StrikeZone Growth Inc. Privacy Policy
Effective Date: February 23, 2026
Last Updated: August 12, 2026
StrikeZone Growth Inc. ("Strikezone," "we," "our," or "us") provides an AI-native CRM and go-to-market software-as-a-service platform for business teams. The Strikezone platform includes CRM records, contacts, companies, deals, tasks, notes, activities, projects, documents, go-to-market planning, ICP and buyer-persona workflows, campaign planning, sales email, connected inbox, connected calendar, meeting scheduling, booking links, email analytics, data connectors, referrals, support workflows, Stripe/payment-related subscription workflows, and Frank AI - Sales Manager (collectively, the "Services").
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit our websites, use the Strikezone application platform, connect third-party services, use Google or Microsoft inbox/calendar integrations, use Strikezone Secure Send, interact with Frank AI - Sales Manager, or otherwise use the Services. It also describes rights that may be available under applicable privacy laws, including GDPR, UK GDPR, Swiss data protection laws, and California privacy laws where applicable.
By using the Services, creating a workspace, connecting third-party services, or authorizing integrations, you acknowledge that you have read and understood this Privacy Policy.
1. Scope
This Privacy Policy applies to:
- Visitors to our websites, including getstrikezone.ai and related Strikezone pages.
- Users of the Strikezone application platform, including workspace owners, administrators, team members, invited users, and authorized users.
- Customers who connect third-party services to Strikezone, including Google Workspace, Gmail, Google Calendar, Microsoft Outlook, Microsoft 365 Mail, Outlook Calendar, HubSpot, Salesforce, Zoho, Brevo, and other connected platforms.
- Users who send emails, schedule meetings, create CRM records, create go-to-market documents, run campaigns, import contacts, use Strikezone Secure Send, or use Frank AI - Sales Manager.
- Individuals whose personal information may appear in business data processed by our customers, such as leads, contacts, prospects, customers, referral contacts, meeting attendees, email recipients, and business partners.
Important B2B context: Strikezone is primarily a business-to-business platform. When a business customer uploads, creates, imports, connects, or processes CRM, sales, marketing, email, calendar, contact, or go-to-market data through the Services ("Customer Data"), that customer typically acts as the data controller or business, and Strikezone acts as a processor or service provider acting on the customer's instructions. If your information is included in a Strikezone customer's workspace, CRM, sales records, email records, meeting records, or marketing records, your privacy request may need to be directed to that customer first. We support our customers in responding to such requests as required by applicable law and our agreements.
2. Services Covered by This Policy
This Privacy Policy covers the full Strikezone platform, including current and planned modules such as:
- Command Center and workspace administration.
- AI-native CRM, including contacts, companies, deals, pipelines, tasks, notes, activities, ownership, permissions, and imports.
- Go-to-Market Builder, ICP and buyer-persona workflows, campaign planning, opportunity qualification, lead workflows, and related GTM records.
- Campaign Builder, email sequences, broadcast or campaign workflows where available, templates, segments, suppression lists, and engagement analytics.
- Connected Gmail, Google Workspace, Outlook, and Microsoft 365 inbox functionality.
- Google Calendar, Outlook Calendar, meeting scheduling, booking links, meeting types, availability, event creation, and CRM meeting activity logging.
- Strikezone Secure Send and customer-domain sending infrastructure, including sending identity, DNS verification, opt-out, bounce, complaint, suppression, and deliverability controls.
- Frank AI - Sales Manager, including AI-assisted drafting, summarization, CRM updates, recommendations, classification, next actions, and workflow support.
- Documents, projects, shared workspaces, internal notes, public-share workflows, support workflows, referral programs, knowledge base, and related collaboration features.
- Data connectors and integrations with systems such as HubSpot, Salesforce, Zoho, Brevo, and other customer-authorized platforms.
- Product analytics, telemetry, audit logs, security logs, customer support, subscription management, and billing-related workflows.
If a feature is not yet generally available, this Privacy Policy describes the data practices that may apply when that feature is enabled, tested, or released.
3. Information We Collect
We collect information in the following categories.
3.1 Account, Profile, Workspace, and Team Information
We may collect names, business email addresses, phone numbers, company names, job titles, roles, workspace membership, team membership, profile information, account status, workspace settings, role-based permissions, authentication metadata, SSO metadata, invitation records, and administrative preferences.
3.2 Billing, Subscription, and Commercial Account Information
We may collect plan, subscription, license, invoice, tax, usage, account-status, payment-provider, and commercial relationship information. Payment card details may be processed by our payment processor, and Strikezone does not need to store full card numbers in order to provide the Services.
