---
title: "Privacy Policy"
description: "Learn how FirstSales collects, uses, and protects your personal data when you use our B2B cold email and outreach platform."
canonical: "https://firstsales.io/privacy-policy/"
---

1. [Home](/)
2. Privacy Policy

# Privacy Policy

This Privacy Policy explains what personal data FirstSales collects when you use our cold email outreach platform, how we use it, and your rights over it. Please read it carefully before connecting your mailboxes or uploading prospect lists.

Last updated June 13, 2026

On this page

* [1\. Introduction and Scope](#introduction)
* [2\. Information We Collect](#information-we-collect)
* [3\. How We Use Your Information](#how-we-use-information)
* [4\. Legal Bases for Processing (GDPR)](#legal-bases)
* [5\. Connected Mailbox and Sending Data](#mailbox-sending-data)
* [6\. User-Uploaded Prospect and Contact Data](#prospect-data)
* [7\. How We Share Information](#sharing-information)
* [8\. Data Retention](#data-retention)
* [9\. Security Measures](#security)
* [10\. International Data Transfers](#international-transfers)
* [11\. Your Privacy Rights](#your-rights)
* [12\. Children's Privacy, Policy Changes, and Contact](#children-changes-contact)

## 1\. Introduction and Scope

FirstSales ('we', 'us', or 'our') operates the FirstSales platform available at firstsales.io, a business-to-business (B2B) cold email outreach product that provides AI-assisted email sequence creation, automated mailbox and domain warm-up, deliverability tooling, prospect list management, and campaign analytics.

This Privacy Policy describes how we collect, receive, use, store, share, transfer, and protect personal data in connection with your use of the FirstSales website and platform (collectively, the 'Service'). It applies to all visitors to firstsales.io, registered account holders, trial users, and any individual whose data is processed through our infrastructure.

For the personal data of our own users and website visitors, FirstSales acts as the data controller — we determine the purposes and means of processing. For personal data that users upload about their own prospects and contacts (recipient lists, enrichment data, CRM imports), FirstSales acts as a data processor operating under the instructions of the user, who is the data controller for that data.

If you are a prospect who received a cold email sent via FirstSales and want to know why you were contacted or request removal from the sender's list, please reply directly to that email or contact the sender. You may also contact us at firstsales@support.communicate.so and we will assist in routing your request.

By creating an account, starting a trial, or using any part of the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, you should not use the Service.

## 2\. Information We Collect

We collect different categories of personal data depending on how you interact with us.

Account and profile data: When you register, we collect your name, email address, and any optional profile details you provide such as company name, role, or website. If you invite team members, we collect their email addresses to send invitations.

Billing and payment data: When you start a paid subscription or $1 trial, you provide billing details such as cardholder name and payment instrument information. Payments are processed by our third-party payment processors (currently Stripe). We do not receive or store your full credit card number, CVV, or full card expiry on our own servers. We receive and store a payment token, last-four digits, card brand, and billing country for subscription management and fraud prevention.

Connected mailbox and domain data: To send email on your behalf, you authorize FirstSales to access your email account via OAuth (Google, Microsoft, or similar providers) or SMTP/IMAP credentials. This grants us access to send emails from your address, read sent-mail delivery status, and, where you enable warm-up, exchange warm-up messages within our network. We store OAuth tokens (encrypted), your email address, display name, provider identity, and sending configuration. We access email metadata (subject, timestamp, message-id, recipient addresses) and in some cases limited email body content solely to execute warm-up, track open and click events, and provide deliverability analytics.

Prospect and contact data uploaded by users: You may upload CSV files, connect CRM integrations, or manually add contact records containing names, business email addresses, job titles, company names, LinkedIn URLs, and other prospecting attributes. This data belongs to you. You are the data controller and are solely responsible for ensuring you have a lawful basis to process and contact each individual.

Usage and product data: We collect information about how you use the Service, including pages visited, features activated, sequences created, campaigns launched, emails sent and tracked, click and open events, and session duration. This data is primarily tied to your account rather than tracked across other sites.

Device and log data: Our servers automatically record your IP address, browser type and version, operating system, referring URL, and timestamps when you interact with the Service. These logs are used for security monitoring, debugging, and abuse prevention.

* Cookies and similar technologies: We use essential cookies to maintain your login session and CSRF protection. We may use analytics cookies to understand aggregate product usage. Preference cookies remember settings such as time zone and language. For full details on cookies, tracking technologies, and how to opt out, please see our Cookie Policy.

