Privacy policy
How PipelinePartner handles personal data: your account, the mailboxes and LinkedIn accounts you connect, and the people your campaigns contact.
Last updated 5 October 2026
Who we are
PipelinePartner is operated by Sprint Partners Consultancy Ltd, a company registered in England and Wales (number 15888168), whose registered office is at c/o Aligned Accountancy Group Ltd, Bromley Old Town Hall, 30 Tweedy Road, Bromley, BR1 3FE. We are the data controller for the information described under “Your account” below. For everything you upload and send through the service, you are the controller and we act on your instructions as your processor.
Privacy questions and requests: privacy@pipelinepartner.io.
The two roles, and why the distinction matters
PipelinePartner is a sending tool. The contact data in it is data you chose to upload, about people you chose to contact, for a purpose you decided. That makes you the controller of it and us your processor: we hold it, send from it and show you what came back, and we do not use it for anything of our own. We never sell personal data, and we do not use your mailbox contents or your contact lists to train AI models.
Separately, we are the controller of your own account information, because that relationship is ours with you.
Your account
- Your name, email address and organisation name.
- Authentication data, held by our authentication provider. We never see your password.
- Sender identities you configure: display names, signatures, and the personas you send as.
- Records of your use of the service, including notification history and errors, which we keep to run and support it.
Our lawful basis is performance of our contract with you, and our legitimate interest in keeping the service secure and working.
The mailboxes you connect
To send on your behalf and to tell you when someone replies, we need access to the mailbox you send from. What we hold depends on how you connect it:
- An app password or SMTP password. Stored encrypted, and used only to connect to your mail provider.
- A Microsoft sign-in. We store the access and refresh tokens your provider issues, encrypted. You can revoke them at any time from your Microsoft account, which stops our access immediately.
What we read. We read messages that arrive in the connected mailbox after you connect it. We never read the mail that was already there: the connection records a marker at the moment you connect and we only ever read past it. We read whole messages, not only replies to your campaigns, because that is the only way to recognise a reply, a bounce or an out-of-office reliably. Messages that turn out to have nothing to do with your campaigns are deleted after seven days, and the rest is kept as your campaign record.
What we send. The messages you compose, to the recipients you choose, from your mailbox. Your mail provider processes them as it would any other mail you send.
The LinkedIn accounts you connect
LinkedIn offers no interface for this, so the service signs in as you and acts in your browser session. That means we hold more sensitive material than a mail connection needs:
- Your LinkedIn session cookie, encrypted.
- Where you choose to let us sign in for you, your LinkedIn email and password, encrypted under a separate key that only the sending tier can read, and deleted when you disconnect the account.
- Your LinkedIn profile name, headline, profile picture and URL, so the app can show you which account is which.
- The invitations and messages you send, and the replies you receive, as part of your campaign record.
Traffic to LinkedIn is routed through a dedicated address assigned to your account, so that your sending is not mixed with anyone else's.
The people your campaigns contact
You upload these records and you decide who is in them. They typically include a name, email address, employer, job title and LinkedIn profile URL, plus any research fields you add, and they are joined by the messages sent and received.
You are responsible for having a lawful basis for contacting these people, for telling them you hold their data where the law requires it, and for honouring their objections. Our terms say the same. We provide the mechanics: an unsubscribe link and one-click unsubscribe header on campaigns where you enable it, a reply-detection gate that stops a sequence the moment someone answers, and a permanent suppression list that applies across your whole workspace.
If you received a message from a campaign
The sender is our customer, not us, and they decide what happens to your data. Replying to ask them to stop works, and stops the sequence immediately. You can also use the unsubscribe link if the message carries one. If you would rather contact us, write to privacy@pipelinepartner.io and we will add you to that customer's suppression list and pass your request on to them.
Automated processing of replies
When a reply arrives, part of it is sent to an AI provider to work out what kind of reply it is: a real answer, an out-of-office, or an automatic acknowledgement. That is what lets the service stop a sequence rather than send a follow-up over someone's answer. The text is processed to answer that question and is not used to train anyone's models. No decision with a legal or similarly significant effect on anyone is made automatically.
Who else processes this data
We keep the list of providers short and use them in these roles:
- Hosting and database. The servers and database the service runs on.
- File storage. Imported CSV files and message attachments.
- AI processing. Categorising inbound replies, as described above.
- Platform email. Sending our own notifications to you, such as invitations and alerts. Not your campaign mail, which goes through your own mailbox.
- Network addressing. The dedicated addresses used for LinkedIn traffic.
- Your mail provider and LinkedIn. The accounts you connect, acting under their own terms with you.
We will tell you exactly who they are, and where they are, on request. Some are outside the UK; where that is so we rely on the UK's approved transfer mechanisms, and we will confirm which apply to a given provider if you ask.
How long we keep it
- Your account and campaign data: while your account is open, and deleted within 90 days of it closing.
- Mail unrelated to your campaigns: deleted after seven days.
- Credentials: deleted when you disconnect the mailbox or LinkedIn account.
- Suppression records: kept indefinitely on purpose. They are how we know never to contact someone again, so deleting them would undo the opt-out.
How it is protected
- Every credential is encrypted before it is stored. LinkedIn passwords use a separate key that the public-facing part of the service cannot read.
- Each workspace's data is isolated, and access is checked on every request rather than trusted from the browser.
- Traffic is encrypted in transit.
- Access to production systems is limited to the people who operate the service.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. Write to privacy@pipelinepartner.io and we will respond within one month.
If the request concerns data a customer of ours uploaded, we will pass it to them, because they decide what happens to it.
You can also complain to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first so we can put it right.
Cookies
This site sets no cookies. The product sets only what is needed to sign you in and remember which workspace you are looking at, and to protect sign-in forms. There is no advertising or analytics tracking anywhere, and nothing to consent to. This site loads its fonts from Google Fonts, which means your IP address reaches Google when the page loads.
Changes
If we change how we handle personal data, we will update this page and change the date at the top. Where a change materially affects you, we will tell you before it takes effect.