Legal
Privacy Policy
Effective 9 October 2026
This policy explains what personal data PitchWhip Ltd collects, why, who sees it, how long we keep it, and the rights you have over it. It covers this website, the customer portal, the PitchWhip Chrome extension and the PitchWhip Cloud services behind it.
1. Who we are
PitchWhip is operated by PitchWhip Ltd, a company registered in England and Wales (company number 17389184). Registered office: 96A Wandsworth Bridge Road, London SW6 2TF, United Kingdom. For the personal data described in this policy where we decide the purposes and means of processing, PitchWhip Ltd is the controller. We have not appointed a Data Protection Officer because we are not required to; privacy questions go to hello@pitchwhip.com. A human answers, usually within two working days.
Two related documents sit alongside this policy: our Terms of Use (the commercial terms) and our Data Processing Agreement (which governs the data we process on your behalf, as your processor). Cookies are covered in the Cookie Policy.
2. The short version
PitchWhip is a Chrome extension for sales professionals. Most of what it does still happens in your browser and in your own Google account. Since August 2026 we also run a small set of cloud services (PitchWhip Cloud). Per licence, they hold your reveal credit balance, the prospect contacts you have chosen to reveal, your own call log and your team settings. If you use them, they also hold your sequences, contact lists and campaign material. All of it is there so that it survives a device change and can be shown in the customer portal. That data is yours. It is readable only with your licence (and, if you join a team, by your team-mates to the extent described below). If your account calls from PitchWhip, they also hold a record of each call you dial and, only where your account switches them on, its recording and transcript (section 5.8). We process it only on your instructions, and it is deleted when your licence ends. We do not sell personal data or train AI models on it. We do not use these customer and prospect records for advertising. Optional website ad measurement is described in section 5.1.
Two things work differently, and we want them visible up here rather than buried. PitchWhip has a prospect index: professional details of people who may be worth contacting, drawn from profiles already published on the web, in which records could be shown to more than one customer. It is switched off at both ends today: nothing is collected and nothing is sent, and it holds no records. Where it operates we are the controller, not your processor. It is scoped to business contact information, records expire, and anyone listed can have themselves removed in one email, a route that works today regardless. Section 8 explains it, and the notice for prospects is written for the people in it rather than for you. The second is the Companies House search in Find companies (section 5.10). We run it as the controller, and it keeps people’s details from the public register for 24 hours. The third is Find investors (section 5.11), which we also run as the controller. It reads shareholder lists from the same register, and it never shows or keeps a private shareholder’s name.
3. Who this policy covers
This policy is written for four groups of people:
- Visitors to pitchwhip.com.
- Customers and users: people who buy a licence, use the extension, or log in to the customer portal, including members of a team plan.
- Prospects: people whose LinkedIn or Sales Navigator profile a user views, researches, reveals contact details for, or calls using PitchWhip. They also include company directors and owners a user finds on the Companies House register (5.10). They also include people who hold shares in UK companies whose shareholder lists Find investors reads (5.11). If that is you, section 7 and section 13 explain how your data reaches us and what to do about it.
- Enquirers: anyone who emails us or fills in a form on the site.
4. Controller or processor: our role for each kind of data
Data-protection law distinguishes a controller (who decides why and how data is processed) from a processor (who processes it on the controller’s instructions). PitchWhip wears both hats, and it matters which one:
| Data | Our role | Governed by |
|---|---|---|
| Customer account data: licence key and status, purchaser name and email, billing state, support correspondence, portal login. | Controller | This policy |
| Website data: technical logs, aggregate analytics, form submissions, cookies. | Controller | This policy and the Cookie Policy |
| PitchWhip Cloud data: your call log, revealed prospect contacts, reveal results cache, team display name and settings. If you use them: sequences and the people in them, contact lists, campaign images, learnings, campaign delivery events and (if you switch it on) open records. If you call from PitchWhip: dialled-call records and, where switched on, recordings and saved call transcripts (5.8). | Processor (you, or your organisation, are the controller) | The DPA; this policy describes the mechanics |
| Prospect index (currently switched off, nothing collected, nothing sent, no records held): professional details of people who may be worth contacting, from profiles published on the web, which could be shown to more than one customer. | Controller (this one is ours, not yours) | This policy and the notice to prospects |
| Find companies: the names, age bands and ownership of company directors and owners, read from the Companies House register and shown to you when you search (5.10). | Controller for the search and its short cache; you are the controller of anything you keep or do with a result | This policy and the notice to prospects |
| Find investors: the shareholder lists of UK companies and the owners of investing companies, read from the Companies House register to name investment firms and count private shareholders (5.11). No private person’s name is shown or kept. | Controller for the search and what it keeps; you are the controller of anything you keep or do with a result | This policy and the notice to prospects |
| Reveal requests: the name, company and LinkedIn URL sent to our data supplier to find a phone number or email address. | Processor for the request, with the supplier as our sub-processor; the supplier is also an independent controller of its own database | The DPA |
| AI generation inputs: profile text and your pitch context and, when you use the live-call features, call transcript text, your coaching lessons and call outcomes, and Redo instructions. Sent through our proxy to generate call preparation, live suggestions, summaries and coaching. | Processor. Transient: we keep none of the content, except the feedback and quality-telemetry records in 5.3 and, where switched on, saved transcripts of dialled calls (5.8). | The DPA |
| Calls you dial from PitchWhip: the number called, kept with the call’s record, the call audio in transit, and recordings where your account switches recording on. | Processor (you, or your organisation, are the controller); Twilio is our sub-processor | The DPA; section 5.8 below |
| Our block list and removal requests: a one-way fingerprint of each profile a person asked us to keep out, and the requests themselves. | Controller (we keep it so that a removal stays a removal) | This policy and the notice to prospects |
| Team Learning: anonymised objection/rebuttal pairs shared inside a team or with the community. | Controller of the anonymised pool (it contains no personal data, because names, companies and contact details are stripped before storage; see 5.6) | This policy |
| Payments: card details, invoices, tax location. | Lemon Squeezy is the merchant of record and controller; we never see card numbers | Lemon Squeezy’s privacy policy |
5. What we collect, why, and for how long
Below is everything we process, grouped by activity, with the lawful basis we rely on under UK GDPR and EU GDPR and how long we keep it. Where the basis is legitimate interests we have balanced our interest against your rights; you can object at any time (section 13).
5.1 Visiting the website
| Data | Why | Lawful basis | Retention |
|---|---|---|---|
| Standard request logs: IP address, user agent, pages requested, timestamps. | To serve the site, keep it secure and diagnose faults. Held by our host, Vercel. | Legitimate interests (running a secure website). | Short rolling window set by our host: typically days, not months. |
| Approximate country, derived from your IP address at the edge and stored in the pw_geo cookie as a two-letter code only. | To help decide whether to ask for consent. Visitors in the UK, EU/EEA and Switzerland are asked; campaign-tagged and Reddit ad arrivals are also asked in every country. | Legitimate interests (meeting consent obligations without asking everyone). | Cookie lifetime; the IP address is not stored by us. |
| Aggregate web analytics (Vercel Web Analytics): page views, referrers, device type, country. No cookies, no cross-site identifiers. | To understand which pages are useful and where visitors come from. | Consent, where your country requires it (you can reject in the banner). Elsewhere: legitimate interests. | Aggregate statistics only; no individual-level record is kept by us. |
| After optional measurement consent: the landing campaign tags and, for a Reddit ad, its click identifier (rdt_cid). An opaque reference connects the visit to a verified paid order, its amount, tax, currency and time. For eligible Reddit ad visits we report button clicks and confirmed purchases with a deduplication identifier. We add no email, licence key, IP address, user agent or full page URL to Reddit payloads. | To distinguish button clicks from verified purchases and assess campaign revenue. Campaign labels without an eligible Reddit click ID stay in our internal purchase report and are not sent to Reddit. We do not infer a missing source from the buyer’s location, email or device. No Reddit tracking script runs in your browser. | Consent. Pending campaign information stays in page memory. The new purchase-measurement notice requires explicit acceptance, including for people who previously accepted button-click reporting. Refusing stops new checkout associations. Once our server receives the withdrawal, it revokes the association and cancels pending purchase sends. If the request temporarily fails, the browser retains only what is needed to retry when you return or refocus the page and does not attach the reference to a new checkout. Requests already sent may finish and cannot be recalled by the banner; contact us about deletion. | The opaque browser reference and raw server click identifier expire within 28 days of registration following acceptance; untagged returns do not extend this. Withdrawal clears the server click ID and campaign labels. Minimal order reconciliation records and hashed reference/revocation records are kept for up to 90 days; billing records have their separate retention described below. Existing button-click rate-limit counters expire after 48 hours. Reddit controls retention of data it receives. |
| Enquiry forms (founding-cohort list, team pricing form): your email address, and on the team form your name, company and team size. | To reply to you and onboard you. | Legitimate interests (responding to a request you made); consent for any marketing follow-up. | Until we have replied and, if you become a customer, for the life of the relationship; otherwise up to 24 months from last contact. |
| Reports of illegal content (the form on our Digital Services Act page, or email). Your name and email address, if you give them, and any organisation you report for. Where the content is, why you believe it is illegal, and your good-faith statement. What the report says about other people, which can include a suspected crime or sensitive details such as someone's health or religion, and our decision. For a form report, the internet (IP) address it came from, kept only as a one-way code to limit how many reports one connection can send in a day. We delete that code after two days. | To assess and act on the report, confirm we received it, tell you our decision and keep a record of how we handled it, as the EU Digital Services Act requires. To tell the police where Article 18 of that Act, or UK law, requires it. To tell the user whose content was reported who reported it, but only where that is strictly necessary, for example to answer a copyright claim. We never do this for a report of child sexual abuse or of a threat to someone's safety. | EU GDPR: legal obligation (Digital Services Act, Articles 16 to 18). UK GDPR: legitimate interests (keeping illegal content out of PitchWhip, and meeting the EU rules that apply to it). Information about suspected crimes, and any sensitive details: the condition for preventing or detecting unlawful acts (Data Protection Act 2018, Schedule 1, paragraph 10), under our appropriate policy document. | 12 months after our decision (or after the report arrives, if we never make one), or longer where the police ask us to keep evidence. |
