Privacy Policy
Last Updated: August 10, 2026
1. Introduction & Overview
Acqly (operated by Knovik LLC, "Acqly", "we", "us", or "our") is committed to respecting your privacy and protecting the data of our users and their business contacts.
This Privacy Policy explains how information is collected, used, disclosed, and safeguarded when you visit our website at acqly.app, use the Acqly Web Application at acqly.app/app, or interact with our automated lead generation and CRM routing platform.
2. Information We Collect
We collect information in three primary categories:
A. Information You Provide Directly
- Account Credentials: Email address, password, organization name, and workspace configuration settings.
- Authentication Data: OAuth profile data (e.g. Google Sign-In details such as your name, email, and profile avatar).
- CRM Integration Credentials: API keys and base URLs for third-party integrations (e.g., Twenty CRM), which are encrypted at rest using AES-256-GCM.
- Support & Communications: Correspondence sent to hello@acqly.app or waitlist signup submissions.
B. Information Collected Automatically
- Usage Metrics & Telemetry: Log files, browser type, operating system, IP address, page views, and feature interactions.
- Cookies & Local Storage: Session tokens (via Supabase Auth) and user preferences necessary for seamless application authentication.
C. Business Prospect & Signal Intelligence Data
Acqly aggregates publicly available business data (e.g., Google Maps listings, public company websites, hiring activity signals, and technical audit findings) to calculate prospect opportunity scores. We do not aggregate or sell sensitive consumer personal data.
3. How We Use Your Information
We utilize collected data for the following legitimate business purposes:
- To provision, maintain, and secure your Acqly workspace and organization accounts.
- To execute automated segment prospecting, calculate lead scores, and push verified opportunities into your connected CRM.
- To process subscription payments and manage billing invoices through Stripe.
- To provide customer support and notify you of critical system updates or security notices.
- To enforce suppression rules and respect user opt-out choices across all outreach pipelines.
4. Data Sharing & Third-Party Service Providers
We do not sell, rent, or trade your personal information to third parties. We share data only with trusted service providers essential to operating the Platform:
- Authentication & Database: Supabase (PostgreSQL, Auth, JWT management).
- Payment Processing: Stripe (PCI-DSS compliant subscription billing).
- Hosting & Infrastructure: Vercel (Serverless web hosting & edge functions).
- Your Connected CRM: Data is pushed only to the external CRM endpoints (such as Twenty CRM) explicitly configured by your organization administrators.
5. Data Security & Encryption
We implement industry-standard technical and organizational security measures to protect data against unauthorized access, alteration, disclosure, or destruction:
- All web traffic is encrypted in transit using TLS 1.3/HTTPS.
- Sensitive API credentials and tokens are encrypted at rest using AES-GCM-256 encryption.
- Row-Level Security (RLS) policies isolate tenant organization data in our PostgreSQL database.
6. Your Rights & Data Choices
Depending on your location (e.g. EU/EEA under GDPR or California under CCPA/CPRA), you have the following rights regarding your data:
- Access & Export: You can export a full JSON dump of your organization data anytime via Workspace Settings → Export Data.
- Rectification: You can update account or organization details directly in your dashboard.
- Deletion / Right to be Forgotten: You can request permanent workspace deletion via Settings → Danger Zone. All organization records, credentials, and data are permanently purged within 30 days.
- Suppression: You can add specific email addresses, domains, or companies to your workspace Suppression List to ensure they are never targeted or pushed to CRM.
7. Privacy Inquiries & Contact
If you have any questions, data access requests, or privacy concerns, please contact our Data Protection Officer: