Skip to content
RelayPDM

Legal

Privacy Policy

Effective date: [EFFECTIVE DATE]

RelayPDM is a workspace for partner teams. It is operated by [LEGAL ENTITY NAME] (“RelayPDM”, “we”, “us”). This policy explains what information we collect when you use this website (relaypdm.com) and the RelayPDM application (app.relaypdm.com), what we do with it, and the choices you have.

The short version: we collect what we need to give you an account and run the service, we do not sell personal data, and we do not use it for advertising.

What we collect

Account information. Your email address and your name. If you are invited to an organization in RelayPDM, we also keep which organization you belong to and your role in it.

Information from Google, if you choose “Continue with Google”. We ask Google only for your basic profile (the openid, email and profile scopes) and receive your email address, your name and your profile picture. We do not ask for access to your Gmail, Calendar, Drive, contacts or any other Google data.

Data you and your team enter into RelayPDM. The records you create in the product, such as partners and their contacts, meetings, referrals, events and campaigns, and the notes and files attached to them. This can include personal information about other people, for example a partner contact’s name and work email.

Referral form submissions. A RelayPDM customer can share a referral link. If you fill in that form, the details you submit go to that customer’s organization in RelayPDM. You do not need an account to do this.

Messages you send us. If you email us, we keep the message and your address so we can reply.

Technical information. Our hosting providers record standard request logs, such as IP address, browser type and the time of each request. We use these to keep the service running and secure.

How we use it

We use the information above only to:

  • create your account and keep it secure;
  • sign you in;
  • provide the service, which includes showing your team the data it has entered and sending the emails the service depends on, such as sign-in codes and invitations;
  • answer you when you contact us; and
  • meet our legal obligations.

We do not sell personal data. We do not use personal data, including Google user data, for advertising, and we do not share it with advertisers or data brokers.

Google user data

If you sign in with Google, RelayPDM receives your email address, name and profile picture from Google. We use this information only to authenticate you: to create your account, sign you in, and identify you inside the product, for example by showing your name to your teammates.

RelayPDM’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • we use Google user data only to provide the sign-in feature described above;
  • we do not transfer it to anyone except the service providers listed below, who need it to run that feature, or where the law requires it;
  • we do not use it for advertising, and we do not sell it;
  • we do not use it to develop, improve or train generalized artificial intelligence or machine learning models; and
  • nobody at RelayPDM reads it, except where you have asked us to (for example, for support), where it is needed for security, or where the law requires it.

You can remove RelayPDM’s access at any time from your Google account at myaccount.google.com/permissions. To have the information we already hold deleted, see “Your choices” below.

Service providers

We use a small number of companies to run RelayPDM. They process data on our behalf, only to provide their service to us:

  • Supabase: the database and authentication. Your account and the data you enter are stored here.
  • Vercel: hosting for this website and the application.
  • Resend: transactional email, such as sign-in codes and invitations.

If you sign in with Google, Google also processes your sign-in under its own privacy policy. We may disclose information if the law requires it, or as part of a merger or sale of the business, in which case this policy continues to apply to it. These providers may process data in countries other than your own, including the United States.

Cookies and local storage

The application keeps you signed in by storing your sign-in session in your browser (local storage, session storage and cookies). It also remembers a few preferences there, such as the light or dark theme and the organization you last used. These are needed for the product to work.

We do not use advertising cookies, and we do not currently use third-party analytics on this website or in the application. If that changes, we will update this policy first.

Data our customers enter

When an organization uses RelayPDM, the records it enters belong to that organization. We process them on its behalf and under its instructions. If your information is in a RelayPDM customer’s records, for example because you are one of its partner contacts, please contact that organization first; we will help it respond to your request.

How long we keep it

We keep account information and the data you enter for as long as the account is open. When you ask us to delete your account or your organization’s data, we delete it from the live service within [DELETION PERIOD]. Copies in backups are overwritten within [BACKUP RETENTION PERIOD]. We may keep limited records longer where the law requires it.

Your choices: access and deletion

You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Email hello@relaypdm.com from the address on your account. We will confirm it is you before we act, and we will answer within the time the law that applies to you requires.

Organization admins can also export their partners, referrals and audit log from inside the product at any time.

Security

No system is perfectly secure, but these are the measures in place today:

  • connections to RelayPDM are encrypted in transit with HTTPS;
  • data is encrypted at rest by our database provider, Supabase;
  • each organization’s data is separated by rules in the database itself, and that separation is tested automatically on every change we ship;
  • access inside an organization is limited by role (viewer, member, admin, owner), and changes are recorded in an audit log;
  • RelayPDM stores no passwords: you sign in with a one-time code sent to your email, or with Google; and
  • we take backups and rehearse restoring from them.

There is more detail on the Security page. If we learn of a breach that affects your personal data, we will tell you as the law requires.

Children

RelayPDM is a business tool. It is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, email us and we will delete it.

Changes to this policy

If we change this policy, we will post the new version here and update the effective date at the top. If the change is significant, we will also tell account holders by email before it takes effect.

Contact

Questions about this policy or your data: hello@relaypdm.com.

[LEGAL ENTITY NAME]
[MAILING ADDRESS]