3.3 CRM, Sales, GTM, and Customer Data
Depending on how a customer uses Strikezone, Customer Data may include contacts, leads, companies, business email addresses, phone numbers, job titles, company information, notes, tasks, activities, deal data, pipeline data, lifecycle stages, opportunity records, campaign records, buyer-persona records, ICP data, meeting records, call notes, documents, project records, support records, referral records, imported files, and related business context.
3.4 Connected Platform and OAuth Data
When you choose to connect a third-party service, we collect and process information necessary to authorize, operate, secure, and maintain that connection. This may include OAuth authorization data, access tokens, refresh tokens, scopes or permissions granted, token status, integration configuration details, connection timestamps, disconnect events, API request metadata, provider error codes, provider request IDs, sync settings, and integration-health logs.
3.5 Google Workspace, Gmail, and Google Calendar Data
If you connect a Google account, Gmail inbox, Google Workspace account, or Google Calendar to Strikezone, we may process Google data needed to provide the user-facing features you choose to use, such as:
- Gmail send authorization and metadata needed to compose, send, log, and troubleshoot emails you choose to send from Strikezone.
- Email draft content, subject lines, recipients, message IDs, send status, timestamps, attachments if included by the user, and CRM activity logs where needed to provide the requested function.
- Calendar IDs, selected calendars, availability, free/busy information, event metadata, meeting details, attendee information, time zone, booking rules, and event creation or update data needed for scheduling and booking links.
- Suppression and unsubscribe data related to recipients who opt out of future sales, outreach, or commercial emails.
Strikezone requests only the Google OAuth scopes needed to provide the connected Gmail and Google Calendar features selected by the user.
3.6 Microsoft Outlook, Microsoft 365 Mail, and Outlook Calendar Data
If you connect Outlook, Microsoft 365, or a Microsoft account to Strikezone, we may process Microsoft Graph data needed to provide the user-facing features you choose to use, such as:
- Microsoft Graph authorization data, delegated permissions, mailbox-send authorization, calendar authorization, token status, connection metadata, provider request IDs, and integration-health logs.
- Email draft content, subject lines, recipients, message IDs, send status, timestamps, attachments if included by the user, and CRM activity logs where needed to provide the requested function.
- Calendar IDs, selected calendars, availability, free/busy information, event metadata, meeting details, attendee information, time zone, booking rules, and event creation or update data needed for scheduling and booking links.
- Suppression and unsubscribe data related to recipients who opt out of future sales, outreach, or commercial emails.
Strikezone requests only the Microsoft permissions needed to provide the connected Outlook and Outlook Calendar features selected by the user.
3.7 Strikezone Secure Send, Email Delivery, and Compliance Data
When you use Strikezone Secure Send or other email-sending features, we may process sender identities, sending domains, DNS verification status, DKIM/SPF/DMARC status, return-path and bounce information, recipient addresses, unsubscribe status, suppression records, email delivery status, message events, provider responses, bounce events, complaint events where available, rate-limit status, reputation-protection information, and audit logs.
3.8 Frank AI - Sales Manager and AI Feature Data
When you use Frank AI - Sales Manager or other AI-assisted features, we may process the prompts, instructions, workspace context, CRM records, GTM records, documents, notes, tasks, email drafts, summaries, recommendations, outputs, edits, and actions needed to provide the AI features you request. AI features may use customer workspace context only as needed to provide user-facing functionality, enforce permissions, troubleshoot, monitor reliability, and improve product quality in accordance with this Privacy Policy and customer agreements.
We do not use Google Workspace API data, Gmail data, Google Calendar data, Microsoft mail data, or Microsoft calendar data to train generalized AI or machine learning models.
3.9 Documents, Files, Projects, and Collaboration Data
If you create, upload, import, share, or edit documents, files, project records, notes, knowledge-base items, public-share links, or collaboration content in Strikezone, we may process that content, related metadata, sharing settings, permissions, access logs, and activity history.
3.10 Support, Feedback, Communications, and Events
We may collect support tickets, chat or email support communications, feedback, feature requests, onboarding information, demo requests, customer-success notes, training records, meeting communications, event-registration information, and related correspondence.
3.11 Technical, Device, Security, Telemetry, and Usage Data
We may collect IP address, device identifiers, browser type, operating system, session activity, log files, error reports, performance metrics, feature usage analytics, API events, audit logs, security events, rate-limit events, suspicious activity indicators, and diagnostic data.
3.12 Cookies and Similar Technologies
We use cookies and similar technologies to maintain sessions, authenticate users, remember preferences, secure accounts, understand product performance, and improve usability. See our Cookie Policy where applicable.
