Privacy policy
Effective October 6, 2026.
This policy describes data handled by Attrival, including agency workspaces, customer lead reporting and direct library connections. Contact: faheemshah693@gmail.com.
Information we handle
- Account identifiers, email addresses, profile information supplied during sign-in, and agency or customer workspace memberships.
- Agency and customer records, including contact information, territories, lead attribution, pipeline outcomes, job values, notes and follow-ups submitted by authorized users or integrations.
- Provider authorization credentials, selected file identifiers, imported document text, spreadsheet content and their source labels or coordinates. The direct Figma connector stores only a selected file’s name, identifier, version and modification date to display a file link. It does not copy Figma file content or images. Public Figma connections remain pending provider review.
- Operational records needed to secure and operate connections, including authorization and configuration events, import timestamps, delivery identifiers and error information.
Google Docs and Sheets
The direct Google library connector requests documents.readonly and spreadsheets.readonly. Google grants readable account access for those file types; the portal imports only the file URLs an agency administrator selects. It reads document text and spreadsheet cells to display them in that agency’s copy library. It does not edit Google files, crawl folders or enumerate an account’s files. Imports are on demand.
Google data is used to provide the features you authorize, under the Google API Services User Data Policy and its Limited Use requirements. We do not sell Google user data, use it for advertising targeting, or use these direct library imports to train AI models. The direct import flow does not send imported Google content through AI processing.
Storage, service providers and access
Vercel hosts the portal frontend. Supabase provides authentication, database storage, backend functions and private file storage. Connected-account APIs receive the requests needed to authorize and perform the requested integration.
Direct library authorization tokens are encrypted on the backend. They are not returned to the browser. Membership checks and database access rules restrict agency and customer records to authorized workspaces. Agency administrators control their team’s access; customer workspace permissions determine who can view or edit customer leads. Other agencies cannot access your agency’s imported library records through the portal.
Authorized service operators may access data when necessary to maintain the system, investigate a support issue, protect security or handle an authorized data request. Data is not shared with unrelated agencies. Providers process service data under their own applicable terms and privacy policies.
Retention, disconnection and removal
Connection credentials remain stored while a connection is active. Disconnecting a direct library connection removes its stored tokens and cancels active imports. Imported references remain available to your agency after disconnection. You can also revoke the app’s authorization in the provider’s account settings.
Imported content, workspace records and necessary operational records remain stored until removed through an authorized administrative process. To request removal of stored provider content or other account data, contact faheemshah693@gmail.com. We verify the requester’s agency or workspace authority before acting. Removal from active storage does not imply immediate erasure from any infrastructure backups; backup retention depends on the configured service.
Your choices
You choose which source accounts to authorize and which files to import. You may stop future direct imports by disconnecting or revoking authorization. Agency and customer administrators can change membership access. For questions about data or correction/removal requests, use the contact above.
Changes to this policy
We will update this page when the described practices change and identify its current publication or revision date.