. Contact
TillQuest · Privacy inquiries · support@tillquest.com
Related documents: Terms of Service · Acceptable Use Policy