| Install-link form (the “email me the link” box in the footer): your email address, and the IP address the request came from. A copy of the address is emailed to hello@pitchwhip.com. | To send you the Chrome Web Store link, and with it any free-trial key issued for that address; to cap how many link emails one address or one visitor can ask for in a day; and so we know someone has raised a hand. | Legitimate interests (answering a request you made, and keeping an open form from being abused). | Held with the trial-key record for that address, so a second key cannot be issued for it. The IP address is an abuse signal only and is never used to look you up. Ask us and we will remove the address, leaving only its one-way hash. |
| Optional PitchWhip setup emails: your email address, the form and disclosure version you agreed to, confirmation and send timestamps, and delivery and stop records. | If you select setup emails and confirm from your inbox, to send up to five messages about getting started and choosing a plan. Requesting an install link or claiming free lookups alone does not subscribe you. Login, support and prospect email fields do not subscribe you either. | Consent for setup emails. Legitimate interests for confirmation, delivery records and a do-not-email list that prevents unwanted messages. Unsubscribe in any message or reply to stop the remaining setup emails. Purchase, a hard bounce or a spam complaint also stops this series. | Confirmation links expire after 24 hours; unconfirmed pending records are deleted after 30 days. Confirmed consent, send and stop records remain after the series ends to avoid duplicate or unwanted email. You can request deletion; we keep the minimum do-not-email record needed to honour your choice. |
| Product updates and personalised offers to free work-email accounts: the work email address you signed up with, the version of the sign-up notice you were shown and when, send timestamps, and delivery and stop records. | Free accounts are for work email addresses only. When you create one with the sign-up form, which tells you so at the time, we email you product updates and personalised offers about PitchWhip. Every other sign-up (the install-link box, the free-lookups claim in the extension, personal addresses) needs your opt-in, as in the row above. | Legitimate interests (telling business users of a free account about the product and offers relevant to them). This is not based on consent: you can object at any time, with the one-click unsubscribe in every email or by replying, and we stop all of these emails for good. Purchase, a hard bounce or a spam complaint also stops them. | Kept while your free account is open. Send and stop records remain afterwards so we never email you again after you unsubscribe. You can request deletion; we keep the minimum do-not-email record needed to honour your objection. |
Replies to PitchWhip setup emails pass through a tagged reply address on replies.pitchwhip.com. Our Worker records the stop and forwards your message to hello@pitchwhip.com so a person can help. This is separate from the reply handling for sequences you send to your own prospects.
5.2 Buying and holding a licence
| Data | Why | Lawful basis | Retention |
|---|---|---|---|
| Purchase details from Lemon Squeezy: your name, email address, product/variant, order and subscription identifiers, licence key, and licence status and expiry. For billing display in the portal, card brand and last four digits. | To issue, validate and support your licence, show your subscription in the portal, and attribute credit-pack purchases to your licence. | Contract (providing what you bought). | Cloud records: life of the licence, then deleted on request or otherwise within 90 days of the licence ending (section 11). Order and refund records: up to 6 years for accounting and tax. |
| Licence validation: your licence key and a random per-device identifier, sent by the extension to us and to Lemon Squeezy. | To confirm the key is active and enforce the two-device seat limit. We cache the verdict briefly so validation is fast. | Contract. | Cached verdicts expire within hours; validation counters expire the following day. |
| Extension install records: the extension's random device identifier, each event, the extension version and the time. Events are installing, setup steps such as a first script or first logged call, giving a work email to claim free lookups, and uninstalling. If you answer the short survey shown after you uninstall, your reason and any words you add. On the install record only, the approximate country our network provider derives from the request's IP address, but not the IP address itself, a city or any precise location. | To understand how many people install and use the extension and why they leave, to stop setup emails once they no longer apply. | Legitimate interests. | Deleted 180 days after the device's last event. |
| Referral credits, where available: an opaque referral code linked to the referring billing account, and the referred purchase's customer, order and subscription identifiers, eligibility checks and reward ledger entry. We use a hash of the purchaser's email to prevent repeated or self-referrals. | To check whether a first paid subscription qualifies, wait for the refund hold period and add eligible credits once. The referring customer sees their code and reward counts, not the new customer's name or email. No friend email address is collected or messaged by this feature. | Contract for the referral reward; legitimate interests for preventing duplicate or abusive claims. | Reward, eligibility and duplicate-prevention records are retained for accounting and administering the program. They are not automatically deleted when a claim finishes. You can ask us to remove personal data, subject to the minimum accounting and duplicate-prevention records we must retain. |
| Support correspondence: whatever you send us and our replies. | To help you. | Contract and legitimate interests (keeping a record of what was agreed). | Up to 24 months after the matter closes, longer if needed for a legal claim. |
5.3 Using the extension: AI generation and metering
When you generate a brief, opener, objection handle, coaching note or similar, the extension sends the LinkedIn or Sales Navigator profile text on your screen, together with your pitch context. It goes through our API proxy (a Cloudflare Worker) to Anthropic’s API, which generates the text. The live-call features send more through the same route. If you turn on live transcription, the transcript of the call so far (the prospect’s words as well as yours) is sent for live suggestions. This applies both to Call mode, where you speak on your own phone, and to a call you dial from PitchWhip. On a dialled call both sides of the conversation are transcribed; in Call mode the other person is included only if they are on loudspeaker. The full call transcript is sent for the post-call summary and coaching, for call replay and, if you enable it, for voice learning. The weekly review sends, for each recent call, the coaching lessons and improvement points, the prospect’s company, the outcome and any hang-up reason. And a Redo instruction you type is sent with the request it refines. If you press Write it to draft a follow-up email, your free-text call note and drafting instruction are sent through the same route to the AI model. Any available call transcript and summary are included too. Our proxy exists so that you do not need your own API key. It forwards each request and streams the answer back; it does not store the content of requests or responses (except quality telemetry, described below, and the code suggestions in 5.10). What it does keep is metering, so that fair-use limits work: token counts per day keyed by your licence key. On the free tier the key is a random device identifier and your IP address, with IPv6 addresses truncated to their /64 prefix. Anthropic processes API inputs under its commercial terms and does not use them to train its models; see Anthropic’s privacy policy. Lawful basis: contract (for licensed users) and legitimate interests (offering a limited free tier, preventing abuse and understanding our costs). Retention: the counters that enforce the daily limits expire within three days. For licensed users we also keep a daily usage record for each licence: how many requests, tokens and web searches each feature used, filed under a one-way hash of your licence key and never containing what you asked or what came back. We keep it for 400 days, to understand our costs and set fair limits.
Web search. Two features ask Anthropic to search the open web as part of answering, using Anthropic’s own server-side search tool. We do not choose or contract with the search engine behind it; the query goes to Anthropic and Anthropic performs the search. First, Enrich, which you press: it searches for public information about the prospect’s company (recent news, their website, public coverage) to judge the buying signals you have defined, and cites its sources. Second, and this one is automatic. When a call is synced to your CRM sheet and the industry, headcount or head-office country is missing, the extension looks the company up so those columns are not blank. That automatic lookup sends the company name and, if known, the contact’s job title. Not their name, not their profile URL, and not your notes. It runs only when you have a Google Sheets sync configured, and is capped at two searches per company. The result is cached so the same company is not looked up twice.
Feedback and quality telemetry. Two things from the extension are stored, keyed to your licence key, in the same Cloudflare database as your cloud data. The first is feedback: text you choose to send us with the “Also send to PitchWhip” button after a Redo. The second is quality telemetry. When our automatic writing checks flag a generated script, the extension sends us a diagnostic record: the identifiers of the rules that fired, which opener style was used, and timings. It does not contain the script itself, the prospect, or anything you wrote. Earlier versions sent short excerpts of the flagged opener; they no longer do. We use both only to tune our writing rules; they are never shown to other users and never used to train AI models. Lawful basis: legitimate interests (improving the product). Retention: until you ask us to delete them, and otherwise for as long as we still need them for tuning; email hello@pitchwhip.com and we will remove every row for your licence.
Install and setup events. The extension tells our server when it is installed and when you first reach a few milestones (for example your first script, or the free daily limit), and the page shown after you uninstall tells us that it was removed, with any reason you choose to give. Each record holds the extension’s random device identifier, its version and a time; a free-lookup claim also records the work email you gave. On the install record only, we also store the approximate country, as our network provider (Cloudflare) derives it from the request’s IP address. We do not store the IP address, a city or any precise location with it. The extension counts installs and first uses, with a random device identifier and the country of the install, to improve the product. You can stop this at any time in Settings with “Send usage statistics”; switching it off also deletes the counts already sent from that device. Error reports are still sent, including a short technical report when a call through PitchWhip fails, because we need them to find and fix faults in the service you use. So is anything you choose to send us. Lawful basis: legitimate interests (improving the product). Retention: deleted 180 days after the device’s last recorded event.
