Last updated: September 30, 2026
This Privacy Policy describes how UpDrift collects, uses, and protects your personal data when you use https://updrift.io and the UpDrift platform, and explains your privacy rights.
We collect the following categories of information:
We use personal data to:
We process personal data to perform our contract with you, to pursue legitimate interests such as securing and improving the service, to comply with legal obligations, and — where required — based on your consent, which you can withdraw at any time.
We do not sell personal data. We share it only with:
The UpDrift CRM can connect to a Google account (Gmail and Google Calendar) or a Microsoft account (Outlook and Microsoft 365). Connecting is optional: you start it from the CRM’s email and calendar settings or from the email and calendar step after sign-up, and you grant access on the provider’s own consent screen. When you connect an account, we access the following through the provider’s APIs:
We use data from connected accounts only to provide CRM features you see in the product: your emails and meetings on the matching person and company records, upcoming meetings and meeting preparation, the relationship strength between your team and each contact, linking correspondents to existing records, creating and enriching records for new correspondents as described below, and sending workflow emails from your mailbox as described above.
Captured emails and meetings are stored in your workspace. You always see the emails and meetings your own mailbox captured in full. The member who connects a mailbox chooses its privacy setting, and only that member can change it: other members of your workspace with access to the CRM see its emails and meetings with participants and dates only, with subjects too, or with subjects and body excerpts. A newly connected mailbox starts with subjects, participants and dates, and you can lower or raise that in the CRM’s email and calendar settings. You can also share an individual email or meeting your own mailbox captured in full, with chosen members or with everyone in the workspace. A colleague whose own mailbox captured the same email or meeting can share it too, but nobody can share mail that only your mailbox captured, including your workspace’s admins, who can only narrow or remove an existing share.
Platform access alone does not let our staff read your connected account content. Without admission, staff see only participants and timestamps, except for their own content or content shared directly with them by name. Staff admitted through your workspace’s admin allow list are teammates and follow each mailbox owner’s privacy settings and shares. Staff can add themselves or other staff to the list; we record these changes in Change history and email your workspace’s non-staff admins. Outside the application, the engineers who run our servers and database do not access message content, except where necessary for security purposes, such as investigating abuse, or to comply with the law.
We do not use data from connected accounts for advertising, we do not sell it, and we do not use it to develop, train, or improve AI or machine-learning models. Access and refresh tokens for connected accounts are encrypted at rest with AES-256-GCM, and all data is encrypted in transit.
By default, the CRM automatically creates a person record, with name and email address, for each new correspondent your team has emailed or met with, and a company record, named after the domain, for the correspondent’s work email domain. Public email providers such as gmail.com never become companies. Workspace admins can limit which correspondents become records, or turn off automatic records or companies, in the CRM’s email and calendar settings, and can turn off automatic enrichment of new records in the CRM’s enrichment settings.
Every new record is then enriched automatically with public professional information, as for any record added to the CRM. Message subjects, body excerpts, and calendar details are never sent for enrichment; only the following are:
We do not transfer data from connected accounts to anyone else, except:
UpDrift’s use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
The Google API Services User Data Policy is published at https://developers.google.com/terms/api-services-user-data-policy.
We keep personal data only as long as needed for the purposes above. Account data is retained while your account is active and deleted or anonymized after account closure, except where law requires longer retention. Usage data is kept for shorter periods used for security and service analytics.
Connected accounts: when you disconnect an account in the CRM’s email and calendar settings, syncing stops and its stored tokens are deleted. For a Google account, we also revoke our access at Google, unless another workspace on the platform still syncs the same mailbox; the same happens when a workspace is deleted. Microsoft does not let an app revoke its own access, so after disconnecting a Microsoft account, remove the app’s permissions yourself: for a work or school account in My Apps (https://myapplications.microsoft.com), where permissions your administrator granted can only be removed by your administrator, and for a personal account in your Microsoft account’s app permissions. You can also withdraw our access at any time in your Google Account (https://myaccount.google.com/connections). Emails and meetings already captured stay on your workspace’s records; contact us to have them deleted.
We are based in the European Union and store data within the EU where possible. When data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission Standard Contractual Clauses.
You can exercise the following rights at any time by contacting us:
You can also update most account information directly in your account settings.
The service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last updated" date, and we will notify you of material changes by email or an in-product notice.
If you have any questions about this Privacy Policy or your personal data, contact us at support@updrift.io.
UpDrift is provided by nFront Ventures OÜ, Vana-Kalamaja tn 6-5, 10412 Tallinn, Estonia, which is the controller wherever UpDrift acts as controller.