The short version
Approvalane exists to run your projects — not to mine your data. We collect only what the product needs to work, we never sell personal data, your files and messages belong to you, and every workspace's data is isolated from every other workspace. Where you connect an outside service or send data to your own endpoints, we tell you exactly what moves. This policy explains the details in plain language.
What we collect
- Account data — your name, email and (for password accounts) a hashed password. Invited developers sign in with magic links, so many accounts never have a password at all.
- Profile data — optional details you choose to add: title, bio, skills, hourly rate, timezone and website. On the developer side this is a working profile, visible to the workspace you're engaged with, alongside the ratings clients leave after an engagement closes.
- Workspace content — projects, milestones, tasks, messages, documents and their version history, reviews, contracts and signatures, proposals, meetings and calendar entries, time entries and timesheets, invoices, disputes and their evidence threads, support threads, and the activity timeline your team generates.
- Prospect & enquiry data — when someone submits a workspace's public intake form, requests a booking or responds to a proposal, we receive what they typed (name, email, phone, company, budget, message) on that workspace's behalf and deliver it into that workspace as its records. Booking also records the timezone their browser reported, so we can write times they'll recognise. Accepting a proposal additionally records the typed name, timestamp and network address as the acceptance evidence. These people are not Approvalane users; the workspace that published the page is responsible for how it uses their data.
- Billing data — your plan, billing period and payment history. Card details go directly to Stripe; we store only a reference (brand, last four digits, expiry) so you can recognise your saved card.
- Payout data — the balance we hold for you and its transaction history. If you take payouts through a connected account we store its identifier and the status Stripe reports (whether payouts are enabled, whether more information is needed). If you use the manual payout rail instead, the account details you enter are encrypted at rest.
- Integration data — for a calendar you connect: the account's email address, access and refresh tokens (encrypted at rest), and the start and end times of your existing events so slots can be blocked. For API access: a hash of each key, its label and when it was last used. For webhooks: the endpoint URL you entered, its secret (encrypted) and its recent delivery status.
- Notification data — your preferences (quiet hours, muted projects, timezone) and, if you turn on push, the push endpoint and keys your browser issues for that device.
- Technical data — sign-in timestamps and network address, and the minimum device information needed for security and for realtime presence.
How we use it
- To run the product: sync your workspace in real time, deliver notifications you asked for, store your files, process payments you initiate, pay out money you've earned.
- To keep accounts safe: hashed passwords, single-use magic links, session controls, tenancy isolation between workspaces, audit trails of sign-ins and staff actions.
- To improve Approvalane using aggregate, de-identified usage patterns — never the contents of your files or messages.
- To send transactional email (invites, receipts, renewal reminders, meeting and payout notices). We don't send marketing email unless you opt in.
AI features
When you use an AI feature (summaries, drafting help, hand-off notes, invoice explanations, the workspace copilot), the relevant content is sent to our AI provider (Anthropic) to generate your result. It is used to answer your request — not to train models on your data. AI features are always something you invoke; nothing is analysed in the background. The copilot reads only what your own role can already see.
Integrations you connect
- Google Calendar. Connecting it is your own action, and the permission you grant is scoped to calendar events. We use it two ways: writing your confirmed Approvalane meetings into your calendar, and reading the times of your existing events so your booking page won't offer a slot you've already spent. We keep only start and end times plus a title for your own reference — never attendees, notes or attachments — and we skip anything marked free or all-day. Disconnecting deletes the tokens and every time we pulled. If Google withdraws our access, we delete those times too.
- API keys. A key you mint carries your workspace's access. We store only a hash of it, so we cannot show it to you again after creation — and neither can anyone who reads our database.
- Webhooks. These send your workspace's data to endpoints you configure — your own service, Zapier, anything you point them at. Each delivery is signed so the receiver can verify it came from us. Once data reaches an endpoint you chose, this policy no longer governs it — the receiving service's does. Repeatedly failing endpoints are disabled automatically.
- Social sign-in. If you sign in with Google or Apple we receive your name and email address to identify your account. Nothing is posted anywhere on your behalf.
Payments & identity verification
- Card payments are handled by Stripe. Card numbers are entered on Stripe's own secured fields and never reach our servers, even though the payment page carries your brand.
- To receive payouts you may complete Stripe onboarding. The identity details and documents that requires — government ID, bank account, business information — go directly to Stripe under its own privacy policy. We never see them. All we learn back is the account's identifier and whether it is cleared to receive money.
- If a cardholder disputes a payment, Stripe shares the dispute's existence and status with us so the affected invoice can be frozen while their bank decides. We hold the record; the decision is the bank's.
