Introduction
This policy explains what we collect when you visit relayengage.com, use the marketplace, subscribe to a plan, connect accounts and run automations. RelayEngage is operated as a marketplace of white-labeled automations for service businesses.
Data we collect
- Account data: name, email, phone, business type, service interest captured via our lead form which saves to our CRM via contacts() and emits events(lead_captured) for welcome sequences.
- Tenant data: workspaces, workflows, nodes, runs, logs you create inside the app.
- Usage data: pages visited, feature usage, workflow execution counts for billing and product improvement.
- Payment data: handled by Stripe. We store only subscription status, plan tier and checkout session IDs. Full card data never touches our servers.
Vault isolation – how we handle credentials
RelayEngage promise is isolated, works as your brand only. When you connect third parties:
- Twilio: we store last 4 digits and a one-way hash in ConnectedAccount vault. Your number remains yours. SMS sending executes from your number, not a shared pool. The full SID/token is encrypted at rest and never shown cross-tenant.
- Google Calendar: OAuth tokens are encrypted, mapped 1:1 to your tenant. Availability checks and create-event calls use your calendar only. We request calendar.events and calendar.readonly scopes, no Gmail access.
- Meta Pages: page tokens are tenant-scoped, last4 + hash pattern similar to Twilio.
No cross-tenant credential access is possible via RLS. Platform functions authorize by tenant_id derived from authenticated user.
Stripe billing
Subscriptions are $99 Starter, $249 Growth, $499 Scale and Implementation $499 one-time. Billing is via Stripe Checkout and Stripe Customer Portal. We retain stripe_customer_id, subscription status and plan tier only.
Cookies and analytics
We use essential cookies for auth and session. We may use anonymized analytics to understand marketplace conversion. No advertising cookies are set without consent.
Data retention
Tenant data is retained while your subscription is active. Upon cancellation, data is soft-deleted after 30 days then purged after 90 days unless legal hold applies. CRM leads captured via contacts() persist for marketing compliance until you request deletion.
Your rights – GDPR & CCPA
- Access, correction, deletion requests: email support@relayengage.com
- Export of your tenant data within 30 days of verified request
- Opt-out of marketing emails via unsubscribe link, opt-out of SMS via STOP keyword as enforced by Twilio
Security
Encryption at rest, TLS in transit, row-level security per tenant, vault hashing for secrets. We run periodic reseed verification and purge checks. No hello@ sending pattern is enforced at code level.
Contact
Questions? Email support@relayengage.com or use workspace support. Physical mail: RelayEngage HQ – details in terms.
