This privacy policy explains how CB Platforms LLC ("CB Platforms", "we", "us") collects, uses, shares and protects personal data when you visit our website, use Verbial (the "service"), or interact with an agency that uses the service. It also explains the choices and rights you have. Terms not defined here have the meaning given in our terms of service at /legal/terms.
1. Scope and our role
This policy covers three groups of people, and our role is different for each.
Website visitors. People who visit our marketing site, read our guides, or contact us. We are the controller of the data we collect from visitors.
Customer users. Employees, contractors and agents of an agency ("Customer") that has an account, who sign in to the service. We are the controller of the account, billing, support and usage data we collect about customer users. We are the processor of the data customer users enter into their workspace.
Clients of customers. Contacts, leads, client staff and other individuals whose information a Customer stores in its workspace, sends messages to, or invites to a client portal, shared link, proposal, invoice or e-signature request. For this data, the Customer is the controller (or "business" under US state law) and we are the processor (or "service provider"). We process it only on the Customer's instructions under our terms of service and data processing addendum at /legal/dpa.
If you are a client of an agency and have a question about how that agency handles your data, or want to exercise a right over data the agency holds about you, contact the agency directly. We will forward any request we receive to the relevant Customer where we can identify it, but we cannot act on it without the Customer's instruction.
2. Data we collect
2.1 Account data
When a Customer creates a workspace, we collect the name, email address and profile image from the Google account used to sign in, the agency name, and the workspace settings the Customer chooses. We use Google sign-in only and do not store passwords.
2.2 Billing data
When a Customer subscribes, Stripe, Inc. collects the payment method, billing name, billing address and tax identifiers. We receive from Stripe a token for the payment method, the card brand and last four digits, the billing address, invoices, and payment status. We do not receive or store full card numbers or bank account credentials.
2.3 Workspace data (Customer data)
Customers and their users enter data into the service in the course of running their agency: contacts, companies, deals, notes, email content and sequences, time entries, project and retainer records, proposals and signed agreements, invoices, payment records including bank transfer references and wallet addresses, reports, cost and salary figures used for profitability, and files. Customers may also import contacts from other systems using the migration hub. All of this is Customer data. We process it as a processor and do not use it for our own purposes except as described in section 3.
2.4 Integration data
When a customer user connects a third-party service, we collect the data needed for that integration and only with the user's consent through the third party's authorization flow. Depending on the integration this may include:
- Google Workspace: email messages and metadata for connected mailboxes (to log correspondence against CRM records and send sequences), calendar events (to log meetings and schedule follow-ups), and files in Drive that the user selects.
- Harvest, Toggl Track, Clockify, Everhour, Productive.io: time entries, projects and users, for migration.
- HubSpot, Pipedrive, Salesforce, Close, Zoho: contacts, companies, deals and activity, for migration or sync.
- QuickBooks via Airtable: invoice and payment records for accounting sync.
- Gusto: payroll and compensation data, used only for cost and margin calculations visible to admin roles.
- Slack: channel and user identifiers, to post notifications.
- Stripe: connected account identifiers, payments, payouts and disputes for the Customer's own Stripe account.
- Ahrefs and YouTube: performance metrics for domains and channels the Customer specifies, for client reporting.
- Anthropic: prompts and workspace context sent to Claude when a user invokes AI features or connects an MCP client.
Integration data becomes part of Customer data once stored in the workspace.
2.5 Client user data
When a Customer invites a client to a portal, or sends a shared link, proposal, invoice or e-signature request, we collect the client user's email address, name if provided, the actions taken (views, comments, approvals, signatures), and for e-signature the signer's name, email, IP address, timestamp and the signed document. This data is Customer data and we process it for the Customer.
2.6 Usage data and logs
We automatically collect information about how the service and website are used: IP address, browser type and version, operating system, device type, referring URL, pages viewed, features used, actions taken, timestamps, error reports, API calls and performance metrics. Application and infrastructure logs may contain identifiers such as user IDs and workspace IDs.
2.7 Cookies and analytics
Our website uses Vercel Analytics, which collects page views and referrers using a privacy-preserving approach that does not set persistent cross-site tracking cookies. The service uses strictly necessary cookies for sign-in sessions and security. See section 13 for details.
2.8 Communications
When you contact us by email, through a form, or through support channels, we collect your name, email address and the content of your message, along with any attachments.