Error reports and bug reports. When something goes wrong, the extension sends us an automatic error report: its version, a fixed error code, the steps it reached and how long they took, and a code for your installation that changes every day, so one installation cannot be followed from day to day. If a company page could not be read, the report also names the company, its LinkedIn page and its website. Error reports never contain page text, a person’s details, a profile address or your licence key. Where the extension offers to send a diagnostic report, it is sent only when you press Send, on a screen that shows what will go: the company and LinkedIn address involved, each step, a reference shown to you, and a one-way hash of your licence key. We also count, each day, how often our page readers succeed, using a separate daily installation code. We keep error and diagnostic reports for 30 days, the daily installation codes for 35 days, and counts that identify nobody for 400 days. If you use Report a bug, we receive what you write, any technical details you choose to include, a reply-to email address if you give one, the extension’s random device identifier and your licence key. We also email a copy, with your licence key shortened, to hello@pitchwhip.com. We keep bug reports until you ask us to delete them (we are setting a fixed period), and the emailed copy for up to 24 months from last contact. Lawful basis: legitimate interests (keeping the product working and answering your report).
5.4 PitchWhip Cloud: your call log, reveals and team
These are the records we hold on your behalf, per licence key. You are the controller of the personal data inside them; we are your processor under the DPA. They exist so that your data survives a device change and can be shown in the customer portal.
| Data | Why | Basis (for you) / role (for us) | Retention |
|---|---|---|---|
| Reveal credit ledger: grants, purchases, spends and refunds of reveal credits, with order identifiers and (for pack attribution) your purchaser email. No prospect data. | To keep an accurate balance you can rely on and to honour refunds. | Contract. | Life of the licence, then deleted on request or otherwise within 90 days of the licence ending; purchase and refund entries up to 6 years for accounting. |
| Revealed contacts: for each prospect you chose to reveal, the name, company, LinkedIn URL, the phone number(s) and/or email address(es) found, status and time. | So a second reveal of the same person is free, and so your revealed contacts survive a device change and appear in the portal. | You are the controller (see section 7); we process on your instruction. | Life of the licence, then deleted on request or otherwise within 90 days of the licence ending. |
| Licence vault: a per-licence snapshot of what makes your copy of PitchWhip yours, so it survives a reinstall or a new machine. It holds your voice profile and coaching lessons, your notes to self, your saved objection phrasings and your queued prospects. It also holds the discovery finds bank and its bin, and the id of your connected CRM sheet. For each find, the bank holds the name, company, title, the why-now line, the verifying quote and its source URL, fit and timing verdicts, and which pitch profile found them. The finds bank and bin also power the read-only Found for you view in the portal. | Licence carryover across devices, and the portal's Found for you view. | Contract; for the prospect data inside it you are the controller (see section 7) and we process on your instruction. | Life of the licence, then deleted on request or otherwise within 90 days of the licence ending. |
| Call log: for each call you log, the prospect name, company, title, LinkedIn URL and country (as shown on their profile), the outcome, duration, callback date and time, meeting date and time, the time of the call and your display name. It also holds what PitchWhip's AI worked out for that call: fit and timing scores, the angle chosen, the “why now” line and the names of the buying signals it found (calls logged by older versions may also carry a single call score). Private extension call notes and per-call coaching text are excluded, and so are transcripts unless your account has switched on transcript saving for dialled calls (5.8). Your coaching lessons and notes to self are stored separately in the licence vault above. | To show your stats and history in the portal and, if you are in a team with call visibility on (the default), to share it with your team. The extension flags on a prospect's brief that a team-mate has already called (who, when, outcome, callback date). Every member, not only the admin, can view and export the team's combined call log in the portal (prospect name, company, title, LinkedIn URL, when, outcome, duration, callback date and who called). | You are the controller; we process on your instruction. | Life of the licence, then deleted on request or otherwise within 90 days of the licence ending. |
| Dashboard-authored shared notes: the text you explicitly write for your own call, its revision, selected export destinations and sync status. These notes are separate from private extension notes and transcripts. Those are not imported, with one exception: where your account has switched on transcript saving for dialled calls, that call's transcript is stored by us as described in 5.8. | To keep a note with your call and, only when you select a destination for that note, request export to HubSpot, Salesforce or Google Sheets. Turning a destination off stops future sync and does not erase earlier exports. Clearing a note requests clearing of known copies only for destinations still selected. Sheets text may remain until the extension updates it; uncertain or manually changed CRM records need review. | You are the controller; we process on your instruction. | The current note stays with the owning call until you clear it or delete the call. Sync records can retain the last-exported note text and record identifiers while a destination is off or an update is unconfirmed, so we can check later changes without overwriting other content. Deleting the call clears the current note and copied note text from PitchWhip's sync records; record identifiers and error history may remain. Existing CRM or Sheets copies are not deleted. |
| Dialled calls: for each call placed through PitchWhip, the time, who dialled and from which device, and the minutes reserved and billed. Also the destination's country and rate band, a one-way hash of the number dialled (for dialling limits and do-not-call checks), the end reason, and our telephony provider's identifiers for the call. To place the call, the number is also held in a short-lived store that expires automatically within about ninety minutes. The number itself is kept with the call (next row). | To bill minutes accurately, to enforce per-seat and per-account dialling limits and do-not-call records, and to answer support questions about a call. | Contract; for the prospect data inside it you are the controller and we process on your instruction. | Life of the licence, then deleted on request or otherwise within 90 days of the licence ending. |
| The number you called: every number dialled from PitchWhip, whether you typed it or clicked a number you revealed, is stored with that call. So is a phone number or email address you type for a call you log. Inside PitchWhip only the person who made the call can see it; it is never pooled across the account. Where you have connected HubSpot or Salesforce it is written to that call's record there, unless your own outcome says the number was wrong. | To keep the call's record complete and in step with your CRM. | You are the controller; we process on your instruction. | Deleted when you delete the call, and otherwise with the call log. |
| Call recordings and saved transcripts of dialled calls, where your account has switched them on: see 5.8. | See 5.8. | You are the controller; we process on your instruction. | The period your account admin chooses: 90 days from the call (the default), 1 year, 2 years, or until you delete them. Where a period is set, they are then deleted automatically (5.8). |
| Team settings: team name, which licence keys belong to it, who is admin, each member's chosen display name, and the sharing / call-visibility toggles. | To run the team features. | Contract. | Life of the team; a member's row is removed when they leave. |
| Portal session: a signed token in the httpOnly cookie pw_session, containing your licence key or an opaque free-account identifier, plus issue and expiry times. | To keep you logged in to the customer portal. | Contract (strictly necessary). | 7 days, or until you log out. |
Optional free dashboard account. You can sign in with an emailed code or a verified Google address without buying a plan. We hold your verified email address encrypted, with an opaque account identifier and whether a team trial has ended. This lets you return to the same locked dashboard and unlock it when a confirmed purchase uses that address. The record expires 90 days after your last free-dashboard sign-in; you can ask us to delete it sooner by emailing hello@pitchwhip.com. We process it to provide the account you request (contract). Signing in does not subscribe you to marketing emails. Free previews contain example layouts, never another customer’s data.
Country coverage requests. If you request another country for Find companies or Find investors, we keep your latest choice for each feature, the request date and an opaque account reference for up to 90 days. These request records contain no name, email address or licence key. We use them to understand demand and plan coverage, based on our legitimate interest in improving the product. A request does not subscribe you to marketing or make that country available. You can ask us to delete it sooner by emailing hello@pitchwhip.com.
5.5 Contact reveals
When you press Reveal phone or Reveal email, our Worker sends the prospect’s name, company and LinkedIn profile URL to our contact-data enrichment provider and returns what it finds. That provider is a US-incorporated B2B contact-data provider we work with under a reseller agreement, with data sources in the EU and US. The extension never talks to the provider directly. A credit is spent only when data is found. The provider is an independent controller of its own contact database and its processing is described in its own privacy policy. For the request itself we act as your processor, and the provider as our sub-processor; for look-ups we make for ourselves, it is our processor. Retention on our side is described in 5.4. Before any lookup we check our block list (section 8), and, if you have looked this person up before, your do-not-call records for the number you found; either one stops the lookup. Bulk reveal works the same way for a batch. You paste or upload profile addresses on the dashboard, or pick people on a Sales Navigator search or list page, and our Worker sends each one to the provider. A credit is charged only for what is found, and the results join your other revealed contacts. Where you gave only a profile address, the provider's answer also supplies the person's name, job title and employer, which we keep with the result. The list you sent is deleted 30 days after the batch ends.
5.6 Team Learning (optional, off by default)
If you or your team admin turn sharing on, the objection/rebuttal pairs from your calls are anonymised inside our Worker before they are stored. Names, companies, emails, phone numbers, places and amounts are removed by an AI scrub pass with a rule-based backstop, and any record that cannot be cleaned is dropped. The pool therefore contains no personal data, because anything that could identify a person is removed before it is stored, and anything that cannot be cleaned is dropped. Every sharing toggle defaults to off and is enforced on our server. Lawful basis: consent (you switch it on) and legitimate interests (improving suggestions for everyone).
