Privacy Policy
Last updated: 30 September 2026
In short: we collect what we need to run Pipeloom and bill for it, we keep it in the EU where we can, we don't track you with analytics or ads, and we don't sell your data.
1. Who we are
Pipeloom is operated by [legal entity name], [registered address] (“we”, “us”). This policy explains how we handle personal data when you visit getpipeloom.com, use the app at app.getpipeloom.com, or contact us.
We have two roles. For your account, billing and our correspondence with you, we are the controller. For the data your pipelines move and the connector credentials you give us (“Customer Data”), your organization is the controller and we are its processor: we handle that data only on your organization's instructions, as set out in our Terms of Service and data processing addendum.
Questions and requests: privacy@getpipeloom.com. [EU representative, if required]
2. What we collect
Account and organization
Your name, email address and password (stored only as a hash), or, if you sign in with Google, the name and email address Google shares with us. We also store your organization and workspace names, your role, and the invitations you send.
Billing
Your plan, seat count, subscription status and billing contact details. Card details are entered on Stripe's pages and held by Stripe; we never see or store full card numbers.
Usage
The runs your pipelines make and the credits they use, which we need to show your usage, enforce your allowance and spend cap, and bill overage.
Customer Data
Connector credentials you save, the pipelines and configuration you build, schemas discovered from your sources, and job logs. Records moved by a sync pass through our servers on their way to your destination and are not kept after the run, except that a job log can contain fragments of records when a connector reports an error.
AI copilot
The messages you send the copilot and its replies, kept with your pipeline so you can pick the conversation up again. Credentials you type into the chat are removed from the stored conversation.
Technical data
IP addresses, browser type and request details in the logs of our servers and of Vercel, which serves our sites, used to operate and secure the service.
Correspondence
Emails you send us, and what you tell us in them.
We don't use analytics or advertising trackers on our websites or in the app, and we don't buy personal data from third parties.
3. Why we use it, and on what basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account and providing the service, including the copilot | Performance of our contract with you or your organization |
| Billing, invoicing and collecting payment | Performance of contract; legal obligation for keeping invoices |
| Service emails: invitations, sign-in and billing notices | Performance of contract |
| Keeping the service secure, preventing abuse and fixing faults | Our legitimate interest in running a secure, reliable service |
| Answering your questions and support requests | Our legitimate interest in responding to you, or performance of contract |
| Telling you about material changes to our terms or prices | Performance of contract; legal obligation |
5. Where your data is kept
Customer Data and account data are stored on servers in the European Union (Contabo, in France). Some providers are in the United States: requests from the app pass through Vercel's network on their way to our servers, and Stripe, Resend, Google and the AI model provider process the data described on the sub-processors page there.
Transfers outside the EU and UK rely on the European Commission's Standard Contractual Clauses (and the UK addendum), or on the EU-US Data Privacy Framework where the provider is certified.
6. How long we keep it
- Account, organization and Customer Data: while your account is open, and deleted within 30 days after it is closed.
- Items you delete (a connector, a pipeline, a copilot conversation) are removed when you delete them, and from backups within [backup retention, e.g. 30 days].
- Job logs: [log retention, e.g. 30 days].
- Billing records and invoices: as long as tax and accounting law requires, typically [number of years for your jurisdiction].
- Server and request logs: up to 30 days, unless needed longer to investigate a security incident.
- Correspondence: as long as needed to deal with your request, and up to 3 years after.
7. Security
Connections to Pipeloom are encrypted with TLS. Access to production systems is limited to the people who run the service, and connector credentials are kept separate from pipeline configuration and are never shown back in the app once saved. No system is perfectly secure; if a breach affects your personal data, we will tell you and the relevant authorities as the law requires. Report vulnerabilities to security@getpipeloom.com.
8. Your rights
Depending on where you live, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or give it to you in a portable format. Email privacy@getpipeloom.com from the address on your account; we will reply within one month. You can update most account details yourself in the app.
If your data is in Customer Data (for example, your details are in a system someone syncs with Pipeloom), please contact the organization that uses Pipeloom, which controls that data; we will help them respond.
You can also complain to your local data protection authority. We would appreciate the chance to resolve your concern first.
10. Children
Pipeloom is a business service for people aged 18 and over. We don't knowingly collect data from children.
11. Changes to this policy
If we change this policy in a way that matters, we will email organization administrators before the change takes effect. The date at the top shows when it last changed.