Privacy Policy
Effective Date: January 15, 2025
Last Updated: January 15, 2025
Privacy at a Glance
- •We collect data you provide and data from connected services (email, calendar) to power our AI assistant
- •Our AI processes your data to take actions on your behalf, draft communications, and provide insights
- •We do not sell your data or use it for advertising
- •You control your data and can export or delete it at any time
- •We use third-party AI providers who process data under strict contractual protections
1Introduction
US Software Company ("Waves," "we," "our," or "us") operates an agentic customer relationship management (CRM) platform that uses artificial intelligence to help you manage business relationships, communicate with contacts, and automate workflows (the "Service").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including when you connect third-party services such as Google Workspace (Gmail, Google Calendar) or Microsoft 365 (Outlook, Microsoft Calendar).
By using our Service, you consent to the data practices described in this Privacy Policy. If you do not agree with our practices, please do not use the Service. We encourage you to read this policy carefully and contact us with any questions.
2Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, password, company name, job title, phone number, and profile information when you register.
- CRM Data: Contact records, organization details, notes, tags, deal information, communication history, and any other data you input about your business relationships.
- User Content: Email drafts, templates, workflow configurations, custom prompts, AI instructions, and preferences you create within the Service.
- Communications: Information you provide when contacting our support team, responding to surveys, or participating in promotions.
- Payment Information: Billing details, payment card information (processed by our payment processor—we do not store complete card numbers), and transaction history.
2.2 Information from Connected Services
When you connect third-party accounts, we access and store data from those services to provide our AI-powered features. This includes:
- Email Data (Gmail, Outlook): Email messages, threads, subject lines, sender and recipient information, timestamps, attachments metadata, labels/folders, and read status. We sync emails to enable our AI to understand your communication history, draft contextual responses, and take actions on your behalf.
- Calendar Data: Events, attendees, meeting details, scheduling information, and availability. Used to help our AI schedule meetings and understand your availability.
- Contact Data: Contact information from your connected address books to enrich CRM records and identify relationships.
- Authentication Tokens: OAuth tokens to maintain secure access to your connected services.
2.3 Information Collected Automatically
- Usage Data: Features used, actions taken, pages visited, search queries, AI interactions, workflow executions, and how you interact with the Service.
- Device Information: Browser type and version, operating system, device type, screen resolution, and unique device identifiers.
- Log Data: IP addresses, access times, referring URLs, and error logs.
- Cookies and Similar Technologies: We use cookies, local storage, and similar technologies to maintain sessions, remember preferences, and improve user experience. See our Cookie Policy for details.
2.4 Information Derived Through AI Processing
Our AI systems analyze the information described above to generate derived data that helps you manage relationships more effectively:
- Relationship Insights: AI-generated summaries of your relationship history, communication patterns, sentiment analysis, and engagement levels with contacts.
- Behavioral Patterns: Understanding of your communication style, preferences, typical responses, and working patterns to personalize AI assistance.
- Suggested Actions: Recommended follow-ups, draft responses, optimal send times, and workflow suggestions based on your data.
- Embeddings and Vectors: Mathematical representations of your content used for semantic search and similarity matching.
3How We Use Your Information
We use the information we collect for the following purposes:
3.1 Core Service Delivery
- Provide, operate, and maintain the CRM platform and all its features
- Sync and display your emails, calendar events, and contacts within the Service
- Enable our AI assistant to understand your relationships and communication history
- Process transactions and manage your subscription
- Authenticate your identity and maintain account security
3.2 AI-Powered Features
- Draft and send communications: Generate email drafts, replies, and follow-ups based on your communication history and style
- Take actions on your behalf: Execute approved workflows, schedule meetings, send emails, and perform other automated actions you configure
- Learn your preferences: Analyze your past actions, communication patterns, and feedback to improve AI suggestions and personalization
- Generate insights: Create relationship summaries, identify opportunities, and surface relevant information from your data
- Semantic search: Enable intelligent search across your emails and CRM data using AI-powered understanding of meaning and context
- Data extraction: Automatically extract contact information, company details, and other structured data from emails and documents
3.3 Service Improvement
- Analyze usage patterns to improve features and user experience
- Develop new features and functionality based on user needs
- Train and improve our AI models to provide better assistance (see Section 4 for details)
- Conduct research and analytics to understand how the Service is used
- Test new features and optimizations
3.4 Communications and Support
- Send transactional communications (receipts, confirmations, security alerts)
- Provide customer support and respond to inquiries
- Send product updates, feature announcements, and educational content (with opt-out)
- Notify you of changes to our policies or Service
3.5 Security and Compliance
- Detect, prevent, and address fraud, abuse, and security threats
- Monitor for violations of our Terms of Service
- Comply with legal obligations and respond to lawful requests
- Enforce our agreements and protect our rights
4AI and Automated Processing
Our Service is built around AI that acts as your intelligent assistant. This section explains how AI processes your data to provide value while respecting your privacy.