## 3\. How We Use Your Information

We use the information we collect for the following purposes:

* Providing and operating the Service: authenticating you, executing email sends and warm-up on your behalf, managing campaigns and sequences, storing and displaying your prospect lists, and delivering analytics dashboards.
* Account management and billing: processing subscriptions, trial activations, and renewals; communicating plan changes, invoices, and payment issues.
* Deliverability and warm-up: analyzing sending patterns, reputation signals, bounce rates, and inbox placement to advise you and automatically adjust warm-up schedules.
* AI-assisted content generation: using your campaign context (target persona, product description, tone preferences) to generate personalized email copy. We do not train shared AI models on your private prospect data or email content without your explicit consent.
* Customer support: responding to your requests, troubleshooting issues, and providing onboarding assistance.
* Safety and abuse prevention: detecting fraudulent accounts, spam abuse originating from our platform, unauthorized access attempts, and violations of our Terms of Service.
* Legal and compliance obligations: retaining records as required by applicable law, responding to valid legal process, and enforcing our agreements.
* Product improvement: analyzing aggregate, de-identified usage trends to improve features, fix bugs, and prioritize the product roadmap.

We do not sell your personal data, your connected mailbox content, or your prospect lists to third parties for advertising purposes.

## 4\. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data under one or more of the following legal bases under the General Data Protection Regulation (GDPR) and applicable national law:

* Contract (Article 6(1)(b)): Processing necessary to perform the contract we have with you, including operating your account, executing sends, managing billing, and providing support.
* Legitimate interests (Article 6(1)(f)): Processing for our legitimate business interests where those interests are not overridden by your rights — for example, fraud detection, security monitoring, product analytics, direct marketing to existing customers about related features, and improving deliverability tooling.
* Consent (Article 6(1)(a)): Where we rely on your consent, such as for optional analytics cookies or marketing communications to prospects of FirstSales. You may withdraw consent at any time without affecting the lawfulness of prior processing.
* Legal obligation (Article 6(1)(c)): Processing required to comply with applicable law, such as tax record retention, responding to court orders, or regulatory requests.

For special categories of personal data (if any inadvertently appear in uploaded prospect lists), we process only under explicit consent or as permitted by applicable law, and we strongly advise users not to upload sensitive category data through the Service.

## 5\. Connected Mailbox and Sending Data

Connecting your mailbox is the core action that enables FirstSales to send emails on your behalf. We treat access to your email account with strict controls and access it only to the minimum extent necessary to operate the features you activate.

When you connect a Google Workspace or Microsoft 365 mailbox via OAuth, you grant FirstSales specific OAuth scopes. For Google, we request scopes sufficient to send email (gmail.send), read labels and metadata necessary for delivery tracking (gmail.readonly or equivalent), and where warm-up is enabled, to insert and manage warm-up messages. We do not request access to your entire inbox or contacts beyond what is necessary for the features you enable.

OAuth tokens are stored encrypted at rest using industry-standard encryption. Access tokens are refreshed automatically and stored only as long as your mailbox connection remains active. Revoking the OAuth grant from your Google or Microsoft account settings will immediately invalidate our access.

* We read email metadata (sender, recipient, subject, message-id, timestamp) to correlate sent messages with open and click tracking events.
* For warm-up, our system sends and receives short, human-like messages between connected accounts in our warm-up network. These messages are clearly machine-generated for warm-up purposes and do not contain your actual campaign content.
* We do not read, index, or analyze the full content of emails in your inbox beyond what you explicitly send through the Service.
* We do not share, sell, or use the content of your email for advertising, data brokering, or training shared AI models without your explicit consent.
* We act solely on your instructions when accessing your mailbox. You remain responsible for ensuring your use of connected mailboxes complies with your email provider's terms of service.

If you disconnect a mailbox from FirstSales, we stop accessing it immediately. Retained metadata (send logs, analytics events) tied to historical campaign activity is retained per our data retention policy to preserve your campaign reporting.

## 6\. User-Uploaded Prospect and Contact Data

FirstSales is a tool for business-to-business outreach. Users upload lists of business contacts — typically professionals at companies — to run cold email campaigns. When you upload prospect data, you are the data controller for that data and FirstSales acts as your data processor.

