Privacy Policy
Effective Date: 10 June 2026 · Last Updated: 10 June 2026
This Privacy Policy describes how MarketWise360 ("we," "our," or "us") collects, uses, shares, and protects information about you when you use our AI-powered sales and marketing platform and all associated services (collectively, the "Service"). By using the Service, you agree to the practices described here. If you have any questions, we're always happy to help at legal@marketwise360.com.
1. Overview
MarketWise360 is a business productivity platform that integrates with your email, calendar, spreadsheets, and social media accounts to help you manage client relationships, automate outreach, and grow your business. Because we access sensitive data — particularly your email messages via Google's APIs — we take your privacy seriously and are committed to transparency about how that data is handled.
Key privacy commitments:
- We do not sell your personal data to third parties.
- We do not use your email content or Google API data for advertising or marketing profiling.
- Google API data is used only to provide the specific features you request within the Service.
- You can request deletion of your account and data at any time.
2. Data Controller
The data controller responsible for your personal data is:
MarketWise360
AI-Powered Marketing and Sales Platform
Email: legal@marketwise360.com
Support: support@marketwise360.com
If you are located in the European Economic Area (EEA), the United Kingdom, or other regions with applicable data protection laws, MarketWise360 is the data controller of your personal data.
3. Information We Collect
We collect the following categories of information depending on the features you use:
3.1 Account & Profile Information
- Name, email address, and profile picture (via Google OAuth or direct registration)
- Password (hashed and salted; never stored in plain text)
- Organization name and settings
- User role (e.g., Organization Admin, Team Member)
- Account creation date and last login time
- Subscription tier and billing status
3.2 Email & Communication Data
When you connect an email account (via Google OAuth or IMAP/SMTP), we access and store:
- Email message bodies (plain text and HTML)
- Email metadata: sender, recipients, subject, date, labels, and thread IDs
- Email attachments (where relevant to AI analysis features)
- Sent emails generated by the Smart Reply or outreach features
- Inbox sync history and last-synced timestamps
Email data is stored in our database and is used solely to provide the email management, AI analysis, and Smart Reply features. We do not read your emails for purposes other than operating the Service features you explicitly use.
3.3 Calendar Data
When you grant calendar access (via Google OAuth), we access and store:
- Calendar event titles, descriptions, times, and attendees
- Event data extracted from emails (via AI event detection)
3.4 Spreadsheet Data
When you connect Google Sheets (via OAuth), we access and store:
- Sheet structure, column headers, and row data from sheets you explicitly link to MarketWise360 features (e.g., contact imports, CRM sync)
3.5 CRM & Contact Data
- Contact names, email addresses, phone numbers, company, and job titles
- Contacts extracted by AI from email threads
- CRM pipeline stages, deal values, and notes
- Interaction history and communication logs
- Contact tags, categories, and custom fields
3.6 AI-Generated Data
- Smart Reply drafts and email suggestions
- AI-identified action items, follow-ups, and summaries
- Extracted contacts and calendar events from email content
- Tone analysis, priority scores, and sentiment results
- Knowledge base articles and AI-generated content you create
3.7 Social Media Data
When you connect social accounts (Facebook, Instagram, Twitter/X, LinkedIn, TikTok), we access:
- Page/profile information, follower counts, and post metrics
- Content you publish or schedule through the platform
- Engagement data (likes, comments, shares) where permitted by platform APIs
Social media data is governed by the respective platform's own privacy policies in addition to this policy.
3.8 Partner & Commission Data (360Hero Program)
- Your referral code and referred clients
- Commission ledger entries and payout records
- Bank or payment account details required for commission disbursement
3.9 Technical & Usage Data
- IP address and approximate geographic location
- Browser type, operating system, and device identifiers
- Pages visited, features used, and session duration
- Error logs and performance diagnostics
- Session cookies and authentication tokens
4. Google API Data — Limited Use Disclosure
Google API Services User Data Policy Compliance
MarketWise360's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.1 Google OAuth Scopes We Request
MarketWise360 requests the following Google OAuth scopes, and only those strictly necessary for the features you use:
https://www.googleapis.com/auth/gmail.readonly— Read email messages and metadata to display your inbox and enable AI analysishttps://www.googleapis.com/auth/gmail.send— Send emails on your behalf via Smart Reply and outreach featureshttps://www.googleapis.com/auth/gmail.modify— Update email labels (e.g., mark as read) and manage your inboxhttps://www.googleapis.com/auth/calendar— Read and create calendar events detected from email contenthttps://www.googleapis.com/auth/spreadsheets.readonly— Read Google Sheets data you explicitly connect for CRM imports or sync
4.2 Limited Use Commitments for Google API Data
With respect to data obtained through Google APIs, MarketWise360 commits to the following:
- Purpose limitation: We use Google API data (including Gmail message content) only to provide the email management, Smart Reply, AI analysis, contact extraction, calendar integration, and inbox organisation features within the Service — the features you explicitly request.
