PRIVACY POLICY — CONNECTORHUB

Last Updated: [Aug, 2026]

1. Introduction

ConnectorHub (“we,” “our,” “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your personal information when you interact with our website, platform, products, or services, and describes the rights available to you regarding that information. By accessing or using ConnectorHub, you acknowledge that you have read and understood this Privacy Policy.

2. Information We Collect

I.Information You Provide Directly

  • Name, email, phone number
  • Company and job title
  • Account login information
  • Support requests, chat interactions
  • Form submissions (demo requests, assessments, contact forms)
  • Billing details (if applicable)

II. Automatically Collected Data

  • IP address and browser type
  • Device identifiers
  • Page visits, session duration, referral site
  • Cookies, analytics data, pixel tags
  • Log data from platform usage

III. Platform & Integration Data (as our customer's processor):

  • Workflow execution logs
  • Run results and error logs
  • Connector usage patterns
  • Configuration metadata

We do not access customer data payloads unless explicitly authorized.

3. Information We Collect From Third-Party Sources

In addition to information you give us directly, we may receive personal data about you from third-party sources, including:

  • Business partners and integration/technology partners (e.g., when a connector or referral introduces you to ConnectorHub)
  • Publicly available sources and professional networking platforms (e.g., company and job title information used for B2B outreach)
  • Marketing and lead-generation service providers
  • Analytics and advertising platforms (e.g., aggregated or device-level identifiers used for attribution)

Where we combine third-party data with data we collect directly, we apply the same purposes, legal bases, and protections described in this Policy.

4. How We Use Your Information & Processing Purposes

The table below maps the categories of data we collect to why we use them.

  • Account & contact data (name, email, company, login) — used to create and manage your account, deliver the platform, and provide support.
  • Billing data — used to process payments and meet accounting/tax obligations.
  • Automatically collected data (IP, device, usage, cookies) — used for security, fraud prevention, product analytics, and improving the platform.
  • Platform & integration data (workflow logs, run results, connector metadata) — used to operate the service, troubleshoot issues, and maintain audit trails, acting as processor on the customer's behalf.
  • Marketing preference and engagement data — used to send product updates, educational content, and marketing communications, where you have opted in or were permitted by law.

We do not sell your personal information. We adhere to data minimization principles, collecting only what is necessary for these purposes, and we do not use data for purposes incompatible with those stated here without notifying you.

5. Legal Basis for Processing (GDPR)

Where GDPR applies, we rely on the following lawful bases, depending on the activity:

  • Contractual necessity — to create your account and deliver the platform you've signed up for
  • Legitimate interests — for security, fraud prevention, analytics, and improving our services, balanced against your rights and interests
  • Legal obligations — for tax, accounting, and regulatory record-keeping
  • Consent — for marketing communications and non-essential cookies, which you can withdraw at any time (see Section 12)

6. Special Category / Sensitive Personal Data

ConnectorHub does not intentionally collect or request special category data (such as data revealing racial or ethnic origin, health data, religious beliefs, biometric data, or Gender) through our website, marketing forms, or account registration process.

7. Cookies, Consent & Tracking Technologies

We use cookies and similar tracking technologies (pixels, tags, local storage) to operate the site, remember preferences, measure performance, and support marketing. Categories include:

  • Strictly necessary cookies — required for core site and platform functionality; cannot be switched off.
  • Performance/analytics cookies — help us understand site usage (e.g., page visits, session duration).
  • Functional cookies — remember preferences and settings.
  • Marketing/advertising cookies — used for retargeting and campaign measurement.

You may request deletion at any time. Specific retention periods vary by data type; for example, account data is retained while active, and logs may be kept for up to 12 months for security purposes. 

8. Information Sharing & Categories of Recipients

We share personal data only with the following categories of recipients, each bound by a Data Processing Agreement (DPA) and contractual confidentiality obligations:

  • Cloud hosting and infrastructure providers
  • Payment processors
  • Customer support and CRM systems
  • Analytics and marketing technology providers
  • Integration and technology partners — only with your consent, or as needed to deliver a connector you've configured
  • Professional advisors (legal, audit) where necessary
  • Law enforcement or regulators — where required by law, court order, or to protect our legal rights
  • A successor entity — in the event of a merger, acquisition, or asset sale, with notice to you were required

We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes without your consent.

