Privacy policy
GTM for One handles two very different kinds of personal data: yours, and that of the business contacts you research. This policy separates them, because the rules and your rights differ.
Who we are
GTM for One, operating from India. Contact: support@gtmforone.com. Postal address: ADD YOUR POSTAL ADDRESS BEFORE LAUNCH.
Your data, as a user
We store what is needed to run the product and nothing else:
- The name and email address you sign your outreach with.
- The domains you research and the campaigns you create.
- Sending mailbox credentials. SMTP and IMAP passwords are encrypted at rest with AES-256-GCM and are never returned to the browser, not even to you. They are decrypted in memory only to open a connection.
- Third-party API keys you supply for enrichment and search providers, used only to make the calls you asked for.
- Cost records: which provider was called, how many units, what it cost.
Business contact data
To find prospects, GTM for One queries third-party providers you have connected and public sources, and stores what comes back: name, job title, employer, business email address, LinkedIn URL, and company firmographics. This is business contact data about people in their professional capacity. Never special-category data, and never consumer or personal-life data.
Under GDPR the lawful basis for processing it is legitimate interest (Article 6(1)(f)) in B2B communication. That basis is conditional, not automatic: it holds only while the outreach is genuinely relevant to the recipient's job, the sender is identifiable, and opting out is easy and honoured. GTM for One enforces the last of those in code (see below) but the relevance of what you send is your responsibility as the sender.
How opting out works
Every email carries a one-click unsubscribe link and a List-Unsubscribe header. The link is an HMAC of the address, so it needs no database lookup and the list cannot be enumerated by guessing.
An opt-out is global and permanent across every campaign and every product run through this installation. Addresses on the do-not-email list are stored as SHA-256 hashes, never in the clear, so the suppression list can never itself be used as a mailing list. Replying to a message also suppresses the address automatically, and hard bounces do too.
Where it lives
In a PostgreSQL database on infrastructure controlled by the operator of this installation. Data is sent to third-party providers only when a step requires it: the LLM gateway for research and drafting, enrichment providers for email lookup, search providers for discovery. Each receives only what that call needs.
How long we keep it
Campaign data is kept until you delete it. Provider lookup results are cached indefinitely so the same query is never paid for twice, including misses. Suppression entries are kept permanently by design: forgetting that someone opted out would let us email them again, which is the opposite of honouring it.
Your rights
If you are in the EU, UK or a comparable regime you may request access, correction, deletion, restriction, portability, or object to processing. Write to support@gtmforone.com and we will respond within 30 days.
If you received an email and want your data gone: say so in a reply, or use the unsubscribe link. Unsubscribing stops all contact immediately. Ask for erasure and we remove the record itself, keeping only the one-way hash needed to ensure you are never contacted again.
What we do not do
- We do not sell data. GTM for One is automation; the data is yours and your providers'.
- We do not use your campaign content to train models.
- We do not track email opens with pixels, or rewrite your links to track clicks.
- We do not run advertising or analytics trackers on this site.
Changes
Material changes will be dated here. Continuing to use GTM for One after a change means accepting it.