Privacy Policy

Effective 31 August 2026. Last updated 8 September 2026.

This Privacy Policy explains how RevENGINE Samora Private Limited, trading as Samora Global ("Samora", "we", "us"), collects, uses, stores, shares and protects information in connection with SamoraTrack, our B2B revenue intelligence platform available at samoratrack.vercel.app and related sites and services (the "Service").

SamoraTrack is a business tool. It is bought by an organisation and used by that organisation's sales team. In most cases your employer is the controller of the data you put into the Service, and we act as a processor on their instructions.

  1. Information we collect
  2. Google user data and Limited Use
  3. Microsoft and other connected services
  4. How we use information
  5. Artificial intelligence processing
  6. How we share information
  7. Where data is stored and for how long
  8. Security
  9. Your choices, access and deletion
  10. Legal bases and international transfers
  11. Children
  12. Changes to this policy
  13. Contact us

1. Information we collect

Account and organisation data

Data you enter

Data from connected mailboxes and calendars

We do not build a copy of your mailbox. Message bodies are processed in memory during a scan and are not written to our database as a mail archive. What we store is the derived result: activity dates, signal scores, engagement counts, stakeholder records, evidence lines and the small quoted fragments shown to you as receipts for a score or an alert.

Meeting transcripts

If your organisation connects a meeting notetaker (for example Fireflies or Read.ai) or forwards notetaker emails to the Service, we store the resulting transcript or summary and link it to the relevant account.

Usage and technical data

2. Google user data and Limited Use

SamoraTrack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request only the scopes we need, and only after you explicitly grant them:

ScopeWhat it allowsWhy SamoraTrack needs it
userinfo.emailRead your email addressIdentify your account and match you to your organisation
gmail.readonlyRead messages and settingsDetect real activity on a deal: who replied, when, how often, and produce the evidence shown behind every score
gmail.modifyRead and modify messages and labels, without deletingApply and read SamoraTrack labels so tracked threads and campaign replies are recognised on later scans
gmail.sendSend mail as youSend the outreach and follow up emails that you compose, review and schedule inside the Service
calendar.readonlyRead your calendarsMeeting preparation briefs, meeting coverage counts and next step verification

Limited Use commitments. We do not, and will not:

Human access. Samora personnel do not read your Google user data except in these narrow cases: you have given explicit consent for a specific issue, for example a support request; it is necessary for security purposes such as investigating abuse or a suspected breach; it is required to comply with applicable law; or the data has been aggregated and anonymised so that it no longer identifies a person and is used only for internal operations such as capacity planning.

Access is controlled by role, logged, and limited to the smallest set of staff needed.

3. Microsoft and other connected services

If you connect a Microsoft work account, we process mail and calendar data through the Microsoft Graph API for the same purposes and under the same restrictions described above.

Your organisation may also connect optional third party services with its own API keys, including SmartReach for sequencing, Lusha, Apollo and Hunter for contact enrichment, and a meeting notetaker. When your organisation enables one of these, data is exchanged with that provider under that provider's terms and privacy policy. Enrichment is run only on contacts already present in your organisation's real activity, and we do not perform cold prospecting or scraping.

4. How we use information

We do not sell personal information. We do not use your data for advertising.

5. Artificial intelligence processing

SamoraTrack is built local intelligence first. Scores, signals, alerts and evidence are computed by deterministic rules inside our own systems.

Research features

Where an organisation supplies an AI provider key, a narrow set of features calls that provider for public research only. Those calls send a company name, and where relevant a contact's name, job title and employer, together with the research instruction. Mailbox content, message bodies, subject lines, calendar entries and deal financials are not included in those prompts.

Responses are cached so that the feature keeps working when the provider is unavailable. Cached AI content is always labelled in the interface.

Assistant connectors

Separately, and only if your organisation chooses to enable it, SamoraTrack can be connected to an external AI assistant such as Claude or ChatGPT, using an access key your organisation creates. This lets a user ask that assistant to read from and write to SamoraTrack in conversation.

When you use such an assistant, the records SamoraTrack returns to it are processed by that assistant's provider under your organisation's own agreement with that provider, not under ours. Those records can include contact names, work email addresses, job titles and employers; campaign content, including the text of outreach emails that have been drafted, queued or sent; pipeline, coverage and performance figures; and account activity derived from your connected mailbox, such as who was contacted, when, and whether they replied.

This connector is off unless an administrator turns it on, and the key can be revoked at any time from Settings, which stops all further access immediately. If your organisation does not want mailbox derived information reaching an external assistant provider, do not enable it.

6. How we share information

We share information only as follows:

7. Where data is stored and for how long

Data is stored in managed cloud infrastructure operated by our providers, in the regions selected for your organisation's instance. We retain data for as long as your organisation's account is active.

8. Security

No system is perfectly secure. If a breach affects your data we will notify your organisation and, where required, the relevant supervisory authority, without undue delay.

9. Your choices, access and deletion

10. Legal bases and international transfers

Where the GDPR or a similar law applies, we rely on: performance of a contract, for delivering the Service; legitimate interests, for securing and improving the Service; consent, for optional integrations and marketing; and legal obligation, where the law requires it.

Data may be processed in countries other than your own, including the United States and the European Union. Where required, transfers are covered by Standard Contractual Clauses or another approved mechanism.

11. Children

The Service is not directed at anyone under 18 and we do not knowingly collect data from children.

12. Changes to this policy

We may update this policy. Material changes will be notified by email to organisation administrators or by an in product notice at least 14 days before they take effect. The effective date at the top of this page always reflects the current version.

13. Contact us

Samora Global
RevENGINE Samora Private Limited
CIN: U62011CH2026PTC047142
126, Sector 10A, Chandigarh 160011, India
Email: vasu@samoraglobal.com