Privacy Policy

Effective Date: December 17, 2025

Last Updated: December 17, 2025

1. Introduction & Scope

AgentSequence ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AgentSequence platform, including our email automation services, CRM features, and related services (collectively, the "Services").

This Privacy Policy applies to all users of our Services, including real estate agents, their contacts, and visitors to our website. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

If you have any questions about this Privacy Policy, please contact us at support@agentsequence.com.

2. Google API Services User Data Policy Compliance

Limited Use Disclosure

AgentSequence's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

What This Means for You

When you connect your Gmail account to AgentSequence, we access certain Google user data to provide our email automation services. We are committed to using this data responsibly and in compliance with Google's policies.

Our Commitments

  • We only use Google user data for the purposes described in this Privacy Policy
  • We do not use Google user data for advertising purposes
  • We do not sell Google user data to third parties
  • We do not use Google user data to build profiles for advertising or marketing purposes unrelated to our Services
  • We limit access to Google user data to only those employees and contractors who need it to provide our Services

For more details about how we handle Google user data, see the "Google Account Information (OAuth)" section below and our dedicated Google API Data Disclosure page.

3. Information We Collect

Account Information

When you create an account, we collect your name, email address, password (encrypted), business name, brokerage information, phone number, and physical business address.

Google Account Information (OAuth)

When you connect your Gmail account to AgentSequence, we request access to the following Google API scopes:

ScopePurposeData AccessedRetention
gmail.sendSend campaign emails from your Gmail addressEmail content and recipientsNot stored (sent immediately)
gmail.readonlyDetect replies to automatically pause campaignsInbox messages related to campaignsProcessed in real-time, not stored
gmail.modifyMark campaign-related emails as readMessage read statusNot stored

OAuth Token Storage

  • Access tokens and refresh tokens are encrypted using AES-256-GCM encryption before storage
  • Encryption keys are stored separately from the database
  • Access tokens expire after 1 hour and are automatically refreshed
  • Refresh tokens remain valid until you disconnect Gmail or revoke access

Data Access Boundaries

We only access emails related to your campaigns. We never read personal emails unrelated to your campaign activities. Our reply detection system only monitors for responses to emails sent through AgentSequence.

Contact Data

When you import or add contacts to our platform, we collect the information you provide about those contacts, including names, email addresses, phone numbers, addresses, and any custom fields or tags you assign.

Payment Information

Payment transactions are processed through Stripe, our third-party payment processor. We do not store your complete credit card information on our servers. We receive and store limited payment information from Stripe, including the last four digits of your card, card type, and billing address.

Usage Data

We collect information about how you use our Services, including features accessed, campaigns created, emails sent, engagement metrics (opens, clicks, replies), and actions taken within the platform.

Technical Data

We automatically collect certain technical information, including IP addresses, browser type and version, device information, operating system, time zone settings, and cookie data.

Communication Data

We collect information from your communications with us, including support emails, feedback, survey responses, and any other correspondence.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Services
  • Process payments and manage your subscription
  • Send transactional emails, including receipts, notifications, and account alerts
  • Enable email automation features, including campaign scheduling and delivery
  • Provide reply detection and campaign management services
  • Analyze usage patterns to improve our platform and user experience
  • Respond to your comments, questions, and support requests
  • Detect, prevent, and address technical issues, fraud, and security concerns
  • Comply with legal obligations and enforce our terms
  • Send marketing communications (with your consent, where required)

Gmail Integration Use Cases

When you connect your Gmail account, we use your Google data specifically to:

  • Send campaign emails from your Gmail address to improve deliverability and trust
  • Monitor your inbox for replies to automatically pause campaigns when contacts respond
  • Track email engagement metrics (opens, clicks, replies) for campaign performance
  • Register Gmail watch notifications for real-time reply detection
  • Refresh OAuth tokens automatically to maintain your Gmail connection

What We Do NOT Do With Your Gmail Data

  • We do NOT use Gmail data for advertising purposes
  • We do NOT sell or share Gmail data with third parties for marketing
  • We do NOT use Gmail data to build user profiles for purposes unrelated to providing our Services
  • We do NOT read personal emails unrelated to your campaigns
  • We do NOT store email content after sending or processing

6. Data Sharing & Third Parties

We share your information with the following categories of third parties:

Service Providers

  • Resend: Email delivery and tracking services
  • Stripe: Payment processing and subscription management
  • Vercel: Website and application hosting
  • Supabase: Database and authentication services
  • Sentry: Error monitoring and diagnostics
  • Perplexity: Market research and AI-powered insights

Google Services

When you connect your Gmail account, we interact with Google's APIs to provide email sending and reply detection features.