4. How We Use Information
We use information to:
- Provide, operate, maintain, secure, and improve the Services.
- Create and manage accounts, workspaces, teams, roles, permissions, and subscriptions.
- Provide AI-native CRM functionality, including CRM records, deals, pipelines, tasks, notes, activities, imports, ownership, search, reporting, and analytics.
- Provide go-to-market workflows, including ICP, buyer persona, campaign planning, sequence planning, opportunity workflows, and related GTM records.
- Provide connected inbox functionality, including composing, sending, logging, and troubleshooting user-directed emails through Gmail, Google Workspace, Outlook, or Microsoft 365.
- Provide connected calendar functionality, including availability lookup, meeting scheduling, booking links, meeting type configuration, calendar event creation, event updates, time-zone handling, and attendee coordination.
- Provide Strikezone Secure Send, including sender-domain verification, sending controls, email delivery, bounce handling, complaint handling where available, rate limiting, unsubscribe processing, suppression, deliverability monitoring, and abuse prevention.
- Provide Frank AI - Sales Manager functionality, including user-directed drafting, summarization, classification, recommendations, workflow assistance, CRM updates, document generation, and next-action suggestions.
- Provide data connectors, imports, exports, synchronization, mappings, and integration health monitoring.
- Provide customer support, onboarding, training, troubleshooting, incident response, and technical assistance.
- Monitor service performance, reliability, usage, and product quality.
- Detect, prevent, and investigate spam, abuse, fraud, unauthorized access, security incidents, policy violations, and misuse of the Services.
- Comply with legal, regulatory, contractual, provider, security, anti-abuse, and tax obligations.
- Enforce our Terms of Use, User License Agreement, Responsible Use Agreement, sender consent rules, anti-spam requirements, and related policies.
We do not sell personal data. We do not use Customer Data, Google Workspace API data, Gmail data, Google Calendar data, Microsoft Graph mail/calendar data, connected inbox/calendar content, or private CRM workspace content for targeted advertising.
5. Google API Services and Limited Use Disclosure
Strikezone's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We access Google user data only when you authorize Strikezone to do so and only for the purposes disclosed in this Privacy Policy and reasonably necessary to provide the user-facing features you request, such as sending emails you compose, logging CRM activity, checking calendar availability, creating or updating calendar events, troubleshooting integration errors, maintaining security, and processing opt-outs or suppression requests.
For Google API data:
- We do not sell Google user data.
- We do not use Google user data for targeted advertising.
- We do not use Google user data to train generalized AI or machine learning models.
- We do not allow humans to read Google user data except where necessary for security, legal compliance, abuse investigation, customer-requested support, or with your explicit permission.
- We only request Google OAuth scopes needed to provide the connected Gmail and Google Calendar features selected by the user.
- You may disconnect your Google integration through Strikezone account settings or through Google account controls where available.
6. Microsoft Graph, Outlook, and Microsoft 365 Data
When you connect Outlook, Microsoft 365 Mail, or Outlook Calendar to Strikezone, we use Microsoft Graph permissions authorized by you or your organization to provide user-directed mail and calendar functionality. This may include sending emails you compose from Strikezone, logging CRM activity, reading calendar availability, creating or updating calendar events, troubleshooting provider errors, and maintaining integration security.
For Microsoft mail and calendar data:
- We do not sell Microsoft mail or calendar data.
- We do not use Microsoft mail or calendar data for targeted advertising.
- We do not use Microsoft mail or calendar data to train generalized AI or machine learning models.
- We only request Microsoft permissions needed to provide the connected Outlook and Outlook Calendar features selected by the user.
- You may disconnect your Microsoft integration through Strikezone account settings or through Microsoft account or organization controls where available.
7. Other Connected Platforms and Data Connectors
If you connect other business systems such as HubSpot, Salesforce, Zoho, Brevo, or other CRM, marketing, data, or productivity platforms, we process the data authorized by you or your organization only as needed to provide the integration, synchronization, mapping, reporting, analytics, CRM, GTM, or workflow functions selected by the user or workspace administrator.
Connected platform data may include authorization metadata, connection status, object mappings, contacts, companies, deals, campaign records, lifecycle data, tasks, notes, events, custom fields, sync status, and provider error data depending on the integration and permissions granted.
8. Recipient Consent, Sales Email, Unsubscribe, and Suppression
Strikezone is a B2B CRM and go-to-market platform. Users are responsible for ensuring they have appropriate consent, opt-in, an existing business relationship, legitimate interest, or another lawful basis under applicable law before sending sales, outreach, marketing, or commercial emails to recipients through Strikezone.