5.7 Sequences, lists, campaigns and reports
If you use sequences, we hold a little more for you: still per account, still as your processor under the DPA. The sending mailbox and stop-on-reply are described in section 6; this is the rest. A sequence itself is its steps and the brief you wrote. For each person in it we hold the same fields as a list row (below), their current step and state, and the contact basis you recorded for them. We also hold the subject line of the first email, kept so that follow-ups can thread as “Re:” and cleared when they finish. The text of a sent email is never stored.
- The contact basis. When you add someone to a sequence we ask why that person may lawfully be emailed, and we store your answer with them. It is one of four values. Inbound: they came to you, through a form, a demo request or a download. Customer: an existing customer or contract relationship. Reply: they replied to you, or you are answering them. Cold: none of those, where the outreach rests on legitimate interests under UK GDPR and, for the email itself, on the corporate-subscriber position under PECR. The record states a relationship you already have. It is not consent, and recording it does not create a lawful basis for you. We act on it and do not verify it: whether someone really did ask to hear from you is something only you can know. A person recorded as cold cannot be added to a sequence that sends through your own connected mailbox, and PitchWhip refuses it at that point. Cold contacts can be sequenced only from the subdomain you verify for campaigns, or in LinkedIn and call steps, which send no email.
- Contact lists. A list is contact data you upload from a spreadsheet, paste in, or add from your own call log or reveals. A row holds name, company, job title, business email address, LinkedIn URL and a segment label (Marketing, Operations and so on). You set the label by hand, or auto-sort assigns it from the job title. You can also add people from Find companies (5.10): their name, company, role, the registered office’s town and a note of what the register showed, with no phone number or email address. The spreadsheet itself never leaves your browser; only those fields reach us. When you add someone to a sequence they are checked first against your do-not-email list (people who unsubscribed or bounced, and addresses you added). Then they are checked against your do-not-contact lists by email, LinkedIn URL, or name and company. Anyone matched is skipped. Lists belong to your account alone: they are never shown to another customer and never added to the prospect index. They are deleted with the account or when you delete the list.
- Campaign images. An account admin can upload an image for a campaign email. We store the bytes on our own infrastructure (Cloudflare) and serve them at a public address made from a random identifier that cannot be guessed. Nothing about who loads an image is logged: no request log, no count. An image is deleted when the admin deletes it or the account closes.
- Learnings and AI-written plans. The “What we’ve learned” box holds notes your team writes about its own outreach, plus short findings the report derives from your own numbers. They are used only in prompts for your account. The sequence plans, email drafts and LinkedIn notes written for you read them, together with your pitch profile and your coaching lessons. They also read the rebuttal pools you already see in the extension, and your own call and sequence statistics. Nothing from another customer’s account is used, apart from the community rebuttal pool you opted into. A plan is only saved when you save it. Learnings are deleted one at a time from the card, or with the account.
- Open tracking. Off by default. Only the account admin can switch it on, after acknowledging that the team is responsible for the consent PECR regulation 6 requires, and then per sequence. When it is on, a one-pixel image served by us goes into each email from a sequence set to track. When a mail client fetches it we record that the email (by its internal sequence and step reference) was opened, when, and how many times. We also record whether the fetch looked like a mail provider’s image proxy. No IP address, browser or device details are stored. The record is kept with the sequence’s other records for the life of the account and deleted with it, and the report shows it as an estimate. Links are never rewritten, so clicks are never tracked. The consent for that pixel is your responsibility, which is why the switch will not move until the account admin has said so.
- Campaign delivery. Campaigns send through Resend from a subdomain you verify. For that we hold the domain name, the DNS records you were asked to add, and the from name and address. We also hold the replies-to address you gave, your business identity line, your daily cap and the domain’s status. Resend tells us what happened to each campaign email (delivered, delayed, bounced or reported as spam) and we keep that per address as a status with a short category, never the message. A hard bounce or a spam complaint adds the address to your do-not-email list and stops that person’s sequence.
- Reports. Sequence reports (reply rate, bounce rate, the step funnel, by rep, by day and hour) are computed when you open them. They read these records: sequence events, the people in the sequence, delivery events, your do-not-email list and your call log. They are cached for a few minutes. The suggestions are fixed rules over those numbers; an AI model only phrases the one-paragraph summary from the findings and the sequence’s name.
Lawful basis: for you, whatever basis you rely on for the outreach itself (section 7); for us, contract, as your processor. Retention: the life of the account, then deleted as in section 11, with one exception. Your do-not-email list (people who unsubscribed or bounced, and addresses you added) is kept after the account closes, so that a person who asked not to be emailed is never emailed again.
5.8 Calls you dial from PitchWhip
This section is about the person you call. They have no relationship with PitchWhip, and in most cases will not know the product exists, so it is written for them as much as for you. Calling is available only on accounts where it has been set up.
What is processed about them. Their telephone number. It is stored with the record of each call you place to it. Inside PitchWhip only you, the rep who made the call, can see it. It is deleted when you delete the call, or with your call log. Where you have connected HubSpot or Salesforce it is written to that call’s record there, unless your outcome says the number was wrong. To place the call it is also held in a short-lived store that expires by itself within about ninety minutes. The time, length and outcome of the call, and its end reason. The call’s audio while it is in transit through our telephony provider, Twilio: the call runs between your browser and Twilio, and the audio does not pass through our servers. We also store a one-way hash of the number dialled, with its country and rate band, for limits, do-not-call checks and support.
Recording. Off unless your account admin switches it on. When it is on, calls dialled from PitchWhip are recorded either from the moment they are answered or, where the account admin has chosen it, only from when the rep presses Start recording during the call; never while the phone rings. Where the rep starts it, the announcement says the call may be recorded, because when it plays nothing is being recorded yet. The rep making the call chooses whether the person called hears an automated announcement that the call is being recorded, played before you are connected. An account admin can require it on every call, and then the rep cannot turn it off. If the announcement is off, telling them, and getting their agreement where the law requires it, is your responsibility. The rep can pause recording during a call and resume it; a paused part is silent in the recording. The audio is held by Twilio; we hold only its identifier. A recording can be played back by the rep who made the call and by the account admin, deleted by either, and is deleted automatically at the end of the period your account admin chooses, unless they choose to keep recordings until they are deleted (see “How long they are kept” below).
Saved transcripts. Off unless your account admin switches it on, and it applies only to calls dialled through PitchWhip, never to Call mode. When it is on, the words of the call (theirs as well as yours, up to 8,000 characters, keeping the end of the call) are stored by us for the period your account admin chooses (below). Only the rep who made the call and the account admin can read one; not a colleague, and not another customer. It is never sent to HubSpot, Salesforce or a spreadsheet, never included in a team view, and never put in an error report. The rep or the admin can delete it, and it is deleted automatically at the end of that period, where one is set. Switching the setting off stops new transcripts being saved; it does not delete those already saved.
How long they are kept. Your account admin chooses how long recordings and saved transcripts are kept: 90 days from the call (the default), 1 year, 2 years, or until you delete them. A change applies to recordings and transcripts made after it; a shorter period also applies to those already kept. If your admin chooses to keep them until you delete them, the company that holds the PitchWhip account (our customer) is responsible for keeping them only as long as it needs them under data protection law. Whatever the choice, they are deleted with your other PitchWhip Cloud data after your licence ends (section 11).
Call diagnostics. To find and fix faults in calling, the extension automatically sends us a record of how each dialled call went: the stages of connecting it, whether it connected, why it ended or failed, any error in the live suggestions, and what your browser and microphone support. Each record carries our own reference for the call, a code for your installation that changes every day, and a one-way hash of your licence key. It never contains the number called, a transcript or anything either person said: our server drops any record that does. We keep these records for 30 days. Lawful basis: legitimate interests (keeping calling working). If you switch off “Send usage statistics” (section 5.3), we receive these records only for calls where something goes wrong.
Live transcription on a dialled call works as it does in Call mode (section 6): it runs on your computer. If your account admin turns it on, Chrome turns both sides of the call into text on the device itself, so no call audio is sent to Google, to PitchWhip or to anyone else to be transcribed. That text goes through our proxy to the AI model for live suggestions and your summary.
Calls to your PitchWhip number. When someone calls a PitchWhip number, we process their number (unless they withheld it), the time and length of the call, and whether it was answered in the browser, forwarded to a mobile or went to voicemail. A voicemail they leave is always recorded and held by Twilio. Only the rep whose number it is can play or delete it. The voicemail and the caller’s number are deleted 90 days after the call; the rest of the call record is deleted after 12 months. When your account admin has switched recording on, an answered call to a PitchWhip number is recorded, announced and kept under the same settings as calls you dial, and saved transcripts work the same way. As for calls you dial, you are the controller and we are your processor.
Who is responsible. You, our customer, are the controller of a call record, a recording and a stored transcript, as you are of the rest of your call log. We are your processor under the DPA, and Twilio is our sub-processor. Deciding whether to record, whether the announcement plays, whether to store transcripts, and on what lawful basis, is yours. If the person called asks us for a copy of, or the deletion of, a recording or transcript, we pass the request to you and help you answer it.
What we will not do. We will not dial a number recorded as do-not-call on your account, and if we cannot check that list we refuse the call rather than place it. PitchWhip can call emergency services only from a PitchWhip number with a registered address. When someone on an account calls 911 from a US PitchWhip number, US law (Kari’s Law) requires us to tell the account’s admins at once: we email them the caller’s name on the account, when they called, the callback number and the registered address. We keep that notice for 12 months. We never tell admins about a 999 or 112 call.
