Trust & Security
We're new. That's a fair reason to ask questions.
This page sets out how PipelineIQ handles your business data today. Where we can’t give a specific answer here, we say so and tell you how to ask us.
Where your data is stored
PipelineIQ runs on Cloudflare: application hosting, server execution, the database, file storage and the Email Routing that receives customer emails forwarded to your Inbox. That covers account identifiers, workspace content, files, forwarded emails and technical records.
When you ask Ryan a question, request AI analysis or AI-assisted CSV repair, or the Inbox sorts an email and drafts a reply, the relevant content is sent to OpenAI to produce the result, and PipelineIQ requests that API responses are not stored. Payments are handled by Stripe, outgoing email (including Inbox replies) is sent through Resend and company mailboxes such as hello@pipelineiq.eu use Google Workspace. The full list is on the Subprocessors page. We give at least 30 days’ notice of a material new subprocessor where reasonably possible.
Some providers may process personal data outside the European Economic Area. Where they do, PipelineIQ relies on a transfer mechanism such as an adequacy decision, the EU–U.S. Data Privacy Framework where valid for that provider, or Standard Contractual Clauses.
We don’t list a specific data region on this page. Ask us for the current data region at hello@pipelineiq.eu.
SourcesSubprocessorsPrivacy Policy
Supabase for sign-in
Authentication and account sessions are handled by Supabase. For this, Supabase processes your name, company, email, authentication records and session data.
Password credentials are handled by the authentication provider. When you sign in, PipelineIQ verifies the Supabase sign-in token on the server against Supabase’s published signing keys.
Supabase is used for sign-in only. Workspace content is hosted on the Cloudflare infrastructure described above.
Ask us which Supabase region is used at hello@pipelineiq.eu.
SourcesSubprocessorsPrivacy Policy
Stripe handles payments
Payments are processed by Stripe. Card details go directly to Stripe and never touch PipelineIQ servers. The connection is encrypted with HTTPS/TLS, and new or updated billing records we store are encrypted with AES-256-GCM.
Payment processing, payouts, connected-account services and PipelineIQ’s own subscription billing are provided by Stripe, Inc. and its affiliates (such as Stripe Payments Europe, Ltd.).
PipelineIQ is not a bank, payment institution or e-money issuer, and it does not hold, receive or transmit your funds. Balances, payouts and transaction details shown in PipelineIQ come from Stripe.
Export and data ownership
You retain ownership of the data you submit. PipelineIQ may host, copy, transmit, analyze and display it only as needed to provide, secure and support the service.
For personal data in your workspace, your business is the controller and PipelineIQ acts as the processor under our Data Protection terms. PipelineIQ does not sell personal data.
In Finance you can export invoices, expenses and transactions as CSV. You can also ask us for an export of your data, and we recommend exporting important records regularly.
SourcesTerms of Service §4Data Protection §1Privacy Policy §6
Workspace access controls
Workspace owners control invitations and roles. Teammates can be invited as a Manager or a Salesperson, and a Salesperson can only change the deals assigned to them. In Procurement, sensitive actions such as changing supplier bank details, voiding payments, terminating contracts and going over a framework agreement’s ceiling are limited to owners and admins.
Our safeguards include authenticated account access, workspace and role checks, tenant separation, encrypted transport, encrypted saved integration credentials, server-side secret handling, input limits and validation, audit-style activity records and monitoring of operational errors. Saved integration tokens are not returned to the browser.
People authorised to process customer data are bound by confidentiality. Ryan, the assistant on our website, cannot access your CRM records.
SourcesData Protection §4Terms of Service §2Privacy Policy §2, §4
Backups and recovery
Our Data Protection terms list backups or recovery mechanisms, where available, among PipelineIQ’s safeguards. Deleted data can take additional time to clear from protected backups.
We use reasonable care to maintain the service, but we don’t promise uninterrupted availability.
We don’t publish backup frequency or retention periods on this page. Ask us for the current backup and recovery details at hello@pipelineiq.eu.
If you leave PipelineIQ
You can cancel your plan from the billing portal at any time, stop using the service and request account deletion.
On termination or written request, PipelineIQ deletes or returns customer personal data, at your choice where technically available, unless the law requires us to keep it. Export the records you need before closing your account.
Account and workspace data are kept while the account is active and for a limited period afterwards when needed for recovery, security, disputes or legal duties. Connected credentials are removed when you disconnect an integration or delete the account.
If PipelineIQ ever discontinues the service, our terms provide for reasonable notice and an opportunity to export your data where practical. We don’t have a published escrow arrangement.
SourcesData Protection §9Privacy Policy §6Terms of Service §11Pricing FAQ
Who is behind PipelineIQ
PipelineIQ is built by Gabriel Gerrits, sole founder, based in Odense, Denmark. PipelineIQ is operated by Gabriel Gerrits, who is the data controller for account administration, website communications and service operations.
Our terms are governed by Danish law. You can complain to the Danish Data Protection Agency (Datatilsynet) about how your personal data is handled.
You can reach us by email at hello@pipelineiq.eu or by phone on +45 25 56 07 08.
Have a security question?
Email hello@pipelineiq.eu with any security or data question, including the current data region and backup details, or to report a vulnerability you have found in PipelineIQ. Gabriel Gerrits, who runs PipelineIQ, reads every message personally.
If you suspect a security incident affecting your workspace, report it straight away.
If PipelineIQ becomes aware of a personal-data breach affecting customer data, we notify the customer without undue delay.