Notifications & push
Real-time alerts inside the app need no extra permission. Push notifications — the ones that reach your phone or desktop when the app is closed — require your browser's permission, and turning them on stores a device-specific endpoint and key pair so your browser vendor can deliver the message. We send only what the notification says; the content passes through your browser vendor's push service to reach you. Revoke the permission or switch push off in the product and the stored subscription is deleted. Quiet hours and per-project mute are enforced on our side, before anything is sent.
Who can see your data
- Your workspace — access follows the product's roles: owners see their workspace; invited developers see only the projects they're assigned to; per-member capability grants narrow it further.
- People you share a link with — a document share link lets anyone holding it download that one file until the link expires or is revoked; proposals are readable by anyone holding their unguessable link until they're decided or withdrawn. Links are workspace-created, expiring, revocable and download-counted — but once someone downloads a file, its onward journey is outside the product.
- Services you connect — the calendar you linked, and any endpoint you pointed a webhook at. You choose these, and you can disconnect them at any time.
- Subprocessors — carefully chosen services that make the product work: Stripe (payments, payouts and identity verification), our hosting and database providers, email delivery, Anthropic (AI features you invoke), Google (calendar sync and social sign-in, when you connect them), and web-push delivery through your browser vendor. Each receives only what its job requires.
- Platform staff — our own team can access a workspace only to operate the platform: resolving a dispute you escalated, investigating a payment problem, or answering a support request. Entering a workspace is logged, time-limited, and visible in the audit trail.
- Legal requirements — we disclose data only when the law genuinely requires it, and we'll tell you when we're allowed to.
- Nobody else. We do not sell or rent personal data. Ever.
Where it lives & how it's protected
- Data is encrypted in transit (TLS). Sensitive values we hold — integration keys, calendar tokens, webhook secrets, manual payout details — are encrypted at rest.
- Passwords are hashed with a modern algorithm; magic links are single-use and expire quickly; API keys are stored only as hashes.
- Every query in the product is scoped to your workspace — cross-workspace access is blocked at the framework level and covered by our automated test suite.
- Uploads are scanned by type and size rules; executable files are refused. Every stored file carries a checksum, so tampering is detectable.
- Money movements are recorded as a double-entry ledger and reconciled nightly — the record can be audited, not quietly edited.
Retention & deletion
- Your content stays as long as your workspace exists — project records (approvals, checksummed files, timelines, signed contracts) are the product's paper trail.
- Leads and enquiries are the workspace's working records: unconverted leads can be deleted by the workspace at any time, and share links die on their expiry date or the moment they're revoked.
- Integration data is short-lived by design: calendar tokens and pulled busy times are deleted when you disconnect or when access is withdrawn, and revoked API keys stop working immediately.
- Push subscriptions are deleted when you switch push off or your browser withdraws the permission.
- If your plan lapses, nothing is deleted; the workspace pauses until you reactivate.
- You can request full deletion of your workspace and personal data at any time; we complete verified requests within 30 days, keeping only what the law requires — see Your rights below for exactly what survives an erasure and why.
Your rights
Wherever you are, we honour the core rights: access what we hold about you, correct it, export it, or delete it.
Export it yourself, whoever you are. Every account — owner, developer or invited client — can download everything we hold that identifies them from Settings → Your data: a machine-readable JSON file plus the documents and attachments you uploaded. Workspace owners additionally get CSVs of the workspace's own book (projects, clients, leads, invoices, time, tasks and team) — that is the workspace's data, which is a different thing from yours.
Erasure, and what survives it. Ask us and we will verify the request and erase you. Your name, email, password, profile, sign-in links, sessions, connected calendars, push devices, preferences and payout details are deleted outright. Three things are kept, without your identity attached to them, because we are not free to destroy them: payment records, which tax law requires and which our double-entry books cannot lose without ceasing to balance; the project timeline, which is a tamper-evident hash chain that every other party relies on to verify their own work; and issued invoices and signed contracts, which the law says must not be rewritten once sent. Messages you sent stay as the other party's record of their own conversation. In each case what remains points at an account that no longer names anyone.
If you enquired through a workspace's public page and never had an account, that workspace can erase you directly — the same request reaches us and we will help them honour it.
Cookies
Approvalane uses first-party cookies for one thing: keeping you signed in securely (session and "remember me"). No advertising cookies, no cross-site trackers.
Children
Approvalane is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.
Changes to this policy
If we change this policy in a way that matters, we'll tell you inside the product or by email before the change takes effect, along with what changed and why.
Contact
Privacy questions or requests: support@approvalane.com. A human reads every message.