Legal

Privacy Policy

What FullArc collects, why, who else touches it, and how to get it back or have it removed. Written to be read rather than to be survived.

Last updated August 20, 2026

This policy covers getfullarc.com and the FullArc application at app.getfullarc.com. It explains what we do with information about you, and what we do with the information you put into the product about other people.

The short version

We do not sell your data, we do not use it to train AI models, and we do not run advertising. AI features run on a key you supply, so that work happens under your own provider account. If you connect a Gmail mailbox, FullArc synchronises it so you can read, write and reply to that mail inside the CRM, and files each message against the customer it concerns — the specifics are in Google user data.

1. Who controls what

FullArc holds two different kinds of information, and our responsibility differs between them. The distinction matters if you are assessing us for compliance purposes.

  • Account data — your name, work email, sign-in credentials, billing details and how you use the product. We decide how this is handled, so we are the controller of it.
  • Customer data — the businesses, contacts, deals, messages and documents you put into FullArc, including personal information about third parties such as your prospects. You decide what goes in and why. You are the controller; we are your processor and act on your instructions.

Because you control customer data, you are responsible for having a lawful basis to collect it and for responding to requests from the people it describes. We will help you do that — see your rights and choices.

2. What we collect

Information you give us

  • Account details — name, email address, password (stored only as a bcrypt hash), organisation name, and two-factor authentication settings.
  • Customer data — everything you or your team enter, import or generate: businesses, contacts, deals, activities, campaigns, documents and invoices.
  • Connected credentials — API keys and mailbox access you choose to add. These are encrypted at rest and described under connected accounts.
  • Correspondence — what you write to us in support or sales conversations.

Information collected automatically

  • Operational logs — request timestamps, IP address, browser and device type, and error diagnostics. Used to keep the service running and secure.
  • Page analytics — aggregate page-view counts through Vercel Web Analytics, which does not use cookies and does not build a cross-site profile of you.
  • Essential cookies — a signed session cookie so you stay logged in, and a CSRF token. We do not use advertising or tracking cookies.

What we do not collect

We do not buy personal data from brokers to enrich your account, we do not run advertising networks, and we do not sell or share personal information for cross-context behavioural advertising as those terms are defined under California law.

3. Google user data

If you connect a Gmail mailbox, FullArc requests access through Google OAuth. You are shown exactly what is being requested and can decline or revoke it at any time. This section describes that access specifically.

Scopes we request and why

ScopeWhy FullArc needs it
gmail.readonlyTo synchronise the connected mailbox so your mail can be read, searched and replied to inside FullArc, and each message filed against the contact and deal it belongs to. Working your customer email inside the CRM is the feature this scope exists for; reading is required because FullArc displays the mail itself, not merely a notification that it arrived.
gmail.composeTo write mail on your behalf when you ask FullArc to: sending from your own address rather than through our shared sending domain, and saving, updating and discarding drafts in your mailbox so a message you start in FullArc is the same message you finish in Gmail. This scope covers both; we do not additionally request gmail.send, which cannot manage drafts, and we do not request gmail.modify, which would let FullArc alter mail it did not create.
userinfo.email
userinfo.profile
To identify which mailbox was connected and display it in the interface, so you can tell several connected accounts apart.

What we store

  • OAuth tokens, encrypted at rest with AES-256-GCM. Disconnecting the mailbox deletes them.
  • The mailbox address, display name and profile picture shown on the connection.
  • Messages synchronised from the connected mailbox — sender, timestamp, subject and body — so they can be read, searched and replied to inside FullArc and filed against the right contact and deal. This is a mirror rather than an archive: a message you delete in your mailbox is removed from FullArc on the next synchronisation, and there is no separate retention period beyond that.
  • Messages you send and drafts you save from a connected mailbox, so your sent items and drafts are visible in FullArc alongside the rest of the thread.

How it is used

Google user data is used only to provide the features above, at your direction. No person at FullArc reads your mail. We access it only where you have specifically asked us to, or where it is necessary for security or to resolve a support issue you have raised — and where the law requires it.

If you have enabled AI features and supplied your own AI provider key, the content of a matched reply may be sent to the provider you chose in order to categorise it or draft a response. That processing happens under your own account and your own agreement with that provider. It does not occur if you have not configured a key.

Limited Use disclosure

FullArc's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: we do not transfer Google user data to third parties except as necessary to provide or improve the features you have enabled, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising; we do not allow humans to read it except with your explicit consent, for security purposes, to comply with the law, or where the data is aggregated and anonymised; and we do not use it to develop, improve or train generalised artificial intelligence or machine learning models.

