← Back to PullSheet.io
Privacy Policy
Last updated: February 17, 2026
1. Introduction
PullSheet.io ("we", "our", "us") is a HubSpot Marketplace application that syncs CRM data to Google Sheets and Microsoft Excel. This policy explains what data we collect, how we use it, and your rights.
2. Data We Collect
- HubSpot OAuth tokens: Access and refresh tokens to read your CRM data. These are encrypted at rest using AES-256-GCM.
- Google OAuth tokens: Access and refresh tokens to write to your Google Sheets. Encrypted at rest.
- Microsoft OAuth tokens: Access and refresh tokens to write to your Excel files. Encrypted at rest.
- HubSpot Portal ID: Your HubSpot account identifier, used to associate your account.
- Sync configuration: Which CRM objects, properties, filters, and schedules you configure.
- Usage logs: Sync run timestamps, row counts, and error messages for debugging.
3. Data We Do NOT Collect
- We do not store your CRM records (contacts, deals, companies, etc.). Data flows through our servers during a sync and is written directly to your spreadsheet.
- We do not collect personal information beyond what is required for OAuth authentication.
- We do not sell or share your data with third parties.
4. How We Use Your Data
- To authenticate with HubSpot, Google, and Microsoft on your behalf.
- To execute scheduled syncs (read CRM data, write to spreadsheets).
- To display sync status and history in your dashboard.
- To enforce plan limits and billing.
5. Data Storage and Security
- All OAuth tokens are encrypted using AES-256-GCM before storage.
- Data is stored in a PostgreSQL database hosted on Railway with SSL encryption in transit.
- We use HTTPS for all communications.
- Server security includes Helmet.js headers, rate limiting, and input validation.
6. Data Retention
Your data is retained as long as you have an active PullSheet.io account. When you uninstall PullSheet.io from HubSpot, all your data (account, syncs, logs, tokens) is permanently deleted.
7. GDPR and Data Rights
You have the right to:
- Access your data via the /auth/status API endpoint.
- Delete your data by uninstalling PullSheet.io from HubSpot (triggers automatic deletion).
- Port your data — sync configurations can be exported via our API.
8. Third-Party Services
9. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via the application.
10. Contact
For privacy inquiries, contact us at privacy@pullsheet.io.