5.10 Find companies (the Companies House search)
With a paid account, you can search the UK Companies House register in the dashboard for companies, and see their directors and owners.
- What we read. The names of active directors and owners, their month and year of birth, the share of the company they own and when they took on the role. We read the month and year of birth only to work out an age and to tell apart people with the same name. We never show it or send it to you.
- What we show. Each person’s name and role, an age band (such as 60–64, never their age), how much they own, how long they have held the role, and a LinkedIn search link. We show these for the people who match your search. When you open one company, we show them for every active director and majority owner of it. Beside a result we may also name, without an age, a person who holds 75% or more, its only registered owner, or the people who own its holding company. They may not match your search. We never show anyone under 18, or anyone who has asked us to keep them out of the search.
- Suggestions. If you ask for suggested industry codes, the words you type go to Anthropic (5.3). If you ask it to draft what good looks like for you, your pitch profile and your search go too. Nothing about the people in your results is sent. We keep the code suggestions for your account for 30 days, so the same words get the same answer.
- How long we keep it. We keep people’s details for 24 hours, so that searches stay fast and within the register’s limits. We keep nothing about them after that, except for a person who asks to be kept out of the search. For them we keep their name, the companies we found them at and one-way fingerprints, so that they stay out (see our notice to prospects).
- Who is responsible. We are the controller of the search. A file you export is yours. A person you add to a list is in your records, and we are your processor for that row (5.7).
- Your part. Use these details fairly and only for business-to-business approaches. Tell people you found them on the Companies House register when you first get in touch.
5.11 Find investors
With a paid account, you can find UK companies in the dashboard that recently issued new shares, and the organisations that invested in them.
- What we read. Share allotment returns, confirmation statements (shareholder lists) and the ownership records of investing companies, all from Companies House.
- What we show. Each company’s round figures, the investment firms and other organisations that hold shares, and how many private individuals hold shares.
- What we never show. A private person’s name, holding or estimated investment, or the name of an organisation that looks like one person’s or one family’s investment company. Where one to four holders in a round are unnamed, we hide every amount in that round, and a count under five reads only “fewer than 5”.
- What we keep. We read people’s names only to tell people from organisations, and we don’t store them. We keep company figures, organisation names and counts for up to 30 days, and the figures from a filing for up to 400 days.
- Who is responsible. We are the controller of this search. A file you export is yours.
- Scanned forms. We don't send scanned forms to Anthropic or any other AI provider. A scanned form is marked as one we can't read. Shareholder lists are never sent to an AI provider.
- Stop naming an organisation. If an organisation you control is named and it is really your own investment company, email hello@pitchwhip.com with its company number and we’ll stop naming it for every customer.
Because we keep no private shareholder’s name, we can’t find one in our records. If you write to us about your own shares, we’ll tell you that, and what the search shows about the companies you name.
5.12 Your PitchWhip phone number
Before your company gets its first PitchWhip number, and for as long as it holds numbers, we keep the records that telecoms rules require of whoever provides numbers.
- The company check. We check your company on the Companies House register: that it exists and is active, and that its name and postcode match what your admin gave us. We search the names of up to five of its directors, and of the named contact, against the public register of disqualified directors, and check that the contact is one of its officers. We also look at risk signals: a free email address, a website on another domain, the network and country the request came from, the time of day, and links to other PitchWhip accounts. A possible match or signal goes to a person at PitchWhip to decide. It is never refused automatically. The one automatic refusal is a company the register shows as dissolved or closed.
- Emergency address. Each number has the address where its user works (it may be their home), so that emergency services can be sent there. Our telephony provider, Twilio, holds it and the emergency services see it when the number calls them.
- Your own number. If a rep uses their own phone number as caller ID, or has calls forwarded to their mobile, we keep that verified number while it is set up on your account, then delete it within 90 days after you remove it or your licence ends.
- Why. To meet the rules for providing phone numbers and emergency calls (legal obligation), and to stop numbers being used for fraud or nuisance calls (our legitimate interests).
- How long. The company check and its decisions are kept while your company has numbers and for 12 months after. An emergency address is kept for 12 months after its number is given up. Records of emergency calls are kept for 12 months.
5.13 Free accounts and password sign-in
To use PitchWhip free you create an account with a work email address. We keep that address, the account key we give you, when you confirmed the address and which version of our Terms you saw. When you sign up we also ask for your full name, company and country, and optionally your LinkedIn profile URL; we keep them with your account. We never sell these details or use them to train AI models, and we share them only with the service providers listed under “Who we share data with” or where the law requires it. We also keep a one-way hash of the address so that one address gets the free allowance once, and the IP address you signed up from, to spot abuse. We count each account’s scripts for the day and its free phone number and email reveals. If you choose a password we store only a salted, slow hash of it, mixed with a secret key held apart from our database, under a code derived from your address rather than the address itself. Sign-in and confirmation codes are stored only as hashes and expire after 15 minutes.
Lawful basis: contract (providing your free account) and legitimate interests (keeping the free allowance to one per person and preventing abuse). Retention: the daily counters expire within three days; your dashboard sign-in record is deleted 90 days after you last sign in; the account itself (address, key and allowance) is kept while you have it. If you ask us to erase it we delete your address, your sign-up details and your password and keep only the hash, so the free allowance is not given again. Emails about your account (the account-ready email, sign-in and password notices) are service messages, not marketing.
6. What stays on your device
The extension also holds data on your device or writes it to your own Google account. The AI processing and private licence backup exceptions are described above:
- Settings, pitch profiles, coaching memory, notes and full call records live in Chrome’s local and sync storage. Some of this data also goes to your private licence vault: your voice profile, coaching lessons, notes to self and saved objection phrasings (5.4). Raw call notes and transcripts are excluded from the shared cloud call log. Coaching lessons and call outcomes can be sent transiently to the AI for live suggestions and the weekly review (5.3). When you request a follow-up email draft, your free-text call note is also sent to the AI as described in 5.3.
- Live transcription runs on your computer. If your account admin turns it on, Chrome turns the call into text on the device itself, so no call audio is sent to Google, to PitchWhip or to anyone else to be transcribed. The first time, Chrome downloads its speech files (about 150 MB) from Google; that download carries no audio and no words. The text (not the audio) then goes through PitchWhip to Anthropic for live suggestions and the call summary. PitchWhip 13.0 and earlier used Google’s online speech service instead; Chrome updates PitchWhip on its own. The resulting transcript is kept on your device and nowhere else, with one exception. If your account admin has switched on saving transcripts of dialled calls, we also store the transcript of a call you dial through PitchWhip.We keep it for the period your account admin chooses (90 days unless they choose 1 year, 2 years or until you delete it). You and your admin can read it (5.8). That switch is off unless an admin turns it on, and it does not apply to Call mode. Note the further exception in 5.3. When you use live suggestions, post-call summaries and coaching, call replay, voice learning or follow-up email drafts, relevant transcript text is sent through our proxy to Anthropic. That is transient: we do not retain it.
- Google Sheets and Calendar sync, if you connect Google, writes to a spreadsheet and calendar events in your own Google account. The extension uses the narrow
drive.filescope (access only to files it created) andcalendar.events.ownedfor bookings. Nothing from your Google account is sent to us. PitchWhip’s use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. - Your sending mailbox, if you connect one so that sequences can send follow-ups from your own address. There are two ways to connect one, and both can only send.
Sign in with Google. For a Gmail or Google Workspace address you sign in with Google and grant one scope,gmail.send, which permits a single action: handing Google a message to send as you. It cannot read, list, search, label, modify or delete anything in your mailbox, and we ask for no other Google data. The tokens Google issues are held encrypted (AES-GCM), with a key kept apart from the database. You can withdraw the grant at any time in your Google account, and disconnecting the mailbox in PitchWhip deletes the tokens from our servers.
An app password. For other providers you give us an app password instead. That is a code you generate inside your own Microsoft, Fastmail or similar account, and it is not the password you sign in with. We hold it encrypted the same way and use it for one purpose: opening a connection to your mail server (SMTP) and handing over the messages your sequences produce. A sending connection of that kind cannot open, search or delete your mail either. Deleting the code inside your own provider account stops the sending immediately, and disconnecting the mailbox removes it from our servers.
We send only the emails your own sequence configuration produces, to the people you added. The text of each email is composed when it is sent and is not retained on our servers afterwards; your own Sent folder is the record. We never send on your behalf for our own purposes, and we do not read your replies. A prospect is marked as replied either by you, or by the stop-on-reply rule described below, which reads only the tagged address a copy was sent to. A sequence sending from this mailbox can only include people you recorded as inbound, customer or reply. Anyone recorded as cold is refused here, and can go out only over campaign sending or in steps that send no email (5.7).
Open tracking is off by default. Only the account admin can switch it on, after acknowledging that the team is responsible for the consent it needs, and then per sequence. Section 5.7 describes what is recorded when it is on, and what never is.
If you switch on stop-on-reply, your sequence emails carry a reply address on your own domain with a short reference on it, so a recipient never sees any address of ours. Their reply goes to your inbox and stays there. A mail rule you create yourself then sends a copy of those replies to our server: only messages addressed to that reference, never your other mail.
