BranchPage CRM

Trust

Privacy Policy

This page covers the data BranchPage itself collects and processes as the vendor of this CRM — the workspaces that use it, and the people whose accounts and contact records live inside it. It does not speak for any tenant's own messaging consent, which is that tenant's commitment, published at their own /legal/<slug> page.

Last updated 11 September 2026

What we collect

Your account
Name, email address, and role within your workspace — created when your workspace invites you, or when you sign in.
Contacts and leads
The records a workspace loads into the CRM: names, email addresses, phone numbers, notes, and the history of messages and activity logged against them. This data belongs to the tenant that entered it, not to us.
Usage metadata
Sign-ins, feature usage, and API activity, kept for security, billing, and the audit log described on our security page.

How AI is used

Several features send data to an AI provider to generate a result. In every case, content aimed at a client or lead is a draft a person reviews before anything is sent — the AI does not send on its own.

AI Companion
Answers questions about your book of business and drafts replies to leads and clients. Drafted replies are never sent automatically; a person reads, edits, and sends them.
AI Automation module
Plans and runs workflow steps a workspace configures, within limits your workspace sets.
AI Studio
Generates flyers and landing pages from a prompt, for a person to review and publish.
Image generation for Social
Generates images for social posts from a prompt; the resulting post is a draft until a person schedules or publishes it.
Which provider
These features run on third-party AI model providers — see the subprocessor table on /security for what each one receives. Data sent to generate a result is not used to train their models.

Who we share it with

We do not sell personal data. The third parties that process it on our behalf — what each one receives and why — are listed in the Subprocessors table on the security page: Supabase, Vercel, Resend, Twilio, Cloudmersive, Atlassian (Jira), Seamless.AI, UpLead, Stripe, Microsoft (Graph), Meta (Facebook / Instagram), LinkedIn, and the AI model providers behind the features described above.

Your rights

Access
You can ask what personal data we hold about you or your workspace's contacts.
Deletion
Contacts and uploaded documents can be deleted from within the product. On termination of a workspace, its data is deleted on the schedule described on /security. Reach out below for a deletion request outside the product.
Questions
Email support@branchpage.com with any privacy question or request, including access or deletion.

For how we handle security, encryption, and tenant isolation, see /security. Questions this page doesn't answer: support@branchpage.com.