All legal information

Privacy Policy

What PitchTrack uses, why it is needed, and how to ask about your data.

Updated 2026-10-08

What this covers

PitchTrack is operated by Jake Phillips, a sole trader trading as PitchTrack. Jake Phillips is the controller for account administration, billing, support and service-security information. Customers are responsible for the contact lists, lawful outreach and recipient permissions they instruct PitchTrack to process.

This notice covers the PitchTrack dashboard, Gmail extension, sending features, reports and support. Questions or requests can be sent to pitchtrack@proton.me.

Information used by the service

PitchTrack stores account details, contacts you add, groups, saved templates, signatures, broadcast content and sending records. Connected-account details are used to sign in and send messages.

Tracking records can include recipient addresses, destinations, times, request information such as browser details and network addresses, and whether activity appears automated. Support requests include the details you submit and request information used to investigate problems and prevent abuse.

When you choose the extension's page email finder, it inspects text on the active page for email addresses and shows candidates for you to select and save as contacts. This is a user-initiated tool, not a collection of your general browsing history. Optional assisted outreach on SoundCloud and Instagram requires permission for the selected site and uses the selected contact, profile address, message and outreach status to support the task you start.

Chrome desktop notifications can display recipient or message details for recorded activity while Chrome is running. Your operating system controls whether those details appear on screen or on the lock screen; disable notifications if you do not want them displayed there.

Why information is used

Information is used to run the features you choose, send messages, show reports, manage subscriptions, respect unsubscribe choices and answer support requests. Connected Google data is used for these user-facing features, not sold.

Connecting Google and using Gmail

Google sign-in uses openid, userinfo.email and userinfo.profile to identify your account and obtain your email address and available profile details, such as your name and profile image. PitchTrack requests gmail.send to send messages through your connected Gmail account after you choose to send an email or start a reviewed broadcast. It does not request Gmail API permission to read, search, modify or delete your inbox. PitchTrack does not ask for your Google password.

Google access tokens and, when provided, refresh tokens are stored to maintain the authorised sending connection. Refresh tokens allow the service to obtain a new access token so a broadcast you started can continue without requiring you to sign in for every message. Tokens are credentials, not your Google password; do not share them with support.

The extension separately accesses the Gmail page you are using, including draft and displayed message information needed for its features. Broadcast content and sending details may be saved for review, sending, retries and reports.

PitchTrack's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

PitchTrack's use of information collected through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use restrictions. Extension data is used for the outreach and tracking features described here, not for unrelated advertising, sale to data brokers, or creditworthiness decisions.

Google user data is used only to provide or improve the user-facing features you choose. It is not sold, used for advertising or retargeting, supplied to data brokers, used for credit decisions, or used to train general-purpose AI models. Human access to Google user data is limited to your explicit agreement to inspect specific data, necessary security or legal purposes, or aggregated and anonymised internal operations permitted by Google's policy.

Disconnecting Google

Open your Google Account's third-party connections page, choose PitchTrack and remove its access. Revoking access prevents further authorised Gmail API access; it does not recall messages already sent. Signing out of PitchTrack or uninstalling the extension is not the same as revoking Google's authorisation.

Revoking access does not erase contacts, saved messages, tracking reports or billing records already held by PitchTrack. Use Settings to request account deletion, or contact pitchtrack@proton.me to request removal of stored Google credentials or other records. Reconnecting Google requires a new authorisation.

Legal bases and responsibilities

Account administration and delivering the service you request rely on performance of our contract with you. Billing and records required by law rely on legal obligations. Necessary fraud prevention, security, troubleshooting and support rely on legitimate interests in protecting and operating PitchTrack, balanced against the rights of affected people.

Where processing requires consent, including tracking that requires recipient consent under applicable law, consent must be obtained before processing and can be withdrawn. Google authorisation and a sender's tracking toggle are not recipient consent. Customers must establish the appropriate legal basis for their contact lists and messages and comply with electronic-marketing rules.

Account identification is needed for signed-in features, and sending authorisation is needed for Gmail API sending. Without it, those features cannot operate. PitchTrack does not use these records to make solely automated decisions with legal or similarly significant effects on people.

Tracking and recipient choices

Open tracking uses a small image; link tracking records a request before forwarding to the destination. Privacy features and automated checks can create or hide activity. A recorded event is not proof a person read or clicked.

For broadcasts, unknown open or click permission leaves that type of tracking off. In normal individual Gmail messages, tracking can be on by default where no saved choice exists. A saved refusal or unsubscribe takes precedence. Senders must decide whether outreach and tracking are permitted; a switch is not evidence of permission.