You are solely responsible for ensuring that you have a lawful basis to process and contact each individual on your prospect list. You must comply with all applicable laws including CAN-SPAM, GDPR, CASL, and any other regulations that apply to your recipients' jurisdictions.

Your responsibilities as the controller of prospect data include:

* Obtaining your contacts through legitimate means (e.g., publicly available professional information, opt-in forms, purchased lists from compliant vendors) and confirming you have a lawful basis for B2B outreach.
* Ensuring each email campaign contains a clear identification of the sender, a truthful subject line, and a functional opt-out or unsubscribe mechanism as required by CAN-SPAM and similar laws.
* Honoring opt-out and suppression requests promptly. FirstSales provides suppression list features you are required to use when a contact requests removal.
* Not uploading special categories of personal data (health, financial, political, biometric, or other sensitive data) into the prospect database.
* Not uploading data for which you do not have lawful authority to process or send commercial email.

FirstSales processes prospect data only to execute your campaigns, display records in your dashboard, and provide analytics on your sends. We do not cross-reference your prospect lists with other customers' lists, sell prospect data, or use it for any purpose other than delivering your instructed campaign activity.

When your account is terminated, prospect data is deleted according to our data retention schedule described in Section 8.

## 7\. How We Share Information

We do not sell personal data. We share personal data only in the limited circumstances described below.

Subprocessors and service providers: We engage carefully selected third-party companies to help operate the Service. These subprocessors may process personal data on our behalf but are contractually required to use it only for the purposes we specify and to maintain appropriate security. Key categories of subprocessors include:

* Cloud infrastructure: hosting and database services that store account data, campaign data, and logs in secure cloud environments.
* Email sending infrastructure: SMTP relay and deliverability services that help route and monitor outbound email.
* Payment processors: Stripe (and equivalents) that handle credit card transactions. These processors are PCI-DSS compliant.
* Analytics and error monitoring: tools that collect aggregate product usage data and application error logs to help us improve reliability and performance.
* Customer support tooling: helpdesk and chat platforms that we use to respond to your tickets and questions.
* Authentication providers: OAuth identity providers (Google, Microsoft) whose authorization servers you interact with when connecting mailboxes.

Legal and safety disclosures: We may disclose personal data if required by law, regulation, legal process, or valid government request (such as a court order or subpoena). We will, where legally permissible, notify you before producing data in response to such a request. We may also disclose data to protect the rights, property, or safety of FirstSales, our users, or the public.

Business transfers: In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, personal data we hold may be transferred to a successor entity. We will notify you of any such transfer and any choices you may have.

With your consent: We will share your data with other third parties when you have explicitly directed us to do so, for example when you authorize a native integration with your CRM.

## 8\. Data Retention

We retain personal data for as long as your account is active and for a defined period afterward, or as required by law.

* Active accounts: account profile, billing records, campaign data, and connected mailbox metadata are retained throughout the lifetime of your account.
* After account termination or subscription cancellation: we retain core account records and billing history for up to 7 years to satisfy financial and legal obligations. Campaign analytics data (aggregate metrics, send logs) are retained for up to 2 years post-termination for dispute resolution.
* Prospect and contact data: deleted within 90 days of account termination unless an earlier deletion is requested.
* OAuth tokens: revoked and deleted immediately upon mailbox disconnection or account deletion.
* Server logs and security logs: retained for up to 12 months for security monitoring and abuse prevention, then deleted or anonymized.
* Backups: encrypted backups may retain data for up to 60 additional days beyond the standard retention window before being purged.

You may request deletion of your account and associated personal data at any time by contacting firstsales@support.communicate.so. We will process deletion requests within 30 days, subject to any legal obligation to retain certain records.

Deletion of your account will permanently remove your campaigns, sequences, prospect lists, connected mailbox configurations, and profile data. This action cannot be undone. Billing records required by tax law will be retained in anonymized or minimal form for the legally required period.

## 9\. Security Measures

Protecting your data and your connected mailbox access is fundamental to our product. We implement technical and organizational security measures appropriate to the sensitivity of the data we handle.

