Privacy Policy
Effective July 8, 2026
Firstpane is a product of Digital Vanguard Solutions (“DVS”, “we”, “us”). This policy explains what data we collect, how we use it, and the choices you have — both for visitors to this site and for users of the Firstpane application.
What we collect
Account information. When a workspace is created or you are invited to one, we store your name, email address, and a hashed password (we never store plaintext passwords), plus workspace membership and role.
Connected-source data. Firstpane works by connecting, at your direction, to business systems such as your CRM (Salesforce, HubSpot), finance tools (Stripe, QuickBooks), and calendar/productivity suites (Google Calendar, Microsoft 365). When you connect a source we sync the records needed to power your workspace — for example deals, companies, contacts, invoices, and meetings — and we store the OAuth tokens or API keys for that connection encrypted (AES-256-GCM) at rest. Each connection belongs to the individual user who created it. Your synced records, dashboards, drafts, and agent conversations are visible only to you — workspace administrators cannot browse them, and stored credentials are visible to no one. Workspace administrators can see workspace membership (names, emails, roles), aggregate usage and health metrics, and an administrative activity log of account and agent actions (whose event summaries can include details such as a record field the agent changed). Our operations staff can see workspace-level metadata, membership, and aggregate metrics — never your records, messages, or credentials — and administrative actions on our platform are recorded in an append-only audit log.
Contact-form submissions. If you request a demo or pilot through this site we collect your email, role, company, and message, and deliver it to our team by email. That’s its only use.
Operational data. Standard service logs and session state needed to run and secure the product (sign-in history is visible to you in your own security settings).
How we use data
We use your data to operate Firstpane for you: rendering your workspace, computing the signals and suggestions you configure, sending the product emails you or your workspace admin enable (such as the morning digest and pilot scorecard), and providing support.
We do not sell your data. We do not use your data for advertising. We do not train AI models on your data. AI features run at your direction: by default a workspace brings its own AI provider key, and inference runs under that provider account and its terms.
Google user data
If you connect Google, Firstpane requests read-only access to Google Calendar only — to show your upcoming meetings and meeting history in your workspace. We do not request access to Gmail, and we do not read Gmail content. We access only what the calendar features need, we display it only to you inside your own workspace, and we never use it for advertising, never sell it, and never let humans read it except with your explicit permission, for security purposes, or as required by law.
Email activity signals (for example, that an email touchpoint with an account occurred) come from metadata — subject, sender, timestamps — synced from your connected CRM or Microsoft 365 mail. Message bodies are not read.
Firstpane’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting Google in your workspace settings revokes and deletes the stored tokens for that connection.
Who processes data on our behalf
We use a small set of service providers to run Firstpane: application and database hosting, transactional email delivery, and hosting for this marketing site. Optional capabilities a workspace enables (such as web search or a managed AI provider) engage the relevant provider only for that workspace. A current list of sub-processors is available on request, and workspace agreements receive notice of changes to it.
Security
All traffic is encrypted in transit (TLS). Customer-supplied connector credentials and API keys stored in our database are encrypted at rest with AES-256-GCM. Data access in the application is scoped per user — the workspace you see is yours. You can review your recent sign-ins and sign out of all sessions at any time from your security settings.
Retention and deletion
We keep your data while your workspace is active. Disconnecting a source revokes and deletes its stored credentials; synced records are removed on request or when your workspace is deleted. You can request access to, correction of, or deletion of your personal data at any time using the contact below, and we will honor applicable data protection rights (including under GDPR and CCPA).
Children
Firstpane is a business tool and is not directed to anyone under 16.
Changes and contact
If this policy changes materially we will update this page and its effective date, and notify workspace admins. Questions or requests: use the contact form on this site and we’ll respond by email.