Privacy Policy
Last updated: 27 September 2026 · Applies to clawbuildr (the service)
1. Who we are
ClawBuildr is an outbound outreach platform operated by ClawBuildr ("the operator", "we"). For questions about this policy or your data, contact us through the details in your account emails. We act as the data controller for your account data and as a processor for the prospect data you import into your own workspace.
2. What we store
- Account data: your name, email address, hashed password and role.
- Workspace data: the contacts, companies, email drafts, sequences and activity you create in your tenant. Each workspace is isolated; only accounts assigned to that workspace can see it.
- Mailbox connection: when you connect your own mailbox, we store the credentials needed to send and read email through your account. We never send from our own mailbox on your behalf without your configuration.
- Usage data: send counts, deliverability signals (bounces, complaints) and audit events, used to enforce plan limits and keep your sender reputation clean.
- Cookies: one essential session cookie (
clb_token) to keep you logged in. No advertising or tracking cookies.
3. Why we process it (legal bases)
- Contract — to provide the service you signed up for (accounts, sending, limits).
- Legitimate interest — to secure the platform (rate limiting, abuse prevention) and improve deliverability.
- Legal obligation — bookkeeping and tax records where applicable.
- Your consent — where required for optional processing; you can withdraw it at any time.
For the prospects you outreach: you are the controller and must have a lawful basis (e.g. legitimate interest under the GDPR/EU rules for B2B outreach) for your own campaigns.
4. Subprocessors
- Google (Gmail / Google Workspace) — sends and reads email strictly through the mailbox you connect.
- Stripe — payments, only once online payments are enabled; we never see your full card details.
- Search & verification providers — public web sources used for lead discovery and email verification.
- Hosting — the service runs in the EU where possible; databases are stored on our production servers.
5. Retention
Account data is kept while your account is active. When you delete your account, your workspace data is removed (immediately if you are the last user of that workspace) and any remaining backups age out within 30 days. Financial records are kept only as long as tax law requires.
6. Your rights
You have the right to access, correct, export, restrict, object to, and erase your personal data, and to lodge a complaint with your supervisory authority.
- Export:
GET /api/gdpr/export(while logged in) downloads everything this account can access as JSON. - Delete:
POST /api/gdpr/deletewith your own email address permanently deletes your account and — when you are the last user — your workspace data.
7. Security
Passwords are hashed, sessions expire, API access requires authentication, rate limits protect auth endpoints, and workspaces are structurally isolated (tenancy is enforced in queries, not hidden in the UI). No system is perfect; if we become aware of a breach affecting your data, we will notify you and the relevant authority as required by law.
8. Changes
If this policy changes materially, we will update the date above and, for registered users, notify you in the product or by email.