Privacy Policy

Last updated: 2026-05-06

1. Who we are

JIITAK Co., Ltd. (“JIITAK”, “SalesOne”, “we”, “our”) operates the SalesOne platform at salesone.now. We are the data controller for personal information about platform users (the people in your organization who sign in to SalesOne) and the data processor for personal information about your prospects (the contacts you upload, enrich, and message through the platform). Privacy queries: privacy@salesone.now. Security incidents: security@salesone.now.

2. Personal information we collect

Account data: name, email, organization, role, IP address, device and browser information, and authentication events. Customer prospect data: contact records you upload or generate via discovery (name, title, company, email, phone, LinkedIn URL, public firmographic and intent signals). Engagement data: messages drafted, sent, delivered, opened, replied to, and any responses received. Telemetry: rate-limit events, error reports (via Sentry), webhook metadata, audit logs of privileged actions. Payment data: handled directly by Stripe — we receive only customer and subscription identifiers.

3. How we use it

We use personal information to (a) provide and operate the Service; (b) authenticate users and enforce role-based access; (c) generate AI-assisted outreach, replies, and personas using vetted model providers; (d) send transactional and account email; (e) measure aggregate platform health, prevent abuse, and respond to security incidents; and (f) comply with applicable law. We do not sell personal information.

4. Subprocessors

We share personal information with the subprocessors listed at salesone.now/trust strictly to provide the Service. Each subprocessor is contractually bound to security and confidentiality obligations consistent with this policy. Where feasible, we strip personally identifiable fields from prompts sent to large language model providers (Anthropic, OpenAI, ElevenLabs) before submission, retaining only the structured signals needed for the model task.

5. International transfers

Our infrastructure is hosted across multiple regions (primarily the United States via Vercel and Neon, with EU and APAC regions for some subprocessors). Where personal data crosses borders, we rely on Standard Contractual Clauses or equivalent safeguards.

6. Security

Personal data is encrypted in transit (TLS 1.2+ with HSTS preload) and at rest. Access is enforced at multiple layers: PostgreSQL row-level security policies on every tenant-scoped table, role-based access control on every privileged route, constant-time-verified HMAC role cookies, signed webhook payloads, and per-request rate limiting. Privileged actions write to an append-only audit log. The platform is built with SOC2-Type-II controls in mind; the Type-II observation period is in progress.

7. Retention

Active accounts: data is retained for the life of your subscription. Closed accounts: Customer Data is retained thirty (30) days for export, after which it is purged from primary stores. Backups are retained for ninety (90) days then expire. Audit log entries are retained for one (1) year. Specific data-retention contracts are available in your subscription agreement.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port your personal information, and to object to certain processing. EU and UK residents have rights under the GDPR; California residents under the CCPA; Japanese residents under the APPI. To exercise any right, email privacy@salesone.now. We will respond within thirty (30) days. You may also lodge a complaint with your local supervisory authority.

9. Outbound email — opt-out

Outbound messaging sent via SalesOne includes List-Unsubscribe headers (mailto and one-click HTTP). Recipients who opt out are added to a tenant-scoped suppression list and excluded from all subsequent campaigns. SalesOne customers are responsible for ensuring their outreach complies with CAN-SPAM, GDPR, the Japanese APPI, and any equivalent law that applies to recipients.

10. Cookies & analytics

We use first-party authentication cookies (set by Clerk and our own HMAC role cookie) essential to the Service. We may use Vercel Analytics and Sentry for performance and error monitoring; both rely on minimal first-party data and do not place cross-site tracking cookies.

11. Children

SalesOne is a B2B service and is not directed to children under 16. We do not knowingly collect personal information from children.

12. Changes

We may update this Privacy Policy. Material changes will be communicated by email or in-app notice at least thirty (30) days before they take effect, except where the law requires shorter notice.

Privacy questions: privacy@salesone.now. Subprocessor list: salesone.now/trust.