- No advertising use: We do not use Gmail data, message content, or other Google API data for serving advertisements or building advertising profiles.
- No resale or transfer: We do not sell, rent, or transfer Google API data to third parties. We only share it with subprocessors as strictly necessary to provide the requested Service features (e.g., AI providers to generate Smart Replies), as detailed in Section 7.
- No use to train AI models: We do not use your Gmail data or email content to train, improve, or develop AI or machine learning models beyond the specific, immediate inference requests you initiate.
- No creditworthiness use: We do not use Google API data to determine creditworthiness or for any lending purposes.
- Human access restrictions: We do not allow MarketWise360 employees or contractors to read your Gmail message content, except: (a) with your explicit consent; (b) when necessary to investigate abuse or a security incident; or (c) as required by applicable law, and only then on an aggregated or minimum-necessary basis.
- Credential security: OAuth tokens and refresh tokens are stored encrypted. We implement access controls to ensure only authorised service components can use your credentials.
4.3 Revoking Google Access
You can revoke MarketWise360's access to your Google account at any time by visiting your Google Account Permissions page and removing MarketWise360. You may also disconnect your Google account within the Service's settings. Revoking access will prevent email sync and AI features from functioning until reconnected.
5. How We Use Your Information
We use the information we collect for the following purposes:
5.1 Providing the Service
- Authenticating your account and maintaining your session
- Syncing and displaying your email inbox and messages
- Generating AI-powered Smart Replies and email analyses
- Extracting contacts, events, and action items from emails
- Managing your CRM pipeline, contacts, and communication history
- Scheduling and publishing social media content
- Calculating and disbursing 360Hero partner commissions
5.2 Improving and Securing the Service
- Diagnosing and fixing technical errors
- Monitoring for security threats and abuse
- Understanding aggregate feature usage to improve the platform
5.3 Communications
- Sending transactional emails (e.g., email sync notifications, sync error alerts)
- Responding to your support requests
- Sending product updates or policy changes (you can opt out of non-essential communications)
5.4 Legal & Compliance
- Complying with applicable laws and regulatory requirements
- Enforcing our Terms and Conditions
- Responding to lawful requests from public authorities
6. AI Processing Disclosure
MarketWise360 uses artificial intelligence features to analyse email content, generate replies, extract information, and provide insights. This processing is triggered only when you actively use an AI feature (e.g., clicking "Smart Reply," running "AI Analysis," or enabling automated inbox triage).
6.1 AI Providers
Depending on your configuration and subscription tier, AI inference may be performed by one or more of the following third-party providers. When an AI feature is used, the minimum necessary content (such as the email body or thread excerpt) is transmitted to the selected provider via an encrypted API call:
- Ollama — Local/on-device model inference (no data leaves your server when using this option)
- OpenRouter — Routes to various large language models; subject to OpenRouter's Privacy Policy
- Google AI / Gemini — Subject to Google's Privacy Policy
- Groq — Subject to Groq's Privacy Policy
- DeepSeek — Subject to DeepSeek's Privacy Policy
- HuggingFace — Subject to HuggingFace's Privacy Policy
6.2 What Is Sent to AI Providers
- Email message text (body content) for Smart Reply generation and analysis
- Thread context for multi-email analyses
- Prompts you explicitly submit through Knowledge Base or AI tools
We do not send your name, passwords, OAuth tokens, payment details, or full contact lists to AI providers. Prompts are designed to include only the minimum content necessary to generate useful responses.
6.3 AI Provider Data Use
Each AI provider's data use policies govern how they handle content sent to their APIs. We encourage you to review their respective privacy policies linked above. MarketWise360 does not authorise AI providers to use your data for training their models beyond what is described in their published API terms.
6.4 Local AI Option
If you configure Ollama (local inference) as your AI provider, email content is processed entirely on your own infrastructure and is not transmitted to any external service.
7. Third-Party Services & Integrations
MarketWise360 integrates with the following categories of third-party services. Each is governed by its own privacy policy in addition to ours:
7.1 Google Services
Gmail, Google Calendar, and Google Sheets via OAuth 2.0. See Section 4 for full details on our Limited Use commitments. Governed by Google's Privacy Policy.
7.2 Social Media Platforms
Facebook / Meta, Instagram, Twitter/X, LinkedIn, and TikTok via their respective platform APIs. Data shared with these platforms is governed by their own privacy policies. We only access data you explicitly authorise during the OAuth connection flow.
7.3 Email (IMAP/SMTP)
You may connect non-Google email accounts via IMAP/SMTP credentials. These credentials are stored encrypted and used solely to sync and send email on your behalf.
7.4 AI Providers
See Section 6.1 for the full list of AI providers and links to their privacy policies.
