— Privacy Policy

How we handle your data.

Effective: 2026-05-20 · Last updated: 2026-07-17

Note · This policy reflects Mallin's current practice during the design-partner phase. Mallin is operated by roomrefund LLC, a Colorado limited liability company, doing business as Mallin. Your data handling is described below. Questions: privacy@mallin.io.

1. Who we are

Mallin is the operating layer of the revenue organization — an AI agent that helps sales reps prepare for, run, and follow up on customer calls. The product is operated by roomrefund LLC (doing business as "Mallin"; the "Company", "we", "us"), a Colorado limited liability company. Our contact email for all privacy matters is privacy@mallin.io.

2. What data we collect

Account data

When you create a Mallin account, we collect: your name, email address, company name, role/title, and authentication credentials (managed by our auth provider — see Subprocessors). If you enable multi-factor authentication, we additionally store the TOTP secret or recovery codes associated with your account.

Deal data

Mallin collects data about the deals you work — account information, opportunity records, stakeholder names and titles, call transcripts (when you load them), notes, stakeholder interactions, and any custom fields you populate. This data either originates inside Mallin (when you write a note or load a transcript) or is synced from your CRM when you connect one.

CRM-connected data

If you connect Mallin to a CRM (HubSpot, Salesforce, Pipedrive), we read deal, contact, account, and activity data from your CRM to populate Mallin's working surfaces. We also write back to your CRM: notes you create in Mallin, action items you save, drafted emails. We never modify CRM data that wasn't explicitly produced or approved in Mallin.

Usage data

We collect telemetry about how you use Mallin: which pages you visit, which features you engage with, errors you encounter, the timing of those interactions. This data is used to operate, debug, and improve the product. Telemetry is associated with your account but is not sold to or shared with advertising networks.

Support chat & cookies

Our in-app support chat is provided by Crisp and appears only on signed-in application pages. It is interaction-gated: Crisp does not load until you click Support to open a conversation. When you do, Crisp uses necessary session technology to provide the chat — including a session cookie (Crisp documents a default expiration of about six months) — and, as your browser connects to Crisp, it may process technical connection data such as your IP address, user agent, connection time, and the page you contacted us from, in addition to the messages you send.

Mallin does not deliberately send Crisp your account email, name, Clerk user ID, tenant ID, or any deal data. Crisp stores core messaging data in the European Union; some of its relay infrastructure outside the EU may process connection logs. See /subprocessors and Crisp's own privacy policy for details.

Visitor identification on public pages

On our public marketing pages — such as our homepage, pricing, and product-overview pages — we currently enable a third-party service, RB2B, for visitors whose connection geolocates to the United States, to help us understand which businesses are showing interest in Mallin. RB2B does not run on signed-in Mallin application pages, and we do not enable it for visitors outside the United States.

When these public pages load for an eligible U.S. visitor, RB2B may process information such as IP address, browser or device information, page and referring-page URLs, timestamps, cookies or similar identifiers, and related technical information. RB2B may use this information together with its own and third-party data sources to identify the visiting company and, where available, an associated professional profile.

We use this information to understand prospective-customer interest and for business-to-business sales and marketing outreach. We do not connect RB2B visitor-identification data to your authenticated Mallin account, deal data, call information, or other customer workspace content. For more information, see our /subprocessors page and RB2B's Privacy Policy.

3. How we use your data

  • Deliver the service: generate pre-call briefs, surface stakeholder intelligence, draft follow-ups, and write back to your CRM.
  • Learn within your tenant: notes you save become context that shapes future briefs for your account only. We do not train shared models on your data.
  • Customer support: respond to your questions, debug issues, send service-related communications.
  • Security & compliance: detect abuse, prevent fraud, meet legal obligations.
  • Improve the product: aggregate, anonymized usage patterns inform engineering priorities.

We do not: sell your data, share it with advertising networks, or use your deal content to train shared AI models. See our AI Governance Policy for the specific rules around the AI layer.

4. Who we share data with

We share data only with the subprocessors required to operate the service. Each one has a specific role and a data-processing relationship with us. The complete list, with location and purpose, is at /subprocessors.

We do not share your data with third parties for any other purpose. We will not share your data with law enforcement without legal process; if we are compelled by valid legal process, we will notify you unless prohibited from doing so.

5. How long we keep your data

  • Account data: retained while your account is active. Deleted within 30 days of account closure (or sooner on written request).
  • Deal data: retained until you delete the deal or close your account. Soft-deleted records purged within 30 days.
  • Backups: our database provider (Supabase) retains point-in-time recovery snapshots for up to 7 days. Deleted data is removed from active systems immediately and from backups within 7 days.
  • Logs & telemetry: retained for up to 90 days for operational debugging, then deleted.
  • Audit logs: retained for the life of the account for compliance and security review.

6. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access: request a copy of the data we hold about you.
  • Rectification: correct inaccurate data.
  • Erasure: have your data deleted (subject to legal retention requirements).
  • Portability: receive your data in a structured, machine-readable format.
  • Restriction: ask us to limit how we process your data.
  • Objection: object to specific processing activities.
  • Withdrawal of consent: where processing is based on your consent, withdraw it at any time.

To exercise any of these rights, email privacy@mallin.io. We respond within 30 days. We may need to verify your identity before fulfilling certain requests.

7. Where your data is stored

Your data is stored on infrastructure operated by our subprocessors. Primary storage (Supabase, Vercel) is in United States data centers (AWS US-East). Some metadata (authentication tokens, session state) may transit through globally-distributed edge networks for performance.

For customers in the European Economic Area, the United Kingdom, or Switzerland, transfers of personal data outside those regions are protected by the standard contractual clauses where applicable. Contact us if you need a Data Processing Addendum (DPA).

8. Security

See our Security & Trust page for the full picture. In short: data is encrypted in transit (TLS 1.3) and at rest (AES-256 via our infrastructure providers); multi-tenant isolation is enforced at the database row level; access controls are role-based with audit logging; multi-factor authentication is available on all accounts.

9. Children

Mallin is a business tool. It is not directed to, and not intended for use by, children under the age of 16. We do not knowingly collect data from children under 16. If you believe we have inadvertently collected such data, contact us and we will delete it.

10. Changes to this policy

We'll update this policy as Mallin evolves. The "Last updated" date at the top reflects the most recent change. Material changes — anything that meaningfully expands the data we collect or how we use it — we notify you of by email before they take effect.

11. How we handle Google user data

When you connect your Gmail account, Mallin requests a single Google permission — gmail.compose — which lets it create draft emails in your Gmail Drafts folder. Our access to and use of Google user data is limited to what is described here.

  • What we access: the ability to create drafts in your Gmail account, and your Google email address (to show which account is connected). We do not read your inbox, sent mail, or any existing messages.
  • How we use it: solely to place Mallin-drafted follow-up emails into your Drafts folder for you to review and send yourself. Mallin only ever creates drafts and never sends email — every message is sent by you, from your own inbox.
  • How we store it: your Google OAuth tokens are stored securely (encrypted at rest via our infrastructure providers) and used only to create the drafts described above. They are never sold, never shared with third parties, and never used for advertising.
  • How to revoke: disconnect Gmail anytime from Settings → Integrations, which deletes the OAuth tokens we store. You can also revoke Mallin's access directly at myaccount.google.com/permissions.

Mallin's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, sell, or use Google user data for any purpose other than providing the drafting feature you requested, and we do not use it to train generalized artificial-intelligence or machine-learning models.

12. Contact

Privacy questions, requests, complaints: privacy@mallin.io.