How Atlas Find processes account, CRM, integration, contact-form and sales workflow data.
1. Information we process
- Basic identity information such as name, email address and profile photo when Google Sign-In is used.
- Email address and authentication information when email/password registration is used.
- Business records, contact information, notes, tasks and sales stages added to CRM.
- Business name, address, rating and similar information returned through Google Places searches.
- When an Instagram professional account is connected: account identifiers, username, authorization data and messaging events used for the connected feature.
- Information submitted through the marketing-site contact form, including name, email, phone, company, subject and message.
- A limited one-way HMAC-derived IP summary may be used for spam and abuse prevention instead of storing the raw IP address for that purpose.
- Limited technical logs used for security, performance and debugging.
2. Why we use this information
- Provide secure account and session management.
- Store CRM records, tasks and sales workflow state.
- Run company searches and AI-assisted analysis requested by the user.
- Display messages for a connected Instagram professional account and transmit user-approved replies.
- Respond to demo, pricing, partnership and support requests.
- Protect the security, availability and performance of the service.
3. Google user data and Gmail access
Google Sign-In is used to create or identify your Atlas Find account and provide secure sign-in. Google Sign-In does not by itself provide Atlas Find with access to Gmail message content.
- Gmail access is separate and becomes active only when a user connects Gmail from the product and explicitly grants permission on Google's consent screen.
- Atlas Find's current Gmail integration requests only
https://www.googleapis.com/auth/gmail.send. This permission is used solely to send a specific email from the user's connected Gmail account after the user has reviewed the recipient, subject and body and explicitly initiates the send action in Atlas Find. - Through the
gmail.sendpermission, Atlas Find does not read the user's Gmail inbox, existing messages, labels, contacts or drafts. - Atlas Find does not send Gmail messages without an explicit user-initiated send action.
- Users can revoke Atlas Find access from their Google account permissions and can request deletion of associated data.
4. Google API Services — Limited Use Compliance
Atlas Find's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Raw or derived user data received from Google Workspace APIs is used only to provide user-requested functionality in Atlas Find.
- Google Workspace API user data is not sold or used for advertising targeting.
- Google Workspace API user data is not shared or transferred for purposes unrelated to providing the user-requested feature.
- Raw, aggregated, or derived user data received from Google Workspace APIs is not used, transferred, or shared for the purpose of developing, improving, or training generalized or non-personalized artificial intelligence or machine learning models.
- Atlas Find's other AI-assisted features do not use Google Workspace API user data to train foundational or general-purpose AI/ML models.
5. Cookies and similar technologies
The marketing site may use essential technologies for security, language preferences, the contact form and storing consent choices. Optional analytics or marketing technologies are not activated without user consent. See the Cookie Policy.
6. Service providers
Atlas Find may use Supabase for authentication and data storage, Google Places for company discovery, OpenAI for AI analysis, Meta for Instagram integrations, Vercel for hosting and server functions, Cloudflare Turnstile for contact-form abuse protection, Resend for form notifications, and iyzico where payment processing is offered. These providers may process data under their own terms and privacy policies.
7. Retention and security
Data is retained for the period needed to provide the service and meet applicable obligations. Documented technical measures include row-level access policies, server-side secret management, Cloudflare Turnstile verification, rate limiting and access controls. For contact-form rate limiting, a one-way digest derived with a secret key is used instead of retaining the raw IP for that purpose.
8. Data deletion
You can request deletion of your account and associated data by following the Data Deletion instructions.
9. Contact
Send access, correction or deletion requests to [email protected]. Account ownership may be verified for security.
Use the email address associated with your account when relevant.