* Encryption in transit: all communications between your browser or email client and our servers use TLS 1.2 or higher. API endpoints are HTTPS-only.
* Encryption at rest: databases, object storage, and backup stores are encrypted at rest using AES-256 or equivalent. OAuth tokens and SMTP credentials are additionally encrypted at the application layer before storage.
* Access controls: access to production systems and customer data is restricted to authorized personnel on a least-privilege basis. All production access is logged and reviewed. We use multi-factor authentication for administrative access.
* Token handling: OAuth tokens are never logged or exposed in plaintext. Refresh tokens are rotated on use. We store the minimum required scopes for each mailbox integration.
* Vulnerability management: we conduct regular dependency audits, apply security patches promptly, and review code changes for security implications.
* Incident response: we maintain an incident response plan. In the event of a personal data breach, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law.

Despite our measures, no internet transmission or storage system is 100% secure. If you suspect unauthorized access to your FirstSales account, please contact firstsales@support.communicate.so immediately and change your password and OAuth grants.

## 10\. International Data Transfers

FirstSales operates globally and may process your personal data in countries other than your country of residence. In particular, our infrastructure is primarily hosted in the United States. If you are located in the EEA, UK, or Switzerland, your personal data may be transferred to and processed in the United States or other countries that may not provide the same level of data protection as your home country.

Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards including:

* Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with subprocessors and data importers.
* The UK International Data Transfer Agreement (IDTA) or addendum to SCCs for transfers from the United Kingdom.
* Transfer impact assessments conducted where required, with supplementary technical measures (encryption, pseudonymization) applied as appropriate.

By using the Service, you acknowledge that your data may be transferred internationally as described above. If you have questions about the specific safeguards applicable to your data, contact us at firstsales@support.communicate.so.

## 11\. Your Privacy Rights

Depending on where you are located, you may have certain rights regarding your personal data. We are committed to honoring these rights promptly and without undue obstacles.

Rights under GDPR (EEA, UK, Switzerland residents):

* Right of access: you may request a copy of the personal data we hold about you and information about how we process it.
* Right to rectification: you may ask us to correct inaccurate or incomplete personal data.
* Right to erasure ('right to be forgotten'): you may request deletion of your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent (and no other legal basis applies), or where processing is unlawful.
* Right to data portability: you may request your personal data in a structured, commonly used, machine-readable format for transfer to another controller, where processing is based on consent or contract and carried out by automated means.
* Right to object: you may object to processing based on our legitimate interests, including direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
* Right to restriction of processing: you may request that we restrict processing of your data in certain circumstances, such as while a dispute about accuracy is resolved.
* Rights related to automated decision-making: we do not make solely automated decisions that produce legal or similarly significant effects about you without human involvement.

Rights under CCPA/CPRA (California residents):

* Right to know: you may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, purposes, and third parties with whom we share it.
* Right to delete: you may request deletion of personal information we have collected, subject to certain exceptions.
* Right to correct: you may request correction of inaccurate personal information.
* Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising. No opt-out action is required, but you may contact us to confirm.
* Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.

How to exercise your rights: submit a request to firstsales@support.communicate.so with the subject line 'Privacy Rights Request'. We will verify your identity before processing your request and respond within 30 days (or 45 days where permitted with notice). There is no charge for one request per 12-month period.

If you are in the EEA or UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority (for example, the Irish Data Protection Commission, the UK ICO, or the relevant authority in your member state). We encourage you to contact us first at firstsales@support.communicate.so so we can try to resolve your concern directly.

## 12\. Children's Privacy, Policy Changes, and Contact

Children's privacy: The Service is intended exclusively for business professionals and is not directed at children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at firstsales@support.communicate.so and we will promptly delete it.

Changes to this policy: We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or product features. When we make material changes, we will notify you by email (to the address on your account) and by posting a prominent notice in the product at least 14 days before the change takes effect. The 'Last updated' date at the top of this page always reflects the date of the most recent revision. Your continued use of the Service after the effective date of an updated policy constitutes your acceptance of the changes.

Previous versions of this Privacy Policy can be made available on request.

How to contact us: If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us:

* Email: firstsales@support.communicate.so
* Subject line for privacy matters: 'Privacy Inquiry' or 'Privacy Rights Request'
* We aim to respond to all privacy inquiries within 5 business days and to fulfill rights requests within 30 days.

For any data protection matter that cannot be resolved through our support channel, EEA and UK residents may escalate to their national data protection supervisory authority. California residents may contact the California Privacy Protection Agency (CPPA).

## Questions about this policy?

We're happy to help clarify anything in this document. Reach our team and we'll get back to you.

[firstsales@support.communicate.so](mailto:firstsales@support.communicate.so)