9. Data Retention & Deletion Criteria

We retain personal data only for as long as necessary to fulfill the purposes it was collected for. Retention periods and deletion criteria:

  • Account and profile data retained while your account is active, and for [X] days/months after closure to allow reactivation and meet legal obligations.
  • Billing records retained for the period required by applicable tax/accounting law (typically 6–7 years)
  • Platform, workflow, and audit logs retained for up to 12 months for security and troubleshooting purposes, then deleted or anonymized.
  • Marketing contact data retained until you opt out or withdraw consent, or after a defined period of inactivity.
  • Support/chat interactions retained for [3-6] months to resolve related issues, then deleted.

At the end of the applicable retention period, data is securely deleted or irreversibly anonymized. You may request earlier deletion at any time, subject to legal retention requirements (see Section 11).

10. Security

We use enterprise-grade protections:

  • Encryption at rest and in transit
  • Granular Role-Based Access Control (RBAC)
  • API key vaulting
  • Audit logs across all runs
  • Tenant isolation
  • Monitoring and anomaly detection
  • Data Loss Prevention (DLP) policies to prevent unauthorized exposure

11. Your Privacy Rights

Depending on your region, you have the right to:

  • Right to be informed - know what data we collect and how it's used
  • Right of access - request a copy of the personal data we hold about you
  • Right to rectification - correct inaccurate or incomplete data
  • Right to erasure - request deletion of your data (“right to be forgotten”)
  • Right to restrict processing - request we limit how we use your data
  • Right to object - object to processing, including for direct marketing
  • Right to data portability - receive your data in a portable, machine-readable format
  • Right to withdraw consent - at any time, without affecting prior lawful processing
  • Right not to be subject to solely automated decision-making
  • Right to lodge a complaint with a supervisory authority

To exercise any of these rights, contact us using the details in Section 18. We will respond within the timeframes required by applicable law (generally within one month under GDPR) and may need to verify your identity before fulfilling a request.

12. Consent Withdrawal & Preference Management  

Where we rely on your consent (e.g., marketing emails, non-essential cookies), you can withdraw it at any time:

  • Marketing emails — click “Unsubscribe” in any email, or update preferences via your account settings.
  • Cookies — use the “Cookie Preferences” link in the site footer to change or withdraw consent.
  • General data processing consent — contact us at the details in Section 18.

Withdrawing consent does not affect the lawfulness of processing already carried out, and does not automatically delete data retained under a separate legal basis (e.g., billing records kept for tax compliance).

13. Marketing Communications & Opt-Out  

With your consent (or another applicable legal basis), we may send product updates, newsletters, event invitations, and other marketing communications. You can opt out at any time by:

  • Clicking “Unsubscribe” at the bottom of any marketing email
  • Updating your communication preferences in your account settings
  • Contacting us directly using the details in Section 18

Opting out of marketing communications does not affect transactional or service-related messages (e.g., security notices, billing communications), which we may still send as necessary to operate your account.

14. Automated Decision-Making & Profiling  

ConnectorHub does not currently make decisions that produce legal or similarly significant effects about individuals based solely on automated processing, including profiling, without human involvement.

15. International Transfers & Safeguards

Data may be processed in the U.S. or other regions outside your home jurisdiction. Where this involves a transfer of personal data out of the EU/EEA, UK, or Switzerland, we rely on recognized safeguards, including:

  • Standard Contractual Clauses (SCCs)
  • The EU–U.S. Data Privacy Framework (DPF), UK Extension, and Swiss–U.S. DPF, where applicable
  • Other GDPR-approved transfer mechanisms and adequacy decisions

We conduct transfer impact assessments where required and ensure recipients maintain protections equivalent to those required under GDPR.

16. Right to Lodge a Complaint  

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with your local data protection supervisory authority. If you are in the EU/EEA, you can find your national authority via the European Data Protection Board: https://edpb.europa.eu/about-edpb/about-edpb/members_en. If you are in the UK, you may contact the Information Commissioner's Office (ICO) at ico.org.uk. We'd also appreciate the chance to address your concern directly first — contact us using the details in Section 18.

17. EU Representative  [NEW/EXPANDED SECTION]

18. Data Protection Officer / Privacy Contact

19. Children's Data

ConnectorHub is not intended for users under 16. We do not knowingly collect data from children under 13 (per COPPA). If we learn we have inadvertently collected such data, we will delete it promptly.

20. Changes to This Policy

We may update this policy periodically. The latest version will be posted here with an updated effective date at the top of the page. For significant changes, we will provide additional notice (e.g., via email or an in-product notice). Continued use of ConnectorHub after changes take effect constitutes acceptance of the revised Policy.