Privacy Policy
Last updated: October 2, 2026
This policy explains how DeskPine (“we”, “us”) handles personal data when you use our website and customer-support application (the “Service”). We act as a data controller for our own customers’ account data, and as a data processor for the support messages our customers manage through the Service on behalf of their own end-users.
Data we collect
- Account data — name, email, hashed password, workspace and team details.
- Support content — the emails, attachments, customer profiles and notes that flow through your shared inbox. This may contain personal data of your customers; you are the controller of that data and we process it on your instructions.
- Billing data — handled by our payment processor, Stripe. We store only subscription metadata (plan, seat count), never full card numbers.
- Email engagement — when open/click tracking is enabled on a mailbox, replies include a tracking pixel and wrapped links so agents can see whether a message was opened or a link clicked. This can be turned off per mailbox.
- Usage & analytics — anonymous, aggregated analytics (Google Analytics) and basic server logs to operate and improve the Service.
How we use it
- To provide, secure and support the Service.
- To process payments and manage subscriptions.
- To send transactional email (replies, notifications, password resets).
- To detect abuse and keep the Service reliable.
We do not sell personal data, and we do not use the content of your support inbox for advertising.
Gmail and Google user data
This section covers the Google user data DeskPine handles when a team connects a Gmail or Google Workspace mailbox with “Continue with Google” / “Connect Gmail”. It applies only to that data, in addition to the rest of this policy.
What Google user data we access
- Email messages in the connected mailbox (scope
https://mail.google.com/): the messages that arrive in its inbox from the moment you connect it, including their sender, recipients, subject, body and attachments. We do not read mail that was already in the mailbox before you connected it. - Sending as that address (same scope): we send the replies your team writes in DeskPine, from the connected address.
- Your Google account email address (scopes
userinfo.emailandopenid): to know which mailbox was connected.
We do not access your contacts, calendar, Drive files or any other Google data.
How we use Google user data
- To show each incoming email as a conversation in your team’s shared inbox, thread replies to it, and let your team assign, tag, search and report on it.
- To send the replies your team writes, from the connected address.
- To produce an AI reply draft or summary of a conversation, only when an agent asks for one.
We do not use Google user data for advertising, we do not sell it, and we do not use it to train or improve AI or machine-learning models, ours or anyone else’s.
How we share Google user data
- With the members of your DeskPine workspace, who see the conversations in the shared inbox.
- With the service providers that run DeskPine on our behalf: DigitalOcean (hosting and database) and, when an agent asks for an AI draft or summary, OpenAI, which receives that conversation’s text for that request only and does not use it to train models.
- When required by law, or to protect the security of the Service and its users.
We do not share Google user data with anyone else, and no person at DeskPine reads your mail unless you ask us to for support.
How we protect Google user data
- OAuth access and refresh tokens are encrypted at rest and never shown to anyone, including your workspace admins.
- All traffic is encrypted in transit (TLS/HSTS), and each workspace’s data is isolated from every other workspace.
- Access to production systems is limited to the people who operate the Service.
How long we keep it, and how to delete it
- Conversations and attachments are kept while the mailbox stays connected and your workspace exists, so your team keeps its support history.
- Deleting the channel (Settings → Email channels) deletes its conversations and stored tokens and revokes our access at Google immediately.
- Deleting your workspace deletes all of its data, including every connected mailbox’s messages and tokens, and revokes our access at Google.
- You can revoke our access at any time from your Google Account’s third-party access page; we then stop reading and sending mail for that mailbox. To have the data already stored deleted, delete the channel or contact privacy@deskpine.app.
- Copies in our encrypted database backups disappear as those backups roll off, on a limited rolling window.
Limited Use
DeskPine’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies & tracking
We use a strictly-necessary session cookie to keep you signed in, and analytics cookies to measure site usage. Email open/click tracking is a feature you control per mailbox and can disable at any time.
Sub-processors
- Stripe — payment processing.
- DigitalOcean — hosting (servers and database).
- Google Analytics — aggregate website analytics.
- Email delivery providers — to send and receive your support email.
- OpenAI — generates AI reply drafts and summaries when an agent asks for one; the conversation text is sent for that request only and is not used to train models.
Data retention
We keep account and support data for as long as your workspace is active. On account closure we delete or anonymize personal data within a reasonable period, except where we must retain it to meet legal or accounting obligations. We keep encrypted database backups for a limited rolling window.
Your rights
Depending on your location (e.g. GDPR/CCPA), you may have the right to access, correct, export or delete your personal data, or object to certain processing. To exercise these rights, contact us. If you are an end-user of one of our customers, please contact that business (the data controller) first.
Security
Connections are encrypted in transit (TLS/HSTS). Passwords are hashed, secrets are encrypted at rest, and each workspace’s data is isolated. No system is perfectly secure, but we work to protect your data and to notify you of material incidents.
Contact
Questions or requests: privacy@deskpine.app or via our contact page.