Legal

Privacy Policy

Effective 10 September 2026

Gravun is software that businesses of any kind use to run their operations: customers, quotes, jobs, invoices, payments, scheduling and communications. Our customers range from sole traders to multi-branch companies, across trades, professional services, retail and more. Gravun is operated by Gravun Inc., a corporation in Ontario, Canada.

This policy explains what personal information Gravun handles, why, who else touches it, and what you can ask us to do about it. It covers the Gravun application at app.gravun.com and the website at gravun.com.

Two different roles, and why the distinction matters

Gravun handles personal information in two capacities, and your rights differ depending on which one applies to you.

  • As the business we serve. If you sign up for Gravun, we hold your account information and decide how it is used. Ask us directly about it.
  • As your customers' records. If a business uses Gravun and you are one of its customers, that business decides what to store about you and for how long. We hold that information on their behalf and act on their instructions. Direct requests about your records to the business you dealt with; if you contact us instead, we will pass the request along and tell you we have done so, rather than act on it ourselves.

There is no third role. We do not build, hold, enrich or sell a commercial dataset of businesses or professionals, we have no advertising business, and we do not buy personal information from anyone.

What we collect

Account information

Your name, email address, workspace and organization names, role, and a cryptographic hash of your password. We never store passwords in a readable form. If you use the phone features we also store the number your calls should be forwarded to, and the business address, phone numbers and tax registration number that are printed on the invoices you send.

We record which version of these documents you accepted, and when. No IP address or browser identifier is recorded with that acceptance.

Business records you enter

Contacts, companies, deals, jobs, appointments, estimates, invoices, payments, expenses, tasks and notes. This is your data. You control what goes in it, and it may include personal information about your own customers: names, phone numbers, service addresses, service history. Every contact also carries an engagement score that Gravun calculates automatically from that person's activity, refreshed hourly. It is a number you can sort by; it takes no action on its own.

Communications

If you connect a mailbox or add a phone number, we store the full content and metadata of the messages and calls that pass through Gravun so they appear on the relevant customer's timeline.

Billing information

Your subscription status, plan, seat count, and Stripe's references for your customer and subscription records. We never receive or store card numbers, expiry dates or security codes. Card entry happens entirely on Stripe's own pages. The only payment details in our database are the method (card, cash, cheque or bank transfer) and Stripe's reference for the transaction.

Security and audit logs

Records of significant actions taken in your workspace: who connected an integration, who changed billing, who created, changed or deleted a record. These exist so you can investigate what happened in your own account. The log records that a record was changed, not what its previous values were.

What we do not collect

There is no product analytics, no session recording, no advertising and no cross-site tracking anywhere in the Gravun application, and no third-party script, font or CDN tag on any page. We do not log IP addresses in the application, we do not track the location of your staff or your customers, and there is no mobile application collecting device identifiers.

Calls, recordings and transcripts

Calls made and received through Gravun are not recorded unless you switch recording on for your workspace. If you do switch it on, Gravun plays no recording announcement. Where recording is on, you are responsible for obtaining every consent the law requires from every party to the call, and for giving any announcement the law requires. Recording law differs by jurisdiction and some places require every party's consent. Note that when your staff dial out from Gravun, it is Gravun's software that places the call.

The recording audio is held by our telephony provider and linked from Gravun. To produce a transcript, Gravun sends the recorded audio to a speech-to-text provider. The transcript, an AI-generated summary and your own call notes are stored in your workspace. When one of your staff takes a call in Gravun, their browser connects directly to the telephony provider, so that provider receives their microphone audio and network address without it passing through Gravun.

Connected mailboxes: Google and Microsoft

Connecting Gmail or Outlook is entirely optional. If you do, you grant access through Google's or Microsoft's own consent screen, and you can revoke it at any time from Gravun's Connections page or from your Google or Microsoft account settings.

We request only what the feature needs: sending mail as you, and reading mail so replies thread onto the right customer. Access and refresh tokens are stored in a restricted database table that the application front end cannot read; only Gravun's server-side functions can use them. Disconnecting deletes the stored tokens.

13.2 Google Calendar.

If you connect a Google Calendar, Gravun requests the calendar.events scope so that appointments booked in Gravun appear on that calendar. We use it in one direction only: we create, update and delete the calendar entries that correspond to your own Gravun appointments, each tagged so we can recognise it later. We do not read your other calendar entries, we do not list your calendars, and we do not change your calendar's sharing, permissions or settings.

A calendar entry we create carries the appointment's title, its time, and the customer's name. It does not carry the customer's phone number, email address or postal address. This is deliberate: a calendar entry syncs to phones, watches and anything else signed into that account, and it appears on lock screens, so it is not a safe place for a customer's contact details.

