Privacy Policy
Last updated August 18, 2026
This page explains what information ClientPad collects when you and your team use it, why we collect it, and how you can see, export, or delete it. We've tried to write it the way we'd want it explained to us — plainly, without legal filler.
What we collect
Two kinds of information pass through ClientPad:
- Your account — your name, email address, and (if you sign in with a password rather than Google or Microsoft) a securely hashed password. Never the plain password itself.
- Your organization's data — whatever you and your team enter or import: contacts, companies, deals, support tickets, notes, and the emails you send through the app. This is your data, not ours — we store it so the product works, and it's isolated from every other company using ClientPad.
How your contacts' information gets in
A contact's details can enter ClientPad a few ways, and we keep track of which one, for every contact:
- You or a teammate types it in directly, or imports it from a CSV file.
- Someone submits one of your lead-capture forms, or books a meeting through your scheduling page.
- Someone emails your support address, or replies to an email you sent them.
- You run a prospecting search and we find publicly listed business information for you.
Who we share it with
We don't sell any data, ever. A few outside services help ClientPad actually work, and each only sees what it needs to do its one job:
- SendGrid sends and receives the emails ClientPad sends on your behalf, and delivers replies back into the right ticket or sequence.
- Google and Microsoft — if you connect a Gmail or Microsoft 365 mailbox or calendar, we only ever ask for permission to send email or create calendar events on your behalf. We do not ask for, and cannot read, your inbox.
- Google Maps powers the prospecting feature's search for companies by location and industry, using only publicly listed business information.
- Cloudflare sits in front of ClientPad to keep the connection secure and block abusive traffic.
None of these providers get to keep or reuse your data for their own purposes — they process it only to deliver the specific feature it's for.
Cookies and local storage
ClientPad uses a session cookie to keep you signed in, and your browser's local storage for a handful of on/off preferences — like your light/dark theme choice and whether you've dismissed a help tip. None of this is used for advertising or tracking you across other sites.
How long we keep things, and your control over it
- Deleting a contact or account first moves it to a recycle bin, kept for 30 days in case it was a mistake, before it's permanently removed.
- An organization's owner or admin can export everything — every contact, deal, ticket, and message — as a plain file, at any time, from Settings.
- Anyone can request a specific contact be permanently erased, which removes their information beyond what we're legally required to retain.
- Every marketing email ClientPad sends includes a one-click unsubscribe link. Using it stops every outreach sequence to that address across the whole organization, right away.
Security
Passwords are never stored in plain text. Access tokens for a connected mailbox or calendar are encrypted before they're stored, and only ever decrypted for the one moment they're needed to send an email or create an event. Your organization's data is kept separate from every other organization's at the database level, not just in the app's interface.
Children
ClientPad is a business tool, not directed at children, and we don't knowingly collect information from anyone under 16.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page. Using ClientPad after a change means you've accepted the update.
Questions
If anything here is unclear, reach out through the contact form on the homepage — a real person reads every message.