Revoking access

Disconnect the mailbox in FullArc under Settings, or revoke it directly from your Google account permissions. Either removes our stored tokens and ends all access, and no further mail is synchronised. Messages already filed against your contacts remain in your account until you delete them, since they are part of your CRM history.

4. Connected accounts and your own AI keys

FullArc runs AI features on credentials you supply. We hold no platform AI key, so there is nothing to fall back to if you remove yours — the feature simply stops.

  • Keys are encrypted at rest, used only for your account's own requests, and are never sent back to your browser after saving.
  • When an AI feature runs, the relevant content is sent to the provider you selected under your key. Their handling of it is governed by your agreement with them, so it is worth reading their policy as well as ours.
  • We record the cost and token count of each call so you can see your spend. We do not retain prompt or response content for that purpose.

5. How we use information

  • To provide the service and the features you switch on.
  • To authenticate you and keep accounts secure, including detecting abuse.
  • To send transactional email you cannot opt out of while you hold an account — password resets, security alerts, billing notices.
  • To provide support you have asked for.
  • To bill you and keep the financial records the law requires us to keep.
  • To understand which parts of the product are used, in aggregate, so we improve the right things.

We do not use customer data to train AI models — not ours, not anyone else's. Your pipeline is not training material.

Where the GDPR applies, we rely on: performance of a contract (providing the service), legitimate interests (security, abuse prevention, product improvement), consent (optional marketing email), and legal obligation (tax and accounting records).

6. Who else processes it

We share data with service providers who help us run FullArc, each bound to process it only on our instructions. The current list:

ProviderPurposeRegion
NeonManaged PostgreSQL — the primary application databaseUnited States
VercelWeb application hosting and privacy-friendly page analyticsGlobal edge
RailwayBackground worker processes and the job queue (Redis)United States
ResendOutbound transactional and campaign email deliveryUnited States
TwilioSMS delivery and inbound message handling, where enabledUnited States
CloudflareDNS, and R2 object storage for uploaded files and documentsGlobal
GoogleGmail API and Places API, each used only against credentials you supplyGlobal

We may also disclose information if legally required, to enforce our Terms, or to protect the rights and safety of our users. If FullArc is ever acquired, data may transfer as part of that transaction — and you would be told before it became subject to a different policy.

We do not sell personal information.

7. How long we keep it

  • Customer data — for as long as your account is active. You can delete individual records at any time and deletion is immediate.
  • After you close your account — we delete or anonymise customer data within 90 days, except where we must keep specific records to meet a legal obligation.
  • Connected credentials — deleted as soon as you disconnect the integration.
  • Operational logs — retained for a limited period for security and debugging, then discarded.
  • Billing records — kept as long as tax and accounting law requires, typically several years.

Want your data out before you leave? Export it first — see your rights and choices.

8. Your rights and choices

Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, receive it in a portable format, object to or restrict certain processing, and withdraw consent. Exercising a right never means worse service.

Write to privacy@getfullarc.com. We respond within 30 days, and we will not charge you for a reasonable request.

If you are a prospect or contact in someone's FullArc account rather than a FullArc customer, the business that added you is the controller of that record. Contact them directly where you can. If you cannot identify them, write to us and we will pass your request to the relevant account and support them in answering it.

You can opt out of marketing email at any time using the unsubscribe link. That does not stop transactional messages about your own account, which you must keep receiving while it exists.

If you are in the EEA or UK and are unhappy with our response, you may complain to your local data protection authority.

9. How we protect it

Traffic is encrypted in transit, stored credentials are encrypted at rest with AES-256-GCM, passwords are hashed with bcrypt, and every record is isolated to one account by three independent mechanisms including database row-level security.

Our security page describes this in detail — including a plain list of what we have not done yet, such as third-party certification. No system is perfectly secure, and we would rather you knew where the edges are.

10. International transfers

FullArc is operated from Nova Scotia, Canada and our providers are listed above with their regions. Using the service may involve transferring your information to a country with different data protection laws than your own.

Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Contact us for details of the safeguards that apply to a particular transfer.

11. Children's privacy

FullArc is a business tool and is not directed at anyone under 16. We do not knowingly collect their personal information. If you believe a child has provided us data, write to privacy@getfullarc.com and we will delete it.

12. Changes to this policy

We update this policy when the product changes or the law does. The date at the top always reflects the current version. For changes that materially affect your rights, we will notify account holders by email before they take effect rather than relying on you to re-read the page.

13. Contact us

Privacy questions and rights requests: privacy@getfullarc.com

Registered entity: Darrell Pardy, operating as FullArc
Postal address: 305 Larry Uteck Blvd., Unit 301, Halifax, NS B3M 0P8, Canada