Access and refresh tokens for the connection are stored in the restricted table described at §6.1. Disconnecting deletes them, and Gravun stops writing to the calendar immediately. Entries already on the calendar are not removed by disconnecting; you can delete them yourself, and each one identifies Gravun as its source.

Google API Services User Data Policy

Gravun's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, in respect of Gmail and Google Calendar data alike: we do not use it for advertising, we do not sell it, we do not transfer it to others except as needed to provide the features you asked for or where required by law, we do not use it to develop, improve or train generalised artificial intelligence or machine learning models, and we do not allow humans to read it except with your explicit consent, for security investigations, to comply with law, or where the data has been aggregated and anonymised.

Artificial intelligence

Gravun's AI features run when someone asks for them; nothing is analysed in the background. When you use one, the content that feature needs is sent to Anthropic in the United States to produce that one result. That can include contact details and notes, deal and job records including a customer's service address, the last ten message bodies on a conversation, and, for a call summary, up to 8,000 characters of the call transcript.

By default the content is sent unchanged. A workspace administrator can switch to a setting that replaces email addresses, phone numbers and account numbers with placeholders before anything leaves us, or can switch the assistant off entirely. The middle setting still sends names, addresses, notes and message text; it reduces what leaves, it does not make it anonymous.

We do not sell personal information, and we do not use your data or your customers' data to train AI models. AI output can be wrong. It is a draft for a person to check, not a decision, and it goes through exactly the same consent and suppression checks as a person clicking send.

Neither does the provider we send it to. Anthropic's published policy for its commercial products states that it does not, by default, use inputs or outputs from those products to train its models. The stated exception is a feedback mechanism, which Gravun does not enable, and we have not opted into any training programme. This applies to anything that originated in a connected Gmail mailbox or Google Calendar exactly as it applies to everything else.

Recordings of telephone calls placed through Gravun are turned into text by a separate provider, OpenAI, whose published policy is that API data is not used to train its models by default. That provider receives only the audio of those calls. Nothing from a connected Gmail mailbox or Google Calendar is ever sent to it. Gravun runs no self-hosted or offline model, and sends data to no AI aggregator, gateway or model hub.

Why we use it

  • To provide the features you signed up for.
  • To bill you, and to work out which features your plan includes.
  • To send transactional messages: password resets, team invitations, receipts, notices that these documents have changed. We do not send marketing email to your customers on your behalf unless you set that up yourself, and when you do, you are the sender.
  • To keep the service secure and investigate abuse or suspected fraud.
  • To meet legal and tax obligations.

Who else handles the data

Gravun is built on other companies' infrastructure. Each of these receives only what its function requires.

ProviderWhat it does, and what it receivesWhere
SupabaseDatabase, authentication, file storage and server-side functions. Receives everything the service holdsUnited States (AWS, us-east-1)
CloudflareHosting and content delivery for the application. Receives request metadata; stores no application dataGlobal edge network
StripeSubscription billing, and card processing for payments you collect from your own customers. Receives billing and payment metadata, and the email address of the customer you are invoicing. No card numbers reach GravunUnited States / global
TwilioPhone numbers, SMS and calls, if you enable them. Receives phone numbers, message bodies, call metadata, the audio of recorded calls, and your staff member's live call audio direct from their browserUnited States / global
AI providerAI drafting, summarising and assistance, where you use it. Receives the record and message content the feature needsUnited States
Google and MicrosoftSend and receive your business email through your own connected mailbox. Receive mail content, recipients, subjects and the access tokens you grantedGlobal
ResendGravun's own account emails (password resets and team invitations), and delivery of the marketing campaign email you send. Receives the recipient address and the full message bodyUnited States
PostmarkReceives email forwarded to a Gravun inbound address, if you enable it, including attachmentsUnited States

Gravun does not operate a mail server. When you connect a Gmail or Microsoft 365 mailbox, the messages you send through Gravun are delivered by that provider, from your address, under your own agreement with them, and a copy lands in your own Sent folder. Marketing campaign email is the one exception: it is delivered by Resend on Gravun's account.

Because these providers operate outside Canada, personal information held in Gravun is stored and processed abroad. The database, storage and server functions all run in the United States. That information may be accessible to foreign courts, law enforcement and national security authorities under the laws of those countries, including where those laws provide fewer protections than Canadian law. We may also disclose information where the law requires it; where the request concerns a business customer's records and the law permits, we will tell that customer first. If Gravun is ever sold or merged, data may transfer with the business, and we would tell you before that happened.