  • Gmail data is processed through Google's APIs and is not transferred to other third-party apps
  • We do not share your Gmail data with any party other than Google (as required to use their APIs)
  • You can revoke our access to your Gmail at any time through your AgentSequence settings or directly at Google Account Permissions

For more information about how Google handles your data, please see Google's Privacy Policy.

Legal Requirements

We may disclose information when required by law, such as in response to valid legal processes, court orders, or government requests.

Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction.

Important: We never sell your personal data to third parties for marketing purposes.

7. Data Retention

We retain your information for as long as necessary to provide our Services and fulfill the purposes described in this Privacy Policy:

  • Active Accounts: Data is retained for the duration of your account plus any period required by law.
  • Deleted Accounts: Following account deletion, we retain data for 30-90 days for recovery purposes, after which it is permanently deleted.
  • Email Logs: Email engagement data is retained for 2 years.
  • Payment Records: Financial records are retained as required by applicable tax and financial regulations.
  • Support Communications: Customer support records are retained for quality assurance and legal compliance.
  • Gmail OAuth Tokens: Encrypted tokens are retained only while your Gmail is connected; they are immediately deleted when you disconnect.

8. Your Rights

GDPR Rights (EU/EEA Users)

If you are in the European Economic Area, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restriction: Request limitation of processing
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time

CCPA Rights (California Users)

If you are a California resident, you have the following rights under the CCPA:

  • Right to Know: Request information about data collected about you
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the sale of personal information (note: we do not sell your data)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

Right to Revoke OAuth Access

You have the right to disconnect your Gmail account at any time:

  • Through AgentSequence: Go to Settings → Email Settings → Disconnect Gmail
  • Through Google: Visit Google Account Permissions and revoke access for AgentSequence

What happens when you disconnect: All stored OAuth tokens (access and refresh tokens) are immediately and permanently deleted from our systems. No Gmail data is retained after disconnection.

Exercising Your Rights

To exercise any of these rights, please contact us at support@agentsequence.com. We will respond to your request within 30 days (GDPR) or 45 days (CCPA).

9. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to collect and track information and improve our Services:

Essential Cookies

These cookies are necessary for the website to function and cannot be switched off. They include authentication cookies and security cookies.

Analytics Cookies

These cookies help us understand how visitors interact with our Services by collecting and reporting information anonymously.

Managing Cookies

Most browsers allow you to control cookies through their settings. However, limiting cookies may impact your experience using our Services.

Do Not Track

Our Services do not currently respond to "Do Not Track" signals, as there is no industry standard for handling such signals.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption: Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption
  • Access Controls: Strict access controls and authentication mechanisms protect your data
  • Security Audits: Regular security assessments and monitoring
  • Incident Response: Documented procedures for security incident handling and notification

Gmail OAuth Security Measures

We implement additional security measures specifically for Gmail OAuth data:

Security MeasureImplementationPurpose
Token EncryptionAES-256-GCMProtect OAuth tokens at rest
Transport SecurityTLS/SSL (HTTPS)Encrypt data in transit
Key SeparationSeparate key storagePrevent unauthorized decryption
Auto Token RefreshHourly refreshMinimize token exposure window
Immediate DeletionOn disconnectRemove tokens when user revokes access

While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own. Our primary data storage is located in the United States.

For transfers from the EEA to countries not deemed adequate by the European Commission, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission.

12. Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@agentsequence.com.

13. Changes to Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

For material changes that significantly affect your rights, we will provide additional notice, such as an email notification or a prominent notice within our Services.

Your continued use of our Services after any changes constitutes your acceptance of the updated Privacy Policy.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Controller: AgentSequence

Email: support@agentsequence.com

Address: 12557 Danbury Way, Rosemount, MN 55068

Data Protection Officer: privacy@agentsequence.com