2.9 Data we do not collect
We do not intentionally collect government identification numbers, health information, biometric data or precise geolocation. Customers are prohibited from storing these categories in the service without our written agreement.
3. How we use data
We use personal data for the following purposes.
- To provide the service: create and administer workspaces, authenticate users, run integrations, deliver email and notifications, host and back up Customer data, and process Customer data on the Customer's instructions.
- To bill and collect: manage subscriptions, seats and add-ons, process payments through Stripe, send invoices and receipts, and handle billing questions.
- To support customers: respond to requests, troubleshoot problems, and, with permission, access a workspace to diagnose an issue.
- To secure the service: detect and prevent fraud, abuse, spam, unauthorized access and security incidents, enforce our terms and acceptable use policy, and protect our sending reputation.
- To improve the service: analyze usage data to understand how features are used, fix bugs, plan improvements, and measure performance. We use aggregated or de-identified data for this where practical.
- To communicate: send service announcements, security notices, changes to terms or pricing, onboarding and product education, and, where permitted, marketing about the service. You can opt out of marketing email at any time using the unsubscribe link or by contacting us.
- To comply with law: meet legal, tax, accounting and regulatory obligations, respond to lawful requests, and establish, exercise or defend legal claims.
We do not use Customer data to train machine learning models. When a user invokes AI features, the relevant Customer data is sent to Anthropic to generate a response and is not used by Anthropic to train its models under our commercial agreement.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.
4. Legal bases for processing (EEA, UK and Switzerland)
Where the GDPR, UK GDPR or Swiss FADP applies to our processing as a controller, we rely on the following legal bases.
| Purpose | Legal basis |
|---|---|
| Providing the service and website to a Customer or visitor | Performance of a contract, or steps at your request before entering one |
| Billing, invoicing, tax records | Performance of a contract; legal obligation |
| Security, fraud and abuse prevention | Legitimate interests in protecting the service, our customers and ourselves |
| Service improvement and analytics | Legitimate interests in understanding and improving the service, using aggregated data where practical |
| Service communications | Performance of a contract; legitimate interests |
| Marketing communications | Consent where required; otherwise legitimate interests in promoting the service to business contacts, with an opt-out |
| Integrations that access third-party accounts | Consent, given through the third party's authorization flow, which you may withdraw |
| Responding to legal requests and claims | Legal obligation; legitimate interests in defending our rights |
Where we process Customer data as a processor, the Customer is responsible for establishing the legal basis.
5. How we share data
We share personal data only as described below. We do not sell it.
5.1 Sub-processors and service providers
We use third-party providers to run the service. They process data only for the purposes we specify and under contracts that require appropriate protection. Our current sub-processors are:
| Provider | Purpose | Location |
|---|---|---|
| Vercel, Inc. | Application hosting, edge network, website analytics | United States |
| Neon, Inc. | Postgres database hosting for each workspace, snapshots and backups | United States |
| Stripe, Inc. | Subscription billing for our customers; card payment processing for customers' invoices | United States |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery and CRM email sending | United States |
| Google LLC | Sign-in, Gmail, Calendar and Drive integrations, YouTube Data API | United States |
| Anthropic, PBC | AI features (Claude) and MCP integration | United States |
| Slack Technologies, LLC | Notification integration | United States |
| Airtable, Inc. | Intermediary for QuickBooks accounting sync | United States |
| Intuit Inc. (QuickBooks) | Accounting sync, via Airtable | United States |
| Gusto, Inc. | Payroll and compensation data for cost calculations | United States |
| Ahrefs Pte. Ltd. | SEO metrics for client reporting | Singapore |
Integrations with Google, Slack, Airtable, QuickBooks, Gusto, Ahrefs, YouTube, Stripe (connected accounts) and Anthropic (MCP) only receive data when a Customer enables them. We will update this list at /legal/dpa and give Customers notice of new sub-processors as described in the data processing addendum.
5.2 At the Customer's direction
When a Customer sends an email, invoice, proposal or report, or shares a portal link, the recipient receives the content the Customer chose to send. When a Customer connects an integration, data flows to and from that third party under the Customer's instruction and the third party's own terms.
5.3 Payment rails the Customer chooses
When a Customer collects payment from a client, the payment is processed by Stripe under the Customer's own Stripe account, by the parties' banks, or on a public blockchain network. We are not a party to those transactions. Blockchain transactions are public and permanent by design.
