Recavo Privacy Policy
Recavo Labs, LLC (“Recavo,” “we,” “us,” or “our”) Effective date: July 1, 2026 Last updated: July 24, 2026
This Privacy Policy explains what personal data Recavo collects when you use Recavo (the “Service”) at recavolabs.com, why we collect it, how we use and share it, and the choices and rights you have. It applies to visitors to our website, people who create an account, and end users of the Recavo application.
Recavo is a single-player CRM for quota-carrying sales representatives. This policy covers two kinds of personal data:
- Your personal data — information about you as an account holder (for example, your name, email, and billing details).
- CRM content you enter — information about your prospects, accounts, contacts, and deals that you choose to store in Recavo. You control this content; for that content, Recavo acts on your instructions. How we handle CRM content on your behalf is governed by our Data Processing Agreement.
1. Data we collect
Account and identity data. When you sign up, we collect your email address and a securely hashed password, or, if you use Google sign-in, your Google account identifier and basic profile information. We also generate session tokens to keep you signed in.
CRM content. Information you add about your accounts, contacts, and deals — including names, job titles, company names, phone numbers, email addresses, addresses, notes, and activity you log. This may include personal data about third parties (your prospects and customers).
Voice recordings and transcripts. If you use voice-to-text notes (Elite Closer tier), we process the audio you record and the transcript generated from it. Audio is sent to our speech-to-text provider to produce the transcript, which is then stored with your notes.
AI Brief inputs and outputs. When you request an AI pre-call brief, we process the account, contact, and company information involved — including web search queries and target URLs — to generate research for you.
Location data. If you use My Day Routing or map features, we process the addresses and location queries you provide to geocode them and plan routes.
Payment data. If you subscribe to a paid tier, our payment processor collects your name, payment method, and billing address. Recavo does not store full card numbers; card data is handled by Stripe.
Inbound email. If you use the Email Drop Box, we receive and process the emails (and attachments) you forward into Recavo, including sender and recipient addresses and message content.
Technical and usage data. We automatically collect your IP address, request headers, device and browser information, and diagnostic data (such as error reports). If you consent to analytics, we also collect page views and product-usage events.
Cookies. We use essential cookies to run the Service and, only with your consent, analytics cookies. See our Cookie Policy.
2. Why we use your data, and our legal bases
We use personal data to:
- Provide the Service — create and secure your account, store and display your CRM data, run AI Briefs, transcribe voice notes, plan routes, and deliver email features. Legal basis: performance of a contract.
- Process payments — bill subscriptions and manage your plan. Legal basis: performance of a contract.
- Secure and maintain the Service — authenticate you, prevent abuse, rate-limit requests, monitor errors, and debug. Legal basis: legitimate interests in keeping the Service safe and reliable.
- Communicate with you — send transactional messages about your account, security, and billing. Legal basis: performance of a contract and legitimate interests.
- Improve the Service through analytics — understand how features are used. Legal basis: your consent (analytics cookies are off until you opt in).
- Comply with law — meet legal, tax, and regulatory obligations. Legal basis: legal obligation.
We do not sell your personal data, and we do not use your CRM content or voice recordings to train our own or third-party AI models.
3. Who we share data with
We share personal data only with service providers (“subprocessors”) that help us operate the Service, and only as needed for them to perform their function. Our full, current list of subprocessors — including each vendor’s legal entity, purpose, the categories of data they process, and processing region — is maintained in the Subprocessor List.
In summary, we rely on subprocessors for: application hosting and infrastructure (Google Cloud Platform), database and authentication (Neon), AI inference and speech-to-text (Fireworks AI, via our self-hosted proxy), web search and page retrieval for AI Briefs (Tavily, Firecrawl), payments (Stripe), transactional and inbound email (Postmark), background jobs (Inngest), mapping and geocoding (Google Maps Platform), rate limiting (Upstash), error monitoring (Sentry), observability (Grafana Cloud), analytics (Google Analytics 4, only with consent), and DNS, domain, and reverse-proxy services (Cloudflare).
We may also disclose personal data (a) to comply with law, legal process, or a lawful government request; (b) to enforce our Terms of Service or protect the rights, safety, and property of Recavo, our users, or others; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this policy or notify you of any material change.
4. Data location and international transfers
Recavo has no regulatory data-localization mandate. We prefer United States processing and select a US region wherever a subprocessor offers one at no additional cost. Some processing is genuinely global: Cloudflare operates in reverse-proxy mode on a non-Enterprise plan, so inbound traffic (including IP addresses, request headers, and URLs) transits Cloudflare’s global anycast edge and cannot be pinned to the US. See the Subprocessor List for the region applicable to each vendor.
If you access Recavo from outside the United States, you understand that your data will be processed in the United States and, for certain infrastructure, at global edge locations. Where required, transfers of personal data out of the European Economic Area, United Kingdom, or Switzerland rely on Standard Contractual Clauses or another lawful transfer mechanism, which we implement through our subprocessor agreements.
5. How long we keep data
We keep your account data and CRM content for as long as your account is active. When you delete specific records, they are removed from active systems and purged from backups on our normal backup-rotation cycle. When you close your account, we delete or de-identify your personal data and CRM content within 90 days, except where we must retain limited information to comply with legal, tax, or accounting obligations, resolve disputes, or enforce our agreements. Voice audio is retained only as long as needed to produce and store your transcript; we retain the transcript with your notes until you delete it.
6. How we protect data
We apply technical and organizational safeguards appropriate to the risk, including: encryption in transit (TLS) and at rest; row-level security so that each user can access only their own data; scoped, authenticated database access; secrets stored in a managed secret manager and never exposed to client code; rate limiting; and error-monitoring configured to minimize personal data (our error monitor runs with default PII capture disabled, and logs are scrubbed of personal data before export to our observability provider — on our marketing site, error monitoring is consent-gated and continuously buffers a masked session replay — a reconstruction of the page with all text, form inputs, and media hidden — in the visitor’s browser, which is typically transmitted to our error monitor only if an error occurs and is otherwise generally discarded). No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you and any affected customers of a personal-data breach as required by law.
7. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority. You can exercise many of these directly in the app by editing or deleting your records, or by closing your account. For any request, contact us at privacy@recavolabs.com and we will respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
Analytics choice. Analytics cookies do not run until you opt in through our consent banner, and you can withdraw consent at any time. See the Cookie Policy.
CRM content about others. Much of the content you enter is about your prospects and customers. As the person who decides what to store, you are responsible for having a lawful basis to do so and for responding to their requests; we will assist you as described in the Data Processing Agreement.
8. Children’s data
Recavo is a business tool intended for users who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us at privacy@recavolabs.com and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app or by email. Your continued use of the Service after an update means you accept the revised policy.
10. Contact us
Recavo Labs, LLC is the controller of your account data. For any privacy question or request, or to reach our privacy officer, contact:
Recavo Labs, LLC Email: privacy@recavolabs.com
Related documents: Terms of Service · Cookie Policy · Data Processing Agreement · Subprocessor List