We do not read prospect reply bodies. Our server reads the reference and routing headers on each reply copy to know which sequence to stop. The reply body is never opened, stored, logged or forwarded onward; the copy is discarded after processing. Turning the setting off stops adding references to future sends. Any forwarding rule you created remains in Gmail until you remove it. We deliberately do not request permission to read your mailbox.
Gmail forwarding setup is a separate, temporary step. When you start it, we read the matching Google confirmation message to extract its approval link for your connected mailbox and forwarding address. The message body is processed in memory and is not saved or logged. We temporarily store the link, its receipt time and the mailbox, address and setup-window identifiers. Only the connected owner can retrieve the link during the 15-minute setup window. Expired links are no longer shown. Changing or disconnecting the mailbox removes access to its setup link. Stored links are erased when you close setup or during expiry cleanup. Opening the link is your choice; it does not prove a reply filter works.
PitchWhip’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Prospect data: your responsibilities
When you use PitchWhip to research, reveal or call prospects you are processing the personal data of third parties, and you (or your organisation) are the controller for that data. We are your processor for the parts that touch our services. In practice that means:
- You need a lawful basis for your outreach. For B2B prospecting under UK GDPR and PECR this is usually legitimate interests, but the assessment is yours to make and document. In the US, cold-calling and texting rules such as the TCPA and Do Not Call registries apply to you.
- You record why each person may be emailed. When you add someone to a sequence, PitchWhip asks for the contact basis and holds the answer you give (5.7). The record describes a relationship you already have; it does not create one, and we do not check it. Where you record cold, PitchWhip will not send to that person from your own mailbox at all.
- Tell prospects where their data came from where the law requires it, and honour objections. In the UK and EU that usually means within a month, or in your first message or call if that is sooner. Say who you are, where you found their details and how to object. PitchWhip’s notice to prospects explains our part, but it does not replace yours. If a prospect asks you to stop or to delete their details, do so, including deleting them from your call log and CRM. Ask us and we will remove the matching rows from PitchWhip Cloud.
- Call-recording law applies to you. In the UK and many US states, recording or transcribing calls may require telling or asking the other party. Check before turning transcription on, before an admin turns on recording or the saving of transcripts for calls you dial, and before you turn the recording announcement off.
- Calling rules apply to you. You are the caller. In the UK, screen numbers against both the Telephone Preference Service and the Corporate TPS before a sales call; sole traders and partnerships register on the TPS. On every call, say who is calling and for which organisation; if the person asks, give an address or a freephone number on which you can be reached. Keep your own do-not-call list. In the US, the Do Not Call rules, calling hours and state telemarketing laws apply. Call at least within the federal window of 8am to 9pm in the called person’s time zone, and within any narrower hours set by state law. Show only a caller ID you have permission to use.
- Revealed contact details are for your own outreach. Do not resell them, publish them or build a database for others; the Terms of Use set out the restrictions that flow down from our data supplier.
If you are a prospect, you can ask PitchWhip to stop passing on your email address or phone number, using the removal form or by emailing hello@pitchwhip.com. PitchWhip then won’t give it to anyone who doesn’t already have it, and PitchWhip’s customers can’t email a removed address through PitchWhip. The same route is how you object to PitchWhip passing on your details. Some organisations already had your details before your request, because they looked them up, called you, or hold them in their own records. They are separate organisations, responsible for their own use of them. We’ll tell the ones we can find through PitchWhip about your request, and you can ask us which ones they are. To stop one of them contacting you, ask them directly. If you do not know who that is, email hello@pitchwhip.com: we will help you identify them where we can, and will act on their instructions to delete data we hold for them. For our own prospect index we are the controller; the notice for prospects sets out how to stay out of it.
8. The prospect index
Everything above section 7 is data we hold for you, apart from the Companies House search in 5.10, which we run as the controller. The prospect index is different, and we would rather say so plainly than let you discover it: it is data we hold for ourselves, and we are the controller of it.
Nothing is currently collected: the index is switched off at both ends and holds no records. It is built to hold professional details for people who may be worth contacting about what our customers sell. The fields are name, job title, employer, the public address of the profile, publicly stated role information, and when we saw it. Were it running, records would come from profiles already published on the web: one a customer was looking at while deciding who to contact. Uploaded lists are never added to the index. We do not buy prospect lists and we do not crawl sites automatically.
Were the index running, a record could be shown to more than one customer: pooling is what would let PitchWhip tell a salesperson that someone is probably not worth their call. Nothing is pooled in the index today. The Companies House search (5.10) is different: people’s details from the public register are kept for 24 hours and used for every customer’s searches.
| Detail | Position |
|---|---|
| Our role | Controller |
| Lawful basis | Legitimate interests (Art. 6(1)(f)): business-to-business outreach, balanced against the rights of the people listed. The assessment is written down and available on request. |
| Scope | Business contact information only. No personal email or phone, no home address, no special category data, no behavioural profiling, no tracking across the web. |
| Retention | Were the index running, 12 months from when the details were last seen published, then automatic deletion. It holds no records today. |
| Objection | Honoured without question, in one email, with a permanent block-list entry so the details cannot return. See the notice for prospects. |
| Never | Sold, used for advertising, shared with data brokers, or used to train AI models. |
What this does not change. Your call log, notes, transcripts, recordings, coaching content and revealed contact details remain yours and remain scoped to your licence and, on a team, to your team as described in section 5.4. Nothing private to your account is pooled. The index holds published professional details and nothing you recorded.
If you are a customer, two things follow. Contacting someone is still your decision and your responsibility under section 7: the index tells you who might be relevant, not that you may lawfully write to them. And if a person objects to you directly, tell us: we will block them centrally so that no other customer is handed the same details.
9. Who we share data with
We share personal data only with the providers below, each under a contract that limits what they may do with it. The exception is where the table says a provider is engaged by you rather than by us (your own Google Sheets and Calendar, and a HubSpot account you connect). There your relationship with that provider governs and we have no contract to rely on. Otherwise we share only when the law requires it (for example a court order) or to protect our rights. We do not sell personal data.
| Provider | What they do for us | Location and safeguards |
|---|---|---|
| Cloudflare, Inc. | Runs our API proxy and PitchWhip Cloud (Workers, D1 database, KV store). Holds the credit ledger, revealed contacts, call log, team settings, and the feedback and quality-telemetry records described in 5.3. Also holds the dialled-call records, recording identifiers and saved call transcripts described in 5.4 and 5.8. And it holds the sequences, contact lists, campaign images, learnings, delivery events and open records described in 5.7. | Global edge network; data stored in Cloudflare's data centres in the UK, EU and US. From the UK: the UK Extension to the EU–US Data Privacy Framework (Cloudflare, Inc. is certified), with the EU SCCs and the UK Addendum in Cloudflare's data processing addendum as a fallback. From the EEA: the Data Privacy Framework, with the EU SCCs as a fallback. |
| Anthropic, PBC | Generates call-preparation text, live suggestions, call summaries and coaching from the profile text, pitch context and, when you use the live-call features, call transcript text and coaching context our proxy forwards. For sequences (5.7): writes sequence plans, email and LinkedIn drafts, sorts a list by job title, and phrases report summaries. For Find companies (5.10): suggests industry codes from the words you type, and drafts what good looks like from your pitch profile and search. Also runs open-web searches on our behalf, using its own server-side search tool, for the Enrich feature and for the automatic company lookup described in 5.3. Not used to train models. | United States. From the UK: the EU SCCs with the ICO's UK Addendum, in Anthropic's data processing addendum. From the EEA: the EU SCCs. |
| Contact-data enrichment provider | Finds business phone numbers and email addresses for the prospects you choose to reveal, as our sub-processor (our processor for our own look-ups). Independent controller of its own database. | United States (US-incorporated), with data sources in the EU and US. Reseller and data-processing terms. EU SCCs (June 2021). For UK data: the UK Addendum to those SCCs, completed and agreed with the provider on 28 September 2026. |
| Twilio | Carries calls made from PitchWhip (5.8). It receives the number being called, the verified caller ID the account calls from, and the audio of the call while it is in progress. Where an account has switched recording on, Twilio makes and holds the recording and plays any announcement to the person called. We hold only the recording's identifier. Recordings are deleted at Twilio automatically at the end of the period the account admin chooses (5.8), and when the rep or admin deletes one. The browser half of a call uses Twilio's own calling library, bundled in the extension, which connects straight to Twilio. Where a customer buys a phone number through PitchWhip, Twilio also provides the number, carries incoming calls and voicemail, forwards calls to the rep's mobile if the rep chooses, and holds the number's emergency address. For the identity and address records that numbers require, and for call records it must keep by law, Twilio is an independent controller under its own privacy notice. | Twilio Ireland Limited contracts with us; calls are processed by Twilio Inc. in the United States, and call audio enters Twilio's network at its nearest edge location. Twilio's data protection addendum: the EU–US Data Privacy Framework and its UK Extension, Twilio's Binding Corporate Rules, or the EU Standard Contractual Clauses with the UK Addendum. |