4.1 How Our AI Works
Our AI assistant processes your data to understand your business relationships, communication patterns, and preferences. This enables the AI to:
- Understand context from your email history to draft relevant responses
- Learn your communication style and tone to match it in suggestions
- Identify patterns in your successful interactions to recommend best practices
- Recognize relationships between contacts, companies, and deals
- Anticipate your needs based on your past behavior and current context
- Execute workflows and automated actions you configure
4.2 Third-Party AI Providers
To deliver AI capabilities, we use third-party AI service providers including:
- OpenAI — For language understanding, generation, and embeddings
- Anthropic — For advanced reasoning and analysis
- Google AI — For language models and processing
When your data is processed by these providers:
- Data is transmitted securely using encryption in transit
- Providers process data solely to return results to us for your benefit
- We have contractual agreements (Data Processing Agreements) with each provider that prohibit them from using your data to train their general models or for any purpose other than providing the service to us
- Providers are required to delete your data after processing (typically within 30 days, per their retention policies)
4.3 AI Learning and Personalization
To provide personalized assistance, our AI learns from your data:
- Per-User Learning: The AI builds an understanding of your specific communication patterns, preferences, and relationships. This learning is specific to your account and used solely to improve your experience.
- Embeddings and Vectors: We create mathematical representations of your content to enable semantic search and similarity matching within your own data.
- Aggregate Insights: We may analyze anonymized, aggregated usage patterns across users to improve our AI models and Service features. Individual user data is never used to train models that would be applied to other users without anonymization.
4.4 Human Review
We limit human access to your data. Our employees or contractors will only access your data:
- When you provide explicit consent (e.g., when requesting support assistance)
- To investigate security incidents, abuse, or violations of our terms
- When required to comply with legal obligations
- To review aggregated or anonymized data for service improvement
We do not allow employees to read your emails or personal content for general product development or quality assurance without your specific consent.
4.5 Automated Actions and Human-in-the-Loop
Our AI can take actions on your behalf. We provide controls to ensure you remain in control:
- Approval Workflows: You can configure which actions require your approval before execution
- Action Queue: Review and approve/reject AI-proposed actions before they are executed
- Scheduling: Set rules for when automated actions can be executed
- Audit Trail: View a complete history of all actions taken on your behalf
5Google API Services Disclosure
Important: This section describes how we handle data obtained from Google APIs, including Gmail and Google Calendar, in compliance with Google's API Services User Data Policy.
5.1 Google User Data We Access
When you connect your Google account, we request access to:
- Gmail API: Read, compose, send, and manage email messages and drafts
- Google Calendar API: Read and manage calendar events
- Google People API: Read contact information
- Basic Profile: Your name, email address, and profile picture
5.2 How We Use Google User Data
Google user data is used exclusively to provide and improve user-facing features within our Service:
- Display your emails within the Waves interface for CRM context
- Enable our AI to draft email responses based on conversation history
- Send emails on your behalf through the Gmail API when you approve them
- Sync calendar events to help schedule meetings and understand availability
- Import contacts to enrich your CRM records
- Generate relationship insights based on your communication history
5.3 Google API Services Limited Use Disclosure
Waves's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we commit to the following:
- Limited Use: We only use Google user data to provide or improve user-facing features that are prominent in the Waves application. We do not use this data for any other purpose.
- No Advertising: We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
- No Data Sales: We do not sell Google user data to third parties.
- No Data Brokering: We do not transfer Google user data to data brokers or information resellers.
- Limited Human Access: We do not allow humans to read Google user data except: (a) with your explicit consent for specific content; (b) as necessary for security purposes or to investigate abuse; (c) to comply with applicable law; or (d) when data has been aggregated and anonymized for internal operations.
- Limited Transfers: We only transfer Google user data to third parties when: (a) necessary to provide or improve user-facing features with your consent; (b) necessary for security purposes; (c) required by law; or (d) as part of a merger, acquisition, or asset sale with your prior consent.
5.4 Google Data Storage and Security
- Google user data is stored in encrypted databases using AES-256 encryption at rest
- All data transmission uses TLS 1.2 or higher encryption
- Access to Google user data is restricted to authorized personnel and systems
- We maintain audit logs of access to Google user data
- OAuth tokens are stored securely and refreshed as needed; you can revoke access at any time
5.5 Revoking Google Access
You can disconnect your Google account from Waves at any time through your account settings. You can also revoke our access directly from your Google Account permissions page. Upon revocation, we will stop accessing new data and delete synced Google data within 30 days, unless retention is required by law.