Users are prohibited from using Strikezone to send emails to contacts who have not consented to receive such communications or where the user does not have another lawful basis to contact the recipient. Users may not use Strikezone to send spam, send deceptive messages, impersonate others, use misleading subject lines or sender identities, upload purchased, harvested, or scraped lists for unsolicited outreach, bypass unsubscribe or suppression controls, or contact recipients who have opted out.
Strikezone may automatically include an unsubscribe or opt-out link in sales, outreach, marketing, or commercial emails sent through the Services, including emails sent through connected Gmail or Google Workspace inboxes, connected Outlook or Microsoft 365 inboxes, and Strikezone Secure Send.
Outbound sales or outreach emails may include unsubscribe microcopy such as:
You are receiving this business email from {{sender_name}} at {{sender_company}}. To opt out of future sales or outreach emails from this sender, click here to unsubscribe.
When a recipient opts out, we process the opt-out request and create a suppression record so future sales, outreach, marketing, or commercial emails to that recipient can be blocked according to the applicable suppression scope. Suppression may apply at the sender, workspace, tenant, sending-domain, or platform level depending on the reason for the opt-out, the applicable law, and product configuration.
We may block sends, disable sending features, suspend workspaces, throttle delivery, or take other protective action if we believe a user is violating applicable law, provider requirements, this Privacy Policy, our Terms of Use, our Responsible Use Agreement, sender consent rules, or recipient opt-out requirements.
9. AI Features and Model/Data Use
Strikezone provides AI-assisted features through Frank AI - Sales Manager and related AI-native CRM and go-to-market workflows. These features may help users draft emails, summarize records, classify contacts, identify next actions, prepare documents, analyze engagement, update CRM records, answer workspace questions, and support go-to-market execution.
AI features operate on data the user or workspace provides, creates, imports, connects, or authorizes. We may process prompts, outputs, workspace context, CRM data, documents, and related metadata to provide the AI feature, enforce permissions, secure the platform, troubleshoot issues, measure reliability, and improve product functionality.
We do not use Google Workspace API data, Gmail data, Google Calendar data, Microsoft mail data, or Microsoft calendar data to train generalized AI or machine learning models. If we use de-identified, aggregated, or synthetic information for product improvement, we take steps designed to prevent that information from identifying a specific person, customer, or workspace.
Users remain responsible for reviewing AI-generated drafts, summaries, recommendations, and actions before relying on them or sending them externally.
10. Legal Bases for Processing
If you are in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring a legal basis for processing, we rely on the following legal bases where applicable:
- Consent, where you authorize integrations, enable optional features, or provide information voluntarily.
- Contract, where processing is necessary to provide the Services or perform our agreements.
- Legal obligation, where processing is required to comply with applicable law, regulatory duties, tax obligations, or lawful requests.
- Legitimate interests, including platform security, fraud prevention, abuse prevention, service reliability, internal analytics, product improvement, customer support, and enforcement of policies, provided these interests are not overridden by your rights.
- Customer instructions, where we process Customer Data as a processor or service provider on behalf of a business customer.
11. How We Share Information
We do not sell personal data. We may share information only in the following circumstances:
- Service providers and subprocessors that help us provide hosting, infrastructure, storage, monitoring, analytics, customer support, AI processing, email delivery, calendar processing, payments, security, and related operational services, under confidentiality and data protection obligations.
- Connected platforms you authorize, when needed to provide the integration, action, sync, send, calendar event, or workflow you request.
- Workspace administrators and authorized users, according to customer workspace settings, roles, and permissions.
- Legal, safety, and compliance purposes, including responding to lawful requests, protecting rights and safety, preventing fraud or abuse, investigating security incidents, and enforcing our agreements.
- Business transfers, such as merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards and notices where required.
- With your instructions, consent, or direction.
We do not share Customer Data, Google user data, or Microsoft mail/calendar data with third parties for targeted advertising.
12. International Data Transfers
Strikezone is a United States company. If you access the Services from outside the United States, including from the EEA, United Kingdom, Switzerland, or other jurisdictions, your information may be transferred to and processed in the United States or other jurisdictions where we or our service providers operate.
Where required, we use appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses or other lawful transfer mechanisms.
13. Data Retention
We retain information only as long as reasonably necessary to provide and maintain the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, support operational integrity, honor opt-out requests, and meet customer contractual requirements.
- Customer Data is retained according to customer agreements, workspace settings, account status, legal requirements, backup/security needs, and deletion requests where applicable.
- OAuth tokens are retained while an integration remains connected and are deleted, invalidated, or made unusable when the integration is disconnected, subject to limited retention of logs for security, compliance, and audit purposes.