7.5 Payment Processing
MarketWise360 uses or may use Stripe for payment processing. MarketWise360 does not store full credit card numbers. Payment data is handled directly by Stripe and governed by Stripe's Privacy Policy.
7.6 Infrastructure & Hosting
The Service is hosted on cloud infrastructure (Railway). Your data is stored in databases provisioned within this infrastructure. These providers operate under strict data processing agreements with us.
8. Data Sharing & Disclosure
We do not sell your personal data. We share data only in the following circumstances:
8.1 Within Your Organisation
If you use MarketWise360 as part of an organisation workspace, Organisation Admins may view certain account activity, shared contacts, CRM data, and pipeline information for team members within that workspace. Personal email content is not shared with other workspace members unless you explicitly use a shared feature.
8.2 Service Providers (Subprocessors)
We share data with subprocessors (AI providers, hosting, payment processors) strictly as necessary to provide the Service. These parties are contractually prohibited from using your data for their own purposes.
8.3 Legal Requirements
We may disclose data when required by applicable law, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
8.4 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the acquiring entity. We will notify you via email or prominent notice in the Service before your data is transferred and becomes subject to a different privacy policy.
8.5 With Your Consent
We may share your data for other purposes with your explicit prior consent.
9. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specific retention practices:
- Account data: Retained for the lifetime of your account and for up to 90 days after account deletion to allow for account recovery and dispute resolution.
- Email data: Synced emails are retained in our database while your account is active. You can delete synced emails through the Service interface at any time.
- AI-generated outputs: Smart Reply drafts and AI analysis results are retained while your account is active. You may delete individual items through the Service.
- CRM & contact data: Retained while your account is active. You can delete contacts and records individually.
- Audit & security logs: Retained for up to 12 months for security and compliance purposes.
- Partner commission records: Retained for up to 7 years to comply with financial and tax record-keeping requirements.
After account deletion, we will delete or anonymise your personal data within 90 days, except where longer retention is required by law.
10. Security
We implement industry-standard technical and organisational measures to protect your data, including:
- TLS/HTTPS encryption for all data in transit
- Encrypted storage of OAuth tokens, passwords (bcrypt), and IMAP/SMTP credentials
- HTTP-Only, Secure, and SameSite=Lax session cookies with a 14-day sliding window
- Role-based access controls limiting which service components can read your data
- Regular security reviews and dependency updates
No method of transmission over the internet or electronic storage is 100% secure. While we apply strong measures to protect data under our direct control, we cannot guarantee absolute security. In the event of a data breach within our systems that is likely to result in high risk to your rights and freedoms, we will notify you and relevant authorities as required by applicable law.
Please also be aware that MarketWise360 integrates with third-party services — including Google, social media platforms, and AI providers — whose systems operate independently of ours. We are not responsible for data incidents, unauthorised access, or security failures that occur within those third-party systems. When you choose to connect a third-party service, your data also becomes subject to that service's own security practices and policies. We encourage you to review the security and privacy practices of any service you connect.
11. Your Rights
11.1 Rights Under GDPR (EEA & UK Users)
If you are in the EEA or the United Kingdom, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data.
- Right to restriction: Request that we restrict processing of your data in certain circumstances.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Rights related to automated decision-making: We do not make legally significant automated decisions about you without human review.
11.2 Rights Under CCPA (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell.
- Delete personal information we have collected (subject to certain exceptions).
- Opt out of the sale of personal information. (We do not sell personal information.)
- Non-discrimination for exercising your CCPA rights.
11.3 How to Exercise Your Rights
To exercise any of the above rights, contact us at legal@marketwise360.com. We will respond within 30 days (or within any shorter period required by applicable law). We may need to verify your identity before processing your request.
If you are in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
13. Children's Privacy
MarketWise360 is a business productivity platform intended for use by individuals aged 18 and older. We do not knowingly collect personal data from children under the age of 16 (or under 13 in the United States). If you believe a child has provided us with personal data, please contact us at legal@marketwise360.com and we will take steps to delete that information.
14. International Data Transfers
MarketWise360 operates from and stores data in facilities that may be located outside your country of residence. When we transfer personal data from the EEA or UK to countries that do not provide an adequate level of data protection, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms.
By using the Service, you consent to the transfer of your information to countries outside your country of residence, including countries that may have different data protection rules than your country.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (at the address associated with your account) and by posting a prominent notice in the Service at least 30 days before the changes take effect. The "Last Updated" date at the top of this page indicates when this policy was last revised.
Your continued use of the Service after the revised Privacy Policy takes effect means you accept the updated practices. If you ever have concerns about a change, please reach out to us — we'll be happy to explain or assist with closing your account if you prefer.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy & Legal
MarketWise360
Email: legal@marketwise360.com
General support: support@marketwise360.com
We aim to respond to all privacy enquiries within 30 days.