Unsubscribe links are added manually by the sender. Unsubscribe records are stored separately so deleting and importing a contact again does not remove their choice.

Sharing and service providers

Google handles account authorisation and Gmail delivery. Supabase provides authentication, application databases and signature-asset storage. Vercel hosts the dashboard and server endpoints. Stripe handles payments and subscriptions. Resend delivers service and support messages, and Proton Mail handles correspondence sent to pitchtrack@proton.me. Providers receive information needed for their role, not permission to use Google data for unrelated advertising.

When you send a message, its content and recipient address are passed to Google for delivery, and the recipient and their email provider receive the message. Trackable links contain destination information; recipients and destination services receive the requests needed to open them. Avoid unnecessary sensitive information in URLs.

Information may be disclosed where necessary to investigate abuse, protect security or comply with law. Transfers of Google user data are restricted to Google's Limited Use exceptions, including user-consented provision of the visible features, security, legal requirements, or a business transfer with explicit prior consent.

The Supabase database region is EU Central (eu-central-1). Other providers and services may process information outside that region or outside the UK. Processing locations and required international-transfer safeguards depend on the provider service and configuration; this is not a promise that all information stays in one country. Contact pitchtrack@proton.me for arrangements relevant to your data.

Cookies, local storage and security

The dashboard uses authentication cookies, and the extension stores session and feature settings locally in your browser. A signed sender-identification cookie helps exclude your own email opens when it is available. Tracking images and links separately record recipient activity as described above.

Access controls and authenticated server endpoints restrict account operations and access to stored credentials. These controls do not make any system risk-free. Do not send passwords, tokens or unnecessary sensitive recipient information in a support request.

How we protect Google user data and sensitive information

PitchTrack uses encrypted HTTPS connections to protect Google user data and other sensitive information in transit between your browser, PitchTrack's production service and the Google APIs. This includes account details, message content and OAuth credentials transmitted for the features you authorise.

Google OAuth credentials retained for server-side Gmail sending are held in a restricted database store separate from browser-readable profile records. Database permissions and row-level security prevent ordinary signed-in users and anonymous visitors from directly reading or changing that credential store. The server accesses it using a server-only service credential, which is not included in the dashboard or extension client code.

Authenticated server endpoints check the signed-in account and restrict account operations to the authorised user. Account ownership checks and database access policies protect stored application records. Google sending permissions are limited to gmail.send; PitchTrack does not request Gmail API permission to read, search, modify or delete mailbox messages. Human access to Google user data is limited as described in the Google connection section above.

You can revoke PitchTrack's Google access through your Google Account connections and request removal of stored credentials or account records by contacting pitchtrack@proton.me. If you suspect unauthorised access or a data exposure, revoke the connection and report the concern to that address so it can be investigated. No storage or transmission system can guarantee absolute security; these safeguards are not a claim of an independent security certification.

Keeping and deleting information

Account, contact, template, signature, campaign and delivery records are kept while needed to provide your account and its history, or resolve an outstanding request or dispute. Tracking history is reviewed against the need for reports and troubleshooting; inactive contacts against the customer's continuing outreach purpose. These reviews do not promise automatic deletion after a fixed interval.

Retention is assessed by data category, considering its purpose, account status, latest relevant activity, unresolved support or security issues, and tax, accounting or other legal obligations. Support correspondence is retained while needed to resolve the issue and related disputes. Minimal suppression records may remain to prevent renewed unwanted contact. Backup copies follow the relevant provider's lifecycle and may remain after removal from active storage; restoration must respect completed deletion and suppression requests.

Requesting deletion starts a review; it does not immediately remove all records or backups. Necessary retained records, including unsubscribe choices, and copies held by other providers need separate consideration. Disconnecting Google stops that connection but does not delete PitchTrack records.

Your choices, rights and complaints

Settings lets you download selected application records and request account deletion. That download is not a complete export of every file, provider record or backup. Removing a contact does not necessarily erase campaign or tracking snapshots relating to them.

Depending on the circumstances, your rights include access, correction, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent without affecting processing that was lawful before withdrawal. You may object to direct marketing at any time. Some rights have legal exceptions, including necessary retained records.

Contact Jake Phillips at pitchtrack@proton.me to exercise your rights or complain. We may need proportionate information to verify ownership and locate records. Requests are handled within applicable legal time limits, with an explanation if an extension or exception applies. If a customer supplied your information, they may also need to respond about their use of it.

You can also complain to the UK Information Commissioner's Office (ICO), or the appropriate supervisory authority where you live. You do not have to give up that right by contacting us first.