6Microsoft Services Disclosure
6.1 Microsoft User Data We Access
When you connect your Microsoft 365 or Outlook account, we request access to:
- Microsoft Graph Mail API: Read, compose, send, and manage email messages
- Microsoft Graph Calendar API: Read and manage calendar events
- Microsoft Graph Contacts API: Read contact information
- User Profile: Your name, email address, and profile information
6.2 How We Use Microsoft User Data
Microsoft user data is used for the same purposes as Google user data, as described in Section 5.2. We apply the same restrictions and protections: no advertising, no data sales, limited human access, and secure storage. You can revoke access through your Microsoft account permissions at any time.
7Data Sharing and Disclosure
We do not sell your personal information. We do not share your data for advertising purposes.
We may share your information in the following limited circumstances:
7.1 Service Providers
We share data with vendors who help us operate the Service, including:
- Cloud infrastructure providers (hosting, storage, databases)
- AI service providers (as described in Section 4.2)
- Payment processors
- Analytics providers
- Customer support tools
- Email delivery services
All service providers are bound by contractual obligations to protect your data and use it only for the purposes we specify.
7.2 Within Your Workspace
If you use Waves as part of a team or organization, other authorized members of your workspace may have access to shared CRM data, workflows, and communications based on the permissions configured by your workspace administrator.
7.3 Legal Requirements
We may disclose your information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to: (a) comply with the law; (b) protect our rights, property, or safety; (c) protect the rights, property, or safety of others; or (d) detect, prevent, or address fraud, security, or technical issues.
7.4 Business Transfers
If Waves is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
7.5 With Your Consent
We may share your information with third parties when you have given us explicit consent to do so.
8Data Security
We implement comprehensive security measures to protect your information:
- Encryption: All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption
- Infrastructure Security: We use enterprise-grade cloud infrastructure with SOC 2 Type II certified providers
- Access Controls: Role-based access controls, multi-factor authentication, and principle of least privilege for all systems
- Monitoring: Continuous security monitoring, intrusion detection, and logging of access to sensitive data
- Secure Development: Regular security testing, code reviews, and vulnerability assessments
- Incident Response: Documented procedures for detecting, responding to, and recovering from security incidents
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to promptly notifying you of any breach affecting your data as required by applicable law.
9Data Retention and Deletion
9.1 Retention Periods
- Account Data: Retained while your account is active and for up to 90 days after deletion to allow for account recovery
- CRM Data: Retained while your account is active; deleted upon account deletion
- Synced Email/Calendar Data: Retained while the integration is active; deleted within 30 days of disconnection or account deletion
- Usage Logs: Retained for up to 24 months for analytics and security purposes
- Backup Data: Retained in backups for up to 90 days after deletion from primary systems
9.2 Deletion Process
You can request deletion of your data at any time by:
- Using the account deletion feature in your settings
- Contacting us at team@ussoftwarecompany.com
Upon receiving a deletion request, we will delete or anonymize your data within 30 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes (such as maintaining records of transactions or resolving disputes).
10Your Rights and Choices
Depending on your location and applicable law, you may have the following rights:
Access
Request a copy of the personal information we hold about you
Correction
Request correction of inaccurate or incomplete data
Deletion
Request deletion of your personal information
Portability
Request an export of your data in a portable format
Restriction
Request restriction of certain processing activities
Objection
Object to processing based on legitimate interests
Withdraw Consent
Withdraw consent where processing is based on consent
Complaint
Lodge a complaint with your local data protection authority
To exercise these rights, contact us at team@ussoftwarecompany.com. We will respond to your request within 30 days (or sooner if required by applicable law). We may need to verify your identity before processing your request.
Additional Choices
- Email Communications: Unsubscribe from marketing emails using the link in each email. Note that you cannot opt out of transactional communications.
- Connected Accounts: Disconnect Google, Microsoft, or other integrated accounts at any time through your settings.
- AI Features: Configure AI automation settings and approval requirements in your workspace settings.
- Cookies: Manage cookie preferences through your browser settings or our cookie consent tool.
11International Data Transfers
Waves is based in the United States, and your information may be processed in the U.S. and other countries where our service providers operate. These countries may have different data protection laws than your country of residence.
When we transfer personal data internationally, we implement appropriate safeguards as required by applicable law, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all service providers
- Technical and organizational measures to protect data during transfer
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on SCCs and other lawful transfer mechanisms to transfer data to the United States.
12Children's Privacy
Our Service is designed for business users and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at team@ussoftwarecompany.com, and we will take steps to delete such information.
13Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
- We will update the "Last Updated" date at the top of this policy
- We will notify you via email or prominent notice within the Service
- For significant changes, we may request your renewed consent
We encourage you to review this policy periodically. Your continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
14Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
US Software Company
- Privacy Inquiries: team@ussoftwarecompany.com
- Data Protection Officer: team@ussoftwarecompany.com
- General Support: team@ussoftwarecompany.com
- Website: crmwaves.com
For users in the European Union, you have the right to lodge a complaint with your local supervisory authority if you believe we have violated applicable data protection laws.