How your data is kept separate and secure

Every workspace's records are isolated at the database level, not merely hidden in the interface. Each request is filtered by database policy against the workspace you belong to, so one Gravun customer cannot read another's data even if the application had a bug. We test this separation adversarially on every change, on every table.

Traffic is encrypted in transit. Credentials for connected services live in a table no browser session can reach. All access is revoked for anonymous and signed-in database roles, and only server-side functions can read it. Those credentials are protected by that access control and by the encryption our hosting provider applies to its disks; they are not separately encrypted by us, and we would rather say so than imply otherwise. Every endpoint reachable without signing in is rate limited.

Two things we are asked about and do not have: multi-factor authentication is not available, and we hold no SOC 2, no ISO 27001 and no independent security audit. If you need either, tell us before you subscribe.

How long we keep it, and how to have it deleted

Your business records stay in your workspace for as long as your account exists. Cancelling a subscription switches off paid features but does not delete anything. Your data is waiting if you come back. Gravun deletes nothing automatically; that is deliberate.

To have your account deleted, write to privacy@gravun.com. We do this by hand within 30 days of your request. We keep records we are legally required to keep, which are invoices and tax records, typically six years under Canadian law. We also keep routine backups, which expire on their own schedule and are not individually edited.

Inside a workspace, you can handle one person's record yourself: export everything held about them, anonymise them, or erase them entirely. Erasure is refused where an invoice or a payment exists, because those must be retained; anonymising is offered instead. Anonymising does not reach website chat sessions, appointment contact details, stored provider webhook data, email delivery events, audit entries, AI assistant history, internal staff chat, or files in storage. Removing those is part of the manual process above.

Cookies, and what is measured

In the Gravun application we set exactly one cookie, a seven-day preference recording whether you left the sidebar open. We also use browser local storage to keep you signed in and remember interface preferences. There is no advertising cookie, no analytics cookie and no cross-site tracking.

In the messages a business sends through Gravun:

  • Links in email are rewritten so the sending business can see that a link was clicked. The redirect records the link and the time; it records no IP address and no browser identifier, and it stores nothing in the recipient's browser. Links in SMS are not rewritten.
  • Delivery outcomes reported by the mail provider are stored: delivered, bounced, complained. "Opened" is reported only where the sending business has separately enabled open tracking in its mail provider's own console. Gravun ships no tracking pixel and adds none.
  • When a customer opens an invoice or estimate page, we record the document, the moment, and one flag saying whether the request looked automated. No IP address, no browser or device identifier, no user-agent string, no cookie and no session identifier is stored. It cannot tell a business which person opened the page, only that it was opened.
  • Gravun's chat widget stores nothing in a visitor's browser, and records no IP address, user agent or referring page against a conversation.

Gravun does not read or honour the browser "Do Not Track" signal.

Your rights

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and comparable laws elsewhere, you can ask us to:

  • tell you what personal information we hold about you;
  • correct it if it is wrong;
  • delete it, subject to the retention rules above;
  • give you a copy in a machine-readable format, which we supply on request within 30 days;
  • withdraw a consent you previously gave, for example by disconnecting a mailbox, though some features stop working when you do.

Every marketing email sent through Gravun carries an unsubscribe link, added at the moment of delivery so a sender cannot remove it, and replying STOP to a marketing SMS opts you out. Both are enforced in the database on every send.

Write to privacy@gravun.com. We answer within 30 days. If you are not satisfied with our response you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial or national privacy regulator.

If you are in California, we act as a service provider for the records a business stores about its customers; we do not sell personal information and do not share it for cross-context behavioural advertising, and you have rights to know, delete, correct and to non-discrimination for exercising them. If the GDPR or UK GDPR applies to you, we are a controller for account information and a processor for a customer's own records, and a Data Processing Addendum is available on request.

Security incidents

If a breach creates a real risk of significant harm, we will notify affected users and the Privacy Commissioner as PIPEDA requires, and tell you what happened and what to do about it. Where a business customer's workspace is affected, we will notify that customer without undue delay so they can meet their own obligations.

Children

Gravun is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 18 as an account holder, and there is no age field anywhere in the product. If you believe a child's information has reached us, write to the address below and we will remove it.

Changes

We will post any revision here with a new effective date. If a change materially affects how we handle your information, we will email account owners before it takes effect. The effective date at the top of this page is the version recorded against every acceptance, so you can always identify the exact document you agreed to.

Contact

Gravun Inc. Ontario, Canada
Privacy enquiries: privacy@gravun.com
General enquiries: support@gravun.com