Who We Are
CSHUBB is a web-based Customer Success workspace for SaaS teams, built and operated by CSHUBB Innovations — a sole proprietorship registered under the Government of India, Udyam MSME Certified.
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use CSHUBB ("the Service"). By using the Service, you agree to the practices described here.
What Data We Collect
Account data — Your full name, work email address, and organisation name, collected when you register via an invite code.
Workspace data — Customer account records you import or create (ARR, health scores, NPS, renewal dates, etc.). This is your business data — we process it only to provide the Service.
Usage data — Page views, feature interactions, and AI tool runs, collected via PostHog with autocapture disabled, session recording disabled, and no personally identifiable information in event payloads.
Technical data — IP address, browser type, and device information, retained for security and audit purposes.
Support data — The content of help requests, feedback, or deletion requests you submit within the platform.
Google Calendar data — If you connect Google Calendar via the Meetings module: calendar event metadata (title, time, attendees, description) you explicitly authorise via Google OAuth, used solely to log meeting activity against customer accounts. We do not access personal calendar events unrelated to your workspace accounts. Calendar content is never stored on our servers — it is fetched at read time and held in browser memory only.
Gmail data — If you connect Gmail via the Emails module: email metadata and content (sender, recipient, subject, body) for emails you explicitly open within the CSHUBB Emails interface. We access only the minimum OAuth scope required (gmail.readonly). Gmail content is never stored on our servers — messages are fetched from Gmail at read time and held in browser memory for the duration of your session only.
How We Use Your Data
We do not sell, rent, share, or trade your personal data with third parties for marketing purposes under any circumstances.
Third-Party Processors
CSHUBB uses the following third-party services to operate the platform. Each is bound by its own data processing agreements:
| Vendor | Role | Data processed | Certification |
|---|---|---|---|
| Supabase (AWS) | Database hosting, Auth, Realtime | Account & workspace data | SOC 2 Type II |
| Cloudflare | CDN, TLS, DDoS mitigation | Network traffic only | ISO 27001, SOC 2 |
| Resend | Transactional email | Email address only | SOC 2 Type II |
| PostHog | Product analytics | Anonymised events, no PII | GDPR compliant |
| AI Providers (Groq/Anthropic/Google) | AI inference | Direct browser-to-API, we are not in the data path | Own policies apply |
| Google Calendar API | Calendar integration for Meetings module (optional) | Event metadata you authorise via OAuth — title, time, attendees, description. Never stored server-side. | Google Privacy Policy applies |
| Gmail API (readonly) | Email display in Emails module (optional) | Email metadata + content fetched at read time, held in browser memory only. Never stored server-side. | Google Privacy Policy applies |
Google Calendar Integration
CSHUBB's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Calendar data received via OAuth is used solely to provide the calendar integration features explicitly requested by the user within the Meetings module. This data is never sold, used for advertising, used to train AI models, or shared with AI providers or third parties except as strictly necessary to deliver the requested functionality. No Google user data is transferred to or processed by any AI tool within CSHUBB.
CSHUBB's Meetings module includes an optional Google Calendar integration. This section explains exactly what we access and how that data is handled.
What we access:
What we do NOT access:
Token storage: Your Google OAuth refresh token is stored encrypted in Supabase, scoped to your workspace, and protected by Row-Level Security. It is used solely to fetch calendar data on your behalf. We never share or expose OAuth tokens to third parties.
Disconnect behaviour: You may disconnect Google Calendar at any time from Workspace Settings → Integrations → Google Calendar → Disconnect. Upon disconnection, your OAuth token is immediately revoked and deleted from our systems. Previously imported meeting metadata already associated with accounts is retained until you delete it or request account erasure.
Google Gmail Integration (Emails Module)
CSHUBB's use and transfer of information received from Google APIs (including the Gmail API) adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Gmail data accessed via OAuth is used solely to display emails within the Emails module — an in-product feature explicitly requested by the user. This data is never sold, used for advertising, used to train AI models, or shared with AI providers or third parties. No Gmail content is stored on CSHUBB's servers; messages are fetched at read time and held in browser memory only for the duration of the session.
CSHUBB's Emails module includes an optional Gmail integration. This section explains exactly what we access and how that data is handled.
OAuth scopes requested:
https://www.googleapis.com/auth/gmail.readonly — to read emails in your inbox for display within CSHUBBWhat we do NOT access:
Server storage: CSHUBB does not store email content on its servers. Messages are fetched from Gmail at read time, rendered in your browser, and discarded when you close the session. Only the OAuth token (used to authenticate future requests on your behalf) is stored — encrypted at rest in Supabase, scoped per user, and protected by Row-Level Security.
Disconnect behaviour: You may disconnect Gmail at any time from Workspace Settings → Integrations → Gmail → Disconnect. Upon disconnection, your OAuth token is immediately revoked via the Google API and deleted from our systems. No email content is retained because none was ever stored.
Data Storage & Retention
Backup Retention: In addition to our primary database, CSHUBB maintains an independent, encrypted backup of platform data for disaster-recovery purposes, stored separately from our primary hosting provider. This backup is retained for 90 days, after which it is automatically and permanently deleted.
If you submit a data erasure request, your data is removed from our live systems within 30 days, consistent with this policy. Because backups exist independently for disaster-recovery purposes, residual data may persist in an encrypted backup for up to 90 days following deletion from live systems, after which it is permanently purged along with the rest of that backup snapshot.
Your Rights
Depending on your location, you may have the following rights under applicable law (including GDPR for EU users and IT Act / DPDP Act 2023 for Indian users):
Right to erasure — how to request it: Users and org admins may request complete data erasure by contacting support@cshubb.com. Org admins can also trigger erasure directly from the Admin Panel → Data & Privacy tab. Erasure requests are processed within 5 business days and permanently remove all personal and workspace data associated with the account.
To exercise any of these rights, email support@cshubb.com. We will respond within 30 days.
Security Measures
We implement multiple layers of technical and organisational security controls:
To report a security concern or vulnerability, email security@cshubb.com. We aim to acknowledge reports within 24 hours.
Children's Privacy
CSHUBB is a professional business tool intended for adults (18+) operating in a business capacity. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided data to us, please contact support@cshubb.com and we will remove it promptly.
International Data Transfers
CSHUBB Innovations is based in India. Data is processed on Supabase's AWS infrastructure which may be located in the United States or other regions. All cross-border data transfers are conducted in compliance with applicable laws and under standard data processing agreements with our service providers.
For EU/EEA users, transfers are covered under Standard Contractual Clauses (SCCs) maintained by Supabase and Cloudflare.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify active workspace administrators via email at least 30 days before the changes take effect.
Continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy. The date of the last update is always shown at the top of this page.
Contact Us
For any privacy-related questions, data requests, or concerns:
This policy was last updated: June 2026