| Lemon Squeezy, LLC | Merchant of record: checkout, invoicing, tax, subscriptions, refunds, licence-key issuance and validation. With optional measurement consent, checkout also receives an opaque attribution reference, which it returns in the signed payment notification. We do not pass Reddit click identifiers or campaign labels to Lemon Squeezy. | United States. Independent controller for payments. For the data we send it: the EU SCCs in its data processing addendum. For UK data, we asked Lemon Squeezy for UK transfer terms on 26 September 2026. |
| Vercel, Inc. | Hosts pitchwhip.com and the customer portal. Portal requests pass through Vercel's servers on their way to Cloudflare; Vercel Web Analytics provides aggregate visit statistics. | United States, with global edge. From the UK: the UK Extension to the EU–US Data Privacy Framework (Vercel Inc. is certified). From the EEA: the Data Privacy Framework or the EU SCCs. |
| Reddit, Inc. | Only with explicit consent and an eligible Reddit click identifier: install-link clicks, checkout clicks and separately verified paid purchases. Purchase data includes click ID, occurrence time, gross amount including tax after discounts, currency and a deduplication ID. No email address, licence key, IP address, user agent or full page URL is added. Without an eligible click identifier, nothing is reported to Reddit. We use our server, not Reddit’s browser tracking script. | United States. Independent controller for its own advertising measurement. The EU–US Data Privacy Framework and its UK Extension (Reddit, Inc. is certified). |
| Web3Forms | Delivers our website enquiry forms to our inbox. It sees what you type into the form and your IP address. It runs a spam check on each form it delivers, and keeps its own copy under its own privacy policy. | Cloud-hosted. Used for enquiries only, never for customer or prospect data we hold. |
| Resend | Delivers portal sign-in codes, requested install-link and confirmation emails, and the optional PitchWhip setup series described in 5.1. If you run campaigns (5.7), it also sends campaign emails from the subdomain you verified. It sees each recipient address and message and sends us delivery notices. It also delivers notices to our own mailbox, such as bug reports you send us. Never call records, reveals or transcripts. | Resend is US-incorporated; our sending region is the EU (Ireland), so sign-in codes and campaign email are processed there. From the UK: the UK Extension to the EU–US Data Privacy Framework (Resend's company, Plus Five Five, Inc., is certified). From the EEA: the EU SCCs. |
| Google LLC | Four separate cases, and only the third and fourth involve us. (1) Live transcription runs on your computer: Chrome turns the call into text on the device itself, so no call audio is sent to Google. The first time, Chrome downloads its speech files (about 150 MB) from Google; that download carries no audio and no words. That is between your browser and Google, acting as the maker of your browser; we have no contract with Google covering it. (2) If you connect Google Sheets / Calendar, the extension writes to your own Google account: again your provider, not ours, and we receive nothing. (3) If you sign in to the portal with Google, we send the sign-in token Google issued back to Google to verify it. We receive back your email address and whether Google has verified it. (4) If you connect a Gmail or Google Workspace mailbox for sending (6), we hand each sequence email to Google to send from your own account. Google therefore sees the recipient address and the message. That is your mailbox and your own relationship with Google: the message would pass through it whichever tool wrote it. Our grant is send-only, so we can read nothing in there. | The speech-file download, Sheets / Calendar and a connected Gmail mailbox: Google's own infrastructure, under your relationship with Google rather than a contract with us. For sign-in: United States, under the EU–US Data Privacy Framework and its UK Extension (Google LLC is certified); we receive only the verified email address. |
| HubSpot, Inc. | Only if you connect it. You paste a private-app token for your own HubSpot account in the portal, and each call your account logs is then written there as a contact and a logged call, plus a follow-up task where you set a callback date. What crosses is the prospect's name, company and job title, their LinkedIn URL, who called and when, the outcome, the duration, any callback date, the intel one-liners (signals and why now), and a phone number or email address your account has already revealed for that person, or the number dialled or typed for that call. Private extension notes and transcripts are excluded. A separate dashboard-authored note is sent only when you explicitly select HubSpot for that note; turning that choice off stops future sync and does not erase earlier exports. Clearing the note while that destination remains selected requests clearing of our own known copy; changed or uncertain records need review. | United States. This is your own HubSpot account under your own contract with HubSpot; we hold the token you paste encrypted and use it only for this sync. |
| Salesforce, Inc. | Only where you connect your own Salesforce org. PitchWhip uses your configured local External Client App, or PitchWhip's own Salesforce Connected App (installed from PitchWhip's managed package), and encrypted OAuth credentials to match existing Contacts or Leads and sync call activities and callback tasks. New Lead creation is optional and off by default. Data includes the person's name and company, and the revealed, dialled or typed contact details needed for matching, logged outcome, duration, call date and callback or meeting dates. Private extension notes and transcripts are excluded. A separate dashboard-authored note is exported only when you explicitly select Salesforce for that note. Turning that choice off stops future sync and does not erase earlier exports. Clearing the note while Salesforce remains selected requests clearing of our own known copy, subject to review if it changed or a write could not be confirmed. Deleting a PitchWhip call does not erase an existing Salesforce record. | Your Salesforce org, under your own agreement and hosting configuration with Salesforce. |
Reports of illegal content. Cloudflare also holds the reports of illegal content made on our Digital Services Act page, and our decisions on them, in PitchWhip Cloud. If you give an email address with a report, Resend sends you our confirmation of receipt.
Where we identify a provider by category rather than by name, we do so for reasons of commercial confidentiality. That provider is named in the sub-processor schedule to our Data Processing Agreement, and we will confirm it in writing on request. We give at least 30 days’ notice before adding or replacing a sub-processor.
We will update this table, and give that notice by email or on this page, before adding a sub-processor that will handle PitchWhip Cloud data. If we are ever acquired or merge, customer data may transfer to the successor under this policy; we will tell you first.
10. International transfers
We are based in the United Kingdom. Some providers above process data in the United States. Where personal data leaves the UK or the EEA we rely on the following. For transfers from the UK, the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. For transfers from the EEA, the EU Standard Contractual Clauses (Modules 2 and 3 as applicable) with a transfer risk assessment. And, where the recipient is certified, the EU–US Data Privacy Framework and its UK Extension. For our payment provider, Lemon Squeezy, we asked on 26 September 2026 for UK transfer terms. Transfers between the EEA and the UK rely on the European Commission’s adequacy decision for the UK. Copies of the relevant clauses are available on request from hello@pitchwhip.com.
11. Retention
The tables in section 5 give the detail. In summary:
- Prospect index records: were the index running, they would expire 12 months after the details were last seen published and then be deleted automatically. Block-list entries are kept indefinitely, so that a removal stays a removal.
- PitchWhip Cloud data (call log, revealed contacts, team settings, credit ledger, sequences, contact lists, campaign images, learnings, delivery events and open records) is kept for the life of your licence. So are the dialled-call records in 5.4. After it ends we delete it on request straight away and otherwise within 90 days, as part of our clean-up of lapsed licences. Purchase and refund entries in the ledger are kept for up to 6 years for accounting and tax. Your do-not-email list is kept so that nobody on it is emailed again (5.7). If a team trial ends without a purchase, the trial team’s data (including contact details revealed during the trial and call records) is deleted 90 days after the trial ends, and we email a reminder beforehand.
- Call recordings and saved transcripts of dialled calls are kept for the period your account admin chooses: 90 days from the call (the default), 1 year, 2 years, or until you delete them. At the end of that period they are deleted automatically, whether or not anyone asks. A new period applies to recordings and transcripts made from then on, and a shorter one also reaches those already kept. You can delete either one sooner from your call history, and deleting a call from your call history deletes both. Switching the transcript setting off stops new transcripts being saved. It does not delete those already saved: your own deletion still reaches them, and so does the automatic deletion where a period is set. Whatever the choice, they are deleted with your other PitchWhip Cloud data after your licence ends.
- Find companies: people’s details from the register are kept 24 hours. A person’s objection to the search is kept indefinitely, so that they stay out. Saved searches hold your filters, not people, and are deleted 400 days after you last use them, and within 90 days after your licence ends.
- Find investors: private shareholders’ names are read in memory and never stored. Company figures, organisation names and counts are kept up to 30 days, and a filing’s figures up to 400 days. A request to stop naming an organisation is kept until it is withdrawn (5.11).
- Calls to a PitchWhip number: the voicemail and the caller’s number 90 days, the rest of the call record 12 months (5.8). Phone-number records: the company check while your company has numbers and 12 months after, an emergency address 12 months after its number is given up (5.12).
- Free dashboard sign-in records expire 90 days after your last free-dashboard sign-in, or are deleted sooner on request (5.4).
- Country coverage requests expire within 90 days of submission, or are deleted sooner on request (5.4).
- Account and licence records are kept while your licence is active and for up to 6 years afterwards for accounting, tax and legal-claim purposes.
- AI request content is not retained by our proxy. The counters that enforce daily limits expire within three days; the daily usage record per licence (counts only, under a one-way hash of the licence key) is kept for 400 days. One exception is the feedback and quality-telemetry records in 5.3 (feedback you choose to send, and diagnostic records that name which writing rules fired, with no script text). We keep those until you ask us to delete them or we no longer need them for tuning. The other is the Find companies code suggestions, kept for your account for 30 days (5.10).
- Enquiries and support email are kept up to 24 months from last contact.
- Reports of illegal content and our decisions on them are kept 12 months after the decision, or longer where the police ask us to keep evidence. A report we never decide on is kept 12 months from when it arrives.
- Extension data on your device is under your control and is removed when you delete it or uninstall the extension.
To have your cloud data deleted before your licence ends, email hello@pitchwhip.com from the address on your purchase. Note that deleting revealed contacts means a later reveal of the same person will spend a credit again.