- Email send logs, delivery logs, bounce logs, complaint logs, suppression records, and unsubscribe records may be retained as needed to honor opt-outs, prevent unwanted email, comply with legal and provider obligations, protect deliverability, and maintain platform integrity.
- AI prompts, outputs, telemetry, and feature logs may be retained as needed to provide the Services, troubleshoot issues, enforce permissions, maintain security, and improve reliability, subject to customer agreements and applicable law.
- Audit logs and security logs may be retained for a reasonable period to detect abuse, troubleshoot incidents, and comply with legal or contractual obligations.
- Backups may retain data for a limited period before normal rotation, unless preservation is required by law, security, or contractual obligations.
14. Data Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. These safeguards may include:
- Encryption in transit, such as TLS.
- Encryption at rest where appropriate.
- Role-based access controls and least-privilege access.
- Secure OAuth token handling and integration monitoring.
- Workspace permissions and audit logging.
- Authentication, SSO, and session-security controls.
- Security monitoring, abuse detection, and incident response.
- Vendor risk management and contractual safeguards with service providers.
- Sender reputation, suppression, unsubscribe, and anti-abuse controls for email-sending features.
No method of transmission or storage is 100% secure, but we work to maintain safeguards appropriate to the nature of the information and the risk involved.
15. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information, and to withdraw consent where processing is based on consent.
California residents may have rights under CCPA/CPRA, including the right to know, access, correct, delete, and opt out of sale or sharing of personal information. Strikezone does not sell personal information and does not share personal information for cross-context behavioral advertising.
Individuals in the EEA, United Kingdom, Switzerland, or other jurisdictions may have rights under applicable privacy laws, including rights to access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority.
To exercise privacy rights, email support@getstrikezone.ai with the subject line "Privacy Request," "GDPR Request," or "California Privacy Request," as applicable. We may need to verify your identity and authority before fulfilling a request.
If your personal information is included in a Strikezone customer's CRM, sales, marketing, email, meeting, calendar, or go-to-market dataset, that customer may be the controller or business responsible for the data. We may direct your request to that customer or support the customer in fulfilling the request as required by applicable law and contract.
16. Your Choices and Controls
Depending on your role and workspace settings, you may be able to:
- Update account, profile, and workspace information.
- Manage connected Gmail, Google Workspace, Outlook, Microsoft 365, calendar, CRM, and data integrations.
- Disconnect Google or Microsoft integrations through Strikezone settings or through provider account controls where available.
- Manage selected calendars, meeting types, booking rules, and scheduling preferences.
- Review or delete certain drafts, documents, records, tasks, notes, and workspace content.
- Manage unsubscribe, suppression, consent, and sending-compliance settings.
- Control cookies through browser settings and available cookie preference tools.
- Request deletion, export, or correction where available and legally required.
Workspace administrators may control workspace-level settings, user access, permissions, integrations, subscription status, and data-retention settings according to the Services and customer agreement.
17. Recipient Opt-Out Rights
If you receive a sales, outreach, marketing, or commercial email sent by a Strikezone user, you may opt out using the unsubscribe or opt-out link in the email where provided. You may also contact the sender directly.
When you opt out, Strikezone may record your email address and related suppression information so that future emails from the applicable sender, workspace, tenant, domain, or platform can be blocked according to the applicable suppression scope. We retain suppression records as needed to honor opt-outs, comply with law, and protect recipients and platform integrity.
18. Children's Privacy
The Websites and Services are not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact support@getstrikezone.ai.
19. Cookies and Tracking Technologies
We use cookies and similar technologies to maintain sessions, enable core functionality, remember preferences, secure accounts, understand performance, and improve usability. You can control cookies through your browser settings and, where available, our cookie preference mechanisms. Disabling certain cookies may affect Service functionality.
20. Third-Party Links and Connected Platforms
Our Websites and Services may link to third-party websites or services. This Privacy Policy does not apply to third-party services except to the extent we process information through integrations you authorize. Please review the privacy policies and terms of Google, Microsoft, HubSpot, Salesforce, Zoho, Brevo, Stripe, and any other connected platform or service provider you choose to use.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, provider requirements, products, integrations, or other factors. When we make changes, we will revise the "Last Updated" date above and, where required, provide additional notice, such as email, in-app notice, or website notice.
22. Contact Information
StrikeZone Growth Inc.
251 Little Falls Drive
Wilmington, Delaware 19808
United States
Support Contact: support@getstrikezone.ai
To exercise privacy rights, ask questions, or request assistance with a privacy matter, email support@getstrikezone.ai and include enough information for us to understand and process your request.
By using the Services and connecting platforms, you acknowledge that you have read and understood this Privacy Policy.