1. Who We Are
PipeGuide (operated by PipeGuide (Pty) Ltd) is a B2B SaaS that provides real-time AI coaching during sales conversations. This Privacy Policy explains how we collect, use, and share information when you use our Service. We act as the Responsible Party (under POPIA) / Data Controller (under GDPR) for the information described in clause 2 below.
2. Information We Collect
Account Information
- Name, email address, role (admin / manager / sales) within your organisation, and department assignment.
- Authentication credentials. Passwords are hashed with bcrypt and never stored in plain text. We also support Google Sign-In (OAuth).
- Organisation profile: organisation name, primary admin, framework configuration (BANT / MEDDIC / etc.), and team size.
- Billing details: subscription plan, billing cycle, and a Paystack customer reference. We do not store full card numbers — those are tokenised by Paystack.
Call and Conversation Data
- Text transcriptions captured via your browser microphone (Deepgram) or via a meeting bot (Recall.ai) that joins online meetings.
- AI-generated qualification scores, coaching suggestions, post-call summaries, recommended next steps and risk assessments.
- Solution notes, requirements, prospect information and company details you enter during or after a call.
- Optional CRM identifiers (e.g. HubSpot deal IDs, Pipedrive contact IDs) when you push a summary to your CRM.
Usage Data
- Login timestamps and session activity (last-active time, IP address for security and rate-limiting).
- Features used, calls completed, tokens consumed, and bot-join success rate.
- Server logs (request URL, status code, response time) for the limited purpose of debugging and abuse prevention.
3. How We Use Your Information
- Service delivery: transcribe conversations, generate live coaching, score qualification, build post-call summaries.
- AI analysis: conversation transcripts are sent to AI language models (currently OpenAI GPT) for analysis. Only the text transcript is sent — no raw audio is sent to AI providers.
- Billing: Paystack processes subscription and top-up charges. We retain payment metadata (status, reference, last 4 digits) for accounting and dispute purposes.
- Account lifecycle: we send transactional emails about failed payments, account suspension, weekly coaching digests, and product updates.
- Analytics: aggregated and de-identified data may be used internally to improve the Service. We do not run third-party advertising or tracking analytics (no Google Analytics, no Mixpanel, no Facebook Pixel).
- Security: we log authentication events, run brute-force protection on the login endpoint, and rate-limit sensitive endpoints to protect your account.
4. Third-Party Sub-processors
To deliver the Service we rely on the following sub-processors. Each is bound by a Data Processing Agreement and processes data only on our instructions:
| Provider | Purpose | Data shared |
|---|
| Recall.ai | Meeting bot — joins Zoom/Teams/Meet, captures audio, returns transcripts | Meeting URL, captured audio, transcript |
| Deepgram | Speech-to-text for browser-microphone calls | Audio stream (not stored after transcription) |
| OpenAI | AI analysis, coaching, summaries | Text transcript only (no audio) |
| Paystack | Payment processing (cards, EFT) | Billing details, transaction metadata |
| Resend | Transactional emails (invites, digests, billing alerts) | Email address, name, message content |
| MongoDB Atlas | Encrypted database hosting | All Customer Data, at rest |
| Emergent.sh | Application hosting and infrastructure | All Customer Data, in transit |
| Google (OAuth) | Optional sign-in via Google account | Email address, name, profile picture |
The current list of sub-processors is always available at app.pipeguide.tech/sub-processors.
5. Data Storage and Security
- Customer Data is stored in encrypted MongoDB Atlas databases hosted in Africa (primary) with backup replication.
- All data transmission uses TLS / HTTPS encryption.
- Passwords are hashed using bcrypt with appropriate cost factors.
- JWT access tokens are short-lived; refresh tokens can be revoked at any time. Token-version bumping enforces immediate logout when an org is suspended.
- Access to data is restricted by role-based permissions: sales reps see only their own calls; managers see their team; admins see their organisation; the platform operator can only access an org via an audit-logged impersonation flow.
- Sensitive third-party credentials (e.g. CRM API keys) are encrypted at rest.
6. Data Retention
- Call transcripts, summaries and AI-generated analyses are retained for as long as your account is active.
- If your account is suspended for non-payment, all data is preserved unchanged until the account is reactivated.
- If your account is terminated (whether by you, by us, or automatically after 30 days of unpaid billing), Customer Data is retained for a further 60 days in a read-only state during which you may request a full export or reactivation.
- After the 60-day retention window expires, all Customer Data is permanently deleted from production systems and from backups within a further 30 days.
- De-identified aggregate analytics (counts, averages) may be retained indefinitely. The minimum metadata required to evidence compliance with this policy (e.g. a deletion audit log entry containing the organisation ID and timestamp) is retained per applicable law.
- Where applicable law requires longer retention (e.g. tax invoices: 5 years under South African tax law), we retain only the specific data required by that law.
7. Your Rights
Depending on your jurisdiction (POPIA, GDPR, CCPA), you may have the following rights:
- Access: request a copy of personal data we hold about you.
- Correction: request correction of inaccurate data.
- Deletion: request deletion of your personal data (subject to legal retention requirements).
- Portability: request your data in a portable format. We provide PDF exports of call summaries and CSV exports of session data from within the app.
- Objection: object to certain processing activities.
- Withdraw consent: where processing is based on your consent, you may withdraw it at any time.
- Lodge a complaint: with your local data protection authority (e.g. the Information Regulator in South Africa).
To exercise any of these rights, contact us at support@pipeguide.tech. We respond within 30 days.
8. International Data Transfers
Some sub-processors (OpenAI, Recall.ai, Deepgram, Resend) operate from the United States and may process your data outside your country of residence. We rely on Standard Contractual Clauses, equivalent safeguards under POPIA section 72, and provider-specific assurances to ensure adequate protection. By using the Service you consent to these transfers.
9. Cookies
We use only strictly-necessary cookies to keep you signed in (session cookies and authentication tokens). We do not use analytics, advertising, or tracking cookies. You can disable cookies in your browser settings, but doing so will prevent the Service from working.
10. Children's Privacy
PipeGuide is a B2B service intended for business professionals. We do not knowingly collect data from individuals under the age of 18.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect.
12. Contact
For questions about this Privacy Policy, to exercise your data rights, or to report a data incident, please contact our Information Officer at support@pipeguide.tech.