5.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of some or all of our assets, personal data may be transferred as part of that transaction. We will notify affected Customers by email or notice in the service before their data becomes subject to a different privacy policy.
5.5 Legal requests and protection
We may disclose personal data if we believe in good faith that it is necessary to comply with a law, regulation, subpoena, court order or other legal process; to enforce our terms; to protect the rights, property or safety of CB Platforms, our customers or the public; or to detect and prevent fraud or security issues. Where a request concerns Customer data and the law allows, we will notify the Customer and give it the opportunity to respond before we disclose.
5.6 With your consent
We may share personal data for other purposes with your consent.
6. Google API Services User Data Policy
The service's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When a customer user connects Gmail, Google Calendar or Google Drive, we request only the scopes needed for the features they enable. We use Google user data only to provide user-facing features in the service: logging email correspondence against CRM records, sending and tracking sequences and one-off messages from the user's mailbox, logging meetings and scheduling follow-ups, and attaching selected Drive files to records.
We do not use Google user data to serve advertisements. We do not sell Google user data. We do not transfer Google user data to third parties except as needed to provide or improve these user-facing features, to comply with law, or as part of a merger or acquisition with prior notice. Humans at CB Platforms do not read Google user data unless the user has given explicit permission for a specific support case, it is necessary for security purposes such as investigating abuse, it is required by law, or the data has been aggregated and anonymized for internal operations. We do not use Google user data, including Gmail content, to develop, improve or train generalized or non-personalized AI or machine learning models.
You can revoke our access at any time at https://myaccount.google.com/permissions. When you do, the related features stop working and we delete data we obtained through the revoked scope within the retention windows in section 7, except for records the Customer has already stored in its workspace as Customer data.
7. Retention
We keep personal data for as long as needed for the purposes described in this policy, and then delete or de-identify it.
| Category | Retention |
|---|---|
| Customer data in a workspace | For the life of the account, then a 30-day grace period after expiration or termination during which the Customer may export, then deletion of the dedicated database |
| Database snapshots and backups | Roll off within 35 days after the underlying data is deleted |
| Account data for customer users | For the life of the account, then deleted with the workspace, except records we must keep for legal purposes |
| Billing records and invoices | 7 years after the transaction, for tax and accounting purposes |
| Usage data and logs | Up to 13 months, then deleted or aggregated |
| Support communications | 3 years after the ticket is closed |
| Marketing contact data | Until you unsubscribe or 2 years of inactivity |
| Website analytics | Aggregated; no individual-level retention beyond Vercel Analytics' processing window |
We may retain data longer where required by law, to resolve disputes, to enforce our agreements, or in aggregated form that does not identify anyone. Data in the possession of third-party services under their own terms is retained according to those terms.
8. Security
We use administrative, technical and physical safeguards designed to protect personal data, including:
- a dedicated Postgres database for each workspace, with no shared tables between customers;
- encryption in transit using TLS and encryption at rest for databases, backups and files;
- Google sign-in with no password storage, and role-based access control within workspaces;
- least-privilege access to production systems for our staff, with access logged;
- daily snapshots and logical backups, and tested restore procedures;
- monitoring, logging and alerting for security events;
- secure development practices, dependency updates and vulnerability management;
- contractual security commitments from sub-processors.
More detail is at /security. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for the security of the Google accounts their users sign in with, for the roles they assign, for the links they share, and for the security of any third-party service, wallet or bank account they connect. If we become aware of a breach of security affecting personal data, we will notify affected Customers as described in the data processing addendum and as required by law.
9. International transfers
We are located in the United States and host the service on infrastructure in the United States. If you access the service from outside the United States, your data will be transferred to, stored and processed in the United States and in the locations of our sub-processors listed in section 5.1.
For personal data subject to the GDPR, UK GDPR or Swiss FADP, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum and Swiss adjustments where applicable) as the transfer mechanism, together with supplementary measures where needed. Customers may obtain the Standard Contractual Clauses by executing our data processing addendum. Where a sub-processor is certified under the EU-US Data Privacy Framework, we may rely on that certification for transfers to that sub-processor.
10. Children
The service and website are intended for businesses and are not directed to children. We do not knowingly collect personal data from anyone under 16. Customers must not store data about children under 16 in the service. If you believe we have collected data from a child under 16, contact us at privacy@verbial.io and we will delete it.
