Privacy Policy
Last updated September 18, 2026
Overview
This Privacy Policy explains what information Outmove LLC (“Outmove,” “we,” “us”) collects, how we use and protect it, and your choices. It covers our website and the Outmove application.
Information we collect
- Account information, your name, email, workspace name, and password (stored hashed).
- Connected credentials, OAuth tokens or API keys for providers you connect. These are encrypted with per-secret, per-tenant envelope encryption, are write-only (never shown back to you or returned by any API), and are decrypted only server-side at the moment of a call.
- Client data you process, the information you and your clients enter into forms, agreements, and payments to run an onboard (names, emails, signatures, uploaded files).
- Usage data, logs, device/browser information, and product analytics used to operate and improve the Service. Credential material is redacted from logs.
How we use information
We use information to provide and secure the Service, process the onboards you configure, communicate with you, enforce our terms and plan limits, and improve the product. We do not sell your personal information.
How we protect it
Tenant credentials are encrypted before they touch our database; the master key lives only in the server environment. Every tenant’s data is isolated with row-level security, inbound webhooks are signature-verified, and sensitive actions are recorded in an immutable audit log. Two-factor authentication is available to protect access to your connected credentials.
Service providers
We use subprocessors to run the Service, currently for cloud hosting and application delivery, database and file storage, payment processing, transactional email, and error and performance monitoring. Each is bound by written terms that limit them to processing data in order to provide their service to us, and that require appropriate security. We remain responsible to you for their handling of your data. We will give notice of a material change to the subprocessors we use, and will name them on request.
Providers that you choose to connect, such as your CRM, chat, or payment tools, are not our subprocessors. Data you send to them is governed by your relationship with them.
Data retention
We keep your data while your account is active and as needed to provide the Service or comply with law. You can request deletion of your account; workspaces where you are the only member are deleted with their data. Some records may be retained where required.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information. You can manage much of this in your account settings, or contact us to make a request.
Our role, and yours
For your own account information we act as the controller, and this policy describes what we do with it. For the client data you process through the Service, the details of your clients and prospects that you and they enter into forms, agreements, and payments, you are the controller and we act as your processor: we handle that data only to provide the Service on your instructions and as permitted by law. You are responsible for having a lawful basis to collect it, for telling your clients what you do with it, and for responding to their requests. Where we receive a request directly from one of your clients, we will normally refer them to you.
Referral and partner information
If you join a referral or partner program, we process your name, contact details, the content of your application, your referral link activity, and the commission and payout records connected to it. Identity, bank, and tax information for payouts is collected and held by our payment processor, not by us; we receive only a confirmation of status and the record of what was paid. We keep commission and payout records for as long as required for accounting, tax, and audit purposes, which may be longer than the rest of your data.
International transfers
We and our subprocessors may process information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for those transfers, such as the European Commission’s Standard Contractual Clauses, and we take account of the protections applicable in the destination country.
Security incidents
We maintain procedures to detect and respond to security incidents. If a breach affects your personal information or the client data you process with us, we will notify you without undue delay, tell you what we know, and give you the information you reasonably need to meet your own notification obligations.
Cookies and similar technologies
We use a small number of cookies, and we list all of them:
- Sign-in and security. Strictly necessary cookies that keep you signed in, protect your session, and support two-factor authentication.
- Preferences. Remember choices such as light or dark theme.
- Referral attribution.If you arrive through a referral or partner link, we set a cookie recording that link’s code so the referrer can be credited if you later sign up. It lasts 90 days, contains only the code and no personal information, and is used only to attribute a signup and to count link clicks. You can refuse or delete it without affecting your ability to use the Service.
We do not use advertising cookies, and we do not sell or share personal information for cross-context behavioral advertising.
Children
The Service is not directed to children under 18, and we do not knowingly collect their data.
Changes
We may update this policy; material changes will be posted here with an updated date.
Contact
Questions or requests? Contact us at support@outmove.app.