Last updated 31 August 2026

Privacy Policy

Pivotloops holds client engagement records for professional services firms. This page says what we collect, why we hold it, who else touches it, and how to get it back or have it removed.

1.Who this is about

Pivotloops is operated by Pivotloops (“we”, “us”). It is software used by professional services firms — consultancies, advisory practices — to run client engagements: companies, contacts, proposals, agreements, contracts and signatures.

That makes two different relationships, and they matter for what follows. A firm using Pivotloops decides what client information goes into its workspace; we hold and process that on the firm’s instructions. A client of that firm may receive a document to read or sign; the firm decides what they are sent, and we handle it on the firm’s behalf. If you are a client and want something changed or removed, the firm that sent it to you is the right first stop — though you can always reach us at privacy@pivotloops.com.

2.What we collect

Account information. Your name and email address, and — if you set a password — a cryptographic hash of it. We never store a password in a form we can read.

If you sign in with Google. We request two scopes and no others: email and profile. That gives us your email address, your name, your profile picture and your Google account identifier. We do not request, receive, or have any access to your Gmail, Drive, Calendar, Contacts, or any other Google service.

Workspace content. Whatever the firm puts in: companies, contacts, proposals, agreements, contract text, comments, uploaded documents and files. We do not choose what goes here.

Signing evidence. When a document is signed, we record the signer’s name and email, timestamps, the IP address and browser user-agent string at the moment of consent, and the consent statement itself. This is not analytics. An electronic signature is only worth as much as the record proving who made it and when, and that record has to survive a dispute.

Feedback you send. If you use the feedback control, we receive your message along with the page you were on, its address, your browser user-agent, and your name and email. The form says so before you send it.

Operational logs. Ordinary server and security logs, kept briefly, used to keep the service running and to investigate abuse.

We do not use advertising trackers, we do not build advertising profiles, and we do not sell personal information to anyone.

3.Why we hold it

  • To provide the service: signing you in, showing your workspace, sending the documents you ask us to send.
  • To produce and preserve signature records that stand up as evidence.
  • To send transactional email — an invitation, a document to sign, a notification you asked for. We do not send marketing email to your clients.
  • To keep the service secure, and to investigate misuse.
  • To meet legal obligations, and to establish or defend legal claims.

4.AI features, and what actually leaves

Pivotloops can answer questions about a contract and draft plain-English explanations. To do that, contract text is sent to a third-party model provider (currently OpenAI).

What is sent is narrower than the document you see, and narrower by construction rather than by care. A single function produces every payload that leaves for a model, and it removes the filled-in values of document fields and every internal counsel note before anything goes. The field markers remain; the values you typed into them stay here.

We will not claim more than that. Redaction cannot rewrite prose it does not understand — if a name or a figure is typed directly into a clause rather than into a field, it travels with the clause. The product reports that residue to you rather than hiding it. If a document must never reach a model, do not use the AI features on it.

We do not permit the model provider to train on your content, and we do not use your content to train models of our own.

5.Who else touches it

We use a small number of providers, each for one job:

  • Supabase — database, authentication and file storage. This is where your workspace lives.
  • Google — only if you choose to sign in with Google, and only for that.
  • Resend — delivery of transactional email.
  • OpenAI — the AI features described above, on the redacted payload.
  • Our hosting provider — running the application itself.

Each is bound to use what it receives only to provide its service to us. We will also disclose information where the law requires it, and we will tell you when we are permitted to. If the business is ever sold or merged, records may transfer with it; the successor is bound by this policy until it publishes one that supersedes it, and you will be told before that happens.

6.Google user data, specifically

Data received from Google APIs is used only to sign you in and to show your name and picture inside the product. It is not transferred to anyone except the providers named above, not used for advertising, not sold, and not used to build any profile of you.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Pivotloops from your Google account at any time at myaccount.google.com/permissions.

7.Where it is held, and for how long

Records are stored on infrastructure operated by the providers above, which may process data in the United States and elsewhere. Where information moves between countries, we rely on the transfer mechanisms our providers make available.

Workspace content is kept while the firm’s account is active. When an account is closed, we delete or anonymise the workspace within 90 days, with two exceptions we think you would want: executed documents and their signature evidence are retained for as long as they may be needed to prove what was agreed, and records we are legally required to keep are kept for that period. Backups age out on their own schedule.

8.Your choices

Depending on where you live you may have rights to access, correct, export, or delete personal information, to object to or restrict how it is used, and to complain to a regulator. We honour these regardless of where you live, subject to the retention exceptions above.

Write to privacy@pivotloops.com. We will answer within 30 days. If you are a client of a firm using Pivotloops, we will pass your request to that firm and tell you we have done so, because the content is theirs to decide about.

9.Security

Every record carries the workspace it belongs to, and the database enforces that boundary itself rather than trusting the application to remember — one firm cannot read another’s rows even if the application asks it to. Traffic is encrypted in transit. Passwords are stored only as hashes. Access to production is limited and logged.

No system is perfectly secure. If a breach affects your information, we will tell you and the relevant regulator without undue delay.

10.Children

Pivotloops is a business tool and is not directed at anyone under 16. We do not knowingly collect information from children. If you believe we have, write to us and we will delete it.

11.Changes, and how to reach us

If we change this policy we will update the date at the top, and for anything that materially affects you we will give notice in the product before it takes effect.

Questions, requests, or a security report: privacy@pivotloops.com. The companion document is our Terms of Service.