12. Security
Everything is encrypted in transit (TLS) and at rest by our hosting providers. Cloud data you own is isolated by licence key (every query is scoped to the calling licence or its team) and licence keys never appear in URLs. The prospect index (section 8) is an exception: it would be ours rather than yours and shared across customers, and it is switched off today. The Companies House search (5.10) is available to paid accounts. It keeps people’s details from the public register for 24 hours and uses them for every customer’s searches. Secrets (API keys, signing keys and the keys that verify provider notices) are held in provider secret stores, never in source code. Access to production systems is limited to the people who run the service, on least-privilege accounts with multi-factor authentication. Notices our payment, data and email providers send to our servers (payment events, delivery and bounce notices) are signature-checked before anything is written. The customer portal never exposes your licence key to browser scripts after login (the session cookie that carries it is HttpOnly); a compromised key can be deactivated on request. If we suffer a breach that affects your data we will tell you and, where required, the regulator without undue delay and within 72 hours of becoming aware. Annex 2 of the DPA lists the measures in more detail.
13. Your rights (UK and EU)
If you are in the UK or the EEA, you have these rights. To access the personal data we hold about you and receive a copy. To rectify it if it is wrong. To have it erased. To restrict processing. To object to processing based on legitimate interests (including any direct marketing, which we will always stop). To data portability for data you gave us that we process by automated means under contract or consent. And to withdraw consent at any time where consent is the basis (for example, analytics cookies: use the “Change your choice” control on the Cookie Policy page). Withdrawing consent does not affect processing before you withdrew it.
To exercise any of these, email hello@pitchwhip.com. We will respond within one month (extendable by two further months for complex requests, which we will tell you about). We may ask you to confirm that the request is yours, usually by writing from the email address on your purchase. There is no fee unless a request is manifestly unfounded or excessive. Where we act as your processor (PitchWhip Cloud data), the customer portal lets you see your call log, revealed contacts and contact lists, and export your call log and lists. We will delete on instruction.
Complaints to us. You have the right to complain to us about how we use your personal data (section 164A of the Data Protection Act 2018). Email hello@pitchwhip.com and say it is a complaint. We will acknowledge it within 30 days, look into it without undue delay, tell you what we are doing about it, and tell you the outcome.
We are registered with the UK Information Commissioner’s Office as a data controller, registration number ZC223705.
You also have the right to complain to a supervisory authority. In the UK, that is the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113); in the EEA, the data-protection authority of the country where you live or work. The European Data Protection Board keeps a list of members. We would appreciate the chance to resolve your concern first.
14. US state privacy rights (California and others)
This section applies if you are a resident of California (under the California Consumer Privacy Act as amended by the California Privacy Rights Act, together the “CCPA”). It also applies to residents of another US state with a comprehensive privacy law: Colorado, Connecticut, Delaware, Iowa, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah and Virginia among them. PitchWhip Ltd is a small UK company and may fall below the thresholds at which some of these laws apply; we honour the rights below for all US residents regardless.
Notice at collection: categories, sources and purposes
In the last 12 months we have collected the following categories of personal information, in each case for the business purposes described in section 5:
| Category (CCPA) | Examples we collect | Sources |
|---|---|---|
| Identifiers | Name, email address, licence key, random device identifier, IP address, cookie identifiers (session, consent, country and optional campaign association), and an eligible Reddit ad-click identifier after consent. | You; Lemon Squeezy (purchases); your browser. |
| Commercial information | Products purchased, subscription status, credit-pack purchases and refunds, reveal credit balance. | You; Lemon Squeezy. |
| Internet or network activity | Pages visited, referrers, device type (aggregate analytics); usage counters for AI generation and reveals; portal request logs. | Your browser; our servers. |
| Geolocation data (coarse) | Country derived from IP address for the cookie banner; and, on an extension install, the country derived from IP address, to count installs by country. The IP address is not stored with it. No city or precise location. | Your browser or the extension / our edge network. |
| Professional or employment information | Company and team size on enquiry forms; your display name in a team. As your processor: the names, titles, companies and business contact details of prospects you reveal, call, upload to a list or add to a sequence. | You; your team admin; our contact-data supplier; spreadsheets you upload. |
| Audio, electronic or similar information | As your service provider, where your account switches it on: recordings of calls dialled from PitchWhip (held by our telephony provider) and saved transcripts of those calls (5.8). | Your calls. |
| Inferences | None about you. As your service provider: fit and timing scores for prospects you research, to help you decide whom to call. | Generated for you. |
| Sensitive personal information | None beyond what is necessary to log you in (your licence key). We do not collect government identifiers, precise geolocation or health data. Call recordings are kept as a record of the call; we do not use them to identify anyone by their voice, and we do not create voiceprints. | Not applicable. |
We disclose these categories to the service providers listed in section 9, for the business purposes of providing the service, processing payments, hosting, security and analytics. We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16 years old. Because we do not sell or share, there is no opt-out to operate. If we ever change that we will add a “Do Not Sell or Share My Personal Information” link to this site first. We treat a browser Global Privacy Control signal as a valid opt-out request. Retention periods for each category are in sections 5 and 11.
Your rights
- Right to know / access: the categories and specific pieces of personal information we have collected about you, the sources, purposes, and the categories of third parties we disclosed it to.
- Right to delete: subject to exceptions (for example, completing a transaction, security, or legal obligations such as tax records).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing, and to limit the use of sensitive personal information: not applicable in practice, because we do neither.
- Right to non-discrimination: we will not deny you service, charge a different price or provide a different level of quality because you exercised a right.
- Right to appeal: if we decline a request you may ask us to reconsider by replying to our decision. Residents of states that provide a statutory appeal may then complain to their state attorney general.
How to exercise them. Email hello@pitchwhip.com with the subject line “Privacy request” (or, for the avoidance of doubt, “Do Not Sell or Share”). We do not operate a toll-free number because we interact with customers online only. We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days with notice. To verify a request we will match it to the email address on your purchase or account and may ask for one further piece of information we already hold. We do not require you to create an account. An authorised agent may submit a request on your behalf with your signed permission, and we may ask you to confirm the agent’s authority directly. Where we hold information only as a service provider (processor) for a PitchWhip customer, we will forward your request to that customer and act on their instruction. That is the case, for example, where a customer revealed or logged a call to you.
Shine the Light. California Civil Code section 1798.83 lets California residents ask once a year what personal information we disclosed to third parties for their own direct-marketing purposes. The answer is: none. We do not disclose personal information to third parties for their direct marketing.
15. Children
PitchWhip is a business tool for adults. You must be at least 18 to buy a licence or use the service, and we do not knowingly collect personal data from anyone under 18 years old. The public Companies House register can list a director or owner under 18. Find companies reads it, but never shows them, and keeps their details only in its 24-hour cache (5.10). If you believe a child has provided us with personal data, email hello@pitchwhip.com and we will delete it.
16. Cookies
Essential first-party cookies include pw_session (portal login), pw_consent (your cookie choice), pw_purchase_consent (acceptance of the purchase-measurement notice) and pw_geo (country code for the banner).
After explicit acceptance, optional first-party cookies hold an opaque campaign reference and supporting flags that can link this browser’s visit to a confirmed purchase for up to 28 days after registration. Untagged return visits do not extend the association. Section 5.1 describes the server records and eligible reporting to Reddit. Web analytics is cookieless and runs only with your consent where consent is required. The extension sets no cookies. Full details and the controls to change your choice or request withdrawal are on the Cookie Policy page.
17. Automated decisions and AI
We do not make decisions about you by automated means that have legal or similarly significant effects. The AI features generate suggestions (openers, briefs, objection handles, coaching) for you to use or ignore. A sequence you set up can run automatically. The emails it drafts send on the schedule you chose, to the people you added, and you can stop it at any time. Separately, confirmed PitchWhip setup emails run on a fixed schedule, and referral credits are awarded automatically after payment and eligibility checks. Neither uses AI to decide whom to email or who earns a reward. Fair-use and credit limits are simple counters, not profiling. Team Learning uses an AI pass only to remove personal data from shared text, and auto-sort only files a list row under a job-title group. During a call, live suggestions are suggestions for the rep to use or ignore; nothing decides anything about the person called. In Find companies, fit and timing scores are worked out from register facts, including a person’s age band and years in their role, to help you decide whom to contact. They decide nothing about the person.
18. Changes to this policy
If we change how PitchWhip handles data (a new sub-processor for cloud data, a new category of data, a new purpose), we will update this page first. The effective date changes before the change takes effect. For significant changes we will also email licence holders. Earlier versions are available on request.
19. Contact
PitchWhip Ltd, 96A Wandsworth Bridge Road, London SW6 2TF, United Kingdom. Email hello@pitchwhip.com.
Data protection representative in the EU/EEA and Switzerland
From 30 September 2026, our representative for data protection matters in the EU/EEA and Switzerland is Data Protection Representative Limited (trading as DataRep). You can contact DataRep about your personal data or to exercise your data protection rights:
- Email: datarequest@datarep.com
- Online form: Contact DataRep
- EU/EEA postal address: DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Republic of Ireland.
- Swiss postal address: DataRep, Leutschenbachstrasse 95, Zurich, 8050, Switzerland.
Put “PitchWhip Ltd” in your email subject line or message. Address letters to “DataRep” and refer to PitchWhip Ltd in the letter. DataRep explains how it handles your data in its privacy notice. For UK privacy matters and general product queries, contact hello@pitchwhip.com.