11. Your rights
Depending on where you live, you may have rights over your personal data. To exercise any of these rights, email privacy@verbial.io. We will verify your identity, which may involve confirming you control the email address associated with the data, and respond within the time required by law. We will not discriminate against you for exercising your rights.
If your request concerns data that an agency holds about you in its workspace, we will refer it to that agency, because the agency is the controller and we act only on its instructions.
11.1 EEA, UK and Switzerland
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- erase your data in certain circumstances;
- restrict processing in certain circumstances;
- receive your data in a portable, machine-readable format;
- object to processing based on legitimate interests, and object at any time to direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal;
- lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office.
We have not appointed an EU or UK representative at this time. You can contact us directly at privacy@verbial.io.
11.2 California (CCPA and CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you rights over personal information we collect as a business. In the preceding 12 months we have collected the following categories of personal information, from the sources and for the purposes described in sections 2 and 3:
| Category | Examples | Disclosed to |
|---|---|---|
| Identifiers | Name, email address, IP address, account ID | Service providers listed in section 5.1 |
| Customer records | Billing name and address, last four card digits | Stripe |
| Commercial information | Subscription history, purchases | Stripe |
| Internet and network activity | Pages viewed, features used, logs | Vercel |
| Professional or employment information | Agency name, job title, role | Service providers as needed |
| Inferences | Product usage patterns | Not disclosed |
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA. We do not knowingly sell or share the personal information of consumers under 16.
You have the right to know what personal information we collect, use, disclose and sell; to delete your personal information; to correct inaccurate personal information; to opt out of sale or sharing (not applicable, as we do neither); to limit the use of sensitive personal information (not applicable); and to not be discriminated against for exercising these rights. You may designate an authorized agent to make a request on your behalf; we may require proof of the agent's authority and verify your identity directly.
Where we process personal information on behalf of a Customer, we act as a service provider and the Customer is the business. Direct requests about that data to the Customer.
11.3 Other US states
Residents of Colorado, Connecticut, Delaware, Iowa, Indiana, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, Virginia and other states with comprehensive privacy laws may have similar rights of access, correction, deletion, portability and opt-out of targeted advertising, sale or profiling. We do not sell personal data, engage in targeted advertising, or profile individuals in a way that produces legal or similarly significant effects. If we deny a request, you may appeal by replying to our decision, and we will respond to your appeal as required by your state's law.
11.4 Canada
If you are in Canada, PIPEDA and applicable provincial laws give you the right to access and correct your personal information and to withdraw consent, subject to legal and contractual restrictions. Your data may be stored and processed in the United States, where it is subject to US law. You may complain to the Office of the Privacy Commissioner of Canada.
11.5 Other regions
If you are in another region with data protection law, you may have similar rights. Contact us and we will respond in accordance with the law that applies to you.
12. Do not track
Some browsers send a "Do Not Track" signal. There is no common standard for how to respond, and our website and service do not respond to Do Not Track signals. Because we do not sell or share personal data for targeted advertising, we treat Global Privacy Control signals as consistent with our existing practice.
13. Cookies
We use a small number of cookies and similar technologies.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| Session cookie | Keeps you signed in to the service | Strictly necessary | Session, or up to 30 days if you stay signed in |
| CSRF token | Protects against cross-site request forgery | Strictly necessary | Session |
| Preferences | Remembers workspace, theme and view settings | Functional | Up to 1 year |
| Vercel Analytics | Counts page views and referrers on the website without cross-site tracking | Analytics | No persistent cookie; a hashed identifier that resets daily |
We do not use advertising cookies or third-party tracking pixels on our website. Custom domains and client portals operated by Customers use the same strictly necessary cookies. You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent you from signing in.
14. Changes to this policy
We may update this policy from time to time. When we do, we will post the updated version at /legal/privacy with a new updated date. For material changes, we will notify Customers by email to the account owner or by notice in the service at least 30 days before the change takes effect, unless the change is required by law sooner. Continued use of the service after the effective date means you accept the updated policy.
15. Contact
CB Platforms LLC is the entity responsible for this policy and for the service.
Email: privacy@verbial.io
Post: CB Platforms LLC, CB Platforms LLC, United States
If you are a client of an agency that uses Verbial and your question is about how that agency handles your data, contact the agency. If you are not satisfied with our response to a privacy request, you may contact the supervisory authority or regulator in your region.