Privacy

Privacy Policy

What ExportPilot collects, why it is needed, and how your exporter workspace is protected.

Introduction

ExportPilot is a SaaS platform for Pakistani exporters. This policy explains how ExportPilot collects, uses, stores, and protects your data.

ExportPilot helps exporters discover buyers, manage outreach, prepare invoices, and understand export services from one workspace.

Data We Collect

  • Account information such as your name, email address, phone number, company name, and plan.
  • Workspace data you create, including CRM leads, search jobs, templates, invoices, documents, and settings.
  • Buyer discovery data such as company websites, public contact details, source URLs, and review notes.
  • Email account connection metadata, such as sender address, provider, verification status, and sending limits.
  • Usage and technical data such as pages visited, feature events, IP address, browser type, device information, and error logs.

How We Use Your Data

  • To provide ExportPilot features including buyer discovery, CRM, email outreach, invoices, documents, and support.
  • To authenticate your account and keep your workspace separate from other users.
  • To operate safety limits for email sending and protect sender reputation.
  • To troubleshoot issues, improve the product, and respond to support requests.
  • We do not sell your data.

Data Storage

  • ExportPilot stores application data in Supabase-hosted infrastructure. Storage and processing locations depend on the service and its configured region; data is not necessarily processed in a single country.
  • Supabase authentication and row-level security are used to restrict access to your workspace data.
  • Files and generated documents may be stored or processed by services required to provide the requested feature.
  • You can request account deletion from Settings or by emailing exportpilotcrm@gmail.com.

Email Outreach

  • Emails are sent through your own connected Gmail / Google Workspace account.
  • ExportPilot does not store your Gmail account password.
  • You are responsible for the contacts you email and for complying with applicable outreach laws.
  • ExportPilot enforces safety controls such as manual review, unsubscribe requirements, and daily sending limits.

Connected-Mailbox Replies

When you separately enable connected-mailbox reply synchronization, ExportPilot requests Google permission to read email messages. That permission is broader than the application's collection filter. ExportPilot processes replies in conversations proven to originate from ExportPilot, not a general copy of your inbox.

Processed data can include reply text and subject, sender and recipient details, message and thread identifiers, timestamps, and links to the associated CRM lead and conversation. We use this data to display tracked replies, update reply status, and stop or hold pending follow-ups. Replies are not automatically classified as won deals.

The retention process targets redaction of captured reply text and subject after 30 days through bounded scheduled maintenance. This is not immediate deletion of every record on day 30. Message identifiers, timestamps, provenance and follow-up-stop evidence remain for deduplication and business records.

Pausing synchronization does not revoke Google's existing permission or delete CRM history. Disconnecting an account and Google-side permission revocation are separate actions. You can manage Google's permission through your Google Account's third-party connections settings.

For account-data or deletion requests, contact exportpilotcrm@gmail.com.

AI Assistance

Connected-mailbox synchronization itself does not send reply bodies to an AI provider. AI assistance is a separate feature: when you request an AI analysis or draft, the input and relevant context for that request are processed by DeepSeek.

Review the content you provide before requesting AI assistance. AI output may be inaccurate and requires your review; generating a draft does not send an email.

Third-Party Services

  • Supabase for database and authentication.
  • Google (Gmail API) for sending email and, with separate permission, synchronizing tracked replies through your connected account.
  • DeepSeek for requested AI analysis and drafting assistance.
  • Serper for web search when buyer discovery is enabled.
  • Hunter.io for additional contact discovery when configured.
  • Sentry for error tracking.
  • Paddle for card payments and subscription billing.

Your Rights

  • Access your workspace data from inside ExportPilot.
  • Request correction or deletion by emailing exportpilotcrm@gmail.com.
  • Disconnect email accounts from Settings.
  • Delete your account from Settings or by contacting support.

Cookies

  • ExportPilot uses cookies and similar storage for login sessions, security, preferences, and product functionality.
  • We do not use advertising cookies.
  • Analytics may be used to understand product usage and improve reliability.

Contact

For privacy questions, account deletion, or data requests, email exportpilotcrm@gmail.com.

Company: ExportPilot

Changes

We may update this policy as ExportPilot evolves. Registered users will be notified when material changes are made.

Last updated: September 2026